The Office of the CIO at the Department of War released Revision 2.3 of the CMMC Program Frequently Asked Questions on April 29, 2026. The release added three new entries and restructured scoping content into a dedicated section. Among the new entries, F-Q5 carries the broadest operational implications. It establishes a documented workflow for managing changes within a CMMC environment, converting a cluster of related controls into a single procedural sequence that the program office now expects organizations to follow.
The threshold question
A reasonable first question is whether F-Q5 applies to every change or only to meaningful ones. The answer is both. The procedure applies broadly to changes that may affect Federal Contract Information, Controlled Unclassified Information, security requirements, or assessment scope. Within that population, a smaller subset crosses the threshold of significant change defined in C-Q12 and may require reassessment.
The operative test for significance comes from a parenthetical inside F-Q5. If the security impact analysis identifies a new risk that is not addressed in the existing System Security Plan, the change is probably significant. That sentence shifts the determination from a subjective judgment to a documentary one. The SSP either contemplates the risk or it does not. The contents of the SSP at the time of the change become the reference point.
F-Q5 names five controls that operate across three phases of every change.
- CM.L2-3.4.4Security impact analysis for the proposed change
- AC.L2-3.1.3Analysis of effects on CUI flow
- CM.L2-3.4.3Documentation of the change in the formal change management process
- CA.L2-3.12.2Operational Plan of Action describing the change and any temporary risks
- CA.L2-3.12.4System Security Plan update reflecting the completed change
The three phases of the workflow
The before phase begins when a change is proposed and ends when the Affirming Official approves the analysis. Two written analyses are produced. The security impact analysis examines whether the change introduces new risk. The CUI flow analysis examines whether the change alters where CUI moves, rests, or is accessed. Both analyses enter the formal change management system, and the change does not advance to execution until the Affirming Official has reviewed them and recorded the review.
The during phase opens with the creation of an Operational Plan of Action. The OPA is distinct from a Plan of Action and Milestones. A POA&M addresses gaps identified during a CMMC assessment and carries a 180 day remediation window, while an OPA is the working record of an in-progress change and any temporary risks that exist while the work proceeds. The OPA functions as protective documentation when temporary deficiencies might otherwise be discovered without context during a later assessment.
The after phase closes the loop with an update to the System Security Plan. The update reaches every section affected by the change, which typically extends well beyond the asset inventory. Data flow diagrams, boundary descriptions, configuration baselines, role definitions, and control narratives may all need revision. The Affirming Official reviews the updated SSP before the next annual affirmation, which is the second of two AO touch points the workflow requires.
The two business consequences
Two consequences flow from the structure of the workflow that executives need to understand. The first is that the individual signing the annual cybersecurity attestation now bears responsibility for a continuous record that an assessor can audit. The False Claims Act can create organizational and, in some circumstances, individual exposure when cybersecurity attestations are knowingly false or unsupported by the facts, and the Department of Justice has pursued contractor settlements under the Civil Cyber Fraud Initiative since 2021. The procedural artifacts F-Q5 describes are the evidence that supports the affirmation.
The second is that operational pressure to move quickly on changes now collides with a procedural workflow that takes time. Building the procedure into normal change management is sustainable across the volume of changes any active business generates, while handling each change as a one-off compliance exercise produces gaps that accumulate over time and become visible during assessment.
The five artifacts F-Q5 produces form a chain that an assessor can follow from end to end.
- 1.Security Impact Analysis referencing the change description and the SSP sections it implicates
- 2.CUI Flow Delta Analysis referencing the SIA identifier and the data flow diagram revision
- 3.Change Management Ticket referencing the SIA and the CUI flow analysis, recording the Affirming Official review
- 4.Operational Plan of Action referencing the change ticket and the SIA, recording progress, mitigations, and closure
- 5.SSP Revision referencing the change ticket and the OPA, recording the Affirming Official review of the completed change
Why this matters now
The transition to third party assessments on November 10, 2026 makes the procedural gap consequential. A C3PAO assessor who finds an SSP update without a corresponding security impact analysis, or a change management entry without an Operational Plan of Action when temporary risk existed, is likely to treat that gap as evidence that the change process did not operate as documented. The cost of building the workflow now, while self-assessment is still the standard under Phase 1, is substantially lower than the cost of remediating it under a 180 day POA&M clock during a third party assessment.
The full white paper walks through each phase with sample artifacts that contractors can adapt to their own change records. The artifacts include a security impact analysis worksheet, a CUI flow delta, a change ticket structure, an Operational Plan of Action entry, and an SSP revision log. The field labels are constant. The content varies with each change. Organizations that adopt the templates as the structure of their internal change records will find that the F-Q5 workflow becomes a normal operating procedure rather than a compliance exercise.
Read the full paper
Sixteen pages. Three phases. Sample artifacts for each. References every claim to the FAQ, the regulation, and the underlying NIST publications.