7 CMMC Predictions for 2026

Another year another set of eerily accurate predictions about defense cybersecurity requirements and the CMMC program. Like usual we got most of our 2025 predictions correct. For 2026 we’re getting specific with False Claims settlements, CMMC 3.0, FAR CUI, and more!


Transcript

[Music] Alrighty, folks. It is the last show of 2025. It’s time for the most accurate CMMC prediction podcast on the internet because we’re the only podcast that does an annual prediction show. We were pretty accurate for our predictions in 2025 and we’ve got a bunch of spicy ones coming up for 2026. That’s what we’re going to talk about in this week’s episode. Yeah, when you came out and you said that we were the most accurate show that there was, you didn’t tell me that we were the only show that does this. So here I was thinking I was going to introduce myself as Sprouse Stradamus or something like that, right? Where I was just going to be able to predict the CMMC future, which by the way I’ve done twice. Not throwing that out there. But when you tell me we’re the only show, I’m like, uh oh, this might not be good. But then I look at the numbers, the numbers aren’t that bad. I don’t know if we actually are the only show, but we are the most accurate because for our 2025 predictions, we were 71% accurate and that’s good enough to pass your final exam and get called doctor or whatever professional licensing certification you needed. So it’s close enough for government work. Let’s review what we predicted for 2025 and then we’ll get into our predictions for 2026.

Okay. So this time in 2024, a year ago, we predicted seven things and most of them came to end up. Hey, what do you know, right? What do you know? Okay, so first off, we said that we will hear about a False Claims Act against a small business of less than 100 employees. This turned out to be correct. We actually saw multiple false claims settlements against small businesses. We saw multiple false claims settlements against large businesses all on the grounds that they were non-compliant with the terms of DFARS clause 252.204-7012 way back in 2021. The Department of Justice launched their Cyber Civil Fraud Initiative. That program has not been derailed. That program has not been changed. That program has been doubled down on by the Department of Justice. We’ve been hearing for a long time that we have a ton of these False Claims Act settlements in the queue and so we started to see those trickle through as actual settlements in 2025 and there were multiple False Claims Act settlements against small businesses. Whistleblowers got paid. There were fines that were over a million dollars. We were absolutely correct on this one. Yeah, we just saw that 2025 was the year in which they were injecting the awareness of these requirements. So more small businesses were going to be aware that these things were required, which means that more people had the ability to blow the whistles. It was a given that this was going to happen. Yeah. Yeah. Absolutely.

All right. So something we weren’t right about that I was actually very surprised did not happen. The DFARS 252.204-7012 proposed rule we thought was going to be published in 2025 and it was not. We have no indication that they’ve started rulemaking on revising DFARS 7012. Remember DFARS 7012 rulemaking is not done by the DoD CIO’s office who does CMMC rulemaking. DFARS 7012 rulemaking is done by the Under Secretary for Acquisition and Sustainment. And they don’t get out much. They don’t do very many webinars. They just kind of do their own thing. They’ve been saying for a while through their unified agenda that it’s on the docket for them to revise the rule. The last time they revised the rule is now 10 years ago. So it’s definitely due for some revisions and they didn’t publish the proposed rule and it doesn’t look like they’re going to do that anytime soon. Yeah, I don’t know what exactly is holding this up. I’d like to naively think that it was something to do with maybe a shutdown or a change in administration or anything like that. I don’t know. It needs to happen. I thought it was definitely going to happen. It didn’t happen.

We had a smaller prediction sort of nested under this that they were going to specify 800-171 Rev 2, which is what I thought, or they were going to specify 800-171 Rev 3. That doesn’t really matter because they never published the rule. So we won’t count that one as a loss. We’re just going to move on to the next prediction. As they say in gambling, if one of the bets doesn’t hit in the parlay, the parlay didn’t hit. Right. And there you go. That is what they say.

All right. Moving on to another prediction that we had that we were also not correct about. FedRAMP equivalency will go away via 7012 rulemaking. Right. So at the very beginning of 2025, the DoD published the infamous FedRAMP equivalency memo that clarified what they mean by the term FedRAMP equivalency. And not only did it turn out that equivalency actually does mean the same as, but you have to do basically everything that you have to do for FedRAMP up to paying a C3PAO to run through your FedRAMP assessment. It’s very involved. There’s a lot of stuff. In many ways, it’s more intense than the actual FedRAMP process itself. It’s debatable about whether it’s less expensive. In many ways, we thought that was going to go away because it’s an open secret that the DoD does not like the language in DFARS 7012 that says you have to use FedRAMP Moderate or equivalent services when you put their CUI in the cloud. But the 7012 rule never got revised, never got published, never went into effect. And so FedRAMP equivalency is still in 7012. The memo is still in effect. We were not correct about this prediction. Yeah. And then we even tried to put a safety bet in place and say that even if it was in place, there would be zero solutions that would be able to meet it. This is the worst parlay in the parlay of 2025. We’re making history because we missed every single leg. And yeah, we openly admit it. But that’s enough bad news. Let’s talk about all the things that we got correct.

The DoD Inspector General audit of the C3PAO accreditation process will be a big nothing is what we said going into 2025. And we were correct. It was such a nothing burger that we did a four-part episode going through every single page of the IG report because as much as I love reading IG reports, if you only read their summaries, it makes everything sound really bad all the time. That’s their business model. So you have to read the whole thing. This was a small debate, I think, for a little while on LinkedIn and social media. So we released a four-part episode series. If you’re really interested in how much of a nothing burger this process was, check out the episodes or we’ll add the link to the IG report down below. It didn’t turn out to be a thing that would derail the program and blow it all up and stop it in its tracks as some other people predicted out there. It didn’t turn out to be anything at all. You know, you’re always happy when you’re right, but this is one of those instances where you’re extra happy that you’re right because it proves that there’s nothing wrong going on. So this was one of those things that needed, for the program to move forward, for people to put some of that bad news to bed. Yeah. Probably the easiest prediction out of all of them were any of the ones that people were like, “This is going to kill CMMC,” and we were like, “Well, no, it’s not.”

Next prediction that we were also correct about. We said that DoD will publish the 32 CFR final rule before the election. And this was true. We ended up getting the rule published in October. In December it went into effect and then we waited through 2025 for the 48 CFR rule to come out. All the rulemaking got tidied up. Everything got published ahead of time. Everything went into effect. We’re now in the phased rollout as we’re talking about this at the end of 2025. Rulemaking didn’t get derailed. It was a multi-year-long process for many reasons and it just sort of chugged along and got done. So people who were betting on rulemaking not happening, that was a bad bet. We turned out to be correct about this. I think at the time that we made these predictions there were things happening within the industry that we were able to see that signaled this was going to move a little bit faster than we thought it was going to. We were able to confidently put that confidence meter to 10 on that prediction right there. And I’m glad that one went through the way it went. Yeah, there was a lot of uncertainty around the election and the rhetoric around the election. Now that the smoke has cleared and we’re a year away from it, it turns out everything that was happening before it is still happening just like it was and it was all talk.

Next, wrapping up here, this was our sixth one out of seven. The FAR CUI proposed rule will be published is what we predicted and we got it. We got it in January of 2025. We got the FAR CUI proposed rule. This is the rule that makes 800-171 a requirement for all federal contractors. It doesn’t really change anything for defense contractors. Most importantly, it standardizes a GSA form that indicates whether or not Controlled Unclassified Information is included in the work that you will be doing on the contract or subcontract. That is a very helpful thing for everybody. We got the proposed rule a decade after we were supposed to. So yeah, we were correct. We were able to see that coming. I think with the election and all the stuff that was going on with the rulemaking and all the craziness at the beginning of the year, not a lot of people actually knew that the FAR CUI rule got published. There were very few public comments on the rule, especially compared to the CMMC final rules. But yeah, we were correct about this. We did get the proposed rule. I think the only thing that comes along with this that I want to add is that with this one getting published, we hope we’re not taking stabs in the dark for the next couple years as to when we see it finalized.

Last prediction from last year’s show. The final version of NIST SP 800-172, Revision 3, would increase by more than 25%. This was correct. The amount of requirements for SP 800-171 Revision 3 and SP 800-172 Revision 3 increased dramatically. We had a whole series of episodes over the course of many months tracking this revision process. We had Ron Ross on the show. It’s going to be a while before the CMMC program is updated to point to those new revised versions of the NIST requirements, but the only way that this thing changes in the future is for your requirements to increase. Back in the day, they took the original NIST requirements out of 800-53 and absolutely shredded them down to the bone to make them as small and as open-ended as possible. That turned out to backfire as a policy. It turns out that most people need very specific and detailed instructions about what the government wants you to do. That means the government is going to be adding details back into those requirements in addition to adding any new requirements that are needed for cybersecurity. As we move forward over the years, those requirements will only continue to increase the size of the baselines over and over again. This turned out to be true as well. Yeah, and what we’ve learned is that the 172 revisions are often things that we learn from experiences that happen. What could have prevented this particular breach? What could have prevented that? Where can we put the control? These are the enhancements placed in 172. That’s why you see a lot of dual authentication requirements after the breaches we’ve experienced over the past couple years. This was an easy one. It was only about 35 controls to begin with, so to get 25% we only needed a small number. But yeah, we got it. There you go. We did it again.

There was a bonus prediction at the end of that episode where you said you thought there would be a major cyber incident involving critical infrastructure that involved the use of AI. Depending on how you define critical infrastructure, there have been a bunch of hacks of AI systems, AI databases, LLM models. I think it was Anthropic that put out a big report about how they got attacked using AI-related methods. It’s hard to discern at the end of 2025 whether people are just labeling everything AI or whether it’s legitimate AI. I’ll call this one correct. Yeah, can I get half credit for my bonus? I agree with the things you mentioned, but I think the biggest epidemic within critical infrastructure is deepfakes generated by AI, like AI-generated interview deepfakes of people trying to infiltrate organizations from within. I think that’s one of the biggest issues being combated right now. Don’t support clanker slop, everybody. Like and subscribe for more organic, free-range, 100% natural human thoughts here on our podcast.

All right, moving into what we think is going to happen for 2026. We’ve got seven things that are going to happen in 2026. We’re feeling real confident. We’re two years in a row with the majority of our predictions being correct.

First up, there will be at least 1,000 CMMC Level 2 certifications by the end of March 2026, and at least 2,500 CMMC Level 2 certifications by the end of the year. I think we’re moving in the right direction. If we look at the law of averages and the way things are going with the productivity increase in certifications every month, I think this is realistic. Over or under 1,000 by the end of March? I think under because of where we’re at right now and the short time frame. Over or under 2,500 by the end of 2026? I think push. Let us know what you think in the comments. We’re coming up on around 700-plus at the end of the year. They did 65 last month. I think we’ll hit at least 1,000 by March. I’ll go over. There we go. Let us know in the comments if you think it’ll be more than 1,000.

Second prediction: there will be at least a dozen False Claims Act settlements with defense contractors over non-compliance with DFARS cybersecurity requirements. There were five in 2025. We think that will at least double to a dozen in 2026. I think more than 12. We’ve been hearing that there are tons in the queue. They take a long time to finalize and get published. Every time one came out in 2025, it got people’s attention. Companies of all sizes are getting hammered for $800,000 here, $1.75 million there, $4 million over there. There’s going to be at least 12, and the majority will include seven-figure penalties. I’ll go over on that too. Let us know what you think.

Prediction three: there will be no major funding appropriations to help offset the cost of DFARS 7012 or CMMC assessments in 2026. There will be no money. Help is not coming. I agree 100%. The FY26 NDAA got signed. There are no dollars in that bill for this. There never have been. Cyber costs are part of your overhead. They’re allowable costs reflected in your rates. Until appropriators color the money correctly, there is no funding coming. It’s not in the plan.

Prediction four: the FAR CUI final rule will be published and go into effect before the end of 2026. The proposed rule was published in January 2025 but got sidetracked by the FAR overhaul process. That process is wrapping up at the end of 2025. There shouldn’t be major blockers now. This would make 800-171 the requirement for all federal contractors handling CUI. It standardizes that GSA form clearly indicating when CUI is involved. We’ve been waiting over a decade. I think it’ll happen. I’m going to disagree. I want it to happen, but I don’t think it will by the end of 2026. We’ll see who’s right.

Prediction five: the CMMC 3.0 proposed rule will be published before Halloween. This would update the program to use 800-171 Rev 3 and 800-172 Rev 3 instead of the current versions. They’ve already started working on it in 2025. Word is they’re far along. I think it’ll happen before Halloween. They’re revising, not building from scratch. The guidance already exists. Trick or treat, everybody.

Prediction six: at least one solicitation will include CMMC Level 3 requirements in 2026. This would be ahead of the phased rollout timeline. They already started Level 3 pilots in 2025. I’m confident. We’re already seeing solicitations ahead of their phase including Level 2. Big programs, high-risk efforts, things like Golden Dome—this is where Level 3 will show up first. I completely agree. We’ll see at least one Level 3 solicitation in 2026.

Prediction seven: the upcoming GAO report on the CMMC program will show no major findings or issues. It was supposed to come out at the end of 2025 but got delayed. Just like prior GAO and DoD IG reports, we think it’ll be another nothing burger. CMMC has been extensively reviewed through rulemaking, GAO reports, IG reports, public comments, and industry analysis. When it comes out, people will probably overreact to the summary, and we’ll do a multi-part breakdown. But I don’t think it’ll be a big deal. I agree. We’ve had three big duds in a row. Why not number four?

All right, folks. That was our review of our predictions for 2025 and our predictions for 2026. I’m very confident we’ll be 100% correct on all of those. Let us know what you think in the comments. It’s the end of another year of the podcast. We appreciate everybody who tunes in, likes, subscribes, shares, and engages. Lots more to talk about moving into 2026. If you’ve found the show valuable, tell your friends, share it on LinkedIn, tag us, send us DMs, leave comments. We appreciate all of you. See you next year, folks. See you guys. [Music]

Contact

Speak With Our Team

Scroll to Top