What a Task Force Report Can and Cannot Change
The report will be read as a verdict. It is closer to an opening argument. Here is how to read it when it arrives, and the three documents that actually change what you owe.
By Rob Maupin, Overwatch Tools — author of the CMMC Practical Guides series: Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2.
The CMMC Reform Task Force report is not public yet. Department of War (DoW) Chief Information Officer Kirsten Davies has said on the record that it will be made public, though she has not set a date. Industry observers have been anticipating a late-September to early-October window. That is their read, not a Department schedule.
When it does, a contractor somewhere is going to read a two-paragraph summary of it, conclude the requirement changed, and stop work.
He will be wrong. Not because the summary will be inaccurate. It may be perfectly accurate. He will be wrong because he does not know the difference between a recommendation and a rule.
A task force report is advice to a Chief Information Officer. It does not touch a single contract clause. Three instruments change what a defense contractor owes: a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170. A contractor who learns to watch for those three things never again has to guess what a headline means.
This article is built to stay useful long after the news cycle moves on. Read it now, and keep it next to the report when the report arrives.
The Chain of Custody, Laid Out
Every change to a contractor's obligations travels the same path. Here it is in order, from the report to your contract.
The Task Force delivers recommendations to the CIO Internal
This step already happened, on or about September 11. Nothing in your contract moved.
The CIO decides what to publish and what to adopt Internal and discretionary
Publishing a recommendation and adopting it are two separate decisions. A published report can contain ideas the Department never acts on.
Adoption requires an instrument Internal and discretionary
Someone has to draft a class deviation, a DFARS rule, or an amendment to the CMMC program rule. Which one, and how quickly, is a choice.
The instrument is published Public
This is the first point in the chain you can actually see: a signed, numbered document, or a notice in the Federal Register.
The contracting officer applies it Your solicitation or contract
A clause is inserted, revised, or removed in a solicitation. For a contract you already hold, that takes a modification.
Your obligation changes
Only here. Not at step one, and not at step two.
Count the steps that happen inside the building. Three of six, and two of those are judgment calls. The report is step one. When it is published, you will be looking at the start of the chain, and the start of the chain has never changed anyone's contract.
The Three Instruments That Actually Matter
Notice what is not on the list below: a report, a memo, a speech, a press release, a conference panel, an FAQ. Those can tell you what the Department intends. A memo can change discretion, meaning what program offices choose to ask for in new solicitations. Only an instrument changes the clause text you are held to.
Class deviation
- What it is
- A signed instruction telling contracting officers to depart from the codified FAR or DFARS text for a whole class of contracts. It stays in effect until it is rescinded or folded into the regulations themselves.
- How fast it moves
- Fast. Days, not months. No public comment period is required.
- Where you can see it
- Posted by the Defense Pricing, Contracting, and Acquisition Policy office on its class deviations page. Each one is numbered, and each change is a numbered revision.
The worked example is the one in front of us. While most of the market was watching for a press release this summer, the change that actually reached contracting officers arrived as a deviation. Revision 2 of class deviation 2026-O0025, issued July 16, carried the CIO's July 13 memorandum into acquisition instruction, three days after the memo. Revision 3, signed September 3 by John M. Tenaglia, principal director for Defense Pricing, Contracting, and Acquisition Policy, superseded it and is the current operative text. Its CMMC language is unchanged from Revision 2. It directs contracting officers to work with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts, in accordance with the July 13 memorandum.
That is what a real change looks like: numbered, signed, and addressed to the people who write your contracts. I walked through the full sequence, and what the September reporting got half-right, in Part 1 of this series. The practical point is that any change in contracting-officer direction would surface most directly as another revision to this same deviation. That is a specific, checkable document.
DFARS rule change
- What it is
- An amendment to the Defense Federal Acquisition Regulation Supplement itself: the clause text, or the rules for when a clause goes into a contract.
- How fast it moves
- Slowly. Usually a proposed rule, a public comment period, then a final rule, measured in months or years. An interim rule can take effect sooner, but it is still published first. For scale, the DFARS rule that put CMMC clauses into contracts was proposed in August 2024, finalized in September 2025, and took effect November 10, 2025.
- Where you can see it
- The Federal Register, under a DFARS case number, with an open docket for comments.
32 CFR Part 170 amendment
- What it is
- A change to the CMMC program rule itself. Part 170 defines the levels, the assessment types, scoping, the affirmation requirement, and the rules for POAMs.
- How fast it moves
- Also slowly, through the same rulemaking path. The current rule was proposed in December 2023, finalized in October 2024, and took effect December 16, 2024.
- Where you can see it
- The Federal Register. Neither the July memo nor any revision of the deviation revoked Part 170. It is still on the books today.
