On September 3, John Tenaglia — the Department’s principal director for defense pricing, contracting and acquisition policy — issued Class Deviation 2026-O0025, Revision 3, directing contracting officers to remove third-party assessment requirements from CMMC contract clauses and to apply the Revolutionary FAR Overhaul framework rather than the November 2025 final CMMC rule.
That is a meaningful change in kind, not just degree. Since July 13, the Phase 2 suspension has lived as departmental policy — a posture the Department could reverse with another announcement. A class deviation is contracting machinery. It reaches down into the clause text that contracting officers actually insert into solicitations and awards, and unwinding it is a procedural exercise, not a press release.
Now read what the deviation did not do. On the CMMC substance, practitioners tracking the revision line-by-line found it carries the same language as Revision 2 from July 16 — nothing added, nothing removed, nothing softened. DFARS 252.204-7012 is untouched. NIST SP 800-171 Rev. 2 remains the standard. Level 1 and Level 2 self-assessments, SPRS scoring, annual affirmations, and 72-hour incident reporting are all still live and still enforced. And the underlying CMMC rule at 32 CFR Part 170 remains on the books — including the Phase 4 full-implementation date of November 10, 2028, which still sits in the clause exactly where it was.
What actually left the contract was the independent verification step. For the past several years, the implied deal was that a C3PAO would eventually confirm what you claimed about yourself. The deviation removes the confirmer and leaves the claim.
The 60-day window closed — what the CIO described is harder than an audit, not easier
The review clock that started with the July 13 suspension ran out this past week. At the Billington CyberSecurity Summit in Washington on September 9 and 10, DoW CIO Kirsten Davies gave the fullest public account yet of what the Reform Task Force has been doing with the record it collected — and a clear signal about where it lands.
The scale first. More than 1,100 RFI responses, over 10,000 pages, and listening sessions across the country that drew more than 3,000 attendees, plus direct meetings with the Cyber AB board, third-party assessor organizations, and small businesses. Davies was pointed about how it is being processed: “AI is not reading that. I have humans reading all of the feedback.” That is the honest explanation for why the recommendation date keeps drifting — and a reminder that the output, when it comes, will be considered rather than fast.
The substance is the part worth planning around. Davies drew a distinction the defense industrial base should read carefully: compliance is not the same thing as security, and the Department is after cybersecurity that is “contiguous and continuous” rather than “point-in-time assessments.”
Sit with what that would actually require of a supplier. A point-in-time assessment is a bad week once every three years. Continuous assurance means your System Security Plan reflects your environment this month, your POA&M items close on a clock rather than roll forward, and your evidence is something you can produce on a Tuesday without a scramble. Reform in that direction lowers the ceremony and raises the floor. It is cheaper to pass and much harder to fake.
Here is the sequence as it now stands:
- Sep 3, 2026Class Deviation 2026-O0025 Rev. 3 issued — third-party assessment requirements struck from CMMC contract clauses.
- Sep 9–10, 2026Billington CyberSecurity Summit — the CIO signals continuous assurance, operational technology, and automation as the reform direction.
- Sep 11–12, 2026The 60-day review window closes. No recommendations released publicly; the CIO controls whether and when they become public.
- Sep 29, 2026Next Cyber AB town hall — the most likely venue for a first public read on what the Task Force concluded.
- Late Sep – early Oct 2026Task Force recommendations — the date most recently signaled from both the Cyber AB and the CIO’s office.
- Mid-Oct 2026 (earliest)Formal determinations — rule text rather than remarks. Nothing binding changes before this point.
With the federal gate out of the clause, your prime is the enforcement authority
This is the practical consequence of the top story, and it is the one most suppliers underestimate. When the Department struck the third-party assessment requirement from its own clauses, it did not touch anybody’s prime contract. Flow-down is a private contractual obligation between you and the company that hired you — it does not run on the Department’s calendar, and nothing in a class deviation releases either party from it.
Primes have their own reason to hold the line: they certify their supply chain to the government, and they carry False Claims Act exposure when that certification is wrong. Their incentive to relax when the government pauses is close to zero. What the majors have published makes the point better than any analysis:
| Prime | What they have published for suppliers |
|---|---|
| L3Harris | An April 6 supply-chain notice set a July 30, 2026 deadline for Level 2 certification by a C3PAO, with assessment reports, for all suppliers receiving CUI at any tier — small businesses and foreign suppliers included, non-COTS. Set on its own authority, and not withdrawn after July 13. |
| Lockheed Martin | All active suppliers must submit CMMC status through the Cybersecurity Compliance Attestation in Exostar, and complete the CCRA — a 60-question assessment built on a subset of NIST SP 800-171 Rev. 2. |
| RTX | Certification at the contract-specified level before a purchase order issues where the CMMC clause applies; POA&M items at Levels 2–3 to close within 180 days; evidence retained for six years. |
| Boeing | The specified CMMC level is a condition of contract award for suppliers handling FCI or CUI, outside COTS, with cybersecurity questionnaires routed through Exostar. |
| General Dynamics | A published minimum SPRS threshold (reported at 88) with no waivers at Mission Systems, 180-day POA&M closure, and annual supplier certification as a condition of future orders. |
| Northrop Grumman | SPRS scores and cybersecurity questions required at onboarding and at renewal, under DFARS 252.204-7012 flow-down. |
Note the shape of it. These are not aspirations tied to a federal deadline — they are award conditions, registration gates, and 180-day clocks already running inside supplier agreements. A supplier who cancelled a readiness program in July on the strength of the pause did not remove a requirement; they removed their own visibility into one that a customer is still measuring them against.
What to do this week
The theme this issue: authority moved. The requirement lives in your contract and your prime’s letter now, not in the Department’s calendar.
- Pull your active awards and read the actual clause. Deviations apply going forward and by contract action — you may be holding several awards under different clause versions at the same time. Know which is which before you plan around any of them.
- Ask every prime for its current position in writing. Not a phone call, not an assumption from July. Then build to the strictest requirement across the set and calendar it.
- Re-verify your SPRS score against your real boundary. With no assessor scheduled to check it, your score is the whole representation — and it is the document federal enforcement examines first.
- Move your POA&M items onto a closing clock. Several primes already impose 180 days. Rolling items forward indefinitely is the pattern that turns a gap into a misrepresentation.
- Start producing evidence monthly, not annually. If reform lands where the CIO pointed it, continuous assurance is the destination. Organizations that can already show current evidence will find that transition trivial; everyone else will find it expensive.
Quick hits
- Nov 10, 2028The endpoint survived the deviation.Phase 4 full implementation remains in the clause at 32 CFR Part 170, unchanged. The deviation removed the near-term verification step; it did not move the destination or shorten the runway required to reach it.
- Sep 14, 2026FAR Overhaul batch two still hasn’t hit the Federal Register.The four proposed rules cleared OMB on August 28, but as of this week publication has not appeared — so the 30-day comment window has not opened. Your opportunity to comment is still ahead of you, not behind. The separate FAR Part 40 CUI rule from batch one likewise has no final rule since its July 23 comment close.
- Sep 10, 2026The talent squeeze is being answered with people, not lower requirements.The Department’s Cyber Registered Apprenticeship Program, launched in July, drew more than 15,000 applications and closed its first round four days early. Additional rounds are planned. Read it alongside the CIO’s line that the Department has to “throw technology” at the cyber problem rather than headcount alone.
- Sep 29, 2026Next Cyber AB town hall.With the review window now closed, this is the first scheduled forum where the Task Force’s conclusions could surface publicly. Worth having someone on your team attend rather than waiting for the recap.
Not sure where your organization stands?
CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.
