Compliance Pulse July 2026 — CMMC RFI and Regulatory Slip Wave

CMMC Reform RFI Closes August 14 — The Pause Is a Comment Window, Not a Break

July 30, 2026•3 min read

COMPLIANCE PULSE | THURSDAY, JULY 30, 2026

Most defense contractors read the CMMC Phase 2 suspension as breathing room. Understandable — for now. But the Pentagon’s reform RFI closes August 14, CIRCIA’s final rule just moved to September, and the requirements that never paused are still in your contracts. The quiet weeks of a regulatory slip are when positions get decided.

DoD: CMMC Phase 2 Is Suspended — the Comment Window Isn’t

On July 13, DoD CIO Kirsten Davies suspended CMMC Phases 2 through 4 and stood up a Reform Task Force to review cost drivers, administrative burden, and which NIST 800-171 controls deliver measurable risk reduction. Phase 1 self-assessments remain in force, and DFARS 252.204-7012 never moved — NIST 800-171 is still a contractual obligation in every covered contract, with SPRS scores and False Claims Act exposure attached.

The task force’s industry RFI closes August 14. That is roughly two weeks to shape what the program becomes — where assessment costs land, whether commercial tooling gets recognized, how existing certifications carry forward. A decision is expected around mid-September.

Bottom line for DIB contractors: the pause changed the certification calendar, not your obligations. Submit an RFI response — and keep executing your SSP and POA&M.

The Slip Wave: CIRCIA to September, HIPAA to July 2027

The Spring Unified Agenda moved two more dates. CISA now targets September 2026 for the CIRCIA final rule — down from the October 2025 statutory deadline and the May 2026 target before it — carrying 72-hour incident and 24-hour ransom-payment reporting for critical infrastructure, with the proposed 316,000-entity scope expected to narrow. And HHS pushed the HIPAA Security Rule overhaul, with its mandatory MFA and encryption provisions, to a projected July 2027.

Bottom line for healthcare CEOs and CFOs: a 2027 final rule is not a 2027 problem. The proposed requirements are already the baseline OCR and breach litigation measure you against — build to them now and the rule becomes a formality.

What Isn’t Slipping: Maritime Deadlines and Federal Oversight

The Coast Guard’s Cybersecurity in the Marine Transportation System rule passed its one-year mark on July 16 with no schedule relief: Cyber Assessments, Cyber Plans, and a designated CySO are due July 16, 2027. The oversight bodies aren’t pausing either — GAO reported on July 16 (GAO-26-107693) that FAA and TSA collaboration on aviation cybersecurity still has key shortfalls, the latest in a run of federal watchdog findings keeping pressure on regulators even while rules slip.

Bottom line for maritime operators: twelve months out, the assessment work starts now. A Cyber Plan drafted in June 2027 is a finding, not a plan.

What This Means for Security Leaders

September is now a convergence point: the CMMC task force decision and the CIRCIA final rule are both expected within weeks of each other, while MTSA’s 2027 deadline holds firm. Slipped rules don’t slip risk — they compress it into whatever window remains, and organizations that treat a pause as permission pay for it later in contract eligibility and market access. Security protects the revenue; the rule, whenever it lands, confirms it.

The organizations that keep executing through a regulatory pause are the ones that get to choose their clients when enforcement resumes.

Is your team submitting a CMMC RFI response before August 14 — or waiting to see what September brings? Drop a comment or DM me — we’re drafting responses with clients right now.

#CompliancePulse #CMMCReform #CIRCIA #CMMC #CUI #GRC #CybersecurityCompliance #DIB #MaritimeCyber #FederalContracting #vCISO

Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Lead Auditor | PSY Logistics Technology Partners

Back to Blog