Skip to main content
CMMC Suspension Just Became a Regulation: FAQCMMC & DIB Assessment
5 min readFor Program Managers

CMMC Suspension Just Became a Regulation: FAQ

These questions started hitting my inbox the morning after John Tenaglia's September 3 memo landed. Program managers, compliance leads, and GC&A teams all asking variations of the same thing: what does this actually mean for my contract pipeline?

The short answer: the Department of Defense just moved the CMMC third-party assessment suspension from a temporary policy hold to a binding class deviation under the Federal Acquisition Regulations System. That's not a subtle shift. Let's work through what you're actually dealing with.

Why are these questions arising?

The CMMC Reform Task Force initiated a 60-day review on July 13, with a deadline of September 11. The DOD received over 1,100 comments on its request for information about what's working and what's creating compliance friction. Now we're in the gap between the task force wrapping up its work and Chief Information Officer Kirsten Davies deciding what to make public. That uncertainty is generating real operational questions for teams managing active solicitations and existing contracts.

What's the practical difference between a suspension and a class deviation?

A suspension is a policy statement. You can reverse it with another memo. A class deviation under 48 CFR is a regulatory instrument that changes how contracting officers must execute acquisitions. Tenaglia's memo directs contracting officers to strip CMMC third-party assessment requirements from contracts and follow the Revolutionary FAR Overhaul instead of 32 CFR Part 170.

Reversing a class deviation requires a formal regulatory process. You're not going back to third-party assessments with a quick policy pivot. This matters for your planning horizon: if you were holding budget for a Certified Independent Assessor Organization (C3PAO) engagement in Q4, that timeline just became much less certain.

Does this mean CMMC is dead?

No. Self-assessment against NIST SP 800-171 Rev 2 is still mandatory under DFARS 252.204-7012. What's suspended is the requirement for independent validation of that self-assessment at Level 2 and above. The controls haven't changed. The attestation obligation hasn't changed. What changed is who verifies your score.

This is where the risk concentrates now. The Justice Department settled with Logzone in June for roughly $500,000 after the company submitted what DOD's audit found to be a wildly inaccurate self-assessment. When third-party assessments aren't validating your score, the scrutiny on Self-Assessment accuracy intensifies. You're still accountable for every control you claim to meet.

Should I stop my CMMC prep work?

That depends on what you mean by prep. If you were scheduling a C3PAO assessment for November, yes, pause that. The phased implementation that would've triggered third-party assessments starting this November is off the table.

But if "prep work" means implementing the 110 security requirements in NIST SP 800-171, no, don't stop. Those requirements are still in your contract clauses. Your self-assessment still goes into the Supplier Performance Risk System. The controls for protecting Controlled Unclassified Information on your networks are still mandatory. The only thing that changed is the independent verification step.

Here's what to prioritize instead: audit your current self-assessment with the same rigor a C3PAO would apply. Document your Plan of Action and Milestones for any gaps. Treat your System Security Plan as a legal document, because it effectively is one. The Logzone settlement demonstrates that DOD will audit self-assessments and pursue enforcement when they find material misrepresentation.

What did DOD actually ask for feedback on?

The request for information asked four specific questions:

  • What drives CMMC compliance costs for your organization?
  • Which administrative requirements create the most burden?
  • Which of the 110 NIST 800-171 controls deliver meaningful risk reduction versus which feel like compliance theater?
  • How can DOD incorporate commercial cybersecurity tools and managed services into the framework?

That third question is the interesting one. DOD is openly questioning whether all 110 controls carry equal security value. That suggests the task force might recommend a risk-based approach that focuses resources on high-impact controls rather than uniform implementation across all requirements. But until Davies releases the task force recommendations, that's speculation.

What happens to contracts that already have CMMC clauses?

Contracting officers are directed to remove third-party assessment requirements from those contracts. If you're in the middle of a proposal that references CMMC Level 2 certification, expect amendments. If you've already been awarded a contract with CMMC clauses, you'll likely see modifications stripping the C3PAO assessment requirement while leaving the underlying NIST 800-171 self-assessment obligation in place.

Track your contract modifications carefully. Make sure the removal of third-party assessment requirements doesn't accidentally remove your self-assessment obligations or change your CUI handling requirements. DFARS 252.204-7012 is still in effect. Your safeguarding obligations haven't changed.

How does this affect my subcontractors?

Flow-down requirements under DFARS 252.204-7012 still apply. Your subcontractors handling covered defense information still need to meet NIST 800-171 requirements and attest to their compliance. What's changed is you're no longer waiting for them to complete third-party assessments before they can perform on your contracts.

That increases your supply chain risk management burden. You can't rely on a C3PAO validation of your subcontractor's security posture. You need to verify their self-assessments yourself or accept the risk that their attestation is accurate. Consider requiring subcontractors to share their System Security Plans and POA&Ms as part of your vendor risk assessment process.

When will we know what comes next?

The task force deadline is September 11. After that, the recommendations go to Kirsten Davies. She decides what gets released publicly and when. There's no regulatory timeline forcing transparency here.

What we know from Davies' comments at the Billington Cybersecurity Summit: "This isn't about whether cybersecurity is important or not. It is. It's critical. It's vital. We wanted to hear more from the defense industrial base on what was important for meaningful, dynamic cybersecurity."

That framing suggests DOD is looking for a compliance model that's less bureaucratic but still effective at protecting CUI. Whether that means a streamlined control set, more reliance on continuous monitoring, or integration with commercial security tools, we'll know when Davies releases the task force findings.

Where to go for more

Monitor the Defense Pricing, Contracting and Acquisition Policy office for updates on the class deviation and any subsequent regulatory changes. If you submitted comments during the RFI period, watch for whether DOD publishes a summary of themes from those 1,100-plus responses.

In the meantime, treat your NIST 800-171 self-assessment as your primary compliance artifact. Document everything. If you claimed a control is in place, be prepared to demonstrate it. The suspension of third-party assessments doesn't reduce your obligation to protect CUI. It just changes who's checking your work.

You Might Also Like