CMMC's Phase 2 suspension locked in with binding regulation

Gettyimages.com/ Kevin Carter / Contributor

Find opportunities — and win them.

A new class deviation moves the pause on third-party assessments for this security standard from policy to an enforceable rule.

The Defense Department has moved beyond a simple suspension of third-party assessment requirements of the Cybersecurity Maturity Model Certification program and onto a binding regulation that essentially codifies the suspension.

A Sept. 3 memo from John Tenaglia -- DOD’s principal director for defense pricing, contracting and acquisition policy -- has directed contracting officers to comply with requirements in the Revolutionary FAR Overhaul instead of the final CMMC rule that has been in place since November 2025 for contract clauses.

The class deviation orders contracting officers to strip out from contracts any and all of CMMC’s requirements for third-party assessments.

DOD was following a phased approach to implementing CMMC with the third-party assessments set to begin this coming November, but the department has since suspended that plan for a 60-day review.

Because this is a class deviation and no longer a suspension, reversing this move is a more involved process.

What comes next is unclear. The 60-day review by the CMMC Reform Task Force force began July 13, which puts the deadline at Sept. 11 (Friday). How quickly the results of that review become public is also an open question.

The task force report will go to DOD Chief Information Officer Kirsten Davies first and it is up to her to make their recommendations public.

The July suspension went into place because of DOD’s concerns with CMMC becoming a bureaucratic burden and increasing costs, particularly for small businesses. CMMC also operational technologies and industrial controls.

Speaking at the Billington Cybersecurity Summit on Wednesday, Davies said cybersecurity is still a top priority for DOD.

“This isn't about whether cybersecurity is important or not. It is. It's critical. It's vital,” she said. “We wanted to hear more from the defense industrial base on what was important for meaningful, dynamic cybersecurity."

DOD has received more than 1,100 comments on the request for information it issued in July, Davies said. The comment period ended Aug. 14.

The department asked for feedback on cost drivers, administrative burdens tied to CMMC compliance and which NIST 800-171 security controls deliver meaningful risk reduction. DOD also wanted to know how it could incorporate commercial cybersecurity tools and managed services into a cybersecurity framework.

For government contractors, what has not changed is that self-attestation of compliance with the NIST standards is still required. There are consequences of those self-assessments that fall short or are not taken seriously.

In June, the Justice Department reached a settlement with Logzone to resolve allegations that the company submitted a nearly perfect score on its self-assessment. A DOD audit found that score to be wildly inaccurate and Logzone had to pay roughly $500,000.

One thing to watch for is whether Davies makes the task force's recommendations public and when. Those recommendations could dictate next steps for CMMC beyond self-attestation.


Edward Graham, managing editor for Nextgov/FCW, contributed to this report.