Blog

CMMC Update: What DoD Class Deviation 2026-O0025 Means

Shield icon with a checkmark centered on a teal gradient background, symbolizing cybersecurity compliance and protection.

Recent updates surrounding the Department of Defense (DoD) former CIO based on the September 4th DoD memo with the subject line of “Class Deviation – Revolutionary Federal Acquisition Regulation (FAR) Overhaul Part 40, Defense FAR Supplement (DFARS) Part 240” has prompted renewed discussion around the future of the Cybersecurity Maturity Model Certification (CMMC) program. While this has caused confusion in the Defense Industrial Base (DIB), particularly concerning third-party assessments and long-term compliance expectations, we’re here to talk about what the memo in question discusses, what that means for CMMC and how compliance and 3rd party assessments are being affected going forward. 

What Happened 

The former DoD CIO shared concerns that Revision 3 would kill CMMC as it would cut out the contract requirements for 3rd party assessments. The post was later removed, and several experts pointed out that the revised deviation focused on areas unrelated to CMMC, such as Chinese military company restrictions, covered lobbyist language, Alibaba-related provisions, and broader supply chain controls.  

Importantly, the CMMC language in Class Deviation 2026-O0025 remained unchanged between Revision 2 (July 16, 2026) and Revision 3 (September 4, 2026). Both versions continue referencing the July 13, 2026 CMMC Pause memo, permit Level 1 and Level 2 self-assessments, uphold compliance with NIST SP 800-171 Revision 2 via DFARS 252.204-7012, and suspend the November 2026 Phase 2 transition. Requirements for program managers and contracting officers to amend or update solicitations also remain intact. 

What This Means for the Future 

The core cybersecurity obligations affecting defense contractors remain fully active. DFARS 252.204-7012 and NIST SP 800-171 Revision 2 are still enforceable, and contractors must continue evaluating and attesting to their compliance. Additionally, 32 CFR Part 170—the formal CMMC program rule—has not been revoked. DCMA retains authority to conduct independent assessments at its discretion. 

The DoD and Small Business Administration (SBA) have highlighted cost concerns around formal assessments while simultaneously calling for more robust cybersecurity practices across the DIB. Initiatives such as ‘Brilliant at the Basics’ and the White House’s ‘Promoting Advanced Artificial Intelligence Innovation and Security’ emphasize growing expectations for automated, scalable security controls. 

The DoD’s 60-day task force, which concluded on September 11, 2026, has 15 days to respond and is expected to provide recommendations that could reshape the future structure of CMMC. These changes will require additional regulatory steps before taking effect. 

Looking Ahead 

In summary, Class Deviation 2026-O0025 Revision 3 does not alter existing CMMC requirements or disrupt the ongoing pause. It preserves the current compliance environment and maintains legal expectations around NIST SP 800-171. Contractors should continue preparing through self-assessments, documentation, and internal readiness while monitoring updates following the task force review. The future of CMMC remains active, though evolving, and further clarity is anticipated as the DoD considers feedback and potential reforms.