Published September 11, 2026.

On September 3, 2026, the Department of War issued DARS Class Deviation 2026-O0025, Revision 3, signed by John Tenaglia. It supersedes Revision 2 from July 16 and writes the July 13 CMMC Phase 2 suspension directly into DFARS Part 240 text. Contracting officers are now directed to remove or revise CMMC requirements in new and existing solicitations, with contracts amended at the next option exercise or scheduled administrative modification.

Within a week, half the defense supply chain decided this meant they have until November 10, 2028. That reading is wrong, and it is the expensive kind of wrong.

What did Class Deviation 2026-O0025 Revision 3 actually change?

It changed who verifies your compliance, not whether you have to be compliant. Revision 3 permits CMMC Level 1 and Level 2 requirements to be satisfied by self-assessment. Third-party certification through a C3PAO is not being written into new solicitations while the deviation is in effect.

That is a procedural change in verification method. Every underlying security obligation survived the memo intact.

The short version: the government stopped asking an outside assessor to check your work. It did not stop requiring the work, or holding you accountable for what you claim about it.

Why November 10, 2028 is not your CMMC deadline

November 10, 2028 is the Phase 4 full implementation date. It has been in the rule since November 2025. The September 3 deviation did not create it, move it, or extend it. It is a program milestone for the Department, not a certification deadline for your company.

Treating it as a deadline makes two assumptions, and both are wrong: that you have two years of runway, and that something specific comes due on that date for your business.

There is no fixed date for when third-party certification returns to solicitations. Anyone quoting you one is guessing. The signals worth watching are Department of War CIO actions and the Federal Register, not the next class deviation. The CMMC Reform Task Force is expected to deliver findings to the DoW CIO internally around September 13, with a public report anticipated near September 28. That report will tell you more about direction than any calendar date circulating on LinkedIn right now.

What did not change on September 3?

DFARS 252.204-7012 and the 110 controls are fully in force

DFARS 252.204-7012 remains in your contracts. All 110 NIST SP 800-171 Revision 2 controls remain fully in force. If you handle Controlled Unclassified Information, your obligation to implement those controls is exactly what it was on September 2.

SPRS status gates three separate events

Your Supplier Performance Risk System status still gates award, option exercise, and period of performance extension. All three are withheld if your status lapses. A supplier who lets an affirmation go stale does not simply miss a new award. They can stall an option year on work they already have.

DCMA can assess you at any time

The Defense Contract Management Agency retains authority to run a Medium or High assessment on any covered system at any time, and that result overrides your posted score. Self-assessment is not the end of the review. It is the opening position you will be asked to defend.

Status validity periods still run on a clock

Conditional status is valid for 180 days before converting to Final, and Final is valid for three years. Those windows do not pause because the verification method changed.

Why self-assessment raises your legal exposure instead of lowering it

When a C3PAO signs off, an independent party shares responsibility for the finding. Under self-assessment, the score in SPRS is your assertion, submitted by your company, relied on by the government for award decisions. That is a representation with legal weight, and it will carry that weight for roughly the next two years.

The CyberSheath 2026 State of the DIB study, covering 302 contractors, found confidence in one's own score at the lowest level ever recorded while reported scores hit a multi-year high. Scores went up. Belief in them went down. That gap is the risk.

Illustrative example, not a specific client engagement: a 60-person machine shop in Everett posts an SPRS score of 88, taken from a spreadsheet a departed IT manager built in 2023. Multifactor authentication reached email but never the engineering file share. DCMA opens a Medium assessment during an option year review, the verified score comes back materially lower, and the option exercise stalls while the company tries to explain an affirmation it cannot document. That sequence did not need a 2028 deadline to hurt.

CMMC Readiness Checklist. A control by control worksheet for defense suppliers who need to know whether their SPRS score would survive a DCMA assessment. Built for manufacturers and aerospace suppliers across Washington, Oregon, Idaho, and Montana.

Get the Checklist Book a 30-Minute Call

What are primes doing while the Department waits?

Flowing requirements down anyway. Primes are pushing CMMC expectations to subcontractors ahead of specific contracts, on their own timeline. Their exposure does not move when a class deviation changes verification method.

For a Tier 2 or Tier 3 supplier in the Puget Sound aerospace cluster, that is the deadline that actually governs. It arrives as a supplier questionnaire or a qualification packet, not as a Federal Register notice. Our manufacturing and Department of Defense clients are seeing these requests now.

What should you do in the next 90 days?

Four things, in this order.

  1. Rescore honestly. Rerun the NIST SP 800-171 self-assessment against current reality, not against the 2023 spreadsheet. Assume someone will verify it.
  2. Update the System Security Plan. The SSP has to describe the environment you operate today, including cloud services and remote access added since the last revision.
  3. Date every POA&M item. An open gap with a realistic remediation date is defensible. An open gap with no date is not.
  4. Collect evidence now. Screenshots, policy documents, configuration exports, training records. Evidence assembled in advance is a document pull. Evidence assembled during an assessment is a fire drill.

None of this depends on knowing when third-party certification returns. All of it is what you would need on the day it does.

Get a second read on your SPRS score. inTech Consulting provides CMMC 2.0 and NIST SP 800-171 compliance consulting for defense suppliers in Kent, Everett, Tacoma, Seattle, Spokane, Portland, and Boise. We do not perform certification assessments. We make sure the number you post is one you can defend.

See CMMC Compliance Services Book a 30-Minute Call with Raj

inTech Consulting is a Minority Business Enterprise (MBE) certified through OMWBE, a member of PNDC, PNAA, and AWB, rated 5.0 across 100+ Google reviews, with no offshore helpdesk. See our compliance and risk services.

About the author. Raj Sidhu is Founder & CEO of inTech Consulting and author of "Beyond the Prompt: A Business Owner's Guide to Understanding AI." He works with aerospace, manufacturing, and defense suppliers across Washington, Oregon, Idaho, and Montana on CMMC 2.0 and NIST SP 800-171 compliance.

Frequently Asked Questions

Does DARS Class Deviation 2026-O0025 Revision 3 mean CMMC is canceled?

No. Revision 3 permits CMMC Level 1 and Level 2 to be satisfied by self-assessment and directs contracting officers to remove or revise CMMC requirements in solicitations. The program continues, DFARS 252.204-7012 remains in force, and all 110 NIST SP 800-171 Revision 2 controls still apply.

Is November 10, 2028 the new CMMC deadline?

No. That date is Phase 4 full implementation and has been in the rule since November 2025. The September 3, 2026 deviation neither created nor moved it, and it is not a certification deadline for individual contractors.

When will third-party CMMC certification come back to solicitations?

No fixed date exists. Watch Department of War CIO actions and the Federal Register rather than waiting for another class deviation. The CMMC Reform Task Force public report is expected near September 28, 2026.

Can DCMA still audit my SPRS score during the suspension?

Yes. DCMA retains authority to conduct a Medium or High assessment on any covered system at any time, and that result overrides your posted self-assessment score.

What happens if my SPRS affirmation lapses?

Award, option exercise, and period of performance extension are all withheld. A lapsed status can stall existing work, not just new opportunities.

How long is a CMMC Conditional status valid?

Conditional status is valid for 180 days before it converts to Final status, which is valid for three years.