Vigilant Cybersecurity

CMMC Weekly Briefing · Aug 3–7, 2026

A quiet week, and a phishing breach at a defense supplier

Top story

It was a quiet week for CMMC policy. We found no new DoW CIO memo, no DFARS class deviation, no Cyber AB announcement, no DOJ settlement and no Federal Register notice between August 3 and 7. The most useful item was an incident report. On August 6, IEH Corporation, a defense supplier, filed an SEC Form 8-K describing an August 4 discovery that "a malicious actor impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link." The filing says the exposed mailbox contents included "customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information."

Rules and policy

  • Nothing new this week. Revision 2 of Class Deviation 2026-O0025 (July 16) is still the operative instruction to contracting officers. The RFI deadline is still 12:00 p.m. ET on August 14.

Industry and enforcement

  • The IEH filing is a lesson in email security. The filing doesn't mention CMMC. But phishing-resistant MFA, awareness training and email scoping are the NIST SP 800-171 controls aimed at this kind of attack. Why it matters: a contractor whose covered defense information is compromised still has to report under DFARS 252.204-7012, whatever happens to CMMC Phase 2.
  • DIB Accelerator 2026 announced. On August 6 the Department announced the DIB Accelerator for August 25–27 at the Pennsylvania Convention Center in Philadelphia. Why it matters: DoW CIO Kirsten Davies later used the event to talk about CMMC reform (see the August 24–28 briefing).

Still on the radar

  • The Reform Task Force review, running since July 13.
  • The Senate NDAA, S. 4784, and its proposed CMMC Level 2 grant program, still stalled.

Watch list

  • RFI responses due August 14.
  • Early signals of what the task force heard.

What to do this week

  • Check that MFA covers every account with email access, including shared mailboxes and service accounts.
  • Run a phishing refresher. The IEH message looked like a routine document-sharing link.
  • Confirm you know your 72-hour reporting steps under DFARS 252.204-7012.

Sources

This briefing summarizes public sources for general awareness. It is not legal advice. Check the linked primary sources before acting on any item.

All weekly briefings

Turn the news into a plan

Not sure how this week's changes affect your contracts? A free scoping call is the fastest way to find out.

Schedule a Complimentary Scoping Call

Or reach a practitioner directly: (907) 229-5222 · [email protected]