The Pentagon suspended CMMC Phase 2 on July 13, 2026, and on September 3 it made that suspension binding. Neither action removed a single security requirement from your contracts. What was paused is the part where an outside assessor checks your work.
Here is the whole of it in one sentence: third-party certification by an accredited assessor, which was due to start appearing in solicitations on November 10, 2026, is off the table for now, while self-assessment, NIST SP 800-171, the safeguarding clause, your score in the Supplier Performance Risk System and your annual affirmation are all still live and still enforceable. The Cybersecurity Maturity Model Certification programme is the Defense Department's scheme for verifying that contractors handling government information actually implement the controls they claim. Phase 1, in effect since November 10, 2025, runs on self-assessment. Phase 2 was the shift to mandatory certification by a C3PAO, a company accredited to assess other companies. Phase 2 is what stopped.
This page is for the people who have to act on that: the IT lead at a mid-sized defense supplier, the contracts manager reading clause lists, the sysadmin who owns the system security plan. The thing most readers get wrong is the direction of the risk. A pause on outside verification does not lower your legal exposure. It raises it, because your self-attestation is now the only thing the government has, and the Justice Department has kept settling cases over inflated scores right through the pause.
One more fact to set expectations. The 60-day review that accompanied the suspension closed around September 11 to 13, 2026. As of September 18, no findings have been made public. The department's chief information officer, Kirsten Davies, receives the report and decides what is released, and Nextgov/FCW reports that timing sits with her. You are working without a published endpoint. Plan accordingly.
Why the September 3 memo mattered more than the July announcement
In July, the department announced a suspension and launched a review. That was policy. A future memo could have undone it in an afternoon.
On September 3, 2026, John Tenaglia, the principal director for defense pricing, contracting and acquisition policy, signed a memo directing a class deviation. A class deviation is an instruction that changes how contracting officers write and administer contracts, and it has the force of acquisition regulation until it is rescinded or folded into the FAR or DFARS. Washington Technology's account makes the practical point: reversing a class deviation takes formal regulatory action, not a press release.
The operational difference is the word "strip". Under the July memo, Phase 2 requirements were held in abeyance. Under the deviation, contracting officers are told to remove third-party assessment requirements from solicitations and from contracts that already carry them, and to designate self-assessment levels instead. CyberZ, which walks through Class Deviation 2026-O0025, Revision 3, quotes the instruction that contracting officers apply the Revolutionary FAR Overhaul Part 240 construct rather than the CMMC final rule clauses issued in November 2025.
| July 13, 2026 suspension memo | Class Deviation 2026-O0025 Rev 3, September 3, 2026 | |
|---|---|---|
| Legal form (Washington Technology, September 2026) | Departmental policy announcement | Binding acquisition regulation until rescinded or absorbed into the FAR or DFARS |
| What contracting officers do (CyberZ, September 2026) | Hold Phase 2 requirements in abeyance | Remove third-party assessment requirements from new and existing solicitations and contracts |
| Which clause set applies (CyberZ, September 2026) | The November 2025 CMMC final rule clauses | The Revolutionary FAR Overhaul Part 240 construct instead of the CMMC final rule clauses |
| What goes in a new solicitation (CyberZ, September 2026) | Phase 2 designations expected from November 10, 2026 | Level 1 Self or Level 2 Self designations |
| How it gets reversed (Nextgov/FCW, September 2026) | Another policy memo | Formal rulemaking |
| Effect on self-attestation (Nextgov/FCW, September 2026) | None, still mandatory | None, still mandatory |
Davies has been explicit that the pause is about cost and burden, not about the value of the controls. "This isn't about whether cybersecurity is important or not. It is. It's critical. It's vital," she told Nextgov/FCW. At a September briefing covered by DefenseScoop, she said the programme had been hitting small and medium-sized businesses "really, really hard and inappropriately hard", and that "compliance doesn't equal security", pointing toward continuous monitoring rather than point-in-time assessment. That is a signal about where reform may go. It is not a change to anything you owe today.
