Skip to content
Back to blog

CMMC Class Deviation 2026-O0025 Revision 3: The Phase 2 Suspension Reaches the Contract File

CMMC Class Deviation 2026-O0025 Revision 3: The Phase 2 Suspension Reaches the Contract File

Revision 3 of Class Deviation 2026-O0025 was released on September 3 and signed by John M. Tenaglia at Defense Pricing, Contracting, and Acquisition Policy. It supersedes the July 16 version and tells contracting officers to use the revised FAR Part 40, DFARS Part 240, and DFARS PGI 240 instead of the codified text. The deviation and its attachments are published on the Defense Acquisition Regulations System class deviation page.

Sera Brynn reads these documents for a living. The firm operates as an Authorized C3PAO under the CyberAB (CPN 59175), a FedRAMP Independent Assessor, and a GovRAMP 3PAO, and has conducted assessments across defense and regulated environments since 2011. That vantage point matters here, because the difference between a policy announcement and a contractual obligation is where most of the confusion in the defense industrial base currently sits.

Most of Revision 3 has nothing to do with cybersecurity. There is a temporary waiver for two Alibaba entities under a court order out of the Northern District of California, semiconductor prohibitions under Section 853 of the FY 2025 NDAA, new restrictions on transferring Department employee data, unmanned aircraft prohibitions carried over from two earlier NDAAs, and cleanup on the definitions of covered lobbyist and Chinese military company.

For anyone holding a defense contract, the paragraph that matters sits on page two. Contracting officers must collaborate with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts, following the Chief Information Officer's July 13 memorandum on the Phase 2 suspension.

That direction first appeared in Revision 2. Its survival into September is the part worth noticing. The Department reopened this deviation eight days before the CMMC Reform Task Force was due to report, adjusted five separate statutory items, and left the CMMC language exactly as it was. No reinstatement, no replacement date, no hint of one.

The instruction contracting officers received

Five things are now directed:

    • Requiring activities may include CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement requests and requirement documents.
    • Baseline compliance with NIST SP 800-171 Revision 2 stays in place under DFARS 252.204-7012.
    • The November 2026 Phase 2 transition is suspended.
    • Program managers must initiate amendments to active solicitations and route them to the cognizant contracting officer, who issues the amendment as soon as practicable.
    • On existing contracts, contracting officers remove CMMC requirements by modification before the next option period is exercised, or through the next scheduled administrative modification.

The last one has a practical consequence that has been mostly lost in the coverage. Removal arrives on the contract file's own schedule. If your next option exercise falls in March, your CMMC clause is very likely still active today, and it binds you until a signed modification says otherwise. A Department announcement does not amend a contract. Only a modification does.

The framework is still printed in the attachment

Revision 3 does not strike CMMC from the DFARS. DFARS 240.371 appears in full, including the definitions of CMMC status, the CMMC unique identifier, and the currency standards for conditional and final assessments. The clause at 252.204-7021 and the solicitation provision at 252.204-7025 are both there, along with the prescription at 240.371-5 telling contracting officers to insert the clause until November 9, 2028 where a requiring activity specifies a level, and on or after November 10, 2028 for any contractor information system that will process, store, or transmit FCI or CUI.

Award eligibility reads the same as it did in June. A contracting officer checks the Supplier Performance Risk System and cannot award to an offeror without a current CMMC status at the required level for each CMMC UID. Levels 2 and 3 may sit conditional for up to 180 days, per 32 CFR Part 170. Level 1 requires a final status at award.

Everything needed to restart Phase 2 is sitting in the regulation, waiting on a decision.

Obligations nobody suspended

DFARS 252.204-7012 is untouched. Contractors handling covered defense information still provide adequate security, still implement NIST SP 800-171 Revision 2, and still report cyber incidents to DIBNet within 72 hours of discovery. Our incident response team handles that reporting window regularly, and 72 hours moves faster than most organizations expect.

DFARS 252.240-7997 continues to govern Medium and High assessments conducted by government personnel using NIST SP 800-171A, with summary level scores posted to SPRS and 14 business days for the contractor to rebut findings before posting. Where DCMA conducts the assessment, those results take precedence over any other assessment. Annual affirmations, subcontractor flowdown, and False Claims Act exposure on an inflated SPRS score are all where they were on July 12.

Practical next steps

Start with an inventory. Pull every active contract and open solicitation, note which ones carry 252.204-7021 or 252.204-7025, and note when each option comes up. That list tells you what you are actually obligated to maintain over the next twelve months, which is not the same as what the headlines suggest.

Then go back to the SPRS score. Rerun the self-assessment against evidence rather than against the memory of what was implemented two years ago. A score that overstates the environment is a False Claims Act problem, and the suspension does nothing to that. Correcting a score voluntarily is a manageable commercial conversation. Being corrected by a DCMA assessor is not. A CMMC mock assessment produces the same evidence review a certification assessment would, without the certification decision attached.

Finish CUI scoping if it stalled. Knowing where CUI lives, how it moves through the environment, and where the boundary sits retains value under every outcome the task force could recommend. Most organizations defer it because it is tedious and requires people from three departments in the same room.

Keep the flowdown assurance current. Primes are still asking suppliers to demonstrate NIST SP 800-171 Revision 2 compliance, and their contractual requirements do not follow Department discretion.

For organizations already engaged with a C3PAO, finishing costs less than restarting. A Final Level 2 (C3PAO) status still posts to SPRS, still satisfies any requiring activity that elects to specify it, and now sits in the market as a differentiator rather than a ticket of entry. Contractors who hold it have already produced evidence their competitors will need later, on a timeline set by someone else.

Dates to keep in front of you

The CMMC Reform Task Force delivers recommendations to the Department CIO around September 11 to 13, sixty days from the July 13 memorandum that Federal News Network first reported. Industry expects the public version between late September and early October.

Three instruments can change what a contract requires: a new class deviation, a DFARS rule, or an amendment to 32 CFR Part 170. Everything else, including the task force report itself, is advice.

The FAR CUI rule folded into the June 23 rulemaking deserves equal attention. Contractors selling to both defense and civilian customers gain little from a Department pause if governmentwide requirements arrive to fill the gap. Holland & Knight reached the same conclusion in its analysis of the July memoranda.

And November 10, 2028 is still in the deviation text. That is the date the CMMC clause applies to any contract involving FCI or CUI on a contractor information system, absent a change to the regulation between now and then.

The executive read

The Department removed a gate. It did not lower a standard. Organizations that treat Revision 3 as permission to stand down will be doing compressed remediation in 2028 while their competitors are bidding. Organizations that keep implementing NIST SP 800-171 Revision 2 are in the same position they occupied in June, with more time and less pressure on the calendar.

Frequently Asked Questions

Is CMMC canceled?

No. CMMC is suspended at Phase 2, not repealed.

The July 13 memorandum paused the November 10, 2026 transition to C3PAO certification as a condition of award, along with later implementation milestones. Class Deviation 2026-O0025 Revision 3 carries that pause into acquisition instruction. The program itself remains codified at 32 CFR Part 170, and DFARS 240.371 and clause 252.204-7021 remain printed in the deviation text.

Does the suspension remove the CMMC clause from a current contract?

Not automatically, and not immediately.

Contracting officers are directed to remove CMMC requirements by modification before the next option period is exercised or through the next scheduled administrative modification. Until that modification is signed, the clause remains in force on that contract. Contractors should confirm removal in the contract file rather than assuming it.

Do defense contractors still need an SPRS score?

Yes. DFARS 252.204-7012 and the assessment requirements at DFARS 252.240-7997 are unchanged.

Contractors handling covered defense information must implement NIST SP 800-171 Revision 2, maintain a current summary level score in SPRS, and file annual affirmations of continuous compliance. An overstated score carries False Claims Act exposure that no memorandum or class deviation suspends.

Should we cancel a scheduled C3PAO assessment?

Not ideal. Completing an engagement in progress costs less than restarting it later.

A Final Level 2 (C3PAO) status still posts to SPRS and still satisfies any requiring activity that elects to specify a certified level. Organizations that hold certification now compete against a field that will need to produce the same evidence on a schedule set by the Department rather than by themselves.

When will the Department announce a decision on CMMC reform?

Recommendations reach the Department CIO around September 11 to 13, 2026, with public release expected between late September and early October.

The task force report is advice, not regulation. Contractual obligations change only through a new class deviation, a DFARS rule, or an amendment to 32 CFR Part 170.

Does the Phase 2 suspension apply to civilian agency contracts?

No. CMMC has always been a Department of War requirement.

Contractors selling to civilian agencies should track the FAR CUI rule folded into the June 23, 2026 rulemaking, which would apply NIST SP 800-171 derived requirements across federal contracts. Organizations serving both markets may see little net relief.