The one-question test for any headline
When a CMMC headline crosses your desk, ask one question: which of the three instruments is this? If the answer is "none of them," it may tell you what the Department intends. It has not changed what you owe.
Know which clauses are actually in your contracts.
In a free 30-minute consultation, we will walk through what your contracts require today, which requirements come from the FAR, which come from the DFARS, and which come from CMMC, and what each one asks of you. No pressure, no six-figure quotes.
Book a Free 30-Minute ConsultationThe Precedent Worth Knowing
This is not the first time the program has been reviewed. In March 2021, the Department began an internal review of CMMC. On November 4, 2021, it announced the result: CMMC 2.0. Five levels became three. The original Levels 2 and 4 were eliminated along with the CMMC-unique maturity processes, and Level 1 moved to self-assessment. The restructured program then went through the full rulemaking path described above, with the program rule taking effect in December 2024 and the DFARS clauses in November 2025.
That is history, and this article stops there. It is not a forecast of what this review will produce, and nothing here should be read as one.
The single takeaway worth carrying forward: the one previous review produced a revised program, not no program. That is a reason to keep implementing.
What Survives Every Outcome
Here is the list that does not depend on what the report says. Each item lives somewhere a CMMC recommendation cannot reach on its own.
| Obligation | Why the report cannot reach it |
|---|---|
| DFARS 252.204-7012 | It sits in your contract, not in CMMC. It has required safeguarding of covered defense information, 72-hour incident reporting, and flow-down to subcontractors since 2017. Neither the memo nor the deviation touched it. |
| NIST SP 800-171 | Its requirements reach you through DFARS 252.204-7012, not through CMMC. Under Secretary of War for Acquisition and Sustainment Michael Duffey said in July that the standards are not being relaxed. Changing what the clause requires would take one of the three instruments. |
| FAR 52.204-21 | The 15 basic safeguarding requirements for Federal Contract Information (FCI) come from a government-wide FAR clause that predates CMMC. Level 1's 15 practices are those requirements. |
| Your Supplier Performance Risk System (SPRS) assessment score | For contractors under DFARS 252.204-7012, the NIST SP 800-171 assessment score comes from its own clause, separate from the CMMC clause. Under the FAR Overhaul deviation it now sits in DFARS Part 240, with the former 252.204-7020 renumbered 252.240-7997. Government-led assessment authority survives there too. |
| Prime contractor flow-downs | Whatever your prime wrote into your subcontract is a contract term between two private parties. A Department report does not rewrite it. |
| The False Claims Act | It has been law since 1863 and does not depend on CMMC existing at all. Two cybersecurity settlements were announced this summer, Logzone in June and Honeywell Aerospace on September 1. Both resolved allegations only, without any determination of liability, and both were announced while third-party certification was not a condition of award. |
One honest exception. The annual affirmation by a named senior official is a CMMC requirement. It comes from 32 CFR Part 170 and the CMMC clause, so it is one of the things a Part 170 amendment could reshape. But Part 170 is on the books, the Phase 1 self-assessment requirements remain in place, and the affirmation applies today. It is also worth noticing what the affirmation actually is: a signed statement to the federal government that the underlying requirements are met. Those underlying requirements are the rows in the table above.
One more precision, because this is where articles slip. At Level 1, there is no numeric SPRS score. Each of the 15 practices is MET or NOT MET, and the result is backed by the annual affirmation. There is no POAM at Level 1, and the document that describes your environment is a system description, not a System Security Plan (SSP).
Both volumes of my CMMC Practical Guides are organized around exactly these obligations, the ones that do not move. Volume 1 covers the FAR 52.204-21 requirements behind Level 1, and Volume 2 covers the NIST SP 800-171 requirements behind Level 2. Neither was written around a phase date, because the obligations were never written around one either.
The L1/L2 Stack Is the Position That Doesn't Depend on the Report
Level 1 covers FCI, and nearly every company in the defense supply chain handles FCI. It is 15 practices, each one MET or NOT MET, an annual affirmation, no POAM, and a system description rather than an SSP.
Level 2 sits on top of Level 1 for contractors holding Controlled Unclassified Information (CUI). It is always in addition to Level 1, never instead of it. It is 110 practices across 14 domains, with an SSP, a POAM framework, a risk register, and evidence that each control actually runs. For a small business with limited CUI needs, a dedicated enclave on Google Workspace or Microsoft 365 GCC High keeps that scope tight. That means no Active Directory, no SIEM, and no enterprise IT department.
Here is the part that matters for this article: none of this was created by CMMC Phase 2, and none of it disappears with Phase 2. Phase 2 was about who checks, meaning third-party certification by a certified third-party assessor organization (C3PAO). The requirements underneath came from FAR 52.204-21 and DFARS 252.204-7012, and they were in contracts long before any phase date was set.
