Continuous monitoring is coming to CMMC: what it means for you

The DoD CIO and the Cyber AB both want CMMC to move past point-in-time checks. No rule or memo requires it yet. What was said, what's guesswork, and the ongoing duties you already have.

Said, not yet required. CIO: point-in-time is not enough. Cyber AB: delta assessments. Today: annual affirmation. Working guide.
In this guide

Updated September 30, 2026

Nothing about continuous monitoring is required of you yet: the officials running CMMC have said they want it, but as of today no rule, memo or published report puts it in your contract. What is already in your contract is a duty to monitor your security controls on an ongoing basis and to affirm "continuous compliance" every year, and most small shops aren't doing either.

That second sentence is the useful one. The headlines are about where CMMC, the Defense Department's cybersecurity program for its suppliers, might go after the reform review that started in July. The obligations below are about where it already is.

Who said what

Start with the record, because a lot of what's circulating is somebody's prediction repeated until it sounds like policy. These are the public statements we could verify, with the date and the source.

Who When What they said Source
Kirsten Davies, DoD Chief Information Officer July 13, 2026 Suspended the November 2026 Phase 2 deadline. Set up a 60-day CMMC Reform Task Force to recommend a framework that "replaces prohibitive, third-party compliance models with scalable, realistic security measures." The memo doesn't mention continuous monitoring. CIO memo
Davies July 17, 2026 Contractors "must continue to self-attest" to NIST SP 800-171 Rev. 2, and DoD can "at any time" conduct in-person or documentation assessments. DefenseScoop
The Cyber AB, the body that accredits CMMC assessors August 14, 2026 Asked DoD to "allow for C3PAOs to conduct continuous monitoring and 'delta' assessments," and to reduce the burden for companies that show continuous control monitoring through tools like managed detection and response and automated configuration monitoring. Cyber AB RFI response
Davies, at the Billington CyberSecurity Summit September 9, 2026 "Compliance equals a point-in-time check of where are you right now." And: "Cybersecurity is a dynamic process." DefenseScoop
Matthew Travis, Cyber AB CEO September 14, 2026 "There's no continuous monitoring. There's no way for a C3PO to do just a delta assessment." He called it "low-hanging fruit" that could potentially be done without new rulemaking. Federal News Network

(A C3PAO is one of the accredited firms that perform official CMMC assessments. A delta assessment would re-check only what changed since the last one.)

So the person who runs the program has called today's assessments a point-in-time snapshot, and the organization that accredits the assessors has formally asked for continuous monitoring. That's a real signal. It isn't a requirement.

What hasn't happened

As of September 30, 2026, the task force's recommendations haven't been published. DoD has issued no memo, deviation or rule that mentions continuous monitoring for contractors. The July memo itself says "further guidance will be promulgated in the coming months," and that's where things stand.

Everything past this point is speculation, including ours. Here's how we'd sort it.

Reasonable to expect, because officials have said so: some move away from a single assessment every three years toward something more frequent or ongoing, and some credit for companies whose monitoring tools already produce that picture. Delta assessments are the most concrete version on the table.

Unknown: who would do the monitoring, whether it would apply to self-assessed companies or only certified ones, what data you'd share and with whom, what it costs, and when. Anyone giving you a date or a tool list for "CMMC continuous monitoring" is guessing.

Unlikely to change: the 110 requirements themselves. Davies said in July that contractors must keep meeting NIST SP 800-171 Rev. 2, and DFARS 252.204-7012, the contract clause that has required those 110 since the end of 2017, is still in force.

You already owe continuous monitoring

This is the part most owners miss. The word "continuous" is already in your contract, and the requirement behind it is already in the standard.

The CMMC contract clause, DFARS 252.204-7021, requires an annual affirmation in SPRS, the DoD supplier website, "of continuous compliance" with your CMMC level (DFARS 252.204-7021(d)(3)). The person who signs it, your Affirming Official, attests that you have implemented and "will maintain" every applicable requirement (32 CFR 170.22). You're promising something about the whole year, not the day you signed.

