Class B and C opened. CMMC still has no date.
The federal compliance calendar moved twice in August, in opposite directions — and a software company preparing to bid has to spend the quarter against both. One pipeline opened. One requirement is still paused with nothing behind it.
By Philip Luca — Founder of GovExpress; prior domain experience at Bloomberg Government and GovWin IQ.
Primary sources last opened . The links below are the set observed on that date; they were not re-opened for this issue — see “How this issue is sourced”.
August was the month FedRAMP’s two permanent certification classes stopped being a plan. Their submission pipelines opened on 31 August 2026, which means a cloud service can now begin the assessment it will actually live under rather than the transitory one that opened four weeks earlier.
CMMC did not move at all. The certification mandate suspended on 13 July 2026 is still suspended, still has no replacement date, and is still being counted down to by a large share of the guidance a software vendor finds when they search for it.
Both land on the same reader — a software company that wants to be a credible answer to a federal buyer’s security question within two quarters — and they pull in opposite directions on where that quarter goes.
What changed this month
Class B and Class C opened on 31 August
FedRAMP published its Consolidated Rules for 2026 in June and, with them, a rollout calendar. The announcement put three dates on the record: marketplace listings opened 6 July 2026, the Class A submission pipeline opened 3 August 2026, and the Class B and Class C pipelines opened 31 August 2026.
The class taxonomy came out of the program’s public rulemaking. FedRAMP’s outcome notice for RFC-0020 maps the new classes onto baselines a compliance team already knows: Class B covers the current Li-SaaS and Low baselines, Class C covers Moderate, and Class D — the High baseline — is still to be developed. The 20x program page adds the qualitative reading: Class B is for “fairly common small-scale or light use services”, Class C for “common enterprise services that are likely to be used in systems across an entire agency.”
The practical difference between what opened on 3 August and what opened on 31 August is the size of the assessment. Class A, per its certification ruleset, admits a provider on the strength of an existing external assessment — a SOC 2 Type II completed within the past twelve months is the headline case — and asks for a reduced set of Key Security Indicators. Class B and Class C are assessed against the full set, and the independent assessment that is optional at Class A is not optional at either of them.
That is the decision now in front of a SaaS company, and the rules are explicit that Class A is a bridge. The outcome of RFC-0022 describes Class A certifications as “intended to be transitory and replaced by a Class B, C, or D FedRAMP Certification”, and the Class A marketplace listing ruleset requires a provider to demonstrate that a Class B, C or D assessment “has been scheduled within 2 years of initial listing”. Before 31 August that scheduling obligation pointed at a pipeline that was not open yet. It is open now, which turns a future commitment into something a vendor can put a date against. The rules themselves were shaped by a staged pilot, down to the named cohorts that ran Phase 2.
CMMC: two months into a suspension, with no replacement date
Nothing on the CMMC side moved in August, and the absence is the story. The Phase 2 requirement for mandatory certification by an authorized third-party assessment organization was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023, and no replacement date has been published since.
Two readings of that are common and both are expensive: treating the suspension as the end of CMMC and standing the work down, or ignoring it and planning against a date that no longer exists.
What was suspended is one step — who confirms your posture. What was not suspended is the posture itself. DFARS 252.204-7012 still obliges adequate security by reference to NIST SP 800-171. The separate requirement to assess yourself against that standard and post the result in the government’s supplier performance system is still in force. The 72-hour cyber incident reporting obligation is untouched, and its clock starts at discovery rather than at confirmation. And the senior-official affirmation remains a representation to the government, whatever the assessment regime does around it.
The second-order effect is the one worth planning around. With no mandate in force, the supply of third-party certification records is not growing. More of what a federal buyer can learn about any vendor — yours, and the ones you are being compared against — is now that vendor’s own claim rather than a government-published record. That makes the distinction between a verified record and a self-attestation more load-bearing in a diligence conversation, not less.
The 1 January 2027 line
The same June announcement that opened these pipelines scheduled the legacy program’s exit. FedRAMP Ready became Legacy on 28 July 2026, temporary Rev5 certification pipelines opened on 10 August 2026, the consolidated rules become mandatory for all stakeholders on 1 January 2027, and no new Rev5 certification application is accepted after 11 June 2027.
For a company that has not started, exactly one of those is actionable, and it is the first of January. After it there is one rulebook. Anything begun under the legacy program between now and then is work done against a set of rules with a published end date.
What it means for a vendor preparing to bid
Pick the class you will end at, not the one you can reach first. The two-year advancement clock starts at a Class A listing, and the eventual target determines how much of the full indicator set is worth building toward now. Aiming at Class C because agency-wide deployment is the goal is a different engineering programme from aiming at Class B.
Treat the external assessment as the critical path. The Class A entry rule is a completed external assessment within the past twelve months. If yours is stale or still in progress, it is the longest pole on the schedule regardless of which class you eventually target — and it is the one item on this list that cannot be compressed by spending more.
Build for continuous evidence, not for a document. The Class A package overview describes a machine-readable report that replaces the historical System Security Plan, maintained “using automation as changes occur” and refreshed at least once every three months. That is a standing engineering cost, and it is the same commitment at Class B and Class C over a larger indicator set.
Do not stand the CMMC work down. The gate moved from the calendar to the document in front of you. An applicable solicitation can still specify a certified assessment on its own terms, and a prime can still flow the requirement down by contract — which is how it usually arrives: a supply-chain questionnaire with a short turnaround, rather than a solicitation you had months to plan for. The distance between having a security program and passing an assessment is measured in quarters, and no proposal window is that long.
Assume the buyer checks. The ruleset was developed in the open across thirty-one public requests for comment, and marketplace status is public. FedRAMP has reported a 20x life cycle running at 30 days or less from submission: the path is faster than it was, and so is a contracting officer’s ability to see who has taken it.
Dates that matter next
1 January 2027 — the 2026 consolidated rules become mandatory for all stakeholders. The only fixed date on this list that reaches every cloud service provider.
11 June 2027 — the last day a new legacy Rev5 certification application is accepted.
No date published — a replacement for the suspended CMMC certification mandate. Reinstating a requirement of this kind is a rulemaking, and a rulemaking is published before it takes effect, so this is a page to watch rather than a date to plan against.
Whenever it arrives — the requirement that the solicitation or the prime’s questionnaire in front of you actually states. Since the suspension this is the only CMMC date that is genuinely yours, and it is not on a public calendar.
How this issue is sourced
Every FedRAMP date above links to where FedRAMP publishes it. Those links were opened and dated on the observation date printed at the top of this page, when we published our Class A explainer, and they have not been re-opened since — which is stated rather than implied, because the alternative is a citation that looks fresher than it is.
The CMMC paragraphs name the memo by its identifier and the clause by its number instead of deep-linking them, for the same reason: a link nobody here has opened would be the one unchecked claim on a page whose argument is that the record is checkable. Confirming those URLs is queued, not skipped.
One further item carrying a 1 January 2027 effective date sits on the acquisition-regulation side of the calendar and is deliberately absent from this issue. Our own fact list records it; no source in this repository states which document it is, and a compliance brief is the wrong place to find out.
This issue summarises published federal rules for general information. It is not legal or compliance advice, and the controlling text is the clause in your contract and the terms of the solicitation in front of you.
Check a vendor's posture in one search
Searching any federal vendor is free — the award record, the compliance overlay, and the readiness score, on public data. Start with your own company, or with a prime you are chasing.
The long version on CMMC
Six pages on what the suspension left standing — scoping, the level question, where the requirement set consumes engineering time, and a sequence that fits inside a live pipeline. One send, after you confirm the address.
It is one document, not a subscription — why that is, on the index.