Want to learn more about our services? Book a free introductory call - "Here"

CMMC Phase 2 Class Deviation: What Changed in September 2026

DoD wrote the CMMC Phase 2 pause into binding contract regulations in September 2026. Here's what the class deviation actually changes, and why your self-assessment still needs to hold up

CMMC BLOG

Daniel McLain

9/22/20266 min read

CMMC's Phase 2 Pause Just Got Written Into Contract Regulations.
Here's What Changed

If you read our article on the July 2026 CMMC Phase 2 suspension and figured the story was over, there's an update worth your attention. In early September, the Department of Defense (DoD) took a second, more formal step: it wrote the pause directly into the regulatory language that contracting officers have to follow. That's a different thing than a policy memo, and it changes how hard this would be to reverse.

At the same time, a June 2026 Justice Department settlement is a useful, concrete reminder of why "Phase 2 is paused" doesn't mean "relax." Here's what actually happened, and what it means for your compliance work right now.

What changed in September

On September 3, 2026, John Tenaglia, DoD's principal director for Defense Pricing and Contracting (DPC), issued a memo directing contracting officers to strip Cybersecurity Maturity Model Certification (CMMC) third-party assessment requirements out of contracts and solicitations (Washington Technology; Nextgov/FCW). The mechanism DoD used is called a class deviation: a formal, documented instruction that tells contracting officers to depart from the standard acquisition regulation language across a whole class of contracts, rather than case by case.

This wasn't DoD's first use of that mechanism for the CMMC pause. Class Deviation 2026-O0025 was first issued on July 16, 2026, just days after the original suspension memo, and was revised again on September 3 and 4. According to industry coverage that reviewed the text directly, the CMMC-related language in the deviation didn't actually change between the July and September versions: both continue permitting Level 1 and Level 2 self-assessment and reference back to the original July 13 pause memo (Fortreum).

So what's actually new isn't the substance. It's the form. A memo is a policy statement. A class deviation is a standing instruction contracting officers are required to follow when writing and administering contracts. Several industry analysts have described this shift as making the pause harder to reverse, since undoing it now would take a formal regulatory step rather than a simple change of direction from department leadership. That's their interpretation of what a more durable deviation means procedurally, not a claim DoD has made about its own intentions, and it's a reasonable read given how class deviations typically work.

What this does not change

It's worth repeating what our July article already said, because none of it moved in September:

  • Phase 1 self-assessment is still required. Level 1 (Federal Contract Information, or FCI) annual self-assessment and Level 2 (Controlled Unclassified Information, or CUI) self-assessment against all 110 NIST SP 800-171 Revision 2 requirements are both still active, with the same Supplier Performance Risk System (SPRS) submission and affirmation requirements as before.

  • DFARS clause 252.204-7012 obligations are untouched. Safeguarding covered defense information, meeting the FedRAMP Moderate baseline for cloud services, and reporting cyber incidents within 72 hours are still binding wherever that clause appears in your contract.

  • The underlying CMMC rule, 32 CFR Part 170, has not been revoked. The class deviation changes what contracting officers put in new and modified contracts. It doesn't repeal the rule itself.

  • The Defense Contract Management Agency (DCMA) retains its own independent assessment authority, separate from the paused C3PAO third-party certification requirement.

If you read one thing into the September news, make it this: the pause got more official, not bigger. The scope of what's actually paused (third-party C3PAO assessment) hasn't expanded to cover self-assessment, SPRS, or your existing contractual obligations.

Where the Reform Task Force stands

The CMMC Reform Task Force's public comment period, opened alongside the July suspension, closed August 14, 2026. The task force's report was due to DoD Chief Information Officer Kirsten Davies within roughly 60 days of the July 13 memo, putting the internal deadline around September 11.

As of this writing, we found no public confirmation that the report has been released or what it recommends. Multiple outlets covering the September class deviation note that Davies controls whether and when the task force's findings become public, and describe the path forward as genuinely unclear (Nextgov/FCW). Treat any specific prediction about a new framework, a revised Phase 2 date, or program changes as speculation until DoD says so directly.

