By Dan Gordon
Last Updated: September 17, 2026
On July 13, 2026, the Department of War suspended CMMC Phase 2, the transition that would have made third-party C3PAO certification a condition of award for most contracts involving Controlled Unclassified Information starting November 10, 2026. Phases 3 and 4 were frozen alongside it.
Two months later, the Department of Justice announced a $2 million False Claims Act settlement with Honeywell Aerospace over alleged NIST SP 800-171 failures. Three months before that, it settled with a Huntsville contractor that had self-reported a perfect SPRS score of 110 and was later assessed by DIBCAC at negative 170.
Those three events tell one story. The verification mechanism changed. The obligations did not, and the legal exposure attached to getting your own assessment wrong went up.
What the CMMC Phase 2 Suspension Actually Changed
DoW Chief Information Officer Kirsten Davies signed the suspension memorandum, publication case 26-P-1023, on July 13. It paused the Phase 2 transition with immediate effect and stood up a CMMC Reform Task Force with 60 days to conduct a top-to-bottom program review, informed by a public Request for Information that closed August 14.
Contracting officers were directed to amend active solicitations to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements as soon as practicable, and to modify existing contracts carrying those requirements no later than the next option exercise or scheduled administrative modification. The Department also confirmed it would not grant CMMC Program waivers during the review period.
The stated rationale was cost and capacity, not a reduced threat assessment. SBA data cited by the DoW CIO suggested future CMMC phases could cost small and midsize businesses more than $7 billion annually. The arithmetic problem was equally hard to ignore: roughly 80,000 companies were expected to need third-party assessments against an authorized C3PAO pool numbering around 100.
Under Secretary of War for Acquisition and Sustainment Michael Duffey framed the change as removing the bureaucracy of third-party assessment rather than relaxing the underlying standard. Davies described the assessment model as a "burdensome, red-tape ridden, check-the-box, point-in-time view" of how a company handles sensitive data.
Note the precise scope. The suspension pauses a verification requirement. It does not repeal 32 CFR Part 170, and the CMMC program remains codified.
| Date | Event | Mechanism |
|---|---|---|
| July 13, 2026 | Phase 2 transition suspended; Phases 3 and 4 frozen; CMMC Reform Task Force stood up with 60 days | DoW CIO memorandum, publication case 26-P-1023 |
| July 16, 2026 | Suspension written into acquisition instruction | DARS Class Deviation 2026-O0025, Revision 2 |
| August 14, 2026 | Public Request for Information closed | CMMC Reform Task Force RFI |
| September 1, 2026 | Honeywell Aerospace agrees to pay $2,042,518 over alleged NIST SP 800-171 failures | DOJ False Claims Act settlement |
| September 3, 2026 | Revision 3 supersedes Revision 2; CMMC language unchanged | DARS Class Deviation 2026-O0025, Revision 3 |
| ~September 11, 2026 | Task Force 60-day clock runs out; findings go to the CIO internally | Internal delivery |
| September 21, 2026 | All FIPS 140-2 cryptographic module certificates move to Historical status | NIST CMVP, never tied to Phase 2 |
| Late Sept to early Oct 2026 | Public Task Force report expected | Advisory; changes no contract obligation on its own |
| November 10, 2026 | Original Phase 2 start date | Suspended |
Key dates from the suspension through the expected Task Force report.
Class Deviation 2026-O0025: How the Pause Became Binding Contract Language
A CIO memorandum sets policy. It does not by itself change what appears in a contract. That step came through DARS Class Deviation 2026-O0025, issued by the Office of the Assistant Secretary of War implementing the Revolutionary FAR Overhaul's Part 40 and the corresponding DFARS Part 240.
Revision 2, issued July 16, first wrote the suspension into acquisition instruction. Revision 3, signed September 3 by John M. Tenaglia, Principal Director for Defense Pricing, Contracting, and Acquisition Policy, superseded it and directs contracting officers to apply the revised FAR Part 40, DFARS Part 240, and DFARS PGI 240 in place of the codified text.
The CMMC language in Class Deviation 2026-O0025 remained unchanged between Revision 2 and Revision 3. Both reference the July 13 pause memo, permit Level 1 and Level 2 to be satisfied through self-assessment, uphold NIST SP 800-171 Revision 2 compliance via DFARS 252.204-7012, and suspend the November 2026 transition. Revision 3's substantive new content addressed unrelated matters, including a new DFARS 240.374 restricting award to entities that transfer covered personally identifiable information of Department employees to third parties.
This distinction matters because Revision 3 circulated widely in early September alongside claims that it would effectively end CMMC. A former Department CIO posted to that effect and subsequently removed the post. Firms that compared the revisions line by line, including Fortreum and Redspin, reached the same conclusion: Revision 3 is a holding pattern, not a decision.
What the deviation does change is durability. A class deviation is binding acquisition regulation. Undoing it requires regulatory action rather than an announcement, which means the self-assessment default now has more staying power than the July memo alone would have given it.
