The Sacred Timeline
The CMMC Sacred Timeline
It can feel like CMMC was sprung on the Defense Industrial Base overnight. It wasn’t. This is the single, unbranching line of decisions — from a 2010 executive order to today — that led here.
To understand where CMMC stands today, you have to see how it got here. Across fifteen years of executive orders, federal rules, oversight, and enforcement, one theme holds steady: when it comes to protecting national security information in contractor hands, the Department of Defense has consistently moved to reinforce — not relax — the standard. CMMC may feel like it was sprung on the Defense Industrial Base overnight, but a long, traceable line of key decisions led directly to it.
It runs newest-first below — scroll down for the full history back to 2010. Every quotation is drawn from the public record — executive orders, the Code of Federal Regulations, DFARS, DoD Inspector General reports, congressional testimony, and Department of Justice settlements. One timeline. No variants, no resets — just how we got here.
-
60-Day Pause: The Department of War Suspends CMMC Phase II
On July 13, 2026, the Department of War immediately suspended CMMC Phase II — the mandatory third-party (C3PAO) certification requirement that was set to take effect November 10, 2026 — and stood up a 60-day CMMC Reform Task Force to review the program top to bottom, with a report due on or about September 13. The underlying duties do not pause: DFARS 252.204-7012, NIST SP 800-171, and CMMC Phase I self-assessment all remain in force. This is a review of how to certify — not a retreat from the obligation to protect CUI.
-
DOJ: LOGZONE, Inc. — $507,144
The enforcement drumbeat continues — a Navy contractor settles FCA liability for knowingly failing to comply with cybersecurity requirements. The record shows this isn’t slowing down.
-
Revised DFARS 252.204-7021 Takes Effect
The clause that puts CMMC into contracts goes live. Contractors must hold — and maintain for the life of the contract — the required CMMC status for every system that touches FCI or CUI.
“Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher… for all information systems used in performance of the contract…”DFARS 252.204-7021(d) ↗
-
DOJ: Georgia Tech Research Corporation — $875,000
GTRC settles FCA allegations tied to certain Air Force and DARPA contracts — research institutions are not exempt from the standard.
-
DOJ: Aero Turbine & Gallant Capital — $1.75 Million
A contractor and its private-equity owner settle FCA liability for knowingly failing cybersecurity requirements in an Air Force contract — notably, the investment firm is named alongside the contractor.
-
DoD Memo: Assessment Levels & Waivers
DoD clarifies that Level 2 (Certification) is the minimum when a contract involves CUI — a third-party assessment under NIST SP 800-171A.
“CMMC Level 2 (Certification) is the minimum assessment requirement when the planned contract will require the contractor (or subcontractors) to process, store, or transmit CUI…”DoD implementation guidance memorandum ↗
-
32 CFR Part 170: The CMMC Program Rule Takes Effect
The program becomes law. Responding to small-business cost concerns, DoD reiterates that requirements align strictly to NIST and that unique CMMC practices have been eliminated.
“The DoD has streamlined CMMC requirements to align directly to NIST guidelines and has eliminated unique security practices to ease the burden on smaller companies.”32 CFR Part 170 ↗
-
DOJ: Penn State — $1.25 Million
Penn State settles False Claims Act allegations of failing to meet cybersecurity requirements across fifteen DoD and NASA contracts or subcontracts.
-
Class Deviation — Revision 1
DoD pins the standard to NIST SP 800-171 Revision 2 for 7012 compliance, rather than automatically adopting the newer revision — giving contractors a stable target.
“The deviation clause requires contractors, who are subject to 252.204-7012, to comply with NIST SP 800-171 Revision 2, instead of the version… in effect at the time the solicitation is issued…”“Class Deviation — Revision 1, Safeguarding Covered Defense Information” ↗
-
Comment Period Closes
Public comment on the proposed rule closes, and DoD begins adjudicating the responses toward a final rule.
32 CFR Part 170 rulemaking docket
-
Proposed CMMC Program Rule Published
The proposed 32 CFR Part 170 rule publishes for public comment — a 60-day window.
-
DoD IG Special Report DODIG-2024-031
The IG finds contracting officials weren’t verifying that contractors met NIST SP 800-171 — the accountability gap that third-party assessment is designed to close.
“…DoD contracting officials did not establish processes to verify that contractors complied with selected NIST SP 800-171 requirements.”DODIG-2024-031 ↗
-
Proposed Rule Reaches OIRA
The proposed CMMC Program rule arrives at the Office of Information and Regulatory Affairs for interagency review — the last stop before publication.
Office of Information and Regulatory Affairs (OIRA)
-
Senate Hearing: Enterprise Cybersecurity
DoD CIO John Sherman explains the move from CMMC 1.0’s five levels to three, aligning to NIST’s 110 controls, and putting the department in the shoes of the small and medium businesses that must implement it.
“We’re not surrendering the ground on cybersecurity, but making it implementable… measure twice, cut once, we want to do this correctly before it gets over to OMB into rulemaking…”Hon. John Sherman, DoD CIO — Senate testimony
-
Pentagon Halts F-35 Deliveries
Deliveries pause after a magnet alloy in the aircraft is traced to Chinese-sourced raw material — supply-chain risk made concrete at the highest-profile program in the department.