Why the pause isn't a reason to ease up on your self-assessment

Here's the part that gets missed. Third-party certification is paused. Self-assessment accuracy is not, and the government has shown it's willing to pursue that separately, through the False Claims Act, when a self-assessment doesn't hold up.

In June 2026, the Department of Justice announced a $507,144 settlement with LOGZONE Inc., a defense contractor based in Huntsville, Alabama, resolving allegations that the company knowingly submitted false claims for payment on two Navy contracts despite not implementing required cybersecurity controls (Department of Justice). DCMA's own assessment scored the company's actual NIST SP 800-171 implementation at -170, close to the bottom of the -203 to 110 scoring range, covering a period from 2021 through 2025.

This wasn't a CMMC enforcement action. Phase 2 didn't exist yet for most of that window. It was a False Claims Act case built on the gap between what the company billed the government for and what its cybersecurity posture actually was. That exposure exists independent of C3PAO certification, and it applies to any contractor currently self-attesting to NIST SP 800-171 compliance, which is most of the Defense Industrial Base (DIB) right now.

A short example. Picture a 40-person contractor that submitted a strong SPRS score two years ago, before the current compliance push, and hasn't revisited it since. Nobody updated the System Security Plan (SSP) when the office moved to a new file-sharing tool. Nobody re-checked whether the multifactor authentication rollout actually covers every privileged account. The company isn't lying, exactly. It just stopped looking. That's precisely the gap a whistleblower, a losing competitor, or a DCMA review can turn into a False Claims Act problem, regardless of whether a C3PAO assessment is required on that contract today.

What an honest self-assessment actually requires

The 110 requirements in NIST SP 800-171 sound like 110 things to check. In practice, NIST SP 800-171A breaks those requirements down into roughly 320 individual assessment objectives, the specific, granular things an assessor (or DCMA, in a review like the one behind the LOGZONE settlement) actually checks for. A self-assessment that only glances at the 110 headline requirements, without working through what each objective actually demands, is the kind of self-assessment that doesn't hold up later.

We'd recommend, as a practical matter rather than a separate legal requirement, that your self-assessment process:

  • Works from NIST SP 800-171A's assessment objectives, not just the 110 requirement titles, the same standard an assessor would use.

  • Documents evidence for each practice you mark as Met: configuration exports, policy documents, screenshots tied to a specific date, not just a checkbox.

  • Gets reviewed by someone other than the person who implemented the controls, since a second set of eyes tends to catch the gaps the first pass missed.

  • Treats the SPRS score you submit as something you could be asked to defend, because you might be.

None of this is new advice, and none of it depends on what happens with Phase 2 or the task force's report. It's what a defensible Level 1 or Level 2 self-assessment has required since Phase 1 took effect in November 2025.

What to do with this right now

  • Don't read the September class deviation as evidence that CMMC is going away. It formalized an existing pause; it didn't expand what's paused.

  • Keep your Phase 1 self-assessment, SSP, and SPRS affirmation on schedule, evaluated against the actual assessment objectives, not just the requirement headlines.

  • If it's been more than a year since your last honest look at your SPRS score, that's worth revisiting now, independent of any Phase 2 news.

  • Watch for the Reform Task Force's report and any DoD announcement about what replaces Phase 2's assessment model, and treat anything short of an official statement as speculation.

A quick note on this article

This is general informational guidance based on publicly available sources as of September 22, 2026, not legal advice. It isn't a substitute for reviewing your specific contract language or consulting a Registered Practitioner Organization (RPO) or a Certified Third-Party Assessment Organization (C3PAO) for a compliance determination specific to your situation. CMMC's regulatory status is still moving.

Before you assume a paused certification requirement means a lighter workload, make sure your self-assessment would actually hold up if someone asked you to defend it. ICTS USA can help you review your SPRS score against real evidence, identify gaps before they become someone else's finding, and figure out a practical next step.

Official resources

Copyright © 2026 ICTS USA LLC - All Rights Reserved.