DFARS Dan Reports on DoD FAQ 2.3

DFARS Dan Reports

Date: May 22, 2026

Subject: The DoD issued Revision 2.3 of the CMMC Program Frequently Asked Questions

Background:

The DoD (The Dept of War/DoD CIO) issued Revision 2.3 of the CMMC Program Frequently Asked Questoins on April 29, 2026.  It was cleared for Release on May 17, 2026.

The DoD CMMC Program FAQ Revision 2.3 provides updated clarifications and guidelines regarding Cybersecurity Maturity Model Certification compliance for defense contractors. [1]

===

Key Changes and Takeaways:

  • Scoping Enforcement: The DoD has doubled down on scoping. Enterprise networking components do not automatically become in scope, but configurations matter. The guidance explicitly clarifies that merely encrypting data does not remove it from the CUI boundary.
  • Cloud & External Provider Responsibility: Managed Service Providers (MSPs), MSSPs, and cloud providers handling Controlled Unclassified Information (CUI) must clearly fall within the assessment scope or maintain appropriate authorizations (such as FedRAMP).
  • Evidence-Based Requirements: The DoD requires demonstrable implementation over policy documentation alone. You must be able to prove your defined CUI boundaries and mature System Security Plans (SSPs) during an assessment.
  • POA&M Clarifications: The DoD clarified that Plans of Action and Milestones (POA&Ms) are for missed security requirements. They cannot be used to paper over a "NOT MET" finding discovered during an official audit.
  • Executive Affirmations: Annual SPRS (Supplier Performance Risk System) affirmations are formal attestations, keeping leadership and affirming officials strictly accountable for their cybersecurity status

The DoD FAQ can be downloaded here: DoD FAQ 2.3 PDF File

Submitted by your DFARS News Guy...

DFARS Dan

Next Post Previous Post