PARTNERSHIPCUI Vault and Trout Software partner to extend the CUI boundary to the machine.CUI Vault partners with Trout Software.Read the announcement

The pause just moved out of a memo and into your contract language

A class deviation issued September 3 tells contracting officers to strike third-party assessment requirements from CMMC clauses. It changes who checks your work. It does not change the work.

On September 3, John Tenaglia — the Department’s principal director for defense pricing, contracting and acquisition policy — issued Class Deviation 2026-O0025, Revision 3, directing contracting officers to remove third-party assessment requirements from CMMC contract clauses and to apply the Revolutionary FAR Overhaul framework rather than the November 2025 final CMMC rule.

That is a meaningful change in kind, not just degree. Since July 13, the Phase 2 suspension has lived as departmental policy — a posture the Department could reverse with another announcement. A class deviation is contracting machinery. It reaches down into the clause text that contracting officers actually insert into solicitations and awards, and unwinding it is a procedural exercise, not a press release.

Now read what the deviation did not do. On the CMMC substance, practitioners tracking the revision line-by-line found it carries the same language as Revision 2 from July 16 — nothing added, nothing removed, nothing softened. DFARS 252.204-7012 is untouched. NIST SP 800-171 Rev. 2 remains the standard. Level 1 and Level 2 self-assessments, SPRS scoring, annual affirmations, and 72-hour incident reporting are all still live and still enforced. And the underlying CMMC rule at 32 CFR Part 170 remains on the books — including the Phase 4 full-implementation date of November 10, 2028, which still sits in the clause exactly where it was.

What actually left the contract was the independent verification step. For the past several years, the implied deal was that a C3PAO would eventually confirm what you claimed about yourself. The deviation removes the confirmer and leaves the claim.

So what: your SPRS score is now the only representation standing between your posture and the government’s understanding of it — with nobody scheduled to check it and one federal enforcement channel that very much does. That is the arrangement that produced a $507,144 settlement in June and a $2 million one this month. Before Friday, pull your active awards and confirm which clause version each one carries, then confirm your score was calculated against your real CUI boundary. A deviation that is hard to reverse means you will be living in this arrangement for a while, not briefly.

The 60-day window closed — what the CIO described is harder than an audit, not easier

The review clock that started with the July 13 suspension ran out this past week. At the Billington CyberSecurity Summit in Washington on September 9 and 10, DoW CIO Kirsten Davies gave the fullest public account yet of what the Reform Task Force has been doing with the record it collected — and a clear signal about where it lands.

The scale first. More than 1,100 RFI responses, over 10,000 pages, and listening sessions across the country that drew more than 3,000 attendees, plus direct meetings with the Cyber AB board, third-party assessor organizations, and small businesses. Davies was pointed about how it is being processed: “AI is not reading that. I have humans reading all of the feedback.” That is the honest explanation for why the recommendation date keeps drifting — and a reminder that the output, when it comes, will be considered rather than fast.

The substance is the part worth planning around. Davies drew a distinction the defense industrial base should read carefully: compliance is not the same thing as security, and the Department is after cybersecurity that is “contiguous and continuous” rather than “point-in-time assessments.”

Sit with what that would actually require of a supplier. A point-in-time assessment is a bad week once every three years. Continuous assurance means your System Security Plan reflects your environment this month, your POA&M items close on a clock rather than roll forward, and your evidence is something you can produce on a Tuesday without a scramble. Reform in that direction lowers the ceremony and raises the floor. It is cheaper to pass and much harder to fake.

Here is the sequence as it now stands:

  • Sep 3, 2026
    Class Deviation 2026-O0025 Rev. 3 issued — third-party assessment requirements struck from CMMC contract clauses.
  • Sep 9–10, 2026
    Billington CyberSecurity Summit — the CIO signals continuous assurance, operational technology, and automation as the reform direction.
  • Sep 11–12, 2026
    The 60-day review window closes. No recommendations released publicly; the CIO controls whether and when they become public.
  • Sep 29, 2026
    Next Cyber AB town hall — the most likely venue for a first public read on what the Task Force concluded.
  • Late Sep – early Oct 2026
    Task Force recommendations — the date most recently signaled from both the Cyber AB and the CIO’s office.
  • Mid-Oct 2026 (earliest)
    Formal determinations — rule text rather than remarks. Nothing binding changes before this point.

With the federal gate out of the clause, your prime is the enforcement authority

This is the practical consequence of the top story, and it is the one most suppliers underestimate. When the Department struck the third-party assessment requirement from its own clauses, it did not touch anybody’s prime contract. Flow-down is a private contractual obligation between you and the company that hired you — it does not run on the Department’s calendar, and nothing in a class deviation releases either party from it.

Primes have their own reason to hold the line: they certify their supply chain to the government, and they carry False Claims Act exposure when that certification is wrong. Their incentive to relax when the government pauses is close to zero. What the majors have published makes the point better than any analysis:

PrimeWhat they have published for suppliers
L3HarrisAn April 6 supply-chain notice set a July 30, 2026 deadline for Level 2 certification by a C3PAO, with assessment reports, for all suppliers receiving CUI at any tier — small businesses and foreign suppliers included, non-COTS. Set on its own authority, and not withdrawn after July 13.
Lockheed MartinAll active suppliers must submit CMMC status through the Cybersecurity Compliance Attestation in Exostar, and complete the CCRA — a 60-question assessment built on a subset of NIST SP 800-171 Rev. 2.
RTXCertification at the contract-specified level before a purchase order issues where the CMMC clause applies; POA&M items at Levels 2–3 to close within 180 days; evidence retained for six years.
BoeingThe specified CMMC level is a condition of contract award for suppliers handling FCI or CUI, outside COTS, with cybersecurity questionnaires routed through Exostar.
General DynamicsA published minimum SPRS threshold (reported at 88) with no waivers at Mission Systems, 180-day POA&M closure, and annual supplier certification as a condition of future orders.
Northrop GrummanSPRS scores and cybersecurity questions required at onboarding and at renewal, under DFARS 252.204-7012 flow-down.

Note the shape of it. These are not aspirations tied to a federal deadline — they are award conditions, registration gates, and 180-day clocks already running inside supplier agreements. A supplier who cancelled a readiness program in July on the strength of the pause did not remove a requirement; they removed their own visibility into one that a customer is still measuring them against.

So what: every prime in your top line of business has a written position on this. Get it in writing, from each of them, and then work to the strictest one — because that is the requirement you are actually contractually bound to, regardless of what the Department does in October. If you sell to more than one of the companies above, your effective deadline already passed for at least one of them.

What to do this week

The theme this issue: authority moved. The requirement lives in your contract and your prime’s letter now, not in the Department’s calendar.

  • Pull your active awards and read the actual clause. Deviations apply going forward and by contract action — you may be holding several awards under different clause versions at the same time. Know which is which before you plan around any of them.
  • Ask every prime for its current position in writing. Not a phone call, not an assumption from July. Then build to the strictest requirement across the set and calendar it.
  • Re-verify your SPRS score against your real boundary. With no assessor scheduled to check it, your score is the whole representation — and it is the document federal enforcement examines first.
  • Move your POA&M items onto a closing clock. Several primes already impose 180 days. Rolling items forward indefinitely is the pattern that turns a gap into a misrepresentation.
  • Start producing evidence monthly, not annually. If reform lands where the CIO pointed it, continuous assurance is the destination. Organizations that can already show current evidence will find that transition trivial; everyone else will find it expensive.

Quick hits

  • Nov 10, 2028
    The endpoint survived the deviation.
    Phase 4 full implementation remains in the clause at 32 CFR Part 170, unchanged. The deviation removed the near-term verification step; it did not move the destination or shorten the runway required to reach it.
  • Sep 14, 2026
    FAR Overhaul batch two still hasn’t hit the Federal Register.
    The four proposed rules cleared OMB on August 28, but as of this week publication has not appeared — so the 30-day comment window has not opened. Your opportunity to comment is still ahead of you, not behind. The separate FAR Part 40 CUI rule from batch one likewise has no final rule since its July 23 comment close.
  • Sep 10, 2026
    The talent squeeze is being answered with people, not lower requirements.
    The Department’s Cyber Registered Apprenticeship Program, launched in July, drew more than 15,000 applications and closed its first round four days early. Additional rounds are planned. Read it alongside the CIO’s line that the Department has to “throw technology” at the cyber problem rather than headcount alone.
  • Sep 29, 2026
    Next Cyber AB town hall.
    With the review window now closed, this is the first scheduled forum where the Task Force’s conclusions could surface publicly. Worth having someone on your team attend rather than waiting for the recap.

Not sure where your organization stands?

CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.

This briefing is a general-information summary of publicly reported CMMC and CUI developments. It is not legal advice; consult your compliance counsel before making contractual or certification decisions.
Talk to us about CUI Vault All issues