Skip to content
Share
Compliance Strategy
September 9, 2026
CONTRACT FILEC3PAO / Level 3Strip at next option or admin modCover memo ¶(b) — existing contractsSTILL OPERATIVEDFARS 252.204-7012NIST SP 800-171 Rev. 2 baselineLevel 1 / Level 2 (Self) still permitted

The Pause Is Now in the Contract File

Class Deviation 2026-O0025, Revision 3 does not give CMMC Phase 2 a 2027 date. It tells contracting officers how to pull third-party assessment language out of live vehicles — and what they must leave in.

The sentence circulating this week is that CMMC got pushed to next year. That is not what the Department of War published. What landed is a class deviation that turns the July 13 Phase 2 pause into instructions every contracting office has to follow.

Class Deviation 2026-O0025, Revision 3 — from the Office of the Assistant Secretary of War (Acquisition and Sustainment), signed by Principal Director John M. Tenaglia — revises and supersedes Revision 2 of July 16, 2026 and is effective immediately. It tells contracting officers to use the rewritten FAR Part 40 and DFARS Part 240 in lieu of the currently codified text. The CMMC order sits in paragraph (b) of the cover memo, and it is more specific than a delay headline.

The one-sentence version

Third-party CMMC language comes out of the contract file. NIST SP 800-171 Rev. 2 under DFARS 252.204-7012 stays. Level 1 (Self) and Level 2 (Self) remain permitted. A 2027 restart date was not issued.

What Revision 3 actually orders

Contracting officers must collaborate with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts, in accordance with the CIO memorandum of July 13, 2026. The cover memo then lists what that collaboration looks like:

Self-assessment is permitted, not a blanket fill-in

Requiring activities may include CMMC Level 1 (Self) or Level 2 (Self) in procurement requests and requirement documents. The verb is “permits.” That is a shift from 32 CFR § 170.3(e), where DoD “intends to include” those self-assessment statuses in applicable solicitations during Phase 1.

NIST 800-171 Rev. 2 remains the baseline

The same paragraph requires baseline compliance with NIST SP 800-171 Rev. 2 in accordance with DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

The November 2026 Phase 2 transition is suspended

That is the C3PAO Level 2 certification-as-a-condition-of-award ramp that 32 CFR § 170.3(e)(2) had set to begin one calendar year after Phase 1. Revision 3 suspends it. It does not replace it with a new calendar date.

Live solicitations get amended now

Program managers and requiring activities must initiate amendments to active solicitations. Contracting officers must issue the corresponding amendments as soon as practicable.

Existing contracts get cleaned at the next touchpoint

Where a contract already contains the paused requirements, contracting officers must remove them by modification before exercising the next option, or through the next scheduled administrative modification. That is why “next year” is showing up in contractor conversations — for many vehicles, the next option is a 2027 event.

We covered the July 13 pause itself in CMMC Phase 2 Is Paused — But the Requirements That Reach Your Front Desk Never Moved. Revision 3 is the follow-through: the pause is no longer only a CIO memo. It is in the DFARS deviation contracting officers are told to use.

The same instrument also implements a court-ordered, temporary waiver of certain 10 U.S.C. 4663 / section 1260H treatments for Alibaba Group Holding Limited and Alibaba Group (U.S.) Inc. That is a separate supply-chain issue. It is not the CMMC change.

What is still in DFARS Part 240

Read the cover memo and the attached Part 240 together. The memo constrains how CMMC is used during the pause. The clause text was not repealed.

Constrained by the memo
  • November 2026 Phase 2 (C3PAO) transition — suspended
  • Level 2 (C3PAO) and Level 3 (DIBCAC) as a condition of award — not to be advanced under the July 13 memo
  • Active solicitations — amend as soon as practicable
  • Existing contracts carrying those requirements — modify before next option or at next admin mod
Still on the page
  • 252.204-7012 — safeguard CUI, report cyber incidents
  • Level 1 / Level 2 (Self) — still a permitted fill-in
  • 252.204-7021 / 7025 — still in the deviation; SPRS still gates award when a level is specified
  • 252.240-7997 — government Medium/High NIST 800-171 assessments still authorized

Two details in the attached text are easy to miss. First, 240.371-5 still says to insert 7021 through November 9, 2028 when the requiring activity names a CMMC level, and more broadly on or after November 10, 2028. That was the original Phase 4 date. Revision 3 did not rewrite it. Second, 240.371-4 still requires contracting officers to check SPRS before award, option exercise, or a period-of-performance extension whenever a CMMC status is required. If your contract still carries Level 2 (Self), the affirmation in SPRS is still a representation the government can hold you to.

