Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
"Suspended" Is the Wrong Word. So Is "Cancelled." | Overwatch Tools
Industry Update · The Deviation, Part 1

"Suspended" Is the Wrong Word. So Is "Cancelled."

The CMMC pause stopped living in a memo in July. And the September document that half the industry read as the end of the program did not change the CMMC text at all. Here is the accurate version, in order.

By Rob Maupin, Overwatch Tools — author of the CMMC Practical Guides series: Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2.

Published September 28, 2026. This article reflects the Department of War memorandum of July 13, 2026, Revision 2 (July 16, 2026) and Revision 3 (September 3, 2026) of class deviation 2026-O0025, and reporting available at the time of writing. The CMMC Reform Task Force's internal reporting deadline was September 11, 2026; as of this date its recommendations have not been made public. Publication is at the discretion of the Department Chief Information Officer and guidance may change. We will update this article as the situation develops.

There are two contractors I keep running into this month, and they are wrong in opposite directions.

The first has been saying the same sentence since July. It's suspended. I'll wait and see. That is reasonable if the pause lives in a memorandum, because a memorandum can be withdrawn on any Tuesday by whoever signs the next one. The second read a headline in early September, concluded the Cybersecurity Maturity Model Certification program had been gutted, and told his team to close the folder.

The pause is more durable than the first contractor thinks. It stopped being a policy memorandum on July 16, 2026, when Revision 2 of class deviation 2026-O0025 carried the Department Chief Information Officer's July 13 direction into the clause-insertion rules contracting officers actually work from. Revision 3, signed September 3, supersedes it and is the current operative text.

And the program is considerably less dead than the second contractor thinks. The CMMC language did not change between Revision 2 and Revision 3. DFARS 240.371 is still printed in full. 32 CFR Part 170 is still on the books. DFARS 252.204-7012 was never in the conversation.

Meanwhile, two False Claims Act settlements landed while the third-party assessor was off the table. Those are the part of this story that changes what a small contractor should do on Monday.

What a Class Deviation Actually Is

If you have never encountered the term, you are in good company — it is an internal acquisition mechanism that rarely matters to anyone outside a contracting shop. Federal buying runs on rules: the Federal Acquisition Regulation and, on the defense side, its DFARS supplement. A deviation is formal authority to depart from them. An individual deviation covers one contract. A class deviation covers a whole class of contracts, department-wide.

A policy memorandum A class deviation
Tells program managers and requiring activities what the Department prefers Tells contracting officers what to do, across a class of contracts
Leaves the rule text untouched Directs which clause set to use in place of the codified text
Reversed by issuing another memorandum Stays in effect until rescinded or folded into the FAR and DFARS
Leaves the contracting officer reading two documents and deciding which governs Produces contract language — solicitation amendments, contract modifications

Undoing a class deviation is a regulatory action, not a press conference. That is the first correction in this article, and it cuts against the wait-and-see position rather than for it.

The practical upside: you now have one thing to watch

Because the pause lives inside this instrument, any future change in what contracting officers are told to do lands first as another revision to this same deviation — a Revision 4, published on the Defense Acquisition Regulations System class deviation page. That is a specific, checkable document at a specific address. It beats refreshing headlines.

The Actual Sequence, Dated

This is the part most coverage compressed, and compressing it is what produced the confusion. Three documents, in order:

Signed December 2025 · Effective February 1, 2026

Class deviation 2026-O0025, original

Part of the government-wide Revolutionary FAR Overhaul. It stood up FAR Part 40 and DFARS Part 240 for information security, moved CMMC's prescription to DFARS 240.371, eliminated DFARS 252.204-7019 as a standalone provision, and renumbered 252.204-7020 as 252.240-7997. It had nothing to do with any pause — it was a relocation exercise that happened to land on CMMC's address.

July 16, 2026

Revision 2 — the one that mattered

Carried the July 13 Department Chief Information Officer memorandum into the deviation. This is the moment the pause entered acquisition instruction — three days after the announcement, and nearly two months before the news cycle that most contractors remember.

September 3, 2026

Revision 3 — current operative text

Signed by John M. Tenaglia, principal director for Defense Pricing, Contracting, and Acquisition Policy, Office of the Assistant Secretary of War (Acquisition and Sustainment). Supersedes Revision 2, effective immediately. The CMMC language is unchanged from Revision 2.

What the deviation directs, accurately stated: contracting officers use the revised FAR Part 40, DFARS Part 240 and PGI 240 in place of the codified text, and collaborate with requiring activities to remove or revise CMMC requirements in solicitations and contracts, per the July 13 memorandum.

What the September Reporting Got Half-Right

When Revision 3 surfaced in the trade press on September 9, the coverage was right about the thing that matters most: the pause sits in binding acquisition instruction, not in a memorandum, and that makes it meaningfully harder to unwind. That is a genuinely important point and it deserved the attention it got.