Our two packages are built on that stack. The L1 Turnkey Package breaks the 15 practices into 142 defined artifacts. The L2 CUI Enclave Package maps the 110 practices to 182 artifacts, with enclave configuration guides for Google Workspace or Microsoft 365 GCC High. We provide the templates, configuration guides, and consulting. Clients implement.
⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.
A Short Watch List You Can Keep
Clip this and tape it next to your monitor. It is all you need to read any CMMC news correctly.
- Class deviations. Check the Defense Pricing, Contracting, and Acquisition Policy class deviations page. The current CMMC text is class deviation 2026-O0025, Revision 3. A new revision number is the signal. A news story about a deviation is not a substitute for reading it.
- DFARS changes. These appear in the Federal Register as a proposed, interim, or final rule under a DFARS case number. A proposed rule changes nothing yet. It opens a comment period, which is your chance to weigh in.
- 32 CFR Part 170 amendments. Also in the Federal Register. An amendment here would change the CMMC program itself: levels, assessment types, the affirmation, the POAM rules. If you see one, read what it actually amends before reading what anyone says about it.
- Your own file cabinet. Regardless of any of the above, check the date on your last self-assessment and affirmation in SPRS. If your environment has changed since then, through new staff, new laptops, or a new cloud service, your assessment describes a network you no longer run. That is true today, under the rules already in force.
From the author
Volume 1: CMMC Level 1 — A Practical Guide for Small to Medium GovCon Contractors
All fifteen practices, the evidence behind them, the system description, and the self-assessment and affirmation that close it out, written for the 5- to 50-employee contractor. Volume 1 on Amazon
Volume 2: CMMC Level 2 — A Practical Guide for Small to Medium GovCon Contractors
The 110 practices across 14 domains, the enclave approach, and the documentation set a small business can actually maintain. Volume 2 on Amazon
Both by Rob Maupin, published by Overwatch Press. Kindle from $12.99.
See the series on AmazonIntent and Obligation
This series started with a vocabulary problem: "suspended" and "cancelled" were both the wrong words. It continued with a reading problem: the seven questions in the Department's RFI said more than most of the coverage did. It ends with the simplest distinction of the three.
When the report arrives, read it. It is the Task Force's own account of what it recommended, and that is genuinely useful context. Then go back to the watch list and ask whether any of the three instruments has moved.
The report tells you what the Department intends. The instruments tell you what you owe. Only one of those two things has ever been enforceable.
Build the position that doesn't depend on the report.
Level 1 for the FCI nearly everyone handles. Level 2 on top of it if you hold CUI. Both built on requirements that were in your contracts before Phase 2 and were never part of what Phase 2 covered. In 30 minutes we will look at which levels your contracts actually call for, where your self-assessment stands, and what it would take to close the gap.
L1 Turnkey Package: $2,495/year (save $500, regular $2,995, limited time) · L2 CUI Enclave Package: $3,495/year · Both together: $5,990/year
Our Analysis, not a commitment: most clients complete their Level 1 assessment in 2–4 weeks. Timelines vary with existing infrastructure and responsiveness.
Talk Through Your L1/L2 Stack⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.
About the author
Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small and medium defense contractors, and the author of the CMMC Practical Guides series published by Overwatch Press: Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2, Kindle from $12.99. Overwatch Tools provides templates, configuration guides, and consulting; clients implement.
A guided documentation path for the L2 CUI Enclave Package is in development.
Sources & Further Reading
- Class deviation memorandum, 2026-O0025 Revision 3, TAB A (September 3, 2026)
- U.S. Department of War — release on the Phase II suspension (July 13, 2026)
- DoD CIO — implementing memorandum, CMMC Phase II suspension
- DefenseScoop — Pentagon task force to review CMMC hits the ground running (July 17, 2026)
- Nextgov/FCW — CMMC's Phase 2 suspension locked in with binding regulation (September 9, 2026)
- Fortreum — what Revision 3 did and did not change
- Pivot Point Security — Revision 3 analysis
- Covington / Inside Government Contracts — CMMC Reform Task Force updates (September 21, 2026)
- DoD CIO — Strategic Direction for the CMMC Program (CMMC 2.0 announcement) (November 4, 2021)
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
- FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems
- Federal Register — where DFARS and 32 CFR rule changes are published
- DOJ — Logzone False Claims Act settlement (June 2026)
- DOJ — Honeywell Aerospace False Claims Act settlement (September 1, 2026)
- NIST SP 800-171
- DoD CIO — CMMC program
This article is general information about an evolving regulatory situation, not legal advice. Contract interpretation and any question touching False Claims Act exposure should go to your attorney.
