Primary sources — cited, current, clickable.
Control catalogs
NIST SP 800-171 Rev. 2 (current CMMC L2 basis)
The 110 security requirements for protecting CUI in non-federal systems. The authoritative catalog CMMC Level 2 maps to today.
Open primary source →NIST SP 800-171A Rev. 2 — assessment procedures
Procedures for assessing the security requirements in 800-171 Rev. 2. The companion assessor guide referenced by CMMC.
Open primary source →NIST SP 800-171 Rev. 3 (forward-looking)
Published 14 May 2024. Not yet the CMMC basis — DoD continues to anchor assessments to Rev. 2 pending future rulemaking.
Open primary source →Program rules
CMMC 2.0 Final Rule (32 CFR Part 170)
Federal Register publication of the CMMC Program rule. Published 15 Oct 2024; effective 16 Dec 2024.
Open primary source →DFARS 252.204-7012 — safeguarding CDI & cyber incident reporting
The foundational DFARS safeguarding clause that introduced NIST SP 800-171 to defense contracts. Still in full force.
Open primary source →DFARS 252.204-7021 — contractor compliance with CMMC level
The DFARS clause requiring contractors to hold the required CMMC certification before award and primes to flow it down. Effective 10 Nov 2025.
Open primary source →DoD CIO — CMMC program portal
Office of the DoD CIO landing page for CMMC. Phase rollout timeline, current rule status, and program-office guidance.
Open primary source →Assessor ecosystem
The Cyber AB — CMMC accreditation body
The non-profit accreditation body for the CMMC ecosystem (C3PAOs, assessors, training organizations).
Open primary source →C3PAO marketplace directory
Searchable directory of authorized Third-Party Assessor Organizations. Use this when selecting an assessor for Level 2 certification.
Open primary source →Threat intelligence
CISA Known Exploited Vulnerabilities (KEV) catalog
Living catalog of CVEs known to be exploited in the wild. Track and patch entries that affect software in your CMMC scope.
Open primary source →CISA Cybersecurity Performance Goals 2.0 (CPG)
CISA’s recommended performance goals for critical infrastructure. Cross-walks well with NIST 800-171 Rev. 2 and CMMC L2.
Open primary source →CISA Cybersecurity Alerts & Advisories
Authoritative cyber advisories. Subscribe to monitor advisories relevant to your defense-base supply chain.
Open primary source →CMMC Phase 2 — suspended, not repealed.
On 13 July 2026 DoD suspended the Phase 2 C3PAO certification requirement and all future implementation milestones, pending a 60-day Reform Task Force review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations all remain in force. Each milestone below links to the authoritative source or to the engagement that handles it.
CMMC 2.0 Final Rule
CFR 32 Part 170 finalized. The CMMC Program rule was published in the Federal Register, codifying Level 1 / 2 / 3.
Read on Federal RegisterCMMC Program Effective
The CMMC Program rule took effect, with phased rollout planned across DoD contracts.
DoD CIO program pagePhase 1 — Self-Assessment Required
DoD began requiring Level 1 and Level 2 self-assessments in applicable contracts. The implementing DFARS rule (DFARS 252.204-7021) took effect. Phase 1 obligations remain fully in force.
DoD CIO rollout overviewDoD Suspends Phase 2 & Future Milestones
DoD suspended the Phase 2 C3PAO certification requirement and all future implementation milestones pending a 60-day Reform Task Force review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations all remain in force.
DoD CIO announcementL2 Certification Assessments — Suspended
Originally the date C3PAO Level 2 certification assessments would begin appearing in applicable solicitations. Held in abeyance since 13 Jul 2026 pending the reform review — a reformed requirement is expected to return, and primes still flow down NIST 800-171 today.
Start with a gap assessmentLevel 3 & Full Implementation — Held in Abeyance
Phase 3 (government-led Level 3 assessments) and Phase 4 (full implementation across DoD solicitations) are likewise held in abeyance pending the Reform Task Force review and any subsequent rulemaking.
Browse all five engagementsCMMC, NIST & cyber intelligence — filtered for the defense base.
Editorially curated from DoD CIO, NIST CSRC, Cyber-AB, CISA, and the Acquisition.gov DFARS catalog. Click any item to read the primary source.
DoD suspends CMMC Phase 2 and future milestones pending 60-day reform review
DoD suspended the Phase 2 C3PAO certification requirement (originally 10 Nov 2026) and all future implementation milestones while a Reform Task Force conducts a 60-day review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations remain in force — a suspension pending reform, not a repeal.
DFARS 252.204-7021 in effect — CMMC certification required prior to award
The DFARS contract clause requiring contractors to hold the required CMMC certification level before award (and primes to flow down the requirement to subcontractors handling CUI/FCI) became enforceable on 10 November 2025.
Revolutionary FAR Overhaul — DFARS Part 240 reorganization takes effect
Class deviations issued under the FAR Overhaul renumber DFARS 252.204-7020 to DFARS 252.240-7997 and eliminate 252.204-7019. Foundational clauses 252.204-7012 and 252.204-7021 remain in full force.
NIST SP 800-171 Rev. 3 published — Rev. 2 remains current CMMC basis
NIST published the final SP 800-171 Rev. 3 and the assessment guide SP 800-171A Rev. 3 on 14 May 2024. DoD continues to anchor CMMC Level 2 assessments to Rev. 2; Rev. 3 implementation is expected to be addressed in future rulemaking.
CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV catalog
CISA added CVE-2025-34291 (Langflow origin validation) and CVE-2026-34926 (Trend Micro Apex One directory traversal) to the Known Exploited Vulnerabilities catalog with binding remediation deadlines for federal agencies.
Microsoft Defender vulnerabilities added to KEV — exploited in the wild
CISA added seven vulnerabilities to the KEV catalog including CVE-2026-41091 (Microsoft Defender elevation of privilege) and CVE-2026-45498 (Microsoft Defender denial of service). Federal civilian agencies have set remediation deadlines.
CISA releases Cybersecurity Performance Goals 2.0 for critical infrastructure
CPG 2.0 updates CISA’s recommended practices to reflect the NIST Cybersecurity Framework 2.0. The goals apply to defense-relevant critical infrastructure and align well with CMMC Level 2 controls.
C3PAO marketplace — accredited assessor count remains in the dozens
The Cyber AB’s C3PAO marketplace lists currently-authorized third-party assessor organizations. Limited assessor supply versus demand makes scheduling Level 2 certification slots a planning consideration.