It was imprecise about two things: when that happened — July 16, not September 3 — and what Revision 3 itself changed, which on the CMMC side was nothing. The former Department Chief Information Officer publicly worried the move would kill CMMC outright; specialist firms that read the document closely have since noted the CMMC text carried over unchanged. This is a dense acquisition document on a deadline, and an easy one to compress badly.

So here is what Revision 3 did not do:

  • It did not strike CMMC from the DFARS. DFARS 240.371 appears in full — CMMC status definitions, the unique identifier, currency standards, all of it.
  • It did not revoke 32 CFR Part 170. The rule that defines the CMMC program is still on the books.
  • It did not touch DFARS 252.204-7012. That clause is unchanged and unrelated to the deviation's CMMC provisions.

A pause is not a repeal. A deviation is not a repeal either. What was removed from solicitations is the third-party certification gate; the architecture it was bolted to is still standing, in full, at a published address you can go read.

What It Did Not Touch

❌ Removed from your solicitation

  • The third-party C3PAO assessment — the certified third-party assessor organization as a condition of award
  • The Phase 2 transition that was scheduled for November 10, 2026, along with pending and future milestones
  • The codified CMMC clause set, replaced in contracting officers' hands by the revised FAR Part 40 and DFARS Part 240 construct

✅ Unchanged and enforceable

  • DFARS 252.204-7012 — including 72-hour incident reporting and flow-down to your subcontractors
  • NIST SP 800-171 — the safeguarding standard itself
  • A current Supplier Performance Risk System (SPRS) self-assessment score as a condition of award
  • The annual affirmation, signed by a named senior official of your company
  • Phase 1 Level 1 and Level 2 self-assessment requirements
  • Government-led assessment authority — DFARS 252.240-7997 retains Government Medium and High assessments, with results posted to SPRS
  • Whatever your prime wrote into your subcontract — which the Department never controlled in the first place

Make the sixth line explicit, because it gets skipped. The third-party assessor left. The government's own ability to come look did not. DFARS 240.371-4 still directs contracting officers to check SPRS before award, before exercising an option, and before extending a period of performance where a CMMC status is required.

Most of that column predates CMMC and outlives it. DFARS 252.204-7012 has been in defense contracts since 2016, and NIST SP 800-171 is a publication of the National Institute of Standards and Technology, not a Department of War program. Under Secretary for Acquisition and Sustainment Michael Duffey has said on the record that the standards are not being relaxed.

That stability is exactly why Volume 1: CMMC Level 1 is organized around the self-assessment and the affirmation rather than around the assessment calendar. The fifteen Level 1 practices, the evidence behind each one, the system description, the MET or NOT MET determination, and the annual affirmation that closes it out — none of that was created by Phase 2, and none of it left with Phase 2.

Not sure what your signature currently covers?

Book a free 30-minute consultation. We will walk through what your contracts and flow-downs actually require today, where your evidence stands, and what a defensible self-assessment looks like for a business your size. No pressure, no six-figure quotes.

Book a Free 30-Minute Consultation →

Two Settlements in One Summer

Here is the piece almost nobody is connecting to the deviation. When a third-party assessor validated the work, the assessor carried part of the weight of the claim: you said you met the requirements, and an accredited organization independently said so too. With that assessor removed from the contract, the entire representation rests on the person who signs the affirmation.

The summer produced two public demonstrations of what that signature is worth.

Logzone — June 2026 · $507,144

LOGZONE Inc. of Huntsville, Alabama settled allegations that it reported a near-perfect self-assessment score that a Department audit later found wildly inaccurate. The matter was initiated by the government, following a DIBCAC assessment. The claims were allegations only, and the settlement resolved them without any determination or admission of liability.

Honeywell Aerospace — announced September 1, 2026 · $2,042,518

The Department of Justice announced a settlement resolving allegations that, from April 2020 through December 2023, a business unit submitted claims for payment while failing to comply with NIST SP 800-171 controls on one of its networks, as required by the contract and the regulation. The matter arose from a qui tam suit filed in 2022 by a former employee, who receives $375,823 of the recovery. No data breach was alleged. Again: allegations only, resolved without any determination or admission of liability.

What they have in common is not the dollar figures. They came from opposite directions. One began with a government assessment. One began with somebody inside the company. Neither required CMMC Phase 2 to exist, and both ran while third-party certification was off the table.

A contractor who concluded that removing third-party certification removed the verification layer has misread which layer was removed. The certification gate at the front of the award process is what came out of solicitations. Government assessment authority is intact at DFARS 252.240-7997. And the False Claims Act never depended on CMMC at all — it attaches to the representation itself, and the people best positioned to know whether a representation is accurate have always worked down the hall from the person who signs it.

