DRAFT PREVIEW — NOT PUBLISHED — PUBLICATION DATE PENDING

The Defense Compliance Report — Research & Data

CMMC Certification Tracker: Level 2 Certifications, C3PAOs & Assessment CapacityDated certification and ecosystem snapshots from Cyber AB town halls

By The Defense Compliance Report · Dataset compiled October 3, 2026 · Draft preview: public update date pending · Latest source snapshot:

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and Defense Industrial Base (DIB) compliance. This page is educational reference material, not legal or compliance advice.


As of the Cyber AB town hall

The Cyber AB reported 2,362 final Level 2 certificates, 71 conditional certificates, and 151 assessments in progress. Its deck also reports 117 Authorized or Accredited C3PAOs, 1,179 Certified CMMC Assessors, and 681 Lead CCAs. These are reported status and ecosystem counts, not unique-company totals, available appointments, or a measured assessment backlog. The data snapshot is September 29; this dataset was compiled October 3, 2026.

Table 1 — CMMC certification ecosystem snapshot
MetricFigureSource snapshot
Final Level 2 Certificates of CMMC Status2,362September 29, 2026, primary deck p. 19
Conditional Level 2 Certificates of CMMC Status71September 29, 2026, primary deck p. 19
Level 2 assessments in progress151September 29, 2026, primary deck p. 19
Authorized or Accredited C3PAOs117September 29, 2026, primary deck p. 20
Certified CMMC Assessors (CCAs)1,179September 29, 2026, primary deck p. 20
Lead CCAs681September 29, 2026, primary deck p. 20
Trailing three-month net change in final certificates232 per monthJuly–September 2026: (200 + 239 + 257) ÷ 3

Source: Cyber AB September 29, 2026 primary slide deck, pp. 19–20. Monthly changes use the July, August, and September decks linked in the data table. Checked October 3, 2026. These are certificate-status counts and ecosystem headcounts, not unique-company counts, a compliance rate, available assessment appointments, or a measured backlog.

How many companies are CMMC certified right now?

The September 29, 2026 Cyber AB town hall reported 2,362 final Level 2 Certificates of CMMC Status, 71 conditional certificates, and 151 Level 2 assessments in progress. These are the latest town-hall figures included in this tracker. CMMC status attaches to an assessed information-system scope; one organization can hold multiple certificates. The certificate count therefore cannot answer how many unique companies are certified.

The company-versus-system distinction is not pedantry. One organization can hold multiple certificates covering different enclaves or systems, each with its own CMMC Unique Identifier (UID). A single certified system operated by a joint venture can satisfy the requirement for multiple JV members, provided the right UIDs appear in the proposal — guidance the CMMC Program Management Office clarified in FAQ C-A6 and the Cyber AB discussed at the May 2026 town hall.

So when this page says “certificates,” it means certificates. The number of unique organizations holding at least one certificate is not publicly reported, and we do not estimate it.

CMMC certification tracker by month: the full Level 2 data table

The retained series runs from April 2025 through September 2026. Final certificates rose from 1,666 in the June snapshot to 2,362 in September, a net increase of 696 across the three intervening town-hall snapshots. The July, August, and September changes were +200, +239, and +257. These are changes between point-in-time reported counts; record corrections and reporting timing can also affect a monthly difference.

Table 2 — CMMC Level 2 certification and ecosystem counts by month ( – )
MonthFinal L2 certsNet newConditionalIn progressAuthorized / accredited C3PAOsCCAsLead CCAs
85—4~10067345—
115+~303–4~6070364—
†168≈53——73389266
258+90—8777455300
‡270+1299179496304
366+9616—82——
431+652110483567—
§459+28——88623384
559+1002911593635377
773+2143410997688425
896+1233611098748452
1,074+17839—103759—
1,198+12442124103766489
1,391+19347140———
1,666+275——1071,013596
1,866+200581681111,082637
2,105+239661591131,130659
2,362+257711511171,179681

Source: Cyber AB monthly town halls (primary: per-month pages with slides and recordings at cyberab.org/News-Events/Town-Halls), plus the direct monthly decks: July 2026, August 2026, and September 2026. The combined C3PAO category is "Authorized or Accredited C3PAOs"; applicant firms are excluded. June’s CCA count is 1,013 from the July deck’s June comparison column. The June final-certificate figure remains qualified as a chart-read value in the retained history. Prior rows and restatement notes remain; they were not all independently re-audited during this update. Compiled and maintained by The Defense Compliance Report. Blank cells indicate the figure was not stated in that month’s public materials; we leave them blank rather than estimate.

† The written record reported figure as 158; subsequent Cyber AB chart materials show 168 for June. We record the restated value — see restatement handling and changelog.

‡ is the series’ clean baseline. The Cyber AB removed duplicate records from eMASS that month, so August’s small net gain (+12) is net of the de-duplication — see restatement handling and changelog.

§ materials referenced 115 assessments “pending affirmation” in SPRS — a post-assessment administrative step — which is not the same measure as “assessments in progress,” so we exclude it from that column. November’s 623 CCA and 384 Lead CCA figures come from the official Cyber AB November town hall deck.

: the 107 C3PAO count and 596 Lead CCA figure appear in the June record. The July deck’s June comparison column gives 1,013 CCAs. The 1,666 final-certificate figure remains chart-read from the June 30 materials; the July–September observations do not retroactively remove that qualification.

Sources by month:the Cyber AB does not publish these figures on a static page; they are presented orally and in slides at each monthly town hall (typically the last Tuesday of the month). The primary record is the Cyber AB’s own per-month town hall page, where each session’s slide deck and recording are posted: August 2025 · September 2025 · October 2025 · November 2025 · December 2025 · January 2026 · February 2026 · March 2026 · April 2026 · May 2026 · June 2026 · July 2026 · August 2026 · September 2026.

Download the October 3, 2026 dataset (CSV) — no email required. Download the dated JSON · Current CSV alias · Before this update: archived audit baseline CSV. Data dictionary: month · final_l2_certificates (value used in the tracker; restated where applicable) · final_l2_reported_value (as originally reported) · net_new_final · conditional_l2 · assessments_in_progress · authorized_c3paos · ccas · lead_ccas · source_url · notes · primary_source_url · secondary_source_url · source_publication_date · source_page · verified_on · c3pao_count_definition.

CMMC certification statistics: what this data shows — and what it doesn’t

The latest three monthly net increases average 232 final certificates per month. At the September snapshot, the Cyber AB reported 117 Authorized or Accredited C3PAOs and 1,179 CCAs, including 681 Lead CCAs. These figures describe reported certificate volume and people or firms in the ecosystem. They do not measure appointment availability, utilization, a queue of ready applicants, or the number of unique certified companies.

It does not show which organizations are certified (no public list exists), how many unique organizations the certificates represent, C3PAO booking calendars, failed or paused assessments, or when any particular contractor’s certification comes due. The Certification Gap below compares a historical planning estimate with certificate counts; it is not a compliance rate or forecast of an individual deadline.

What is the CMMC Certification Gap?

This tracker’s Certification Gap is a model comparison: the original program-rule RIA’s 76,598 planned Level 2 certification-assessment entities minus the reported final-certificate count. With the September 29 snapshot, the arithmetic is 76,598 − 2,362 = 74,236. Entities and information-system certificates are different units, and one entity may hold multiple certificates. Treat this as a planning proxy, not a count of noncompliant companies, a booking backlog, or assessments due on one date. The July 13 suspension also means the original later-phase schedule is not an operative procurement deadline.

The denominator comes from DoD’s own Regulatory Impact Analysis for the CMMC Program rule (32 CFR Part 170, RIN 0790-AL49). Its “Estimated Number of Entities by Type and Level” table projects 76,598 entities requiring a Level 2 certification assessment — 56,689 small entities and 19,909 other-than-small — out of 221,286 total defense industrial base (DIB) entities. The full document is public on Regulations.gov.

Which number is right — 70,000 contracts, 76,598 entities, or 80,000 organizations?

Several official-sounding denominators circulate, and they measure different things. Writers routinely conflate them, so here is the reconciliation:

Table 3 — The four numbers people quote for “how many need CMMC Level 2”
FigureWhat it countsSource
76,598Entities DoD estimates will need a Level 2 certification (C3PAO) assessmentDoD Regulatory Impact Analysis, 32 CFR Part 170 — the denominator this tracker uses
80,598All Level 2 entities: the 76,598 above plus ~4,000 expected to qualify for Level 2 self-assessmentSame DoD RIA table (76,598 + 4,000)
~70,000Contracts — not entities — DoD estimates will carry a Level 2 certification requirementDoD PMO statement at the Cyber AB town hall, which also noted the number of affected organizations could run higher
~221,000The entire DIB, all CMMC levels including the ~139,000 Level 1 self-assessment populationDoD RIA (221,286 total); often rounded up to “300,000+” in vendor materials

Source: DoD Regulatory Impact Analysis for the CMMC Program rule (Regulations.gov, docket DOD-2023-OS-0063); Cyber AB November 2025 town hall.

We retain the original 76,598 program-rule planning estimate for comparison; it is not a current census or a queue of ready applicants. On the historical all-Level-2 planning basis, the analogous arithmetic is 80,598 − 2,362 = 78,236 at the September snapshot. That population includes an estimated self-assessment group, so it should not be treated as a third-party assessment queue.

How many C3PAOs are there?

The primary deck reports 117 Authorized or Accredited C3PAOs. The same deck reports 1,179 Certified CMMC Assessors, including 681 Lead CCAs.

The category name matters: 117 is the combined authorized-or-accredited count, not a count of applicants and not a count of fully accredited firms alone. The Cyber AB Marketplace is the place to check an individual firm’s current status. An ecosystem total does not establish that a particular firm can take your assessment, serves your industry, or has appointments available.

Source: September 2026 Cyber AB primary deck, p. 20. The Cyber AB Marketplace is the place to check an individual firm’s current status.

Is there enough CMMC assessment capacity? Illustrative scenarios

Public certificate and assessor counts do not establish a national booking backlog. The calculations below show what would happen under fixed assumptions; they do not forecast when a contractor will become eligible, when an assessor can book work, or when suspended procurement phases will resume.

Table 4 — Illustrative time to cover the 74,236 planning gap at the September snapshot
ScenarioAssumed monthly paceMonths to clearYearsAssumptions
A — Latest three-month average held flat232/month320.026.7July +200, August +239, September +257; 696 ÷ 3
B — Six-month linear trend held flat at its next-three-month mean308.27/month240.820.1OLS fit to April–September changes [124, 193, 275, 200, 239, 257], x = 1–6; mean predicted x = 7–9
C — Hypothetical three-person teams393/month188.915.71,179 CCAs ÷ 3; each hypothetical team completes one assessment per month

Source: Cyber AB monthly primary-deck figures and retained historical tracker values. Calculations by The Defense Compliance Report, October 3, 2026. The denominator is the original program-rule RIA estimate, not a current census. Inputs are unrounded; months and years are rounded for display.

Scenario C is an illustrative staffing assumption, not measured capacity or a regulatory ceiling. The calculations omit assessor availability, Lead CCA requirements, organizational affiliation, conflicts of interest, readiness, assessment scope, failed assessments, POA&M closeouts, reassessments, changing demand, and future workforce growth. A certificate represents an assessed system scope, not necessarily a unique entity. For actual scheduling, obtain availability and scope-specific terms directly from the assessor.

Comparing activity with historical DoD planning models

The original program-rule RIA included a multi-year assessment-demand model. Its projections are historical planning context, not a restored Phase II deadline after the July 13 suspension. Certificate issuance cannot be compared with modeled entities or assessment events as if the units were identical.

This tracker preserves the source model and its assumptions so readers can reproduce historical comparisons without mistaking them for a compliance rate, current forecast or national booking backlog.

What changed in the restatement?

In , the Cyber AB reported 270 final Level 2 certifications and noted that duplicate records had recently been removed from eMASS — the DoD system where C3PAOs upload assessment results — “providing a more accurate count.” August’s unusually small net gain (+12 over July’s 258) is net of that cleanup. We treat as the clean baseline for the modern series, and we flag the earlier 2025 rows as pre-de-duplication figures that are not perfectly comparable.

A tracker that pretends every month-over-month change is organic growth is quietly wrong. Point-in-time counts pulled from a live administrative system get restated, and the honest way to handle that is to keep both the originally reported value and the restated value visible. That is how the CSV is structured: a final_l2_reported_value field holds the value as originally reported, the final_l2_certificates field holds the value the tracker uses (restated where applicable), and a note explains the difference. The figure is the other current example — reported as 158 in the written record, shown as 168 in later Cyber AB chart materials — and both values are preserved in the dataset with the discrepancy logged.

Is there a public list of CMMC certified companies?

No. The Cyber AB stated at its town hall that, for privacy and security reasons, it does not publish a public list of certified organizations. Certification status lives in eMASS and flows to SPRS (the Supplier Performance Risk System), where it is visible to DoD contracting officers — not to the public. That is why aggregate monthly counts, and this tracker of them, are the only public measure of certification volume.

For anyone who needs to verify a specific partner’s status — a prime vetting a subcontractor, for instance — here is what is and isn’t publicly checkable:

Table 5 — Public CMMC verification paths
QuestionPublic answer available?Reliable verification pathWhat remains nonpublic
Is a firm an authorized C3PAO?YesCyber AB Marketplace listing, which distinguishes authorized from candidate statusInternal authorization timelines and scheduling
Is an organization Level 2 certified?No public listeMASS/SPRS status, visible to DoD contracting officers; primes verify through contracting channels rather than public lookupThe certified-organization roster and certificate details
Is a certificate document trustworthy on its face?NoVerify against eMASS-backed status, not the paper — certificates carry CAGE codes and UIDs the Cyber AB advises against sharing publicly anywayWhether a supplied document matches the system of record, without a check
Can a prime verify a subcontractor?Yes, through contracting channelsSPRS-based verification during source selection and flowdown managementSub-tier statuses outside the prime’s contractual line of sight

Source: Cyber AB town halls, and ; compiled by The Defense Compliance Report.

The last two rows are not hypothetical. At the town hall, the Cyber AB disclosed that a counterfeit Certificate of CMMC Status had been discovered circulating among prime contractors vetting teaming partners — complete with a fabricated certifying official and a UID apparently lifted from a legitimate certificate. The fraud would not survive an eMASS check, which is precisely the point: as certification becomes a competitive differentiator, document-based verification is no longer enough.

What’s the difference between a Final and a Conditional Level 2 certificate?

A Conditional Level 2 (C3PAO)status means the assessment passed with an allowable Plan of Action and Milestones (POA&M) still open; under 32 CFR § 170.21, the POA&M must be closed out within 180 days or the conditional status expires. A Final Level 2 (C3PAO)status means all applicable security requirements were met — either outright, or after a successful POA&M closeout assessment. This tracker’s headline metric counts final certificates only; conditionals are tracked as their own column and never merged into the headline number.

Table 6 — Final vs. Conditional Level 2 status at a glance
Conditional Level 2 (C3PAO)Final Level 2 (C3PAO)
What it meansPassed with a limited POA&M openAll 110 NIST SP 800-171 Rev. 2 requirements met
Time limitPOA&M closeout within 180 days, per 32 CFR § 170.21Valid three years, with annual affirmations in SPRS
Counted in our headline metricNo — tracked separatelyYes
Latest public count71 ( town hall)2,362 ( town hall)

Source: 32 CFR Part 170 (§§ 170.17, 170.21, 170.22); Cyber AB town halls, primary deck, p. 19.

For the twelve snapshots where both counts are available, conditional certificates represent 2.9% to 4.9% of combined public final and conditional statuses. This is a descriptive ratio only; it does not measure assessment quality, unique organizations, or a trend in future POA&M outcomes.

Table 7 — Conditional certificates as a share of public Level 2 statuses
MonthFinalConditionalConditional share
27093.2%
366164.2%
431214.6%
559294.9%
773344.2%
896363.9%
1,074393.5%
1,198423.4%
1,391473.3%
1,866583.0%
2,105663.0%
2,362712.9%

Source: Cyber AB monthly town halls; share = conditional ÷ (final + conditional), calculated by The Defense Compliance Report.

What the July 13, 2026 suspension means for this tracker

The original phased schedule in 32 CFR Part 170 remains in the codified rule, but it is not the current implementation schedule. On July 13, 2026, the Department suspended the Phase II transition and later milestones. There is no active November 10, 2026 C3PAO procurement deadline and no announced replacement date.

This tracker continues to measure ecosystem output and capacity. Its “certification gap,” velocity, and months-to-clear figures are scenario analyses against the rulemaking demand model—not forecasts of a currently operative federal deadline.

Original phased schedule before the July 13, 2026 suspension — not currently operative

The dates below remain part of the original rulemaking schedule but are not the current implementation timetable.

Table 8 — CMMC phased implementation (original 32 CFR schedule, not current operative timetable)
PhaseBeginsWhat it adds
Voluntary periodRule effective; organizations could pursue Level 2 certification before any contract required it (early counts were seeded partly by Joint Surveillance Voluntary Assessments converting to certificates)
Phase 1 — ActiveDuring the suspension, new procurement requirement documents may designate only Level 1 (Self) or Level 2 (Self). New Level 2 (C3PAO) designations are suspended; check written amendments or modifications for existing instruments.
Phase 2 — SuspendedNew solicitations routinely require Level 2 C3PAO certification; DoD may defer within a contract; Level 3 may appear at DoD discretion — suspended July 13, 2026
Phase 3 — SuspendedLevel 3 (DIBCAC) requirements begin appearing routinely — suspended
Phase 4 / Full implementation — SuspendedAll applicable solicitations and contracts carry CMMC requirements as a condition of award — suspended

Source: 32 CFR § 170.3(e); Cyber AB town halls, and ; DoW July 13, 2026 suspension announcement.

The current observed benchmark is 232 net additional final certificates per month across the July–September snapshots. Original rulemaking demand projections remain historical models after the July 13 suspension. Neither those projections nor this tracker’s count establishes a universal November 2026 deadline or a current national booking backlog.

Prime contractors continue to set their own internal certification deadlines for suppliers as supply-chain risk decisions independent of DoD’s timeline. The cost of overstating your posture is also not theoretical: in the Department of Justice announced a $507,144 settlement with an Alabama defense contractor resolving False Claims Act allegations that it had self-reported a perfect 110 NIST SP 800-171 score in SPRS while a subsequent government assessment scored the same environment at −170; the settlement resolves allegations, with no determination of liability.

Methodology: how we build this tracker

We extract certification and ecosystem-capacity figures from each monthly Cyber AB town hall, record them against the month reported, preserve the original source for every cell, and log any later restatement instead of silently overwriting it. The source hierarchy is fixed: Cyber AB town hall materials first — the slide decks and recordings posted on each month’s page at cyberab.org/News-Events/Town-Halls, which is the primary source, since the Cyber AB is the DoD-authorized accreditation body and these figures originate as point-in-time pulls from eMASS; the written recap record second, used to corroborate and to fill months where a deck is not posted; secondary commentary never, except to cross-check. The CSV carries both source layers for every row.

July 13, 2026 suspension sources added to this tracker’s methodology: Department of War July 13, 2026 suspension announcement and the Implementing Procedures 26-P-1023 memorandum. Demand-model calculations in this tracker are scenario analyses against the rulemaking demand model — not forecasts of a currently operative federal deadline.

Fields captured each month: final Level 2 certificates, net-new finals, conditional certificates, assessments in progress, authorized C3PAOs, CCAs, and Lead CCAs. Cells the Cyber AB did not state that month stay blank — we do not interpolate, estimate, or carry values forward. Chart-read figures (values presented graphically rather than in text) are flagged as such until confirmed.

Formulas, stated so anyone can reproduce them: Certification Gap= 76,598 (DoD RIA estimate of Level 2 certification-assessment entities) − cumulative final Level 2 certificates. Trailing three-month velocity= sum of the last three months’ net-new final certificates ÷ 3. Months to clear= Gap ÷ velocity. Scenario assumptions are printed with each scenario. Everything derived is recomputed after each town hall; the underlying denominator is re-verified quarterly and whenever DoD amends the rule or publishes revised estimates.

Limitations: what this tracker does not tell you

Stating these plainly matters more to us than a tidier story would.

  • Certificates are not companies.CMMC status attaches to information systems within an assessment scope. One organization can hold several certificates; one certificate can serve a joint venture. The unique-organization count is not public.
  • The denominator is a planning estimate, not a census.DoD’s 76,598 figure is a rulemaking-era model built from historical contracting data and subject-matter judgment. DoD’s own RIA cautions that actual volumes may vary significantly because assessment demand is market-driven. The Gap inherits every limitation of that estimate.
  • Not everyone in the Gap is “due” at once.The original rollout dates are historical references; later-phase implementation milestones were suspended on July 13, 2026. The gap is not a due-date list and does not establish a count of currently non-compliant firms. Use the actual written solicitation, contract, and any amendment or modification.
  • Counts are point-in-time and restatable.Figures are eMASS pulls as of each town hall (typically the last Tuesday of the month), so “monthly” intervals are approximate, and history has been restated at least twice ( de-duplication; the 158/168 discrepancy). The changelog records every known case.
  • Capacity is more than headcount.C3PAO throughput depends on Lead CCA availability, background-investigation timing, team composition rules, conflict-of-interest restrictions, accreditation deadlines, and scope complexity — none of which a simple count captures. Future reassessments may also compete for assessor capacity; this tracker does not measure that demand.

This page is educational reference material, not legal or compliance advice. For obligations under a specific contract, the controlling sources are the solicitation itself, 32 CFR Part 170, and the official CMMC documentation at dodcio.defense.gov/CMMC.

How to cite this page

The Defense Compliance Report — Research. “CMMC Certification Tracker: Level 2 Certifications, C3PAOs & Assessment Capacity.” https://thedefensecompliancereport.com/research/cmmc-certification-tracker/. Draft preview; public update date pending. Dataset compiled October 3, 2026; latest source snapshot September 29, 2026. Underlying primary sources: Cyber AB monthly town halls; DoD Regulatory Impact Analysis, 32 CFR Part 170; DoW July 13, 2026 suspension announcement; Implementing Procedures 26-P-1023.

Dated per-month anchors (for example, #jun-2026) resolve to each month’s changelog entry, so a citation can point to a specific month’s snapshot even after later updates.

Frequently asked questions

How many companies are CMMC certified?

The Cyber AB town hall reported 2,362 final Level 2 Certificates of CMMC Status and 71 conditional certificates. These counts represent assessed information-system scopes, not unique companies. No unique-company total is supplied by these figures.

