Defense contractors hoping for a full repeal of CMMC got something narrower and more tangled instead: a binding regulatory memo that locks in the program's delay while quietly attaching bans on Chinese semiconductor suppliers, restricted drone components and the sale of employee data. On September 3, 2026, the Department of War issued Revision 3 of Class Deviation 2026-O0025, replacing the CMMC final rule's clause set with new DFARS Part 240 language tied to the Pentagon's Revolutionary FAR Overhaul.
Signed by John Tenaglia, DoD's principal director for defense pricing, contracting and acquisition policy, the deviation directs contracting officers to strip third-party CMMC assessment requirements performed by C3PAOs from both new and existing solicitations and contracts. It is the third version of a class deviation first issued earlier this year, and it formalizes what had been treated as a temporary pause: the suspension of the November 2026 transition to CMMC Phase 2, when third-party certification was set to become mandatory for contracts touching controlled unclassified information.
Self-Assessment Still Rules Under DFARS 252.204-7012
Revision 3 does not touch the underlying cybersecurity obligations contractors have followed since 2017. DFARS clause 252.204-7012 remains in force, along with the requirement to implement all 110 security controls in NIST SP 800-171 Revision 2, to score that implementation in the Supplier Performance Risk System, and to submit an annual affirmation of compliance. Attorneys at Covington & Burling, who reviewed the deviation for clients, summarized the practical effect plainly: "The suspension does not affect the underlying requirements to comply with NIST SP 800-171 Revision 2."
In other words, the paperwork burden of hiring an outside assessor disappears for now, but the compliance obligation itself does not. Companies still have to self-certify, still have to maintain a current SPRS score, and still face False Claims Act exposure if that self-assessment turns out to be inaccurate.
The Huawei, Drone and Data-Sale Provisions Riding Along
The deviation is not only about CMMC. It also folds in unrelated statutory requirements from recent National Defense Authorization Acts that contracting officers now must apply. Section 853 bars the Department of War from contracting with entities that knowingly supply semiconductors, semiconductor manufacturing equipment or chip-design tools to Huawei and its affiliates. Sections 803 and 836 prohibit contractors from selling, licensing or otherwise transferring Department of War employees' personal data to non-government parties, a restriction that must flow down, in substance, to every subcontract. Sections 817 and 848 bar the use or procurement of unmanned aircraft systems, and UAS detection equipment, built in China, Russia, Iran or North Korea, or that rely on flight controllers, radios, cameras, gimbals, ground-control software or network connectivity sourced from those countries.
Revision 3 also corrects a drafting problem from Revision 2. The earlier version defined "Chinese military company" too broadly; the new text narrows it to only those entities on the Section 1260H list maintained by the Department of War, a list that itself requires annual publication and updates through December 31, 2030. That narrowing matters beyond CMMC: a separate federal court order currently blocks the department from treating Alibaba Group Holding Limited and Alibaba Group (U.S.) Inc. as a Chinese military company for purposes of the covered-lobbyist ban under 10 U.S.C. § 4663, and Revision 3 builds that temporary waiver directly into the regulation, showing how contested the underlying list remains even as contracting officers are told to rely on it going forward.
A Reform Task Force That Hasn't Reported Yet
The timing is notable. The CMMC Reform Task Force's 60-day review deadline landed on September 11, 2026, eight days after Revision 3 was signed. DoD Chief Information Officer Kirsten Davies now holds that report and will decide what, if anything, to make public. Functionally, the class deviation locked self-assessment in as the de facto standard before any task force recommendation reached daylight, leaving the formal reform process to catch up to a regulatory reality that had already changed on paper.
Davies has been careful to frame the pause as procedural rather than a retreat from security. "This isn't about whether cybersecurity is important or not. It is. It's critical. It's vital," she said at the Billington Cybersecurity Summit, according to Nextgov/FCW's reporting on the binding regulation. Industry's read is similar. Stephanie Kostro, president of the Professional Services Council, told Federal News Network that the deviation should not be mistaken for the program's end: "This is not the death knell of CMMC. In no way, shape or form does this class deviation say CMMC is dead."
What It Means for Contractors
For companies with contracts touching controlled unclassified information, the near-term relief is real: no C3PAO assessment fees, no third-party audit scheduling, no scramble to hit a November 2026 Phase 2 deadline that is now formally suspended rather than informally paused. But the self-assessment obligations under DFARS 252.204-7012 have not moved, and SPRS scores and annual affirmations remain the operative compliance record that contracting officers and DoD Inspector General auditors will check.
The provisions bundled into the same memo demand separate attention. Companies in the semiconductor and electronics supply chain need to confirm they are not knowingly selling chips, fabrication equipment or design tools to Huawei or its affiliates under Section 853, since that exposure can disqualify a company from Department of War work regardless of CMMC status. Any contractor handling DoW employee personal data needs written flow-down language in subcontracts reflecting the Section 803/836 transfer restrictions, now built directly into contract clause 252.240-7992. Drone and UAS component suppliers should re-check their bill of materials against the Section 817/848 banned-country list, which reaches into flight controllers, radios, cameras, gimbals, ground-control software and data storage, not just the airframe itself. And because the underlying Section 1260H list changes annually through 2030, and remains subject to litigation like the pending Alibaba dispute, compliance teams should treat that list as a moving target rather than a one-time check.
The larger signal is that the Pentagon is comfortable using class deviations, not just notice-and-comment rulemaking, to make binding changes to contract requirements while a formal policy review is still underway. Contractors watching for the CMMC Reform Task Force's eventual public report should not assume it will reopen questions Revision 3 has already settled, since the deviation already functions as the operative rule contracting officers are applying to live solicitations today.
Sources
- Class Deviation 2026-O0025, Revision 3 – Revolutionary FAR Overhaul Part 40, DFARS Part 240
- DoW Issues Revision 3 of its Class Deviation on Security Requirements (Covington & Burling)
- As the Pentagon rethinks CMMC, cybersecurity isn't pausing (Federal News Network)
- CMMC's Phase 2 suspension locked in with binding regulation (Nextgov/FCW)