Compliance Pulse September 2026 — CMMC Assessment Suspension and FCA Liability

Two Regulators Deferred, One Did Not — And the Security Obligation Never Moved At All

September 10, 2026

Compliance Pulse  |  Thursday, September 10, 2026


Three federal and international regulators moved compliance deadlines in three different directions inside a ten-day window. Two deferred. One landed on schedule. Not one of them changed the security obligation underneath. This week's Compliance Pulse is about the difference between those two things, and about what happens to a control budget that was never told the difference.

DoD: the assessment gate came out of contracts

On September 3, 2026, the Department of Defense's principal director for defense pricing, contracting and acquisition policy issued a class deviation directing contracting officers to remove CMMC third-party assessment requirements from contracts (Nextgov/FCW). The action converts July's policy suspension of CMMC Phase 2 into binding acquisition direction. The clause at issue is DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.

What the deviation does not do is the part practitioners need in writing. DFARS 252.204-7012 remains in every affected contract. All 110 controls of NIST SP 800-171 Rev. 2 remain the applicable standard for CMMC Level 2, anchored there by 32 CFR Part 170 and distinct from the FAR and DFARS Rev. 3 tracks. Self-assessment scores and SPRS submissions remain conditions of contract eligibility. And False Claims Act exposure for a false or stale representation continues in full through the suspension (Latham & Watkins).

The 60-day CMMC Reform Task Force review that began July 13 carries a September 11 deadline. Whether its recommendations are published is a separate decision, and it has not been made.

DoJ: the enforcement side never paused

Two days before the deviation, on September 1, 2026, Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements in a Department of Defense contract. The standard at issue was NIST SP 800-171. The conduct period ran from April 2020 through December 2023 — entirely before CMMC became an enforceable gate on any contract. The case arrived as a qui tam action brought by a former employee, Rachel Tenney, who received $375,823 of the settlement.

That sequencing is the whole argument. Liability attached to the control, in a period when the certification apparatus did not exist. The assessment is how a program demonstrates the control. It is not the control, and removing it does not remove the exposure. The Assistant Attorney General's framing was unambiguous: contractors that obtain defense information in administering their contracts must follow required cybersecurity standards.

GAO named the capacity risk in March

None of this arrived without warning. In GAO-26-107955, published March 12, 2026, the Government Accountability Office found that DoD had addressed six of seven strategic elements in its CMMC planning but had not assessed or documented how it intended to mitigate the risk that private-sector assessor capacity would be insufficient for a base of roughly 200,000 companies. DoD concurred, submitted a corrective action plan on April 29, 2026, and committed to complete the documentation by December 31, 2026. Six months later the assessment requirement came out of contracts. Read together, the March finding and the September deviation describe the same constraint from two ends.

HHS: the HIPAA Security Rule rewrite moved to Long-Term Actions

The HIPAA Security Rule overhaul, RIN 0945-AA22, now sits on the Unified Agenda's Long-Term Actions list with a projected date of July 2027 (Clark Hill). The January 2025 proposed rule would have made multi-factor authentication, encryption, asset inventory and network mapping explicit requirements rather than addressable ones. Those proposals are now roughly two years out.

A move to Long-Term Actions is not a non-event. It is a transfer of authority. While the rewrite waits, the bar is set by HHS Office for Civil Rights enforcement of the Security Rule as currently written — a risk-analysis-centred text that OCR has enforced against exactly the deficiencies the rewrite was meant to close. Covered entities and business associates do not get a deadline to budget against. They get the same breach exposure, the same enforcement posture, and no forcing function.

The EU: the one date that held

On September 11, 2026, the reporting obligations of the EU Cyber Resilience Act, Regulation (EU) 2024/2847, begin to apply. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents affecting product security: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days once a corrective measure is available, or within one month for severe incidents. Reports go through the CRA Single Reporting Platform to the CSIRT of the manufacturer's main establishment, with simultaneous notification to ENISA (European Commission).

This binds US manufacturers placing product on the EU market. It arrived on the date it was always going to arrive. For anyone who spent 2026 tracking American deadlines, it is the milestone that did not slip, attached to the consequence that matters most to a CFO: market access.

Two more items that did not make the post

CISA's BOD 26-04 is now issuing split remediation windows. On August 26, 2026, three-day deadlines were assigned to current-year flaws in Gitea, Citrix NetScaler and Microsoft SQL Server while four legacy vulnerabilities disclosed between 2015 and 2021 received fourteen days — same catalog, same day. Deadlines are scored per entry against exposure, known exploitation, automation potential and technical impact. A fixed 21-day internal patch SLA no longer maps to the federal expectation.

In the maritime sector, 33 CFR Part 101 Subpart F is in force and unchanged this window. The Cyber Assessment, Cyber Plan and Cybersecurity Officer designation milestone remains July 16, 2027 — about ten months out, which makes assessment scoping a this-quarter activity rather than a next-year one.

Milestone calendar — sectors covered this edition

SectorInstrumentMilestoneDate
DIB / DoWDFARS 252.204-70213rd-party assessment removed from contracts (class deviation)2026-09-03
DIB / DoWCMMC Reform Task Force60-day review report due2026-09-11
DIB / DoWDFARS 252.204-7012 / SP 800-171 Rev. 2In force — unchangedNow
DIB / DoWGAO-26-107955 corrective actionDoD external-factor documentation due2026-12-31
HealthcareHIPAA Security Rule, RIN 0945-AA22Long-Term Actions — projected final2027-07
IIoT / GlobalReg. (EU) 2024/2847 Art. 14CRA reporting obligations apply2026-09-11
IIoT / GlobalReg. (EU) 2024/2847Main obligations apply2027-12-11
Maritime33 CFR 101 Subpart FCyber Assessment / Cyber Plan / CySO2027-07-16
Cross-federalCISA BOD 26-04Per-entry KEV deadlines (3-day and 14-day issued 2026-08-26)Ongoing

Practitioner checklist

  • Confirm in writing which of your contracts had DFARS 252.204-7021 removed and which retain 252.204-7012. They are different clauses with different consequences.
  • Re-date your most recent SPRS submission. If the score reflects a plan of action rather than implementation, that gap is the FCA exposure, not the assessment status.
  • Identify every control whose funding justification cited a CMMC assessment date or the HIPAA Security Rule rewrite. Re-justify each one against the asset it protects, or defund it deliberately and record who decided.
  • If you manufacture anything with digital elements sold into the EU, name the person who owns the 24-hour early-warning clock and confirm they can reach the CRA Single Reporting Platform today.
  • Rebuild patch SLAs around per-entry KEV deadlines rather than a fixed cycle.
  • Maritime operators: scope the Cyber Assessment this quarter.

Which of your controls exist because a rule requires them, and which because the risk does? The two lists diverged this month. Yours should be able to show where.


Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Senior Lead Auditor  |  PSY Logistics Technology Partners

Sources

Back to Blog