What This Means for the Contractor Who Paused

Plenty of contractors stopped work in July, and some of that was sound. The useful exercise is telling which parts were which.

Reasonable to have paused

  • Scheduling and paying for a C3PAO assessment. Nobody is requiring one right now, though voluntary assessments remain available and valid if you want one.
  • Consulting scoped specifically to certification readiness — the mock assessment, the assessor prep, the pre-audit dry run. That work aimed at a gate currently out of the solicitation.
  • Budget cycles built around a November 10, 2026 transition that contracting officers are now instructed to remove or revise.

Risky to have paused

  • Anything that is also a NIST SP 800-171 requirement. Access control, audit logging, media protection, incident response — the standard did not move, and DFARS 252.204-7012 still points at it.
  • Your self-assessment and the date on it. An SPRS score is a condition of award, and contracting officers are still directed to check it.
  • Evidence collection. Evidence is perishable in a way policy documents are not. The screenshot you could have taken in July is harder to reconstruct in March, and the person who configured the thing may not work there anymore.

The diagnostic worth running this week

For most small shops, the "CMMC project" and the "800-171 project" were the same budget line with one name on it. So ask your bookkeeper or your managed service provider a plain question: of the work we stopped in July, which items were assessment preparation and which were control implementation? If nobody can separate those two lines, that inability is itself worth knowing — because the second category was never paused, by anyone, at any point.

From the author

Volume 1: CMMC Level 1 — A Practical Guide for Small to Medium GovCon Contractors

All fifteen practices, the evidence behind them, the system description, and the self-assessment and affirmation that close it out — written for the 5- to 50-employee contractor. Volume 1 on Amazon

Volume 2: CMMC Level 2 — A Practical Guide for Small to Medium GovCon Contractors

The 110 practices across 14 domains, the enclave approach, and a documentation set a small business can actually maintain. Volume 2 on Amazon

Both by Rob Maupin, published by Overwatch Press. Kindle from $12.99.

See the Series on Amazon →

Your Prime Contractor Doesn't Answer to the Deviation

Short section, large consequences. The class deviation directs contracting officers — it tells the government's own buying workforce which clause set to use and how to handle CMMC requirements in government solicitations. It does not rewrite a subcontract that a prime already wrote and you already signed.

If your prime put CMMC language, a security questionnaire, a flow-down matrix, or an annual attestation into your subcontract, that is a term between two private companies. It changes when the prime changes it, on the prime's schedule. Meanwhile DFARS 252.204-7012 continues to obligate primes to flow safeguarding and incident-reporting requirements down to subcontractors handling covered defense information — which is why most flow-down language stays put regardless of where CMMC lands.

Read your subcontract. Not the trade press, not this article. The document with your signature on it.

If You Hold CUI, the Calculus Moved in Your Favor

For contractors handling Controlled Unclassified Information (CUI), be precise about what the last two months did. Phase 1, which began in November 2025, covered self-assessments at both Level 1 and Level 2. The third-party assessment was the Phase 2 piece, and that is what contracting officers are removing from solicitations.

Level 2 as a body of requirements did not move: 110 practices across 14 domains, with the documentation that makes them provable. What left was the most expensive line item. For a small business with limited CUI needs, a dedicated CUI enclave — on Google Workspace or Microsoft 365 GCC High, with no Active Directory, no security information and event management platform, and no enterprise IT department — is a reachable target. It takes disciplined documentation: a System Security Plan, a POAM framework, a risk register, and evidence that the controls run.

And Level 2 always sits on top of Level 1, never instead of it. The enclave holds the CUI; your main environment still holds Federal Contract Information (FCI) and carries its own Level 1 obligation — 15 practices, a system description rather than a System Security Plan, a MET or NOT MET determination on each practice, no POAM, and the annual affirmation.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

What to Watch For Next

The CMMC Reform Task Force delivered its work internally on a September 11, 2026 deadline. As of this writing the report has not been made public; publication is at the Department Chief Information Officer's discretion. Industry observers anticipate release in the late September to early October window — an expectation held by people who watch this closely, not a schedule the Department has committed to, and not a forecast of what the report says.

What is worth knowing is what to watch for. Three instruments change what you owe:

  1. Another revision to this class deviation — a Revision 4, published on the Defense Acquisition Regulations System class deviation page. This is where a change in contracting-officer direction would appear first.
  2. A DFARS rule change — proposed and final rules in the Federal Register, with comment periods.
  3. An amendment to 32 CFR Part 170 — the rule that defines the CMMC program itself.

A report is none of those three. A press release is none of those three. A memorandum changes discretion; a rule changes obligations. Learn to check which kind of document a headline is describing and you will never have to guess what a CMMC news cycle means for your company — which, on the evidence of this month, puts you ahead of a fair amount of the coverage.