U.S. Department of Defense
-
Joint Surveillance Voluntary Assessments Begin
The first CMMC-style assessments launch under the Joint Surveillance Voluntary Assessment (JSVA) program. A perfect DIBCAC High score can later convert to a Level 2 (C3PAO) status valid for three years.
“…will be given a CMMC Status of Level 2 Final (C3PAO) with a validity period of three (3) years from the date of the original DCMA DIBCAC High Assessment.”32 CFR § 170.20(a)(1) ↗
-
DOJ: Aerojet Rocketdyne — $9 Million
A major defense contractor settles False Claims Act allegations of misrepresenting its cybersecurity compliance — an early sign the DOJ Civil Cyber-Fraud Initiative has teeth.
-
DoD IG Report DODIG-2022-061
Academic and research contractors are again found not consistently implementing controls to protect CUI — missing MFA, unpatched systems, unmonitored networks.
“The 10 academic and research contractors we assessed did not consistently implement required cybersecurity controls to protect CUI stored on their networks…”DODIG-2022-061 ↗
-
CMMC 2.0
After 850+ public comments, DoD streamlines the program: five levels become three, and the DoD-unique controls layered on top of NIST are removed in favor of aligning directly to NIST.
“This review resulted in “CMMC 2.0,” which updates the program structure and the requirements to streamline and improve implementation of the CMMC program.”“CMMC 2.0 Updates and Way Forward” ↗
-
Three DFARS Clauses & the Interim Rule
DFARS 252.204-7019, -7020, and -7021 take effect — requiring a current NIST SP 800-171 self-assessment in SPRS and introducing CMMC. The Level 3 Assessment Guide (v1.10) layers 20 additional “Delta” requirements on top of NIST 800-171, spanning asset management, audit, incident response, recovery, risk management, and more.
“…the Offeror shall have a current assessment (i.e., not more than 3 years old…) for each covered contractor information system that is relevant to the offer…”DFARS 252.204-7019(b); CMMC Assessment Guide Level 3 v1.10 ↗
-
Solarium Commission Endorsement & DoD MOU
The Cyberspace Solarium Commission recommends tying program participation to a firm’s cyber maturity, and DoD signs the Memorandum of Understanding formally establishing CMMC accreditation, certification, and assessment.
“…smaller entities with fewer resources to devote to cyber security may provide an opening for adversaries to access information paramount to national security.”Cyberspace Solarium Commission; DoD–CMMC-AB MOU
-
The CMMC Accreditation Body (now the Cyber AB) Is Established
The independent body that will accredit assessors and C3PAOs — and maintain the marketplace of authorized firms — is stood up.
-
NDAA for FY2020, Section 1648
Congress directs DoD to establish unified cybersecurity standards and third-party certification for the defense industrial base — the legal foundation for CMMC.
“Identification of unified cybersecurity standards, regulations, metrics, ratings, third-party certifications, or requirements to be imposed on the defense industrial base…”NDAA FY2020 § 1648(b)(1) ↗
-
DoD IG Report DODIG-2019-105
The Inspector General finds contractors inconsistently implementing required controls — weak multi-factor authentication, weak passwords, unpatched vulnerabilities.
“DoD contractors did not consistently implement DoD-mandated system security controls for safeguarding Defense information.”DODIG-2019-105 ↗
-
Senate Hearing: Securing the Defense Industrial Base
Lawmakers press DoD on why smaller contractors weren’t held to the same standards as the primes.
“…everyone should meet the same standards… I don’t understand why we let the small contractors get by just because they’re small.”Sen. Joe Manchin (D-WV), DIB cybersecurity subcommittee hearing
-
MITRE: “Deliver Uncompromised”
A landmark report warns that adversaries are exploiting the defense supply chain, and that security must become a primary factor in acquisition — not an afterthought.
“We are in an era of adversarial asymmetric warfare for which we have no comprehensive deterrence.”MITRE, “Deliver Uncompromised” (2018) ↗
-
Chinese Theft of U.S. Navy Undersea-Warfare Data
State-sponsored hackers breach a Navy contractor and exfiltrate highly sensitive undersea-warfare plans — including a supersonic anti-ship missile program. A concrete example of why contractor security is national security.
Reported breach of a U.S. Navy contractor
-
DFARS 252.204-7008 & -7012 Finalized
DoD directs contractors to implement NIST SP 800-171 to safeguard covered defense information — with a hard deadline.
“The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017.”DFARS 252.204-7012(b)(2)(ii)(A) ↗
-
32 CFR Part 2002: The CUI Rule Takes Effect
The CUI program becomes binding regulation — and it names NIST SP 800-171 as the standard for protecting CUI on non-federal (contractor) systems.
“Agencies must use NIST SP 800-171 when establishing security requirements to protect CUI’s confidentiality on non-Federal information systems…”32 CFR § 2002.14(h)(2) ↗
-
Executive Order 13556: Controlled Unclassified Information
The White House establishes a uniform, government-wide program for handling sensitive-but-unclassified information — the birth of “CUI.”
“…establishes an open and uniform program for managing information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies…”Executive Order 13556 ↗