The CMMC Sacred Timeline

It can feel like CMMC was sprung on the Defense Industrial Base overnight. It wasn’t. This is the single, unbranching line of decisions — from a 2010 executive order to today — that led here.

To understand where CMMC stands today, you have to see how it got here. Across fifteen years of executive orders, federal rules, oversight, and enforcement, one theme holds steady: when it comes to protecting national security information in contractor hands, the Department of Defense has consistently moved to reinforce — not relax — the standard. CMMC may feel like it was sprung on the Defense Industrial Base overnight, but a long, traceable line of key decisions led directly to it.

It runs newest-first below — scroll down for the full history back to 2010. Every quotation is drawn from the public record — executive orders, the Code of Federal Regulations, DFARS, DoD Inspector General reports, congressional testimony, and Department of Justice settlements. One timeline. No variants, no resets — just how we got here.

Policy & Rulemaking Legislation Milestone Oversight Threat Enforcement
  1. Jul 2026 Policy & Rulemaking You are here

    60-Day Pause: The Department of War Suspends CMMC Phase II

    On July 13, 2026, the Department of War immediately suspended CMMC Phase II — the mandatory third-party (C3PAO) certification requirement that was set to take effect November 10, 2026 — and stood up a 60-day CMMC Reform Task Force to review the program top to bottom, with a report due on or about September 13. The underlying duties do not pause: DFARS 252.204-7012, NIST SP 800-171, and CMMC Phase I self-assessment all remain in force. This is a review of how to certify — not a retreat from the obligation to protect CUI.

    U.S. Department of War — “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements” (July 13, 2026) ↗

  2. Jun 2026 Enforcement

    DOJ: LOGZONE, Inc. — $507,144

    The enforcement drumbeat continues — a Navy contractor settles FCA liability for knowingly failing to comply with cybersecurity requirements. The record shows this isn’t slowing down.

    U.S. Department of Justice press release ↗

  3. Nov 2025 Policy & Rulemaking

    Revised DFARS 252.204-7021 Takes Effect

    The clause that puts CMMC into contracts goes live. Contractors must hold — and maintain for the life of the contract — the required CMMC status for every system that touches FCI or CUI.

    “Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher… for all information systems used in performance of the contract…”DFARS 252.204-7021(d) ↗
  4. Sep 2025 Enforcement

    DOJ: Georgia Tech Research Corporation — $875,000

    GTRC settles FCA allegations tied to certain Air Force and DARPA contracts — research institutions are not exempt from the standard.

    U.S. Department of Justice press release ↗

  5. Jul 2025 Enforcement

    DOJ: Aero Turbine & Gallant Capital — $1.75 Million

    A contractor and its private-equity owner settle FCA liability for knowingly failing cybersecurity requirements in an Air Force contract — notably, the investment firm is named alongside the contractor.

    U.S. Department of Justice press release ↗

  6. Jan 2025 Policy & Rulemaking

    DoD Memo: Assessment Levels & Waivers

    DoD clarifies that Level 2 (Certification) is the minimum when a contract involves CUI — a third-party assessment under NIST SP 800-171A.

    “CMMC Level 2 (Certification) is the minimum assessment requirement when the planned contract will require the contractor (or subcontractors) to process, store, or transmit CUI…”DoD implementation guidance memorandum ↗
  7. Dec 2024 Milestone

    32 CFR Part 170: The CMMC Program Rule Takes Effect

    The program becomes law. Responding to small-business cost concerns, DoD reiterates that requirements align strictly to NIST and that unique CMMC practices have been eliminated.

    “The DoD has streamlined CMMC requirements to align directly to NIST guidelines and has eliminated unique security practices to ease the burden on smaller companies.”32 CFR Part 170 ↗
  8. Oct 2024 Enforcement

    DOJ: Penn State — $1.25 Million

    Penn State settles False Claims Act allegations of failing to meet cybersecurity requirements across fifteen DoD and NASA contracts or subcontracts.

    U.S. Department of Justice press release ↗

  9. May 2024 Policy & Rulemaking

    Class Deviation — Revision 1

    DoD pins the standard to NIST SP 800-171 Revision 2 for 7012 compliance, rather than automatically adopting the newer revision — giving contractors a stable target.