What is paused and what is still live
Read this table as your scope statement. The left column is the obligation, the middle is its status on the date of writing, the right is who says so.
| Obligation | Status on September 18, 2026 | Reported by |
|---|---|---|
| CMMC Phase 2 transition, originally November 10, 2026 | Suspended in July, now stripped from contracts by class deviation | Federal News Network, July 2026; CyberZ, September 2026 |
| Level 2 C3PAO certification and Level 3 DIBCAC designations | Paused | Secureframe, September 2026 |
| CMMC waiver procedures | Paused | Secureframe, September 2026 |
| CMMC Phase 1 self-assessment, in effect since November 10, 2025 | Unaffected and in force | Wiley Rein, July 2026 |
| NIST SP 800-171 Rev 2, all 110 security requirements | In force as the operative standard during the pause | Wiley Rein, July 2026; DefenseScoop, September 2026 |
| DFARS 252.204-7012 safeguarding and 72-hour incident reporting to DIBNet | Untouched by the deviation and fully applicable | CyberZ, September 2026; Wiley Rein, July 2026 |
| A current self-assessment score posted in SPRS | Required for CUI work and treated as a legal representation to the government | CyberZ, September 2026 |
| Annual affirmation of continuous compliance by a named official | Still required | CyberZ, September 2026; Summit 7, 2026 |
| Government-led Medium and High assessments by DIBCAC | Continue unchanged, scores uploaded to SPRS by DIBCAC | Summit 7, 2026 |
| Prime contractor flowdown requirements | In force | Secureframe, September 2026 |
| False Claims Act exposure for an inaccurate score or affirmation | In force and actively enforced | CyberZ, September 2026; Nextgov/FCW, September 2026 |
The clause numbering is where people trip. Two sources disagree, and the disagreement is worth knowing about before you argue with anyone internally.
Summit 7 reports that the Revolutionary FAR Overhaul, which took effect on February 1, 2026 through 38 simultaneous DFARS class deviations, eliminated provision 252.204-7019 entirely and renumbered clause 252.204-7020 to 252.240-7997, removing the basic self-assessment upload requirement that used to sit under those two. In that account, the SPRS obligation did not vanish; it moved, because clause 252.204-7021, the CMMC clause, was not changed and still requires a current self-assessment plus an annual affirmation.
IT SecOps Cloud, writing in July 2026, describes 7019 as unaffected and continuing, and 7020 as continuing unchanged.
Both accounts land in the same place for practical purposes: your score has to be current, accurate and defensible, and the government retains its access to assess you. What settles the numbering question for your company is not a blog post, it is the clause list in your own contracts and a written answer from your contracting officer. That is step one below.
The work to do in the next three weeks
Gather these before you start. If you begin the SPRS work without the evidence files, you will do it twice.
-
SPRS access for every CAGE code you hold
You need to see the score, the date it was entered, the assessment scope and the date of the last affirmation. Read-only access is enough for the audit; someone with entry rights has to be available for corrections.
-
The clause list for every active contract and open solicitation
Specifically whether each one carries 252.204-7012, 252.204-7021, 252.204-7025 or 252.240-7997. This is the document that tells you what you actually owe, not the trade press.
-
Your current system security plan and POA&M
The SSP describes how each of the 110 NIST SP 800-171 Rev 2 requirements is met. The plan of action and milestones lists the ones that are not met yet, with dates.
-
An inventory of FCI and CUI
Federal Contract Information and Controlled Unclassified Information: what you hold, which contract it arrived under, which systems it touches, and how the government marked it when it came in.
-
The name and title of the official who signs the annual affirmation
That person is making a representation to the government. They should have read what they are affirming.
-
Contracting officer contacts, per contract, and prime security contacts, per subcontract
You will be writing to both in the steps below.
1. Find out which clauses you actually carry. Go contract by contract and record the clauses. Under the class deviation, contracting officers were told to strip third-party assessment requirements from existing contracts as well as new ones, but a clause in a signed contract binds until the contract is formally modified. You have done this step when you can name, for each active award, which safeguarding and assessment clauses apply and whether a modification is pending. Half a day for a small portfolio; longer if your contracts live in three systems and a filing cabinet.