What Still Applies: DFARS 252.204-7012, NIST SP 800-171, and SPRS
This is the section to send to anyone in your organization who has concluded that CMMC went away.
| Obligation | Status |
|---|---|
| CMMC Phase 1, Level 1 and Level 2 self-assessment in applicable solicitations | In force |
| DFARS 252.204-7012 safeguarding requirement | Unchanged, in force since 2017 |
| NIST SP 800-171 Rev 2, all 110 controls | Unchanged and enforceable |
| SPRS score submission | Required |
| Annual affirmation by a senior official | Required |
| 32 CFR Part 170 CMMC program rule | Codified, not repealed |
| Government-led DIBCAC Medium and High assessments | Survive under DFARS 252.240-7997 |
| Prime contractor flow-down requirements | Unaffected, primes set their own terms |
| Existing Level 2 C3PAO certifications | Remain valid |
| Phase 2 third-party certification as condition of award | Suspended |
Two of these deserve emphasis. First, DoD tied interim enforcement to NIST SP 800-171 Revision 2, not the Revision 3 published in 2024, so the control set you are assessed against has not moved. Second, nothing invalidates a certification already earned. The Cyber AB reported 1,391 Final Level 2 certificates issued as of its May 2026 town hall, and DFARS 252.204-7021(d)(1)(i) requires the stated level or higher, meaning a Level 2 (C3PAO) status satisfies any lesser designation during the suspension. If you completed an assessment, that investment retains value with primes and in acquisition diligence.
Equally important is what your prime requires of you. DFARS 252.204-7012 obligates primes to flow cybersecurity requirements down the supply chain, and several have told subcontractors to confirm applicable requirements with their buyer before canceling a scheduled C3PAO assessment. The Department paused its own requirement. It did not pause your customer's.
Why False Claims Act Exposure Increased When the Assessment Requirement Paused
The counterintuitive consequence of the suspension is that self-assessment moved from an interim mechanism to the primary one. When a C3PAO validates your posture, an inaccurate SPRS score is likely to surface during assessment. Without that step, the score you post is the government's primary representation of your security posture, and it is a representation you make to obtain payment.
The Department of Justice has been demonstrating what that means.
In June 2026, DOJ settled with LOGZONE Inc. of Huntsville, Alabama for $507,144 over alleged NIST SP 800-171 failures under two Navy contracts. LOGZONE had submitted a perfect self-assessment score of 110 in October 2021, and a February 2024 DIBCAC assessment produced a score of negative 170, near the bottom of the applicable range of negative 203 to 110. The case was not brought by a whistleblower. It was triggered by the government's own assessment process.
On September 1, 2026, DOJ announced that Honeywell Aerospace agreed to pay $2,042,518 to resolve allegations that from April 2020 through December 2023, a business unit of Honeywell International submitted false claims for payment by failing to comply with NIST SP 800-171 requirements on one of its networks. The matter originated in a whistleblower suit, and the relator, a former Honeywell employee, received $375,823. The claims are allegations only and there was no determination of liability.
These sit alongside the $4.6 million MORSECORP settlement from March 2025. The pattern across all three is that no breach was required to generate liability. The gap between the posture a contractor attested to and the posture its systems actually supported was sufficient.
| Contractor | Announced | Amount | How it surfaced | Breach involved |
|---|---|---|---|---|
| MORSECORP | March 2025 | $4.6 million | Alleged NIST SP 800-171 non-compliance | No |
| LOGZONE Inc. | June 2026 | $507,144 | Government DIBCAC assessment; self-reported 110, assessed negative 170 | No |
| Honeywell Aerospace | September 1, 2026 | $2,042,518 | Whistleblower suit by a former employee, who received $375,823 | No |
Recent DOJ False Claims Act settlements tied to NIST SP 800-171. Amounts and dates as announced by the Department of Justice; settlements resolve allegations only.
For a CIO, that reframes the question. It is no longer whether you will pass an assessment in November. It is whether the score you already posted is defensible if DIBCAC or a former employee decides to test it.
What the CMMC Reform Task Force Report Could Change, and What It Cannot
The 60-day clock from July 13 ran out around September 11, with some trackers anchoring internal delivery to September 13. The findings go to the CIO first, and that step is internal. Davies indicated the task force would then have roughly fifteen days to synthesize recommendations, which puts a public report somewhere between late September and early October. As of mid-September it has not been released. At DIBX 2026, Davies said the Department received roughly 1,100 RFI responses totaling more than 11,000 pages, with more than half supportive of reform.
Whatever it recommends, a task force report changes no contractual obligation on its own. Only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 does that. Watch for those three mechanisms rather than for headlines.
History offers a reasonable prior. CMMC 1.0 was paused for review in 2021 and returned as CMMC 2.0 with five levels compressed into three and third-party assessment requirements narrowed rather than abandoned. A pause for reform has so far meant a leaner version of the same idea.
What DoD Contractors Should Do Between Now and the Report
It is reasonable to defer scheduling and paying for a C3PAO assessment where the contract requirement is suspended and no prime is demanding it, and to pause consulting engagements scoped specifically to certification readiness rather than to control implementation.
