Contact Us

BREAKING: The CMMC Suspension Is Now a Regulation. Here Is What Changed.

Published 2026 | TIKC NewsWire

The CMMC story just took a decisive turn, and defense contractors need to read it carefully. On September 3, 2026, the Department of Defense converted the Phase 2 suspension from a policy memo into a binding acquisition regulation, signing Revision 3 of DFARS class deviation 2026-O0025. The practical message: the pause is now durable enough to plan around, but the legal exposure for a bad self-assessment is very much alive. Two fresh DOJ settlements prove it.

What actually changed on September 3

Back in July, DoD suspended CMMC Phase 2 (the third-party certification tier) through a policy memo. That was reversible with the stroke of a pen. The new class deviation makes it stickier, because reversing a regulation requires affirmative regulatory action, not just a new memo. The deviation directs contracting officers to apply the Revolutionary FAR Overhaul clause set (the new Part 40 framework) instead of the CMMC final-rule clauses, and to remove third-party (C3PAO) assessment requirements from solicitations and contracts (Kiteworks, 2026; Nixon Peabody, 2026).

What did NOT change: your obligations are intact

This is the part contractors keep getting wrong. The suspension pauses the outside certification. It does not pause the underlying security duties. Still fully in force:

  • DFARS 252.204-7012, the safeguarding clause requiring NIST SP 800-171 Rev 2 implementation and 72-hour cyber incident reporting.
  • Your SPRS self-assessment score, which remains a condition for handling controlled unclassified information and is a legal representation to the government.
  • The annual affirmation, which a named senior official must still sign.
  • Government-led assessments, which are preserved so DoD can still check your posture directly.
GovCon iSource. Your pipeline runs while you run your business.

The enforcement warning: two settlements during the pause

Here is why the suspension is a trap for the complacent. Even as the certification requirement paused, DOJ kept pursuing contractors for inaccurate self-assessments under the False Claims Act. LOGZONE settled for $507,144 over Navy cybersecurity gaps, and in September 2026 Honeywell Aerospace agreed to pay roughly $2.04 million to resolve allegations tied to NIST 800-171 shortfalls (Shumaker, 2026; Nixon Peabody, 2026). The pattern is unmistakable: no C3PAO is checking your work right now, which means your self-reported SPRS score carries the legal weight, and if it is inflated, that is the theory of a False Claims Act case.

What this means for small defense contractors

The suspension became permanent enough to plan around. So did the exposure. If you paused your compliance work thinking CMMC went away, you have it backwards. The right read is: keep building toward NIST 800-171, keep your SPRS score honest and supportable, and treat that number as a certification, because the government does. When Phase 2 eventually returns in some form, the firms that stayed the course will be ready, and none of them will have handed DOJ a false-claims case in the meantime.

What to do now

  • Do not stop your NIST 800-171 work. The safeguarding obligation under DFARS 7012 never paused.
  • Make your SPRS score accurate and defensible. Score against the real state of your systems and keep the evidence (system security plan and POA&M).
  • Sign the annual affirmation truthfully, and make sure the named official can stand behind it.
  • Watch for the Task Force report and the eventual return of third-party assessment, so you are ahead of it, not scrambling.

A pause is not a pass. The rule got stickier and the enforcement got sharper on the same page. Keep your posture honest. Brick by brick.

Not sure where you fit? Start with a call. Book Free Call.

FAQ

Is CMMC cancelled now?

No. Phase 2 third-party certification is suspended, and that suspension was made a binding DFARS class deviation on September 3, 2026. The underlying cybersecurity requirements remain in force, and the program is expected to return in some form.

Why does a class deviation matter more than the July memo?

A policy memo can be reversed easily. A regulation requires affirmative regulatory action to undo, so the suspension is now more durable and easier to plan around.

Can I be sued if no one is certifying my cybersecurity?

Yes. With third-party assessment paused, your self-reported SPRS score carries the legal weight. DOJ has settled cases (LOGZONE and Honeywell) over inaccurate self-assessments under the False Claims Act.

What should I keep doing?

Keep implementing NIST SP 800-171, keep your SPRS score accurate and supported, sign your annual affirmation truthfully, and maintain your incident-reporting readiness under DFARS 252.204-7012.

GovCon iSource. Your pipeline runs while you run your business.

Sources

Kiteworks. (2026, September). DFARS Class Deviation 2026-O0025, Revision 3: What it actually changes for CMMC.

Nixon Peabody LLP. (2026, September 9). Honeywell settlement shows FCA risk for NIST 800-171 gaps.

Shumaker, Loop & Kendrick, LLP. (2026, September). DOJ’s $2 million Honeywell settlement reinforces cybersecurity as a False Claims Act risk.

This article is general information, not legal advice.

Melanie Patterson

About the Author

Melanie Patterson

Founder and CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale, brick by brick. Contact

Most Read

Federal law bars using appropriated funds to lobby for a contract or grant, and requires
If your firm advises the government, an impaired-objectivity conflict can bar you from related work.

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading