Regulatory Whiplash

Pentagon Converts CMMC Phase 2 Suspension into a Binding Regulation

On September 3, 2026, the Department of War formalized what had been a temporary reprieve for defense contractors. John Tenaglia, the department's principal director for defense pricing, contracting and acquisition policy, signed Revision 3 of Class Deviation 2026-O0025. This converts the earlier suspension of Cybersecurity Maturity Model Certification Phase 2 third-party assessments from a discretionary policy memo into a binding acquisition regulation. The shift traces back to a July 13 suspension announcement that paused the program while the department reconsidered its approach. It was detailed this week in reporting from Nextgov/FCW that walked through exactly what contracting officers must now do differently.
Practically, the class deviation orders contracting officers to strip any and all third-party assessment requirements from new and existing solicitations, replacing the CMMC final rule's contract clauses with the Revolutionary FAR Overhaul's Part 240 clause set. Where a contract once required a Certified Third-Party Assessment Organization audit for CMMC Level 2, agencies must now accept a contractor's own Level 1 or Level 2 self-assessment instead. The official CMMC program page maintained by the DoD Chief Information Officer still describes the phased rollout that this deviation has effectively paused, underscoring how quickly the ground has shifted beneath contractors who spent the last two years preparing for mandatory outside audits.
Why a Memo Wasn't Enough
The distinction between a suspension and a class deviation matters more than it might sound. A policy memo can be rescinded as easily as it was issued, but a class deviation is a formal acquisition regulation that stays in effect across the department until it is either rescinded outright or folded into a permanent update to the Federal Acquisition Regulation or the Defense Federal Acquisition Regulation Supplement. Analysis from cyberz.pro has argued that this procedural detail is the real story: reversing course now requires the department to go through rulemaking again, which raises the bar for reinstating mandatory third-party assessments going forward.

The original suspension grew out of concerns that CMMC Phase 2, as written, would become a bureaucratic burden and a significant cost driver, particularly for small and mid-sized companies in the defense industrial base. The department opened a formal comment period, described on its own CMMC 2.0 resource page, and received more than 1,100 responses before it closed in mid-August. Speaking at the Billington Cybersecurity Summit this week, DoD Chief Information Officer Kirsten Davies said the review was not a retreat from security itself, telling attendees that cybersecurity remains critical and that the department wanted to hear more from industry about what meaningful, workable protections should look like.
Companies that kept their documentation current will be the ones ready to move quickly instead of starting over.
What Has Not Changed, and Why That Still Matters
None of this touches the underlying legal obligation that has applied to defense contractors since 2017. Contracts that reference DFARS clause 252.204-7012 still require full implementation of the 110 security controls in NIST Special Publication 800-171. Contractors must still submit a current self-assessment score into the Supplier Performance Risk System, the department's system of record for cybersecurity scoring. Government-led Medium and High assessments continue as well. The class deviation removes an outside verification step; it does not touch the underlying requirement to actually meet the standard or to tell the truth about where a company stands against it.

That distinction has real teeth. In June, the Justice Department announced a settlement with LOGZONE Inc., a Huntsville, Alabama logistics contractor, over allegations that it reported a perfect self-assessment score of 110 on two Navy contracts. A subsequent government audit found a score of negative 170, near the bottom of the possible range. LOGZONE agreed to pay $507,144 to resolve the False Claims Act allegations, and as DefenseScoop reported at the time, the case did not even require a whistleblower to surface, since it grew directly out of a routine government assessment. With third-party audits paused, self-reported scores are likely to draw even closer scrutiny, not less.
Regulatory whiplash like this is exactly when gaps quietly open up.
What Contractors Should Do in the Meantime
The CMMC Reform Task Force's 60-day review began July 13 and its report was due to DoD CIO on September 11. However, there is no public timeline yet for when, or whether, its recommendations will be released. Whatever emerges, it is unlikely to relax the substance of NIST SP 800-171, only the mechanism used to verify compliance with it. Contractors are better served treating this pause as a planning window rather than a reprieve. This time can be used to close gaps in their System Security Plans, Plans of Action and Milestones rather than assuming the requirement itself is going away.
It is also worth remembering that the third-party assessment ecosystem has not disappeared, only paused. The Cyber AB, which accredits the assessors known as C3PAOs, continues to operate. Companies already in an assessment queue, or holding a certification, should stay current with it rather than letting it lapse. When and if mandatory third-party assessments return, whether through a future rulemaking or a reworked CMMC framework informed by the task force's findings, companies that kept their documentation current will be the ones ready to move quickly instead of starting over.
Get Ahead of the Uncertainty with Webcheck Security

Regulatory whiplash like this is exactly when gaps quietly open up between what a contract requires on paper and what an organization's environment actually looks like. If your organization holds, or is pursuing, a Department of War contract and wants a clear-eyed read on where your NIST SP 800-171 implementation, SPRS score and System Security Plan actually stand today, reach out to Webcheck Security and let their team help you get, and stay, ahead of whatever comes out of this review.
Whether Phase 2 returns next year in its original form, in a scaled-back version, or not at all, the underlying self-attestation obligations and the risk of a False Claims Act inquiry are not going anywhere. Getting an independent assessment now, before a contracting officer, an auditor, or a plaintiff's attorney does it for you, is the kind of preparation that turns this period of regulatory uncertainty into a competitive advantage rather than a liability.





Comments