" /> CMMC Class Deviation Rev 3: Phase 2 Still Suspended, DFARS 240
september 15, 2026

CMMC Class Deviation Revision 3: DFARS Part 240, Phase 2 Suspension Confirmed (September 2026)

Compliance news · CMMC · DFARS · Updated September 15, 2026

On September 3, 2026, the Department of War issued Class Deviation 2026-O0025, Revision 3 (DARS Tracking Number 2026-O0025, Revision 3), signed by John M. Tenaglia, Principal Director of Defense Pricing, Contracting, and Acquisition Policy. The headline for defense contractors: the CMMC Phase 2 suspension survives into September, NIST SP 800-171 Rev 2 remains the enforceable baseline under DFARS 252.204-7012, and the information security rules you knew under DFARS 204 now live in a new DFARS Part 240.

Revision 3 supersedes Revision 2 of July 16, 2026. If you read our July analysis of the CMMC Phase 2 suspension, this is the follow-up: what carried over, what is genuinely new, and what you should be doing about it before your next option period.

What Revision 3 keeps in place for CMMC

The CMMC instructions from Revision 2, driven by the DoW Chief Information Officer’s memorandum of July 13, 2026 (Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements), carry into Revision 3 unchanged. Contracting officers must still:

  • Collaborate with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts.
  • Limit new procurement requests to CMMC Level 1 (Self) or Level 2 (Self) assessments. Level 2 (C3PAO) and Level 3 (DIBCAC) demands are off the table for new requirements while the suspension holds.
  • Require baseline compliance with NIST SP 800-171 Revision 2 under the clause at DFARS 252.204-7012.
  • Keep the November 2026 CMMC Phase 2 transition suspended.
  • Amend active solicitations as soon as practicable, and for existing contracts, remove the requirements by modification before the next option exercise or through the next scheduled administrative modification.

Read that last bullet again if you hold a contract with a CMMC clause in it: your contracting officer is instructed to strip it out at the next modification. If you have been budgeting for a rushed C3PAO assessment to keep an existing contract, the deviation just moved your deadline.

What is genuinely new in Revision 3

Revision 3 is not only a CMMC document. It implements several statutes and one court order:

Change What it does Where it lands
Alibaba carve-out Implements the July 5, 2026 order in Alibaba Group Holding Ltd. v. U.S. Department of Defense (N.D. Cal., 26-cv-6227-EKL): contracting officers must temporarily not treat Alibaba as a Chinese military company for purposes of 10 U.S.C. 4663 and the covered lobbyist prohibition, until the court rules on the TRO and preliminary injunction motion or 60 days after the hearing DFARS 240.70, Prohibited Sources
Huawei semiconductor prohibition Implements section 853 of the FY 2025 NDAA: no DoW contracts for covered semiconductor products and services with any entity that knowingly supplies them to Huawei New provision 252.240-7998 and clause 252.240-7999
DoW employee data Implements section 803 (FY 2024 NDAA) and section 836 (FY 2025 NDAA): contractors may not sell, license, or transfer personally identifiable information of DoW employees and service members to anyone but the Federal Government New clause 252.240-7992
Drone restrictions Implements section 848 (FY 2020 NDAA) and section 817 (FY 2023 NDAA): prohibitions on foreign-made unmanned aircraft systems from China, Russia, Iran, and North Korea, including DJI, plus counter-UAS detection gear New provision 252.240-7993 and clause 252.240-7994
Definition corrections Fixes errors in the definitions of covered lobbyist and Chinese military company DFARS 240.7003

Your DFARS map has been redrawn: 204 becomes 240

Under the Revolutionary FAR Overhaul, information security and supply chain security requirements now live in FAR Part 40 and a new DFARS Part 240, replacing the familiar 204 sections. The clauses you flow down keep working, but the prescriptions moved:

Requirement Old home New home under Revision 3
Safeguarding covered defense information, 72-hour cyber incident reporting DFARS 204.73 DFARS 240.370, clause 252.204-7012 (JUN 2026 deviation version)
NIST SP 800-171 DoD Assessments and SPRS scores Clauses 252.204-7019 and 252.204-7020 New clause 252.240-7997, NIST SP 800-171 DoD Assessment Requirements (FEB 2026)
CMMC level requirements DFARS 204.75 DFARS 240.371, clause 252.204-7021 (NOV 2025) and provision 252.204-7025
Chinese military company prohibitions DFARS 225.770 sections DFARS 240.7003, clause 252.240-7007 (SEP 2026)

Medium and High assessments will use the scoring methodology at 32 CFR 170.24, conducted against NIST SP 800-171A, and DCMA DIBCAC results take precedence over other assessments. Your SPRS score still gates awards.

The dates that matter now

Date What happens
November 2026 The CMMC Phase 2 transition that would have made C3PAO assessments mandatory in new solicitations: suspended
Until November 9, 2028 Clause 252.204-7021 goes into solicitations only when the program office or requiring activity specifies a CMMC level
On or after November 10, 2028 Clause 252.204-7021 applies to any contract where contractor systems process, store, or transmit FCI or CUI, unless the rules change again before then

The suspension removed a gate. It did not lower the standard. Every obligation in 252.204-7012, the 110 controls of NIST SP 800-171 Rev 2, the system security plan, the current SPRS submission, and 72-hour incident reporting to dibnet.dod.mil, is fully enforceable today, and the False Claims Act risk for overstated scores did not go anywhere.

What defense contractors should do this quarter

  1. Keep your SPRS score current and honest. Self-assess against NIST SP 800-171 Rev 2, post the score, and make sure your affirming official can stand behind it. Use our free SPRS score calculator to check where you stand.
  2. Watch your solicitations and modifications. Amendments removing CMMC language are arriving contract by contract. Confirm what your contracting officer intends before you spend on assessment prep that a modification is about to delete.
  3. Do not abandon Level 2 readiness if CUI is your business. The November 10, 2028 applicability date is still standing, primes are still flowing down requirements contractually, and a C3PAO certificate remains valid for 3 years. Companies that keep implementing now will be the ones that win when the gate returns. Our suspension scenarios analysis walks through how each path plays out.
  4. Budget with real numbers. The CMMC cost and roadmap planner and our 2026 certification cost breakdown reflect the post-suspension market, where assessment prices have softened.

BOOK A FREE CMMC SCOPING CALL

Looking for a CMMC consultant in the United States? See ITSecOps CMMC consulting for US defense contractors: a fixed-fee gap assessment from $5,000 with a defensible SPRS score, implementation, SSP and POA&M.

Frequently asked questions

Is CMMC cancelled after Class Deviation 2026-O0025 Revision 3?

No. The 32 CFR part 170 program rule remains law, and clause 252.204-7021 still phases in through November 10, 2028. Revision 3 continues the suspension of the Phase 2 transition and limits new requirements to Level 1 (Self) and Level 2 (Self) while the DoW CIO’s July 13, 2026 memorandum stays in effect.

Do I still have to comply with NIST SP 800-171?

Yes, fully. Revision 3 explicitly requires baseline compliance with NIST SP 800-171 Rev 2 under DFARS 252.204-7012 in every applicable contract, and the new clause 252.240-7997 preserves Government Medium and High assessments with results posted to SPRS.

What is DFARS Part 240?

Part of the Revolutionary FAR Overhaul: information security and supply chain security content from DFARS 204 and related parts has been consolidated into a new DFARS Part 240, paired with FAR Part 40, used in lieu of the codified text while the class deviation is in effect.

What happens to CMMC requirements already in my contract?

Revision 3 instructs contracting officers to remove them by modification before the next option exercise or through the next scheduled administrative modification. Confirm the plan for each affected contract with your contracting officer in writing.

Is my C3PAO certification wasted?

No. Certificates remain valid for 3 years, conditional statuses for 180 days, and the 2028 applicability date is unchanged. A current Level 2 (C3PAO) status also satisfies any prime that keeps flowing the requirement down contractually.

Does the Alibaba part affect defense contractors?

Only narrowly. A federal court in the Northern District of California ordered a temporary waiver, so contracting officers must not apply the Chinese military company and covered lobbyist prohibitions to Alibaba Group Holding Limited and Alibaba Group (U.S.) Inc. for 10 U.S.C. 4663 purposes until the court resolves the TRO motion or 60 days after its hearing. For every other purpose, Alibaba stays on the 1260H list.

Related reading

CMMC Phase 2 suspended: the July 2026 CIO memo explained · Three scenarios for how the suspension ends · CMMC readiness services · NIST 800-171 controls list · C3PAO certification cost · CMMC for non-US suppliers

Popular guides and pricingCybersecurity price comparison 2026  ·  EDR pricing per endpoint  ·  MDR pricing per device  ·  Veeam vs Acronis vs Datto  ·  Remote IT support pricing  ·  White-label help desk pricing  ·  24/7 SOC monitoring cost  ·  Top MDR providers  ·  White-label NOC and SOC for MSPs  ·  Top ISO 27001 consulting firms  ·  ISO 27001 implementation plan  ·  CMMC readiness services  ·  Top CMMC consulting firms  ·  ISO 42001 AI certification  ·  Global laptop provisioning and MDM  ·  Security stack recommender  ·  Managed IT services Norway