CMMC Phase 2 Pause: DFARS Revision 3 Explained

DFARS Class Deviation 2026-O0025, Revision 3: What It Actually Changes for CMMC

Defense contractors watching the CMMC timeline got another data point on September 3, 2026, when the Department of War issued Revision 3 of DARS Class Deviation 2026-O0025. The revision writes the July 13, 2026 suspension of CMMC Phase 2 directly into the DFARS Part 240 text, giving contracting officers explicit instructions on how to handle CMMC requirements in solicitations and contracts while the program review continues. If you’re an IT, risk, or compliance professional in the Defense Industrial Base, here’s what changed, what didn’t, and why the parts that didn’t change probably matter more.

Executive Summary

Revision 3 formally codifies the CMMC Phase 2 pause into contract language, permits CMMC Level 1 and Level 2 to be satisfied through self-assessment, and pushes the date when CMMC becomes an automatic, universal contract requirement to November 10, 2028, two years later than the market had expected. None of that touches the underlying obligation to protect covered defense information under DFARS 252.204-7012, and the government retains full authority to conduct its own Medium and High NIST SP 800-171 assessments regardless of a contractor’s self-assessed status.

Why you should care: A self-assessed CMMC status is still a representation you’re making to the government, one that gets posted to the Supplier Performance Risk System (SPRS) and can be checked later. If your self-attestation doesn’t hold up under a government-led assessment, you’re not just out of compliance. You’re potentially exposed under the False Claims Act for a claim the government relied on when it awarded, extended, or renewed your contract.

Five Key Takeaways

  1. Self-assessment is now written into the contract, not just a temporary workaround. Revision 3 permits CMMC Level 1 and Level 2 as Self assessments in procurement documents, and directs contracting officers to amend active solicitations accordingly. This isn’t informal guidance. It’s now the standing instruction contracting officers must follow.
  2. DFARS 252.204-7012 never paused. The clause requiring contractors to safeguard covered defense information and implement NIST SP 800-171 remains fully in force. Nothing in Revision 3 changes the underlying security requirement, only the mechanism for verifying it.
  3. DoD kept its own assessment authority. Revision 3 preserves the government’s ability to run Medium and High NIST SP 800-171 DoD Assessments on any covered contractor system, self-assessed status or not. When the Defense Contract Management Agency (DCMA) conducts one, its results take precedence over any other assessment on record, including your own Self status.
  4. The universal CMMC mandate didn’t disappear, it moved two years out. Until November 9, 2028, the CMMC clause is inserted only when a program office decides case by case that a contractor needs a specific level. On or after November 10, 2028, insertion becomes automatic for any contract touching FCI or CUI. That’s the real trigger date, not November 2026, and it points toward Phase 2 returning in some form rather than disappearing.
  5. Award and option exercise both depend on a current CMMC status. Contracting officers must check SPRS before award, before exercising an option, and before extending a period of performance, and must withhold all three if the status has lapsed. A status that goes stale mid-contract can stall a renewal just as easily as it can block new business.

What Revision 3 Actually Does

Revision 3 supersedes Revision 2 of the same class deviation and does three distinct things. First, it directs contracting officers to collaborate with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts, in accordance with the Department of War CIO’s July 13, 2026 memorandum suspending the advancement to CMMC Phase 2. That memo permits CMMC Level 1 and Level 2 to be included as Self assessments and requires baseline compliance with NIST SP 800-171 Rev 2 under DFARS 252.204-7012.

Second, and this is the detail that changes the actual compliance calendar rather than just the messaging around it, Revision 3 sets two different bases for when the CMMC clause, 252.204-7021, gets inserted into a contract. Until November 9, 2028, the clause is inserted only when a program office or requiring activity specifically decides a contractor needs a stated CMMC level, case by case, much as things work today. On or after November 10, 2028, insertion becomes automatic whenever a contract involves systems that process, store, or transmit Federal Contract Information or Controlled Unclassified Information, no case-by-case determination required. That November 10, 2028 date is the real universal-mandate trigger, and it’s two years later than the November 2026 date the market had been building toward.

