---
title: "The CMMC Pause Isn&#8217;t a Holiday"
description: "This week, two things happened involving the same federal document. On September 9, Washington Technology reported that the Cybersecurity Maturity Model Certification (CMMC) Phase 2 suspension had been \"locked in with binding regulation,\" a step change from a mere pause"
url: https://kaynemcgladrey.com/blog/the-cmmc-pause-isnt-a-holiday/
date: 2026-09-10
modified: 2026-09-10
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/09/2026-O0025_Rev3_TAB_A_Deviation_Memo_1.webp
categories: ["Blog"]
type: post
lang: en-US
---

# The CMMC Pause Isn&#8217;t a Holiday

This week, two things happened involving the same federal document. On September 9, [Washington Technology](https://www.washingtontechnology.com/contracts/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415883/) reported that the Cybersecurity Maturity Model Certification (CMMC) Phase 2 suspension had been “locked in with binding regulation,” a step change from a mere pause that would make reversal harder. The same week, the analysts at [RedSpin](https://redspin.com/blog/class-deviation-revision-3-still-in-the-holding-pattern/) compared the new document line by line against its predecessor and reached the opposite conclusion: nothing about CMMC has changed, we’re still in the same holding pattern, and we’re still waiting.

Both takes describe [Class Deviation 2026-O0025, Revision 3](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_Rev3_TAB_A_Deviation_Memo.pdf), issued September 3 by John Tenaglia, the Department of Defense’s (DoD) principal director for defense pricing, contracting and acquisition policy. Both are partly right, which is why your compliance officer, your general counsel, and your inbox are all confused. The truth is narrower and more useful than either headline: the September 3 deviation wasn’t about CMMC at all. It just wouldn’t stop being read that way.

## What actually happened, in order

On July 13, Department of War (DoW) CIO Kirsten Davies suspended the advancement to CMMC Phase 2, the rollout of mandatory third-party assessments that was scheduled to begin in November 2026, and kicked off a 60-day review by a CMMC Reform Task Force. Three days later, Revision 2 of the class deviation folded that suspension into binding contracting policy, telling contracting officers to strip or revise CMMC requirements out of new and existing solicitations and contracts.

On September 3, Revision 3 superseded Revision 2. Its actual purpose, per the memo itself, was implementing an unrelated raft of statutory requirements: the Huawei semiconductor prohibition from National Defense Authorization Act (NDAA) FY25 Section 853, restrictions on transferring DoD employee data, drone sourcing bans, and corrected definitions tied to [the July 5 court order](https://storage.courtlistener.com/recap/gov.uscourts.cand.472746/gov.uscourts.cand.472746.29.0.pdf) in *Alibaba Group Holding Limited, et al v. U.S. Department of Defense* (N.D. Cal., 26-cv-6227-EKL). The CMMC language carried forward unchanged.

That’s the whole controversy. A class deviation is how DoD changes contracting behavior immediately, without waiting for rulemaking, so it reads like regulation without being a new rule. Revision 3 didn’t pause anything; the pause already existed, and Revision 3 restated it.

| Date | Instrument | Effect |
| --- | --- | --- |
| July 13, 2026 | DoW CIO memo | Suspends CMMC Phase 2; starts 60-day reform review |
| July 16, 2026 | Class Deviation Revision 2 | Converts the pause into contracting policy |
| September 3, 2026 | Class Deviation Revision 3 | Carries the pause forward; fixes definitions and supply chain provisions |

## Level is not Phase

The number confusion is doing real damage here, and RedSpin nailed the distinction in their [September 10 analysis](https://redspin.com/blog/class-deviation-revision-3-still-in-the-holding-pattern/). Level describes how sensitive the information on your contract is: Level 1 for federal contract information (FCI), Level 2 for controlled unclassified information (CUI), Level 3 for the most sensitive CUI. Phase describes the government’s rollout schedule for enforcing those levels.

We’re in Phase 1. Phase 2, the third-party certification requirement, is what got suspended.

> Suspended third-party certification is not suspended self-assessment.

If your contract requires a Level 2 self-assessment with an affirmation in the Supplier Performance Risk System (SPRS), that obligation is live right now, enforced, independent of anything happening with third-party assessors. The suspension removed the government’s exam schedule, not your homework.

### One number to handle carefully

The deviation’s clause text ties full implementation, with no program office discretion, to November 10, 2028. That date predates the suspension and nothing in the deviation moved it. RedSpin’s caution is the right one, though. Don’t budget against a date the Reform Task Force, and eventually fresh rulemaking under 32 CFR Part 170, can still change.

## What still applies today

This is the section to forward to whoever owns your SPRS score. While Phase 2 waits, the deviation keeps all of this in force:

- **Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting**, now in its June 2026 deviation version, remains the baseline and anchors compliance to National Institute of Standards and Technology (NIST) SP 800-171 Revision 2. Yes, Revision 2, not Rev 3. Read the clause before anyone tells you otherwise.
- **SPRS self-assessment scores and annual affirmations** of continuous compliance remain required, entered by your affirming official.
- **72-hour cyber incident reporting** to DoD’s DIBNet portal stays mandatory for covered contractors and subcontractors, at every tier.
- **The assessment machinery didn’t vanish with the renumbering.** What most contractors knew as clause 252.204-7020 now appears in the deviation attachment as 252.240-7997, NIST SP 800-171 DoD Assessment Requirements. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) can still show up and score your implementation of 800-171.
- **Existing contracts lose CMMC requirements only via modification**, before the next option exercise or the next scheduled administrative modification.