“Permits” is not the same as “you can stop”

Discretion over whether a new solicitation includes Level 1 or Level 2 (Self) is a requiring-activity decision. It does not waive 7012 on contracts that already have it, and it does not erase a self-assessment already posted to SPRS. An affirming official’s annual statement is still a statement.

Why people are saying “next year”

Under 32 CFR § 170.3(e), Phase 2 was to begin November 10, 2026; Phase 3 on November 10, 2027; Phase 4 on November 10, 2028. The July 13 memo froze those future milestones until further notice. Revision 3 is the DoD-wide contracting instruction that implements that freeze: C3PAO language comes out of live files at the next option or admin mod, which for a large share of the industrial base is a 2027 event.

Inference is not a date. The Reform Task Force stood up in July is still due to report around mid-September 2026. Until a class deviation, DFARS rule, or 32 CFR Part 170 amendment publishes a new phase-in, “delayed to 2027” is industry shorthand — not an issued schedule.

What still reaches the front desk

Visitor escorting, physical-access logs, and control of CUI areas are not C3PAO inventions. They are NIST SP 800-171 Physical Protection controls 3.10.1, 3.10.3, and 3.10.4. Those live inside the 7012 baseline Revision 3 expressly keeps, and inside any Level 2 (Self) assessment a requiring activity is still permitted to include. The audience for that evidence may be a self-assessor, a DCMA / DIBCAC team running a Medium or High assessment under 252.240-7997, or a C3PAO if third-party assessment returns. The evidence does not change with the audience.

Where SecurePoint fits: the visitor platform generates timestamped access logs, escort records, and an audit trail that support those Physical Protection and Audit & Accountability families, and screens visitors and vendors against restricted-party lists with a recorded disposition. That is assessment evidence. It is not a CMMC certification, and we do not claim otherwise.

What to do with the contract file this month

Read the actual vehicles. If a live solicitation still names Level 2 (C3PAO) or Level 3 (DIBCAC), expect an amendment — and confirm it with the contracting officer rather than assuming the clause vanished on its own.

Keep DFARS 252.204-7012. Safeguarding CUI and 72-hour incident reporting were not paused.

If you already posted a Level 1 or Level 2 self-assessment to SPRS, keep the affirmation current. Revision 3 did not convert an existing score into a free pass.

Separate C3PAO-queue spend from control implementation. The appointment may wait. The 110 NIST 800-171 requirements, including physical access, did not.

Make visitor, escort, and CUI-area access evidence retrievable now — mapped to 3.10.1, 3.10.3, and 3.10.4 — so whichever assessor asks next is not reconstructing a log from a binder.

Watch the Reform Task Force report, then verify any new date or clause against DARS and 32 CFR Part 170. Do not treat a LinkedIn summary as the deviation.

Frequently asked questions

No date of that kind appears in Class Deviation 2026-O0025, Revision 3. The cover memo suspends the November 2026 Phase 2 transition and tells contracting officers to remove or revise CMMC requirements in new and existing solicitations and contracts in accordance with the July 13 CIO memorandum. For existing contracts that already contain those requirements, the instruction is to strip them by modification before the next option or at the next administrative modification. That is a contracting calendar, not a published 2027 restart.

Primary & source coverage

This article is based on Class Deviation 2026-O0025, Revision 3 (cover memo and attached DFARS Part 240), which supersedes Revision 2 dated July 16, 2026 and is effective immediately. Class deviations and CMMC phase status change. Verify the current text on the DARS class-deviation page and 32 CFR Part 170 before relying on any statement here. This is educational and is not legal advice.

The file still has to show the control

C3PAO language can come out at the next option. The visitor log, escort record, and screening disposition still have to be there the day someone asks. See how SecurePoint USA produces that evidence.

Found this helpful? Share it with a colleague.

Visitor Compliance Checklist

  • ITAR/EAR and CMMC L2 requirements
  • Audit-ready evidence collection
  • AI assists, humans approve
Download PDF

Stay ahead of compliance changes

Get weekly insights on sanctions, export controls, and visitor compliance delivered to your inbox.

No spam. Unsubscribe anytime.

Related posts

Keep exploring compliance playbooks

More guidance on sanctions, export controls, and visitor management for regulated facilities.

View all articles
CMMC Class Deviation 2026-O0025 Revision 3: The Pause Is Now in the Contract File | SecurePoint USA