How many companies need CMMC Level 2 certification?

DoD’s Regulatory Impact Analysis for the CMMC rule estimates 76,598 entities will need a Level 2 certification (C3PAO) assessment, and 80,598 will fall under Level 2 overall including the ~4,000 expected to qualify for self-assessment. Separately, the DoD PMO has estimated roughly 70,000 contracts will carry a Level 2 certification requirement. These are planning estimates, not a census.

How many C3PAOs are there?

The Cyber AB primary deck reports 117 Authorized or Accredited C3PAOs. This combined count excludes applicant C3PAOs and is not a count of fully accredited firms alone. Check the Cyber AB Marketplace for an individual firm’s current status.

What is the CMMC Certification Gap?

Using the tracker’s historical program-rule planning basis, the September arithmetic is 76,598 planned entities minus 2,362 final certificates, or 74,236. This is a model comparison between different units; it is not a compliance rate, a booking backlog, or assessments due on one date.

Does a Conditional Level 2 certificate count as certified?

Conditional Level 2 is a recognized CMMC status subject to POA&M closeout within the applicable 180-day period. This tracker reports conditional and final certificates separately: the September 29, 2026 snapshot shows 71 conditional and 2,362 final certificates.

Is the CMMC deadline?

No. November 10, 2026 was the original 32 CFR Part 170 start date for Phase 2. The Department suspended the Phase II transition and later implementation milestones on July 13, 2026. There is no active November 10, 2026 C3PAO procurement deadline and no announced replacement date. Verify the current requirement from the written solicitation amendment, contract modification, or contracting-officer/prime direction.

How often is this tracker updated?

The tracker is refreshed when a new Cyber AB town-hall source has been reviewed. The page states the latest source snapshot and dataset compilation and public page-update dates separately. A new page date does not mean the underlying data were observed that day.

Changelog

Draft preview — public release date pending; dataset compiled October 3, 2026.

Added July 28, August 25, and September 29 primary-deck snapshots; latest figures are 2,362 final certificates, 71 conditional certificates, 151 assessments in progress, 117 Authorized or Accredited C3PAOs, 1,179 CCAs, and 681 Lead CCAs. Refined June’s CCA value to 1,013 from the July deck’s June comparison column, retaining the June final-count qualification. Recomputed model comparisons and scenarios, clarified that they do not establish a compliance rate or backlog, and replaced the unsupported 48-hour update promise. Historical data and restatement notes remain available. This entry will receive its public date only at release.

— v1.2.

Accuracy audit update: added “What the July 13, 2026 suspension means for this tracker” section; relabeled the four-phase table as historical context (original 32 CFR schedule, not current operative timetable); updated FAQ answer for “Is November 10, 2026 the CMMC deadline?” in both visible text and JSON-LD schema; added DoW July 13 suspension announcement and Implementing Procedures 26-P-1023 to the methodology source list; updated Last verified date. No change to data, formulas, or certified-count figures — latest count remains June 2026 (1,666 final certificates from the June 30 town hall).

— v1.1.

Post-audit corrections, all logged per our restatement policy: July 2025 capacity fields added from the written town hall record (77 C3PAOs, 455 CCAs, 300 Lead CCAs); November 2025 Lead CCA count (384) and March 2026 conditional count (39) added from the official Cyber AB town hall decks; Phase 2 contract-modification language corrected to reflect the 48 CFR rule’s bilateral-modification provision; CSV restructured to carry primary and secondary source URLs per row.

— v1.0.

Initial publication. Series compiled through from Cyber AB town hall disclosures. Known restatements carried into the dataset: (1) eMASS de-duplication — the Cyber AB noted duplicates were removed, “providing a more accurate count”; (270 final) is treated as the clean baseline. (2) figure reported as 158 in the written record, restated to 168 in later Cyber AB chart materials; both values preserved in the CSV. final-certificate figure (1,666) is chart-read pending written confirmation.