2. Write to the contracting officer on anything carrying a CMMC clause. Ask two questions in writing: whether a modification removing the third-party assessment requirement is coming, and what assessment designation applies in the meantime. Keep the answer. If the review produces a new rule later, the written record of what you were told is the thing that protects you. Cost is an email and a fortnight of patience.
3. Open SPRS and look at the date. Not the number, the date. A score entered eighteen months ago against a system that has since moved to a new tenant is not a current representation of anything. Note the score, the scope of the system it covers, and when the affirmation was last made. Twenty minutes.
4. Rebuild the score against evidence, requirement by requirement. This is the longest step and the one that matters most. For each of the 110 requirements in NIST SP 800-171 Rev 2, ask whether you can put a document, a screenshot, a configuration export or a log in front of an assessor today. Not a policy that says you will do it. Evidence that you do. The advisory guidance circulating since the pause, including ComplianceHub's breakdown of the task force decision point, puts this first for a reason: during the pause your self-assessment is the only verification in the system. Budget weeks, not days, if it has never been done properly.
5. Correct anything that is overstated, and correct it now. If the rebuilt score is lower than what is posted, post the lower one. A voluntarily corrected score is a compliance record. A stale inflated score found later by an auditor or a whistleblower is a False Claims Act exhibit. The step is done when the number in SPRS is the number your evidence supports.
6. Close POA&M items rather than rolling their dates. Every deferred item is a requirement you have told the government you will meet by a date you then moved. Pick the items that are cheapest to actually finish and finish them. Success looks like a shorter POA&M at the end of the quarter than at the start.
7. Confirm the 72-hour incident reporting path works. DFARS 252.204-7012 requires rapid reporting of cyber incidents to the department through DIBNet, and the clause is untouched by any of this. Check that the medium assurance certificate is valid, that at least two people know how to file, and that the on-call runbook names them. Test it as a tabletop. An afternoon.
8. Ask your primes what their own deadlines are. Flowdown requirements did not pause. Secureframe's timeline notes that Elbit America told suppliers on July 16, 2026 that "this pause is an opportunity to strengthen your program, not a reason to delay it", and that L3Harris Missile Solutions did not withdraw a July 30 Level 2 certification deadline for its missile solutions suppliers. Your contract with a prime is a commercial contract. The department's class deviation does not rewrite it.
9. Split the budget in two. One line for implementing controls, one for certification readiness. The first is spending you owe regardless of what the task force recommends. The second is spending whose timing is now genuinely uncertain. Keeping them separate is what lets you defend the first line when finance asks why you are still spending on a suspended programme.
10. Keep the people. The single most expensive mistake available to you right now is releasing the staff who know your SSP, then rehiring in a hurry when a new rule lands with a compliance date attached.
The mistakes the reporting keeps turning up
Reading "suspended" as "withdrawn". The clearest evidence against that reading is the enforcement record. CyberZ notes two Justice Department settlements over self-assessment accuracy: LOGZONE at $507,144 in June 2026, and Honeywell Aerospace at $2,042,518 on September 1, 2026, two days before the class deviation was signed. Nothing about the pause slowed that down. If anything the sequencing reads as a statement.
Assuming your legal exposure went down. It went up. When a third party certifies you, the certification is a second set of eyes and a partial shield. Without it, the only representation on file is yours. ComplianceHub puts the principle in one line: "A suspension is a change to when a third party checks, not to what is required." Recognise this failure by the sentence "we'll sort the score out when the assessors come back". The fix is step four above.
Concluding that the SPRS obligation disappeared with 7019. Under the Revolutionary FAR Overhaul, the self-assessment upload requirement moved out of the old provision and clause pair, but clause 252.204-7021 was not amended and still demands a current score and an annual affirmation from a named official. If someone in your organisation has concluded that no clause now requires a score, make them show you the clause list for a specific contract. That argument dies on contact with the actual document.
Documenting controls instead of implementing them. An SSP that describes multifactor authentication on a system that does not have it is not a compliance artefact, it is a written misstatement. Recognise it by the gap between the SSP text and what an engineer can demonstrate from a console in ten minutes.
Scoping CUI by guesswork. DefenseScoop reports that industry flagged inconsistent government marking of CUI as a source of operational friction, and Secureframe cites the SBA Office of Advocacy identifying definitional uncertainty around CUI as the top cost driver for small businesses: "no small business should have to build and price cybersecurity architecture around an undefined category of information." That complaint is legitimate and it may be addressed by the reform. Until it is, the safe move is to document how you determined your scope, keep the contract language that drove the decision, and raise unmarked or ambiguously marked material with the contracting officer in writing.
Cancelling everything. Third-party assessor organisations themselves have raised concerns about their future role, according to DefenseScoop, which tells you the market is uncertain. That is a reason to pause a purchase of assessment services, not a reason to stand down the engineering work those services were going to examine.
Cases where the answer changes
You already have a signed contract with the CMMC clause in it. The clause is binding until the contract is formally modified, per IT SecOps Cloud's reading of the July position, even though contracting officers have since been told to strip third-party requirements. Do not self-modify. Get the modification.
You handle FCI but no CUI. Level 1 self-assessment territory. The safeguarding obligations for Federal Contract Information continue, and the Wiley Rein alert confirms both Level 1 and Level 2 self-assessments remain required. What you are not doing is preparing for a C3PAO.
DIBCAC calls. Government-led Medium and High NIST SP 800-171 assessments continue unchanged under the renumbered clause 252.240-7997, and DIBCAC uploads the resulting score to SPRS itself, according to Summit 7. This is the part people forget: the pause removed the commercial assessor, not the government one. If your score is optimistic, a Medium assessment will find out.
You are a subcontractor to a prime that set its own date. The prime's requirement governs your subcontract. L3Harris is the documented example of a deadline that stayed in place after the announcement.
You already paid for and passed a C3PAO assessment. Industry has asked for safe harbour for firms already assessed, along with a graduated path between Level 1 and Level 2, risk-based prioritisation of high-impact controls, and reciprocity with FedRAMP. Those are requests in the RFI record as reported by Secureframe. None of them is policy yet. Treat your assessment as evidence of a mature programme, not as a credit against a future requirement, until a rule says otherwise.
You are trying to time the next move. Four outcomes are plausible from the review, in ComplianceHub's framing: Phase 2 resumes later largely as designed; certification narrows to a smaller population with most contractors on self-assessment, which that source calls the most likely; enhanced self-assessment plus senior executive attestation replaces certification for the majority; or the model is restructured more deeply with a longer runway. Notice what every one of those has in common. The safeguarding clause, the 110 requirements, the SPRS score and the False Claims Act exposure survive all four.
The numbers driving the review, and what a wrong score costs
Put the two halves of that grid next to each other and the case for the pause is visible. The Wiley Rein alert cites an SBA cost figure approaching $600,000 per company across more than 100,000 small businesses. RFI feedback summarised by Secureframe puts per-company cost at $250,000 to $500,000 over a three-year window. IT SecOps Cloud reports roughly 100 approved C3PAO assessors available against more than 100,000 organisations needing assessment, which is the arithmetic that made November 10, 2026 look implausible whatever anyone thought of the controls.
The attrition argument sits behind it. Secureframe cites a 32 per cent decline in small business prime contractors, from 43,621 in 2014 to 29,584 in 2024. DefenseScoop reports that more than half of RFI respondents supported pausing Phase 2.
Now the other side of the ledger. Two settlements in four months, for a combined $2.5 million, both about the accuracy of what a contractor said about itself rather than about a breach. That is the price list for the one obligation the pause left entirely intact. Whatever the review recommends, a score you cannot defend with evidence is the exposure that is live today.
Questions people are asking
What to do this week
Open SPRS today and read the date on your score. If it predates your last significant infrastructure change, it is not current, and currency is the part the government can check without visiting you.
Then do three things before the task force findings land. Send the written question to each contracting officer about clauses and pending modifications. Start the requirement-by-requirement evidence rebuild, beginning with the requirements you scored highest on, because those are the ones an auditor tests first. Ask each prime whether its certification deadline stands.
Everything else is waiting for a report that has not been published and a rule that has not been written. The obligations that survive every plausible version of that rule are the ones listed above, and they are enforceable now.
Comments
No comments yet. Be the first to comment!
Leave a Comment