The CMMC Suspension Is Now a Regulation. Here Is What Changed on September 3.
For two months, the CMMC Phase 2 pause was a policy memo. As of September 3, it is written into the acquisition regulations that contracting officers are bound to follow. That distinction is the whole story.
On September 3, 2026, John Tenaglia, the Department’s Principal Director for Defense Pricing, Contracting, and Acquisition Policy, signed Revision 3 of DARS class deviation 2026-O0025. The deviation directs contracting officers to apply the Revolutionary FAR Overhaul clause set instead of the CMMC final rule clauses, and to strip third-party assessment requirements out of solicitations and contracts. Unlike the July 13 suspension memo, a class deviation is binding acquisition regulation: it stays in effect until it is rescinded or incorporated into the FAR and DFARS, which means undoing it takes regulatory action, not a press conference.
- Revision 3 of class deviation 2026-O0025, signed September 3, 2026, converts the CMMC Phase 2 suspension from a policy choice into binding contract regulation. Contracting officers are directed to remove third-party assessment requirements from solicitations and contracts and to use the FAR Overhaul Part 240 clause set.
- The deviation landed eight days before the CMMC Reform Task Force's September 11 review deadline. The legal ground moved before the report did: self-assessment is now the codified default, and whatever the task force recommends has to travel through more regulatory action to change that.
- Nothing in the deviation touches DFARS 252.204-7012, the 110 controls of NIST SP 800-171 Rev 2, the SPRS score, or the annual affirmation. Government-led Medium and High assessments also survive under DFARS 252.240-7997.
- Self-attestation carrying the load is not a relaxation. DOJ settled with LOGZONE for $507,144 in June over a near-perfect self-assessment score a DoD audit found inaccurate, and with Honeywell Aerospace for $2,042,518 on September 1. The gap between the score you post and the truth is the live exposure.
- This week's job: identify which clause set each of your contracts actually carries, confirm your SPRS score still describes your environment, and keep the evidence trail running. The verification model changed. The obligations did not.
What the September 3 memo actually does
The memo, signed by Tenaglia on September 3 and reported by Washington Technology on September 9, issues Revision 3 of class deviation 2026-O0025. Two instructions matter.
First, contracting officers are directed to comply with the Revolutionary FAR Overhaul requirements, the Part 240 construct, instead of the CMMC final rule clauses that took effect in November 2025. Second, they are ordered to strip out of contracts the CMMC requirements for third-party assessments. Not pause them. Remove them from the documents.
Some context makes the mechanics legible. The original 2026-O0025 deviation took effect on February 1, 2026, as part of the government-wide FAR Overhaul. It stood up a new DFARS Part 240 for information security, eliminated DFARS 252.204-7019 as a standalone provision, and renumbered 252.204-7020 to 252.240-7997. Revision 3 now points the CMMC-specific requirements at that same construct, with the C3PAO condition-of-award language taken out. In practice, new solicitations designate self-assessment levels, and third-party assessment requirements come out of active paperwork.

Why a class deviation is a different animal than a memo
The July 13 suspension was a policy memorandum. A memo governs how the Department exercises its own discretion. It can be reversed by another memo, on any morning, with a signature. That is why the prudent read all summer was that Phase 2 was paused, not gone.
A class deviation is different in kind. It is an instruction to every contracting officer about which clauses go into contracts, issued under the Department’s acquisition authority, and it remains in effect until it is rescinded or incorporated into the FAR, the DFARS, and the DFARS PGI. Reversing it means affirmative regulatory action. As Washington Technology put it when it broke the story, because this is a class deviation and no longer a suspension, reversing the move is a more involved process.
Here is the practical translation for a contractor trying to plan. Before September 3, the default future was the codified one: third-party assessments phasing in, with a memo temporarily holding them back. After September 3, the default is inverted. Self-assessment is what the contract documents themselves now require, and third-party assessment is the thing that would need new regulatory action to come back. Defaults matter because government defaults are sticky.
The timing is the tell
The 60-day review clock the July 13 memo started runs out on September 11. The task force’s findings go first to DoW Chief Information Officer Kirsten Davies, and it is her call when, and in what form, the recommendations become public. Cyber AB CEO Matthew Travis has pointed to early October. The task force preview published last week walked through what that report can and cannot legally change, and its one-line summary was: watch what the Department publishes, not what it announces.
Eight days before the report was due, the Department published. That sequence is worth sitting with, because it inverts the order most contractors expected. The assumption was report first, then regulatory action implementing whatever it recommends. Instead, the binding instrument came first, and it codifies the self-assessment regime as the operating state. The report now arrives into a world where its most drastic possible recommendation, restoring mandatory third-party assessment, would require unwinding a regulation the Department just issued.
Davies, speaking at the Billington Cybersecurity Summit on September 9, said the Department received more than 1,100 comments on the July request for information, and stressed that the review is not a retreat from cybersecurity, which she called critical. Nothing about the deviation contradicts that. It just relocates where the pressure sits: away from a scheduled third-party checkpoint, and onto the accuracy of what contractors say about themselves.

What the deviation cannot touch
The list of things Revision 3 does not change is longer than the list of things it does, and it is the list your legal exposure lives on.
DFARS 252.204-7012 is untouched. The safeguarding clause that requires implementation of NIST SP 800-171 and 72-hour incident reporting to DIBNet predates CMMC and sits in your contracts independently of it. All 110 controls of Rev 2 remain the standard. The incident reporting walkthrough covers the half of that clause contractors most often discover late.
The SPRS score is untouched. Posting a current self-assessment score remains a condition of doing CUI work, and the score remains a representation to the government, not an internal metric. If your score has drifted from reality, the score improvement guide covers how to move the number by moving the facts under it.
The annual affirmation is untouched. A named affirming official still signs, once a year, a statement that the company is compliant. The affirmation liability breakdown made the case that this signature is the entire False Claims Act exposure surface for most small contractors. The deviation strengthens that case: with the third-party checkpoint gone, the signature is now the primary verification event the government relies on.
Government-led assessment is untouched. DFARS 252.240-7997 preserves Medium and High assessments performed by the government, the DIBCAC model. Self-assessment being the default does not mean nobody checks. It means the check, when it comes, is an audit rather than an appointment.
Self-attestation with teeth
If the regime the deviation codifies sounds comfortable, the Justice Department spent the review window demonstrating it is not. In June, DOJ settled with LOGZONE, an Alabama defense contractor, for $507,144 over allegations it submitted a near-perfect self-assessment score that a DoD audit found to be wildly inaccurate. On September 1, Honeywell Aerospace agreed to pay $2,042,518 to resolve allegations of NIST SP 800-171 noncompliance on a single network, in a case brought by a former employee. The Honeywell analysis has the full mechanics.
Neither case required CMMC to exist, and neither required a breach. Both ran on the gap between what the contractor said and what was true, paired with invoices. That theory of liability is completely indifferent to the deviation, the task force, and everything else in this news cycle. If anything, a self-attestation regime feeds it, because it multiplies the number of legally significant statements contractors make about themselves while removing the third party who might have caught the overstatement first.
For a 15-person machine shop or a 40-person engineering sub, this is the honest framing of what changed on September 3: the government just told you it will mostly take your word for it, and the FCA docket shows what taking your word for it costs when the word is wrong.
What to do with this before the report lands
Pull your contracts and identify the clause set. Depending on award date, your instruments may carry the legacy 7019/7020 pair, the November 2025 clause structure with 252.204-7021, or the deviation-era 252.240-7997. Your obligations flow from the clauses in your documents, not from the news. If a solicitation or modification arrives with third-party language removed, read what replaced it before assuming anything got lighter.
Do not treat removed requirements as reduced obligations. The C3PAO appointment coming out of your contract does not take a single control off your plate. It removes the scheduled event that would have verified them, which shifts verification to your own attestations and to government audits that arrive on the government’s schedule.
Re-verify the SPRS score against the current environment. This remains the highest-leverage hour a small contractor can spend, because it is the item the FCA cases keep turning on. A score submitted against last year’s network is a live misrepresentation, not an old file.
Brief the affirming official. Whoever signs the annual affirmation should know that the deviation made their signature more load-bearing, not less, and should see the evidence behind what they are signing.
Keep the evidence trail running. DIBCAC authority survived the deviation intact, and a whistleblower with payroll access does not need any authority at all. Dated policies, configurations, tickets, screenshots. The question in every scenario is whether you can prove your statements were true when you made them.
The bottom line
On September 3, the Department of War converted the CMMC pause from something it was choosing into something it has codified. Contracting officers are now bound by regulation to strip third-party assessment requirements out of contracts, and that regulation holds until affirmative action replaces it, whatever the task force report says when it becomes public. What survives is everything that was already dangerous: DFARS 252.204-7012, the 110 controls, a SPRS score with legal weight, an affirmation with a name on it, and a Justice Department that collected from two contractors during the review window alone. The suspension became permanent enough to plan around. So did the exposure.
If the immediate item is making the score defensible, the NIST 800-171 SPRS Score Workbook for CMMC Level 2 ($87) walks the scoring methodology control by control. If you are rebuilding the whole posture under the self-assessment regime, before an audit or an affirmation deadline forces the timeline, the CMMC Level 2 Readiness Kit: 5 NIST 800-171 Tools ($147) covers scoping, the SSP, the SPRS score, the POA&M, and the evidence trail a government assessor or a DOJ attorney would ask for.
Sources
- U.S. Department of War, DARS class deviation 2026-O0025, Revision 3, memorandum signed by John M. Tenaglia, September 3, 2026
- Washington Technology / Nextgov, “CMMC’s Phase 2 suspension locked in with binding regulation,” Nick Wakeman, September 9, 2026
- U.S. Department of War, DARS class deviation 2026-O0025 (original), effective February 1, 2026, establishing DFARS Part 240 and DFARS 252.240-7997
- U.S. Department of War, CIO memoranda suspending CMMC Phase 2 and establishing the CMMC Reform Task Force, July 13, 2026
- U.S. Department of Justice, press release, LOGZONE Inc. False Claims Act settlement ($507,144), June 2026
- U.S. Department of Justice, press release, Honeywell Aerospace False Claims Act settlement ($2,042,518), September 1, 2026
- Kirsten Davies remarks, Billington Cybersecurity Summit, September 9, 2026, as reported by Nextgov/FCW
- 32 CFR Part 170; DFARS 252.204-7012; NIST SP 800-171 Rev 2
Get CMMC deadline updates
Plain-English alerts when CMMC requirements, scoring, or deadlines change. Sent only when something actually moves.