    “The deviation clause requires contractors, who are subject to 252.204-7012, to comply with NIST SP 800-171 Revision 2, instead of the version… in effect at the time the solicitation is issued…”“Class Deviation — Revision 1, Safeguarding Covered Defense Information” ↗
  10. Feb 2024 Policy & Rulemaking

    Comment Period Closes

    Public comment on the proposed rule closes, and DoD begins adjudicating the responses toward a final rule.

    32 CFR Part 170 rulemaking docket

  11. Dec 2023 Policy & Rulemaking

    Proposed CMMC Program Rule Published

    The proposed 32 CFR Part 170 rule publishes for public comment — a 60-day window.

    Proposed rule, 32 CFR Part 170 ↗

  12. Nov 2023 Oversight

    DoD IG Special Report DODIG-2024-031

    The IG finds contracting officials weren’t verifying that contractors met NIST SP 800-171 — the accountability gap that third-party assessment is designed to close.

    “…DoD contracting officials did not establish processes to verify that contractors complied with selected NIST SP 800-171 requirements.”DODIG-2024-031 ↗
  13. Jul 2023 Policy & Rulemaking

    Proposed Rule Reaches OIRA

    The proposed CMMC Program rule arrives at the Office of Information and Regulatory Affairs for interagency review — the last stop before publication.

    Office of Information and Regulatory Affairs (OIRA)

  14. Mar 2023 Oversight

    Senate Hearing: Enterprise Cybersecurity

    DoD CIO John Sherman explains the move from CMMC 1.0’s five levels to three, aligning to NIST’s 110 controls, and putting the department in the shoes of the small and medium businesses that must implement it.

    “We’re not surrendering the ground on cybersecurity, but making it implementable… measure twice, cut once, we want to do this correctly before it gets over to OMB into rulemaking…”Hon. John Sherman, DoD CIO — Senate testimony
  15. Sep 2022 Threat

    Pentagon Halts F-35 Deliveries

    Deliveries pause after a magnet alloy in the aircraft is traced to Chinese-sourced raw material — supply-chain risk made concrete at the highest-profile program in the department.

    U.S. Department of Defense

  16. Aug 2022 Milestone

    Joint Surveillance Voluntary Assessments Begin

    The first CMMC-style assessments launch under the Joint Surveillance Voluntary Assessment (JSVA) program. A perfect DIBCAC High score can later convert to a Level 2 (C3PAO) status valid for three years.

    “…will be given a CMMC Status of Level 2 Final (C3PAO) with a validity period of three (3) years from the date of the original DCMA DIBCAC High Assessment.”32 CFR § 170.20(a)(1) ↗
  17. Jul 2022 Enforcement

    DOJ: Aerojet Rocketdyne — $9 Million

    A major defense contractor settles False Claims Act allegations of misrepresenting its cybersecurity compliance — an early sign the DOJ Civil Cyber-Fraud Initiative has teeth.

    U.S. Department of Justice press release ↗

  18. Feb 2022 Oversight

    DoD IG Report DODIG-2022-061

    Academic and research contractors are again found not consistently implementing controls to protect CUI — missing MFA, unpatched systems, unmonitored networks.

    “The 10 academic and research contractors we assessed did not consistently implement required cybersecurity controls to protect CUI stored on their networks…”DODIG-2022-061 ↗
  19. Nov 2021 Milestone

    CMMC 2.0

    After 850+ public comments, DoD streamlines the program: five levels become three, and the DoD-unique controls layered on top of NIST are removed in favor of aligning directly to NIST.

    “This review resulted in “CMMC 2.0,” which updates the program structure and the requirements to streamline and improve implementation of the CMMC program.”“CMMC 2.0 Updates and Way Forward” ↗
  20. Nov 2020 Policy & Rulemaking

    Three DFARS Clauses & the Interim Rule

    DFARS 252.204-7019, -7020, and -7021 take effect — requiring a current NIST SP 800-171 self-assessment in SPRS and introducing CMMC. The Level 3 Assessment Guide (v1.10) layers 20 additional “Delta” requirements on top of NIST 800-171, spanning asset management, audit, incident response, recovery, risk management, and more.