It is not reasonable to pause anything that is also a NIST SP 800-171 requirement. The common failure mode is a contractor that halts its CMMC program and inadvertently halts its 800-171 remediation, because internally the two were one project with one name. If your program cannot separate certification-specific spend from control-implementation spend, that is itself a finding.
Three things are worth doing this quarter. Identify which clause set each of your contracts actually carries, since amendments are rolling out at different speeds across contracting offices. Confirm your SPRS score still describes your environment, because staleness and inaccuracy carry the same exposure. Keep the evidence trail running, since the absence or inaccuracy of a system security plan has itself formed the basis of FCA allegations in recent matters.
One date is worth flagging separately. On September 21, 2026, NIST moves all FIPS 140-2 cryptographic module certificates to Historical status. That deadline was never tied to Phase 2 and has not moved. Confirm the FIPS 140-3 status of the cryptographic modules your Windows environment actually runs. Our analysis of what the FIPS 140-2 sunset means for SC.L2-3.13.11 covers the module-level detail.
File Access Controls Under a Self-Assessment Regime
Under Phase 2, a C3PAO would have examined your access controls, audit logs, and encryption posture and told you where the gaps were. That review is gone for now. The controls it would have examined are not.
The Access Control, Audit and Accountability, Identification and Authentication, Media Protection, and System and Communications Protection families still account for a substantial share of the 110 requirements, and file infrastructure sits at the center of all five. Least-privilege permissions, comprehensive access logging, FIPS-validated encryption in transit and at rest, and controls on CUI movement are all things you now attest to without an external check.
That is the practical argument for infrastructure that produces real evidence rather than a policy document describing intended behavior. If your remote file access runs through a platform that inherits NTFS permissions, logs every access event with user identity and timestamp, forwards those logs to your SIEM, and keeps CUI on storage inside your own boundary, your SPRS score has something behind it. If it runs through a consumer sync tool and a spreadsheet of good intentions, the LOGZONE arithmetic is the risk you are carrying.
MyWorkDrive is a gateway, not a repository. It provides secure access to files where they already live on your Windows file servers, NAS, or SharePoint, with no file content stored on MyWorkDrive infrastructure, which keeps your CMMC assessment boundary confined to systems you already own and document. See how the architecture maps to the NIST SP 800-171 control families on our CMMC compliance file sharing page, or read our analysis of whether CMMC requires GCC High if you are weighing enclave options.
Frequently Asked Questions
Is CMMC cancelled?
No. The Department of War suspended the Phase 2 transition on July 13, 2026, which paused the requirement for third-party C3PAO certification as a condition of award. The program itself remains codified at 32 CFR Part 170, and Phase 1 self-assessment requirements continue to appear in solicitations.
Do I still need to submit a SPRS score?
Yes. SPRS score submission and the annual affirmation by a senior official are unchanged. Nothing in the July memorandum or Class Deviation 2026-O0025 touched them. Because self-assessment is now the primary verification mechanism rather than an interim one, the accuracy of that score carries more weight than before.
Does the suspension affect DFARS 252.204-7012 or NIST SP 800-171?
No. DFARS 252.204-7012 has been in force since 2017 and is unaffected. All 110 controls in NIST SP 800-171 Revision 2 remain enforceable, and the Department tied interim enforcement to Revision 2 rather than the Revision 3 published in 2024, so the control set has not moved.
Is my existing CMMC Level 2 certification still valid?
Yes. Certifications already issued remain valid, and the Cyber AB reported 1,391 Final Level 2 certificates as of its May 2026 town hall. DFARS 252.204-7021(d)(1)(i) requires the stated level or higher, so a Level 2 (C3PAO) status satisfies any lesser designation during the suspension.
Should I cancel a scheduled C3PAO assessment?
Check with your prime first. The Department paused its own requirement, but DFARS 252.204-7012 obligates primes to flow cybersecurity requirements down the supply chain, and several have told subcontractors to confirm applicable terms before canceling. Deferring is reasonable where no customer is asking for certification.
When will the CMMC Reform Task Force report be released?
The 60-day clock from July 13 ran out around September 11, and findings go to the Department CIO first. A public report is expected between late September and early October 2026. As of mid-September it has not been released.
Will the Task Force report change my contract requirements?
Not on its own. A task force report is advice. Only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes a contractual obligation, so those are the three mechanisms to watch rather than the coverage of the report itself.
Can I still be penalized for a NIST 800-171 gap while Phase 2 is suspended?
Yes. The Department of Justice settled with LOGZONE Inc. for $507,144 in June 2026 and with Honeywell Aerospace for $2,042,518 on September 1, 2026, both over alleged NIST SP 800-171 failures. Neither required a breach. The gap between the attested posture and the actual one was sufficient.
Start a free trialBook a demoView pricing
Daniel, Founder of MyWorkDrive.com, has worked in various technology management roles serving enterprises, government and education in the San Francisco bay area since 1992. Daniel is certified in Microsoft Technologies and writes about information technology, security and strategy and has been awarded US Patent #9985930 in Remote Access Networking.