The Bottom Line

The good news is real. The most expensive, most capacity-constrained element of CMMC — a third-party audit priced against an assessor pool that was never going to be big enough — is out of the solicitation, by binding instrument rather than by memo.

The part that did not change is the part to act on. The standard is the same standard. The clause is the same clause. The score is the same score, in the same system, checked at the same points in the award process. The government can still come look. And the affirmation is the same affirmation, signed by the same named official — with one fewer professional standing beside them when it goes in.

The auditor left. The affirmation didn't.

Make the affirmation one you can defend.

Thirty minutes, no cost, no obligation. We will look at what your contracts and flow-downs require right now, what your last self-assessment actually covered, and what it would take to close the distance between the two — at Level 1, at Level 2, or both.

Schedule Your Free 30 Minutes → Run the Free Level 1 Gap Check

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

About the author

Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small and medium defense contractors, and the author of the CMMC Practical Guides series published by Overwatch Press — Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2, Kindle from $12.99. Overwatch Tools provides templates, configuration guides, and consulting; clients implement.

A guided documentation path for the L2 CUI Enclave Package is in development.

Sources & Further Reading

  • Class deviation 2026-O0025, Revision 3, TAB A — deviation memorandum (September 3, 2026)
  • Fortreum — what Revision 3 did and did not change
  • Pivot Point Security — analysis of Revision 3
  • Nextgov/FCW — "CMMC's Phase 2 suspension locked in with binding regulation" (September 9, 2026)
  • U.S. Department of War — release on the Phase II suspension (July 13, 2026)
  • U.S. Department of Justice — LOGZONE Inc. False Claims Act settlement (June 2026)
  • U.S. Department of Justice — Honeywell Aerospace Inc. False Claims Act settlement (September 1, 2026)
  • Covington / Inside Government Contracts — CMMC Reform Task Force status (September 21, 2026)
  • DefenseScoop — Department review of industry feedback on CMMC reform (September 9, 2026)
  • NIST SP 800-171
  • DoD CIO — CMMC program

This article is general information about an evolving regulatory situation, not legal advice. Contract interpretation and any question touching False Claims Act exposure should go to your attorney.

Tags: cmmc, FCI_vs_CUI, Google, L1, L2, Level 1, Level 2, MS365, NIST
Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
NIST Rev. 2 to Rev. 3: What Ch...
Rev. 2 to Rev. 3: What Changes for a Small Enclave
The Department Asked Seven Questions. Read Them Closely.
The Department Asked Seven Que...

Related posts

Your Whole Office Doesn't Need to Be Level 2
Read more

Your Whole Office Doesn’t Need to Be Level 2

Your Whole Office Doesn’t Need to Be Level 2 | Overwatch Tools The Enclave Build · Part 1 of 6 Your Whole Office Doesn’t Need to Be Level 2 If your CUI lives on one or two contracts, a Level 1 workplace with a small Level 2 enclave is often the better build: easier to work in,... Continue reading
What a Task Force Report Can and Cannot Change
Read more

What a Task Force Report Can and Cannot Change

What a Task Force Report Can and Cannot Change | Overwatch Tools Reference · The Deviation, Part 3 What a Task Force Report Can and Cannot Change The report will be read as a verdict. It is closer to an opening argument. Here is how to read it when it arrives, and the three documents that actually... Continue reading
The Department Asked Seven Questions. Read Them Closely.
Read more

The Department Asked Seven Questions. Read Them Closely.

The Department Asked Seven Questions. Read Them Closely. | Overwatch Tools Analysis · The Deviation, Part 2 The Department Asked Seven Questions. Read Them Closely. The Task Force report isn’t public. The questions that shaped it have been public since July — and almost nobody has read them carefully. By Rob Maupin, Overwatch Tools — author of... Continue reading
Rev. 2 to Rev. 3: What Changes for a Small Enclave
Read more

NIST Rev. 2 to Rev. 3: What Changes for a Small Enclave

Rev. 2 to Rev. 3: What Changes for a Small Enclave | Overwatch Tools The Second Front · Part 3 of 4 Rev. 2 to Rev. 3: What Changes for a Small Enclave The Department of War enforces one revision of NIST SP 800-171. The proposed FAR CUI rule reaches for the next one. If both touch... Continue reading
Do You Actually Hold CUI on a Civilian Contract?
Read more

Do You Actually Hold CUI on a Civilian Contract?

Do You Actually Hold CUI on a Civilian Contract? | Overwatch Tools The Second Front · Part 2 of 4 Do You Actually Hold CUI on a Civilian Contract? Sensitive, proprietary, and export-controlled are three different things. None of them is automatically Controlled Unclassified Information — and the difference decides your scope. By Rob Maupin, founder of... Continue reading

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool