CMMC Updates: DoW Pause and Huntress Hits 50% of Requirements

Imported from official source

Cybersecurity Classified by Officially

DoW hit pause on the Phase II certification deadline. 

Huntress just increased from 37 of the 110 NIST SP 800-171 requirements to 55, thanks to Managed ISPM.

TL;DR: Nothing about your obligation to protect CUI got lighter this month. DoW bought suppliers' time, not an exemption. Huntress is using this moment to keep investing in coverage, not coast on it. And so should you. 

DoW Paused the Deadline. Your Compliance Work Isn't Paused.

The short version: the November certification deadline is paused, but NIST SP 800-171 self-assessments, DFARS 252.204-7012 obligations, and prime contractor expectations all remain in place; and complying with the False Claims Act is still your North Star. The FAR Council is also moving forward on a separate government-wide CUI rule. Stay the course in protecting your CUI to future-proof your DoW revenue.

The need to protect CUI and self-assess for L1, L2, and L3 doesn't go away. The only thing being suspended is the DoW requirement for a C3PAO or DIBCAC to certify you before November 2026. DoW still requires you to meet the 110 L2 requirements to protect CUI, and it reserves the right to audit your self-assessment at any time.

Read between the lines here: this is DoW admitting that suppliers aren't ready. For SMBs, that's a gift of extra time. Use it wisely. This is not an excuse to delay preparation. It's a chance to walk into your eventual assessment prepared, rather than scrambling.

Separately, the FAR Council proposed a rule on June 23 to make CUI incident reporting in under 72 hours a government-wide requirement, not just DoW. 

CUI protection isn't slowing down. It's expanding.

DFARS 252.204-7012 and NIST SP 800-171 Rev 2 are still in force. There's no change. You still have to do that. Full stop.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/huntress-managed-ispm-cmmc-compliance

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/huntress-managed-ispm-cmmc-compliance

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.