The Department of Defense has scheduled an interim final rule for the Cybersecurity Maturity Model Certification (CMMC) Program that would formally require contractors to transition their security-control baseline from NIST SP 800-171 Revision 2 to Revision 3, according to the DoD's entry in the Unified Regulatory Agenda.

Background

CMMC assessments are currently anchored to NIST SP 800-171 Revision 2, the security-control catalog the Defense Department has used since the program's rulemaking took effect, codified at 32 CFR Part 170. DoD has continued to allow contractors to satisfy CMMC requirements against Revision 2 while it works out how the newer Revision 3 catalog will be incorporated into that same assessment framework.

Revision 3, published by NIST, restructures the control set contractors must implement to protect controlled unclassified information (CUI). According to DoD's own filing, the update introduces organization-defined parameters (ODPs), which let agencies tailor certain control thresholds rather than applying a single fixed value across the board, and adds specificity to existing security requirements throughout the catalog. Moving CMMC's baseline to match Revision 3 has been anticipated since NIST finalized that revision, but the interim final rule is the first concrete regulatory vehicle DoD has scheduled to make the switch official.

The rule appears under RIN 0790-AM01 in the Unified Agenda, with a target publication listed as July 2026, though the agenda entry uses a placeholder day ("07/00/2026") rather than a fixed date. The Unified Agenda is the twice-yearly compilation federal agencies use to disclose planned and pending regulatory actions; a RIN, or Regulation Identifier Number, is the tracking number assigned to a rulemaking so it can be followed across agenda cycles until it publishes in the Federal Register. Listing a rule as an "interim final rule" rather than a proposed rule generally signals that the agency intends the requirement to take effect upon publication rather than first going through a standard notice-and-comment period, though agencies sometimes still accept public comment after an interim final rule publishes and before it becomes truly final.

Key Details

The Unified Agenda listing states that the regulation "modifies the CMMC Program by establishing transitional requirements between NIST SP 800-171 Revision 2 and Revision 3." Beyond swapping the underlying control catalog, DoD's own filing estimates that roughly 20% fewer companies will fall within the affected Defense Industrial Base population than prior sizing estimates had projected — meaning fewer contractors would need Revision 3-aligned assessments than earlier CMMC scoping documents suggested.

The agency contact listed for the rulemaking is Carrie Cardwell, an Acquisition Analyst in the Office of the DoD Chief Information Officer, the office that has owned CMMC policy development throughout the program's build-out.

Federal News Network reported July 7, 2026 that a cluster of major federal cybersecurity rules is converging on overlapping timelines this summer and fall. Alongside the CMMC interim final rule, that cluster includes a rule standardizing cybersecurity requirements across federal contracts and a separate federal contracting rule on cyber threat and incident reporting and information sharing, both targeted for finalization in September 2026 according to the same report. The report also covers the CIRCIA rule — a separate rulemaking that applies across 16 critical infrastructure sectors such as electric utilities, water systems, hospitals, and chemical facilities, rather than to defense contractors specifically — which is likewise targeted for finalization in September 2026. A related DFARS clause update tied to the CMMC transition is listed with an NPRM expected in August 2026, according to the same reporting.

Because the CMMC rule remains at the interim-final-rule stage rather than published text, the specific mechanics of the Rev 2-to-Rev 3 transition — including whether existing Rev 2 certifications will need re-assessment, any grace period for contracts already in the CMMC pipeline, and how the new ODPs will be applied to DoD-specific requirements — are not yet public. The Unified Agenda entry describes the rule's intent and the industrial-base sizing estimate but does not include the regulatory text itself.

What It Means for Contractors

Contractors that store, process, or transmit CUI and are subject to CMMC requirements should treat the Revision 3 transition as a near-term certainty rather than a distant possibility, given that DoD has now placed a specific rule and target month on its regulatory agenda. Companies currently pursuing or holding CMMC Level 2 or Level 3 certifications under Revision 2 should watch for the interim final rule's publication in the Federal Register, since it will determine whether current certifications carry forward, require supplemental assessment against the updated requirements, or need to be redone entirely. The stakes differ by tier: Level 1 relies on annual self-assessment for contractors handling only federal contract information, while Level 2 generally requires third-party assessment against the CUI-focused control catalog now anchored to Revision 2 and set to shift to Revision 3, and Level 3 layers on government-led assessment for the highest-priority programs. Any change to the underlying control catalog therefore has the most direct, near-term impact on companies at Level 2 and Level 3.

The added specificity and new organization-defined parameters in Revision 3 represent new compliance surface area beyond what Revision 2 required, even without a wholesale rewrite of the underlying control set. Contractors that have already built System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms) around Revision 2 should begin mapping those documents against the Revision 3 catalog now, rather than waiting for the interim final rule to publish, given the compressed timeline DoD has signaled.

The estimated 20% reduction in the affected industrial-base population is notable but should not be read as a signal that fewer contractors overall will need to comply with cybersecurity requirements — it reflects DoD's own re-scoping of who falls under the CMMC Program specifically, not a broader loosening of federal cybersecurity expectations. Contractors should also track the related DFARS clause update expected as an NPRM in August 2026, since that rulemaking will likely specify how the Revision 3 transition is written into contract clauses, and the separate federal contracting rule on cyber threat and incident reporting targeted for September 2026, which will impose reporting obligations layered on top of CMMC assessment requirements. Contractors uncertain about their current classification should confirm with their contracting officer whether their contracts already reference CMMC assessment requirements, since the interim final rule will govern how those clauses are updated once published.

Sources