Third, it addresses an unrelated matter tied to active litigation: a temporary waiver of the Chinese military company prohibition at 10 U.S.C. 4663 for a specific named entity, issued in response to a federal court order. That provision has nothing to do with CMMC, but it does tell you something about how these deviations work. They bundle whatever regulatory changes are pending at the time of issuance, and they’re built to be revised again as circumstances change. Revision 3 exists because Revision 2 needed updating. Revision 4 is not a hypothetical.

For contractors already carrying CMMC Phase 2 language in an existing contract, contracting officers are required to remove it via modification, either before the next option period is exercised or at the next scheduled administrative modification. That’s a real operational step, not a policy statement sitting on a webpage. If you have a contract with Phase 2 language in it, expect a modification to come through, and don’t assume the absence of one yet means anything about your obligations under 252.204-7012.

Why Self-Assessment Doesn’t Reduce Your Exposure

It’s worth being direct about the parts of Revision 3 that read as relief but aren’t. Self-assessment sounds like less scrutiny. In practice, it removes the one thing that used to sit between your internal claim and the government relying on it: an independent, third-party check. When a C3PAO conducts an assessment, there’s a professional intermediary vouching for what got tested. When you self-assess, there isn’t. The accuracy of your SPRS score becomes entirely your own responsibility, and that score still gets used by contracting officers to decide whether to award, renew, or extend your contract.

That matters because Revision 3 didn’t touch the government’s own assessment authority. DFARS 252.240-7997 still allows DoD to conduct Medium and High NIST SP 800-171 assessments on covered contractor systems, and the clause specifies that when DCMA conducts one, its results take precedence over any other assessment, including your own Self status. If a High Assessment turns up gaps that your self-assessment missed, or misrepresented, you’re not looking at a paperwork problem. You have 14 business days after an assessment concludes to submit additional evidence or rebut the findings before DoD posts the summary score to SPRS. After that, the score is the record, and it’s visible to the DoD components making award decisions.

This is where the False Claims Act consideration becomes relevant, not as a certainty, but as a risk worth taking seriously. A self-attested CMMC status is a representation the government relies on. If that representation turns out to be materially inaccurate and the government can show you should have known it was inaccurate, that’s the kind of gap the False Claims Act is designed to catch. The civil penalty range for a false claim, adjusted for inflation as of July 2025, runs from $14,308 to $28,619 per claim, assessed per false claim submitted, not per unmet control. The Department of Justice reported more than $6.8 billion in total False Claims Act recoveries for fiscal year 2025, a record for the statute. That figure spans every category of FCA enforcement, not cybersecurity cases specifically, but it’s a useful indicator of how active the government’s enforcement appetite currently is. Nobody wants to find out how that plays out through a government-led assessment on a contract they’ve already been awarded.

The Suspension Isn’t a Repeal

One detail worth sitting with: Revision 3 frames its CMMC provisions as implementing a specific CIO memo, tied to a specific date, addressing a specific transition milestone. That’s the language of a pause, not the language of a rule change. The CMMC Program rule at 32 CFR Part 170 is untouched. The requirement for contractors handling controlled unclassified information to eventually reach a verified CMMC status hasn’t gone anywhere; the timeline and the verification mechanism are what moved.

Contractors who read this as “CMMC is over” are setting themselves up for a scramble when Phase 2 requirements come back into contracts, whether that happens through a new class deviation, a final rule, or another CIO memo. Building toward genuine CMMC Level 2 readiness now, while self-assessment is an option, puts you ahead of that scramble instead of behind it.

A Separate, Independent Requirement Rode Along in the Same Deviation

Not everything in Revision 3 is about CMMC. The revision also implements new DFARS 240.374, which prohibits awarding a contract to an entity that sells, licenses, or otherwise transfers covered personally identifiable information of Department of Defense employees, including members of the Armed Forces, to anyone other than the federal government. The exceptions are narrow: transfers required to perform the contract, transfers authorized by a waiver, or transfers otherwise authorized by law. The corresponding clause, 252.240-7992, gets inserted into solicitations and contracts, including commercial product and service acquisitions, unless waived.