    “…the Offeror shall have a current assessment (i.e., not more than 3 years old…) for each covered contractor information system that is relevant to the offer…”DFARS 252.204-7019(b); CMMC Assessment Guide Level 3 v1.10 ↗
  21. Mar 2020 Milestone

    Solarium Commission Endorsement & DoD MOU

    The Cyberspace Solarium Commission recommends tying program participation to a firm’s cyber maturity, and DoD signs the Memorandum of Understanding formally establishing CMMC accreditation, certification, and assessment.

    “…smaller entities with fewer resources to devote to cyber security may provide an opening for adversaries to access information paramount to national security.”Cyberspace Solarium Commission; DoD–CMMC-AB MOU
  22. Jan 2020 Milestone

    The CMMC Accreditation Body (now the Cyber AB) Is Established

    The independent body that will accredit assessors and C3PAOs — and maintain the marketplace of authorized firms — is stood up.

    CMMC-AB / Cyber AB ↗

  23. Dec 2019 Legislation

    NDAA for FY2020, Section 1648

    Congress directs DoD to establish unified cybersecurity standards and third-party certification for the defense industrial base — the legal foundation for CMMC.

    “Identification of unified cybersecurity standards, regulations, metrics, ratings, third-party certifications, or requirements to be imposed on the defense industrial base…”NDAA FY2020 § 1648(b)(1) ↗
  24. Jul 2019 Oversight

    DoD IG Report DODIG-2019-105

    The Inspector General finds contractors inconsistently implementing required controls — weak multi-factor authentication, weak passwords, unpatched vulnerabilities.

    “DoD contractors did not consistently implement DoD-mandated system security controls for safeguarding Defense information.”DODIG-2019-105 ↗
  25. Mar 2019 Oversight

    Senate Hearing: Securing the Defense Industrial Base

    Lawmakers press DoD on why smaller contractors weren’t held to the same standards as the primes.

    “…everyone should meet the same standards… I don’t understand why we let the small contractors get by just because they’re small.”Sen. Joe Manchin (D-WV), DIB cybersecurity subcommittee hearing
  26. Aug 2018 Oversight

    MITRE: “Deliver Uncompromised”

    A landmark report warns that adversaries are exploiting the defense supply chain, and that security must become a primary factor in acquisition — not an afterthought.

    “We are in an era of adversarial asymmetric warfare for which we have no comprehensive deterrence.”MITRE, “Deliver Uncompromised” (2018) ↗
  27. Jan 2018 Threat

    Chinese Theft of U.S. Navy Undersea-Warfare Data

    State-sponsored hackers breach a Navy contractor and exfiltrate highly sensitive undersea-warfare plans — including a supersonic anti-ship missile program. A concrete example of why contractor security is national security.

    Reported breach of a U.S. Navy contractor

  28. Oct 2016 Policy & Rulemaking

    DFARS 252.204-7008 & -7012 Finalized

    DoD directs contractors to implement NIST SP 800-171 to safeguard covered defense information — with a hard deadline.

    “The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017.”DFARS 252.204-7012(b)(2)(ii)(A) ↗
  29. Sep 2016 Policy & Rulemaking

    32 CFR Part 2002: The CUI Rule Takes Effect

    The CUI program becomes binding regulation — and it names NIST SP 800-171 as the standard for protecting CUI on non-federal (contractor) systems.

    “Agencies must use NIST SP 800-171 when establishing security requirements to protect CUI’s confidentiality on non-Federal information systems…”32 CFR § 2002.14(h)(2) ↗
  30. Nov 2010 Policy & Rulemaking

    Executive Order 13556: Controlled Unclassified Information

    The White House establishes a uniform, government-wide program for handling sensitive-but-unclassified information — the birth of “CUI.”

    “…establishes an open and uniform program for managing information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Government-wide policies…”Executive Order 13556 ↗

Wherever You Are on the Timeline, We’ll Get You There

Even with Phase II under review, the obligation to protect CUI hasn’t moved — and the requirement will return in some form. As Florida’s accredited C3PAO, Cybersec Investments helps you get ready and stay ready, whatever the task force decides.

Talk to an Assessor