The Department of War suspended CMMC Phase 2 on July 13, which took the November 10 transition date out of the Q4 2026 calendar. What remains for security leaders this quarter is a shorter list than a compliance countdown page would show, and a more specific one. I think the right way to plan Q4 is to fund the dates that have a technical or legal mechanism behind them and to treat everything else as readiness work with a named trigger.

The CMMC date that no longer binds anyone

The November date had a paper trail. The CMMC program rule says Phase 2 begins one calendar year after Phase 1, and the DFARS rule that started Phase 1 took effect on November 10, 2025. In Phase 2, DoD intended to require Level 2 certification by a third-party assessor (a C3PAO) as a condition of award on applicable contracts.

On July 13 the DoD CIO suspended that transition. Under the implementation procedures, program managers and requiring activities “may not designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments during this period.” Only Level 1 (Self) or Level 2 (Self) may be named. Waivers are suspended, and existing contracts that carry a C3PAO or DIBCAC requirement are to be modified before the next option period or at the next administrative modification. The department says it will enforce NIST SP 800-171 Rev 2 baseline compliance through self-assessments and select government-led assessments, and the DFARS 252.204-7012 requirements stay in effect. The CIO’s CMMC page says Phase 1 self-assessment requirements “remain firmly in place.”

Media Partner

Web3 x AI Fusion — Media Partner

The procedures promise further guidance when the CIO’s 60-day review ends. Sixty days from July 13 is September 11. As of October 1 the CIO’s CMMC page still carries only the July announcement, and I found no published outcome of the review. A supplier that pauses its Level 2 self-assessment work because of the suspension is betting on the review’s result. I would not make that bet, since the baseline the department says it will keep enforcing is the same one the work was meant to document.

Two Microsoft dates that still stand

Microsoft’s Secure Boot guidance lists three certificate expirations: Microsoft Corporation KEK CA 2011 on June 24, Microsoft UEFI CA 2011 on June 27, and Microsoft Windows Production PCA 2011 on October 19, 2026. The first two have passed and the third falls in Q4.

Microsoft says devices without the 2023 certificates “will continue to start and operate normally” and will keep installing standard Windows updates. They will not receive new early-boot protections, “including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot level vulnerabilities.” Nothing visibly breaks on October 20, which is why the date needs an owner. CyberTech has argued that patch clocks should start on release day. A device that cannot receive a boot-level fix sits outside any patch clock. The inventory question is which devices already hold the 2023 certificates and which do not.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

The second date is October 14. Microsoft’s lifecycle page for Office 2021 lists that as the retirement date for the Home and Business, Home and Student and Professional editions. Any estate still running them needs an upgrade path or a written exception before then.

Rules already running, and one with no date

The EU Cyber Resilience Act’s reporting duties started on September 11, 2026. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within 14 days of a corrective measure for vulnerabilities or within a month of the 72-hour notification for severe incidents. Reports go through the Single Reporting Platform to the manufacturer’s national CSIRT and to ENISA. Open-source software stewards face the same duties from December 11, 2027. Q4 is the first full quarter under the rule, so it is the first quarter in which a product security team can find out whether its 24-hour clock has an owner. CyberTech’s column on a NetScaler flaw exploited after its patch shipped shows why a team that learns of exploitation late will struggle with a 24-hour clock.

The US counterpart has no date. CISA’s CIRCIA page says the agency “continues to work on the final rule” and that reporting remains voluntary until it takes effect. The proposed rule would require covered incident reports within 72 hours and ransom payment reports within 24 hours. I would not buy tooling for a rule without a date. I would expect the evidence collection built for the CRA’s 24 and 72 hour steps to carry over, because the proposed US clocks are similar.

What I would do this quarter

Put October 14 and October 19 in the change calendar this week. By the 14th, list every Office 2021 install and decide between upgrade and exception. By the 19th, count the devices that hold the 2023 Secure Boot certificates and name one owner for the rest. Keep the Level 2 self-assessment on its existing schedule, and ask each contracting officer or prime in writing which CMMC level the current requirement names, because the suspension changed what new solicitations may ask for and the review has published no result yet. If you ship products into the EU, run one tabletop in November in which an exploited vulnerability is confirmed on a Tuesday and the 24-hour early warning is due Wednesday.

Sources