This requirement implements section 803 of the NDAA for Fiscal Year 2024 and section 836 of the NDAA for Fiscal Year 2025. It doesn’t depend on a CMMC level, a self-assessment, or any DoD calendar. It’s live now, and it’s checkable now, which makes it worth treating as its own compliance conversation rather than folding it into the broader CMMC discussion.

What This Means for Your Compliance Posture

The practical takeaway is that the substance of the work didn’t change. You still need to implement the 110 controls in NIST SP 800-171 Rev 2. You still need documented evidence, not just a checked box in SPRS, because a government assessment can happen at any point and the clause governing it doesn’t ask whether you have a Self or a C3PAO status first. You still need a system security plan that would hold up under the kind of document review and validation a Medium or High Assessment involves.

The best move available to compliance teams right now is treating self-assessment as an opportunity to close gaps with less external pressure, not as a reason to slow down. That’s a narrow window, and Revision 3 itself signals it won’t stay open indefinitely.

How Kiteworks Helps

Kiteworks gives Defense Industrial Base contractors a way to back a self-attested SPRS score with actual evidence, rather than a paper claim. The platform is FedRAMP High In Process and has been FedRAMP Moderate Authorized since 2017, supports 90% of CMMC 2.0 Level 2 requirements out of the box, and is FIPS 140-3 validated. For a contractor preparing for a Medium or High NIST SP 800-171 DoD Assessment, that means audit logging, access controls, and encryption practices that are already documented and in place, not something assembled after a Government notice arrives. The same data governance, controlled-egress, and audit-logging capabilities apply directly to the new DFARS 240.374 employee-data requirement, giving contractors visibility into where personally identifiable information moves and a documented trail if that movement is ever questioned. The gap between a self-assessed claim and a government-verified one is exactly where Kiteworks is built to help contractors close ground.

Frequently Asked Questions

Does DFARS Revision 3 eliminate CMMC requirements?

No. Revision 3 codifies the temporary suspension of the CMMC Phase 2 transition and permits CMMC Level 1 and Level 2 self-assessments. It does not rescind the CMMC Program rule at 32 CFR Part 170, and contracting officers still must confirm a current CMMC status before award, option exercise, or period of performance extension.

Is DFARS 252.204-7012 affected by this deviation?

No. Revision 3 explicitly preserves DFARS 252.204-7012, which requires contractors to safeguard covered defense information and implement NIST SP 800-171. That obligation runs independently of whichever CMMC phase is currently in effect.

Can DoD still assess my company even if I only submitted a self-assessment?

Yes. DFARS 252.240-7997 preserves DoD’s authority to conduct Medium and High NIST SP 800-171 DoD Assessments on any covered contractor system. When DCMA performs one, its results take precedence over your own Self status.

How long does a self-assessed CMMC status remain current under Revision 3?

A Conditional Level 2 or Level 3 status is valid for 180 days. A Final Level 2 or Level 3 status is valid for up to 3 years, and a Final Level 1 status is valid for 1 year, each requiring an annual affirmation of continuous compliance.

What happens if a government assessment finds gaps my self-assessment missed?

You have 14 business days after the assessment concludes to submit additional evidence or rebut the findings. After that window, DoD posts the summary score to SPRS, and it becomes the record contracting officers rely on for award and option decisions.

When does CMMC become a mandatory requirement in every DoD contract?

Not until November 10, 2028. Before that date, the CMMC clause is inserted only when a program office specifically decides a contractor needs a stated level. On or after November 10, 2028, insertion becomes automatic for any contract involving systems that process, store, or transmit FCI or CUI.

Does Revision 3 include anything unrelated to CMMC?

Yes. It also implements new DFARS 240.374, prohibiting award of a contract to any entity that transfers covered personally identifiable information of DoD employees to third parties, except in narrow circumstances. That requirement runs on its own timeline, independent of CMMC.

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks