Every defense contractor tracking CMMC has spent the summer waiting on the same document. It is not a rule, not a deadline, and not a contract clause. It is a report, and the clock on it runs out this month.

The CMMC Reform Task Force is expected to deliver its findings to the Department of War Chief Information Officer around mid-September 2026, roughly sixty days after the July 13 memo that suspended CMMC Phase 2 and launched a top-to-bottom review of the program. The public report and recommendations are expected between late September and early October. Whatever the report says, it cannot by itself change a single contractual obligation: DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS scoring, and the annual affirmation all remain in force, because a task force report is advice, and only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes the law.

KEY TAKEAWAYS
  • The sixty-day review clock started July 13 and runs out around September 11. DoW CIO Kirsten Davies has said the task force then gets roughly fifteen days to synthesize recommendations, with the report made public shortly after. Cyber AB CEO Matthew Travis has suggested contractors may see the recommendations in early October.
  • The report is recommendations, not rules. Implementing any of it requires a class deviation, DFARS rulemaking, or an amendment to 32 CFR Part 170. Watch what the Department publishes, not what it announces.
  • The realistic outcome range runs from Phase 2 returning on a revised timeline to a longer overhaul that leaves the current self-assessment regime in place for an extended stretch. Under every scenario, the 110 controls of NIST SP 800-171 Rev 2 stay the standard.
  • Enforcement did not pause with the program. DOJ announced two cybersecurity False Claims Act settlements during the review window, LOGZONE in June and Honeywell on September 1. The gap between what you attest and what is true stays the live risk regardless of what the report says.
  • The no-regrets position: keep the SPRS score current and defensible, keep evidence collection running, and treat the report as a scheduling question, not a scope question. The scope has not moved.

Where the clock actually stands

On July 13, 2026, the Department suspended CMMC Phase 2, which would have made third-party C3PAO certification a condition of award for most contracts involving Controlled Unclassified Information starting November 10. Phases 3 and 4 were frozen with it. The same memo, signed by Chief Information Officer Kirsten Davies, stood up a CMMC Reform Task Force and gave it sixty days to review the program top to bottom. Davies has been blunt about her view of the current model, calling the assessments a “burdensome, red-tape ridden, check-the-box, point-in-time view” of how a company handles sensitive data.

Sixty days from July 13 lands on September 11. Some industry trackers anchor the internal delivery to September 13. Either way, the findings go to the CIO first, and that step is internal. Davies told reporters in July that once the sixty-day period closes, the task force gets about fifteen days to synthesize the recommendations and the industry feedback, with the report made public shortly thereafter. Matthew Travis, CEO of the Cyber AB, told a July 28 town hall that contractors may see the recommendations in early October.

Timeline of the CMMC review from the July 13 suspension through the RFI close, the mid-September internal delivery, and the expected public report

The raw material for the report closed on August 14, when the request for information titled “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base” stopped accepting responses. If you filed one, the walkthrough of what the seven questions were actually asking is in the RFI response guide from early August. Acting Deputy CIO J. Aaron Bishop oversees the panel analyzing those responses and drafting the reform recommendations.

So the next three to five weeks look like this: internal findings around the middle of September, a synthesis window, then a public report and recommendations somewhere between late September and early October. That is the schedule contractors are actually waiting on, and it is worth being precise about what that document can and cannot do when it lands.

A report is not a rule

This is the part most of the commentary skips, and it is the part that determines what happens to your contracts.

CMMC exists in two regulations. The program rule lives at 32 CFR Part 170. The acquisition rule, which puts DFARS 252.204-7021 into contracts, lives in 48 CFR. Both went through full notice-and-comment rulemaking. The July 13 suspension did not repeal or amend either one. It was a memo, and a memo governs how the Department exercises its own discretion, not what the law says.

The same constraint binds the task force. Its report can recommend anything: a revised Phase 2 date, a narrower population required to get third-party assessments, a different scoring model, a replacement framework. None of it becomes an obligation or a relief until the Department does one of three things: issues a class deviation, changes the DFARS through rulemaking, or amends 32 CFR Part 170. The first can happen quickly. The other two run on rulemaking timelines, which are measured in months and sometimes years.

The practical translation: when the report drops, the headline will describe intentions. Your obligations will change on the day a deviation or rule is published, and not before. Watch what the Department publishes, not what it announces.

The realistic outcome range

Nobody outside the building knows what the report will say, and this site does not pretend to. But the public record, the memo’s own language, and the way the Department has behaved during the pause bound the plausible outcomes reasonably well. The memo tasked the group with recommending a framework that lowers barriers for small, medium, and non-traditional businesses and moves away from what it called prohibitive third-party compliance models toward scalable, realistic security measures. Read against that charge, four shapes cover most of the probability:

Phase 2 returns on a revised timeline, adjusted. The assessment transition comes back with a later date and changes at the margins: scoping relief, phased applicability by contract type, or cost measures aimed at small businesses. Prime contractor behavior points this direction; several have kept telling subcontractors that compliance requirements are coming regardless of the pause.

Third-party assessment narrows. C3PAO certification is retained for a smaller, high-priority slice of the DIB, while most contractors stay on self-assessment plus targeted government-led reviews, the DIBCAC model. This matches the memo’s language most literally.

Enforcement replaces assessment. The Department leans on what already exists: self-assessment, SPRS scores, annual affirmations, and the False Claims Act as the penalty for misstatement. This is arguably the de facto state of the world right now, made permanent.

A deeper overhaul on a long runway. The review is folded into the broader Acquisition Transformation Strategy alignment it was chartered under, and real structural change waits on new rulemaking. In this scenario the current interim regime, self-assessment with FCA teeth, runs for a long time.

Notice what is common to all four. In none of them does NIST SP 800-171 Rev 2 stop being the standard, because it is wired into contracts through DFARS 252.204-7012, which predates CMMC and was untouched by the suspension. In none of them does the SPRS score stop being a representation to the government. And in none of them does the affirmation go away as a signature with legal weight, a point covered in detail in the affirmation liability breakdown.

Checklist of the obligations that remain binding during the CMMC pause: DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS score, annual affirmation, and False Claims Act enforcement

Enforcement did not take the summer off

If the pause created an impression that the government relaxed while it rethinks the program, the Justice Department spent the review window correcting it. DOJ announced a cybersecurity False Claims Act settlement with LOGZONE in June. Then, on September 1, ten days before the task force clock runs out, it announced that Honeywell Aerospace will pay $2,042,518 to resolve allegations of NIST SP 800-171 noncompliance on a single network, in a case brought by a former employee. The full breakdown of that settlement, including the spin-off liability wrinkle, is in the Honeywell analysis published yesterday.

Neither case needed CMMC to exist. Both ran on DFARS 252.204-7012 and the False Claims Act. That is worth sitting with, because it means the mechanism that actually costs contractors money right now is completely indifferent to what the task force recommends. A misstatement about your security posture, in an SPRS score or an affirmation, paired with invoices, is the entire theory. The report cannot recommend that away, and nothing in the public record suggests anyone wants to.

There is a second continuity most coverage misses: the government-wide CUI rule was folded into the FAR Overhaul rulemaking on June 23 and moves on its own track. Contractors with mixed defense and civilian work get no relief from the CMMC pause on that side, as covered in the FAR CUI rule walkthrough.

What a small contractor should do with the next three weeks

The temptation between now and the report is to wait, on the theory that preparing for requirements that might change is wasted work. That logic fails on its own terms, because the work that matters is the work that survives every scenario.

Keep the SPRS score current and honest. A score submitted when your environment looked different is not a historical artifact, it is a live representation. If controls have drifted since the last self-assessment, the score needs to move with them. This is the single highest-leverage item because it is the one the FCA cases keep turning on.

Keep evidence collection running. Whether the future is a C3PAO, a DIBCAC review, or a whistleblower’s lawyer, the question is the same: can you show that what you attested was true at the time you attested it? Screenshots, configurations, policies with dates, tickets. An assessment model can change; the need to prove your own statements cannot.

Treat the report as a scheduling input, not a scope input. When it lands, it will tell you when and how verification happens. It will not change which 110 controls you owe, because that lives in DFARS 7012 and your contracts today. Plan the calendar around the report. Plan the work around the clause.

Read the actual documents when they publish. The report, and then whatever deviation or rule follows it. The gap between trade-press headlines and regulatory text is where contractors make expensive assumptions. The question of whether CMMC is even still required gets asked enough that it has its own plain-English answer, and the short version has not changed since July: the program is paused, the obligations are not.

The bottom line

Sometime in the next several weeks, the Department publishes a document that tells the defense industrial base what it intends to do about CMMC. It will be treated as a verdict. It is closer to an opening argument, because everything in it still has to travel through deviation or rulemaking to touch a contract. Meanwhile the obligations that were binding on July 12 are binding today: DFARS 252.204-7012, all 110 controls of NIST SP 800-171 Rev 2, an accurate SPRS score, and an affirmation someone in your company signs under their own name, with the Justice Department demonstrating twice this summer that the signature has consequences. The contractors who come out of this window ahead are the ones who spent it making their attestations true, not the ones who spent it refreshing the news.

If you are holding prep steady through the uncertainty, the CMMC Level 2 Readiness Kit: 5 NIST 800-171 Tools ($147) covers the work that survives every task force outcome: scoping, the SSP, the SPRS score, the POA&M, and the evidence trail a reviewer of any kind will ask for. If the immediate item is the score itself, the NIST 800-171 SPRS Score Workbook for CMMC Level 2 ($87) walks the scoring methodology control by control.

Sources