And four of the 110 requirements are about doing the work continuously (NIST SP 800-171 Rev. 2):

  • 3.12.3: "Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls." The NIST discussion calls this a continuous monitoring program and points to its own guide on the subject, SP 800-137. Missing it costs 5 points, the maximum (32 CFR 170.24).
  • 3.12.1: "Periodically assess the security controls" to see if they work. Also 5 points.
  • 3.12.4: "Develop, document, and periodically update system security plans." Your SSP, the document describing your systems and how each requirement is met, has to describe the network you have now. Without an up-to-date one, an assessment can't be completed at all.
  • 3.11.2: Scan for vulnerabilities "periodically and when new vulnerabilities affecting those systems and applications are identified." 5 points.

None of these say "monthly." NIST leaves the frequency to you, as long as it's "sufficient to support risk-based decisions." But all of them assume someone looks at the controls between assessments, and an assessor will ask to see proof that someone did.

What a gap between checks looks like

Here's the kind of failure that continuous monitoring is meant to catch. It's a composite, and it's ordinary.

In March, the owner of a 30-person shop signs the annual affirmation. The self-assessment behind it was honest: multi-factor login on every account, logs kept for a year, laptops encrypted. In May, the office manager sets up a new estimator's account in a hurry and leaves out the MFA enrollment, meaning to come back to it. In June, the MSP replaces the firewall and the new one isn't sending logs anywhere. In August, an engineer gets a personal laptop approved "just for CAD viewing," and nobody adds it to the SSP.

Nothing broke and nothing was stolen. But by September, three of the statements in that March affirmation are no longer true, and nobody in the building knows it. If DCMA's assessors (DIBCAC, the government's own assessment team) show up in October, they'll score what they find, and their result takes precedence over yours (32 CFR 170.16). If a former employee calls a lawyer instead, the False Claims Act cases show where that goes.

A point-in-time assessment is a photograph. That shop had a good photograph of March.

What to do now

You don't need to wait for the task force to start, and the work isn't wasted whatever DoD decides. If continuous monitoring arrives, you'll already have the history. If it doesn't, you'll have met 3.12.3, which you owe anyway.

Pick a monthly date and check the things that drift. In most small shops that's a short list. Who has an account, and does every account have MFA? Are the systems that should send logs still sending them? Did any device, cloud service or person join or leave the CUI environment? Is anything overdue for a patch? Write down what you checked, what you found and what you fixed, and keep it. That record is your 3.12.3 evidence.

Every quarter, reread the SSP against what you found. If the network changed, the SSP changes the same week. Then, when the annual affirmation comes around, the person signing it is looking at twelve months of records instead of a feeling. What the affirmation commits you to →

The more of those checks come straight from your systems, the less they depend on someone remembering. A monthly export of MFA status from Microsoft Entra or Google Workspace takes minutes. Pulling it automatically takes none. Which evidence counts →

Common questions

Is continuous monitoring part of CMMC now? Not as a separate program. Requirement 3.12.3, ongoing monitoring of your controls, has been part of NIST SP 800-171 all along, and CMMC Level 2 assesses it.

When will DoD announce changes? No date has been published for the task force's recommendations. And a recommendation still needs a memo, deviation or rule before it changes your contract.

Will continuous monitoring replace the three-year assessment? Nobody official has said so. The Cyber AB asked for delta assessments and credit for continuous monitoring, which suggests adding to the cycle rather than replacing it. That's our reading, not an announcement.

Do I need to buy a monitoring tool now? Not because of the reform. Buy what meets the requirements you already have, like logging (3.3.1) and vulnerability scanning (3.11.2). How the pause changed spending →

Does the CMMC pause stop the annual affirmation? No. Contracts with the CMMC clause still require it.

Mock assessment

See continuous evidence in Garde1.

Garde1 pulls evidence from your connected systems on a schedule, so when an account loses MFA or a log source goes quiet in June, it shows up in June, not at your next assessment.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE