Home / Article

The CMMC Review Window Closed. What Happens While Decisions Are Being Drafted?

October 05, 2026 · cmmc, task-force, news

You are waiting on the CMMC Reform Task Force. Your compliance calendar will not wait.

CMMC stands for Cybersecurity Maturity Model Certification. The task force is reviewing the program after the Phase 2 pause. Its recommendations are being drafted right now. That leaves a gap of several weeks before anything is announced.

What did the latest update say?

The Cyber AB held its September town hall while the task force moved into drafting. The Cyber AB is the CMMC Accreditation Body. It runs the assessor ecosystem.

According to the recap, the 60-day review period has ended. The task force is now in a roughly 15-day window drafting recommendations with DoW CIO Kirsten Davies. DoW is the Department of War.

Once the CIO approves, more reviews follow. They come from the General Counsel, the Small Business office, and the Office of Management and Budget (OMB). Travis gave a personal estimate: public release in the back half of October at the earliest. That is an estimate, not a date. (Cyber AB September 2026 Town Hall Recap)

What keeps running right now?

The program itself never paused. Only the Phase 2 contractual requirements were suspended on July 13. The rest is still operating.

DFARS 252.204-7012 stays in force. C3PAOs are still conducting Level 2 certification assessments. A C3PAO is a CMMC Third-Party Assessment Organization. CMMC eMASS and SPRS are still processing Level 2 certifications. SPRS is the Supplier Performance Risk System. DIBCAC keeps assessing candidate and authorized C3PAOs. There are now 117 authorized or accredited C3PAOs. Four are fully accredited to ISO/IEC 17020.

Certification numbers kept climbing in September. Final Level 2 certificates reached 2,362. That is up 12% from August. Conditional certificates rose 7% to 71. Assessments in progress dipped 5% to 151.

A survey by ISC2, the cybersecurity professional association, found 68% kept doing CMMC work despite the uncertainty. Only 26% delayed or canceled assessment preparation.

What should you do this week?

First, if an assessment is in progress, keep it moving. The machinery never stopped. A certificate issued this month still has full value.

Second, if you were waiting to start, start now. More than 2,300 contractors finished ahead of you. Waiting buys you nothing.

Third, check your posted SPRS score against your live controls. The score must match reality. It is a signed claim.

Fourth, keep collecting evidence continuously. Assessor visits favor current exports over old screenshots. Evidence pulled from your live tenant stays current. It reruns after every fix.

Fifth, watch for the task force output in late October. Do not freeze planning while you wait. Plan on the current rules.

One more note from the town hall. The program office had drafted a rule amendment before the pause. It would plan a transition to NIST SP 800-171 Rev 3. NIST is the National Institute of Standards and Technology. That draft has been held since July 13. Do not act on it yet. There is no published transition plan.

Sources

Next step

See how PolicyCortex reads live Azure configuration and checks it against NIST 800-171, then re-verifies after each fix.