That last bullet is the one your general counsel cares about. The modification lands at the next option exercise or administrative modification, not the moment the memo drops. Until your amendment arrives, the clause you signed still binds you.

## The enforcement floor didn’t move

In June I [wrote about LOGZONE](https://kaynemcgladrey.com/blog/whats-a-280-point-difference-between-friends/), a veteran-owned small business in Huntsville that self-reported a perfect 110 on its NIST SP 800-171 assessment in October 2021. In February 2024, DIBCAC ran a Medium Assessment and scored them a -170, near the floor of the possible range. The settlement, executed June 17, 2026, cost them $507,144, split roughly half restitution and half penalty, against $682,193.37 in Navy billings spanning May 2021 through March 2025, with criminal liability and debarment rights left open.

Here’s why that case is part of this conversation. The suspension eliminates third-party certification requirements from solicitations, but it does nothing to the self-assessment regime under 252.204-7012, nothing to SPRS scoring, and nothing to DIBCAC’s authority to audit. It shifts weight onto the honor system at exactly the moment the Department of Justice (DOJ), through its Task Force to Eliminate Fraud, has shown it will convert a padded self-score into a half-million-dollar liability.

## This is a financial problem

I wrote a book called [Cyber Risk Is a Myth](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054), and the thesis is that there are just business risks, some of which involve computers. CMMC is a clean example. Look at what the LOGZONE settlement actually priced:

- Restitution for revenue earned under a false compliance representation
- A penalty on top of the restitution
- Legal costs
- Preserved debarment exposure
- A name that now circulates in every procurement office that runs a vendor risk screen

None of that is a security outcome. It’s a balance sheet outcome.

> CMMC compliance isn’t an IT budget line. It’s a contingent liability.

Read that way, the compliance question facing a defense industrial base (DIB) executive is capital allocation. The government kept every representation you’ve already signed, kept the audit authority behind them, and kept a DOJ unit whose explicit job is litigating misstatements about exactly those representations. Whatever regime Davies builds next, the spend you’re considering deferring isn’t insurance against threat actors. It’s protection against the invoice-audit mismatch LOGZONE just paid for.

## The OT gap nobody scoped

The most important thing a defense official said this week got the least attention. Speaking at the Billington Cybersecurity Summit on Wednesday, Davies told the audience, as [GovCIO reported](https://govciomedia.com/dow-cio-says-there-is-work-to-do-on-cmmc/):

> “Nowhere in CMMC was there even a mention of how to build cyber resilience for a manufacturing line.”

### She’s right

CMMC and DFARS are information-security regimes, built almost entirely around data: CUI, FCI, clean information handling. Manufacturing lines, industrial controls, and the systems that actually stop moving when things go wrong sit largely outside that frame.

### The uncomfortable implication

Most DIB companies are finding basic IT compliance expensive and slow. The ones struggling with 800-171 fundamentals are, almost by definition, not running strong operational technology (OT) security programs, and OT remains a largely underserved market with fewer practitioners and less mature tooling. If the reformed framework extends into OT, as Davies’ comments hint it might, that gap becomes everyone’s problem at once.

### Expect the vendor stampede

Which brings me to the part I’d put money on: if the next regime leans into OT, expect a wave of fear-based OT security sales at RSA 2027 and Black Hat 2027, aimed squarely at DIB manufacturers, each vendor claiming their product is what the new rules will require. Nobody knows what the rules will require. Davies explicitly offered “no spoilers” at Billington, her department collected more than 1,100 responses to its request for information, and the reform recommendations hadn’t been published as of this writing. When the recommendations arrive, separate what the standard actually says from what the sales engineer promises it will say.

## What’s settled, and what isn’t

### Settled

- Third-party CMMC assessments won’t appear in solicitations for now
- The 800-171 Rev 2 baseline under 252.204-7012 remains binding
- SPRS scores, affirmations, and incident reporting continue
- Your existing contract keeps its existing clauses until modified

### Open

- The Reform Task Force’s report, due to Davies around now, with publication entirely at her discretion
- Whether 32 CFR Part 170 changes, which requires its own rulemaking
- What, if anything, November 2028 survives the process
- How fast your prime moves. Flow-down requirements are a prime’s own business decision, and several are already demanding third-party certification from subcontractors regardless of the federal pause. Your government timeline and your prime’s timeline are different clocks.

The government stopped scheduling exams in July. It didn’t stop keeping records, and it didn’t stop suing. Twenty days before the suspension, I predicted enforcement would accelerate with or without CMMC; LOGZONE proved the claim didn’t need the certification program to come true. Treat the pause as what it is: more time to get the self-assessment honestly right, because the one document nobody suspended is your signature under 252.204-7012.
