The Department of Defense's pause on CMMC Phase II just became much harder to reverse. On September 3, 2026, DoD's principal director for defense pricing, contracting and acquisition policy issued a class deviation directing contracting officers to follow the Revolutionary FAR Overhaul instead of CMMC's third-party assessment requirements — converting what had been a temporary suspension into binding regulation (Nextgov/FCW, 2026). For contractors, the headline hasn't changed since July: Phase II third-party assessments remain paused, but NIST 800-171 self-assessment obligations never went away.CMMC Phase II Pause Is Now Locked In, What Defense Contractors Still Must Do

What Actually Changed on September 3?

The class deviation memo strips CMMC's third-party and government-led assessment requirements out of new contract clauses, replacing them with the Revolutionary FAR Overhaul framework. The practical difference from the original July 13 suspension is durability — a policy pause can be reversed with another policy memo, but a class deviation is a formal regulatory mechanism that's considerably harder to unwind, which is why this development is being read as the pause getting "locked in" rather than just extended (Nextgov/FCW, 2026).

What's Still Paused, and What Was It Supposed to Replace?

Still paused: third-party C3PAO assessments, government-led DIBCAC assessments, Level 2 and Level 3 designation requirements in new solicitations, and CMMC's waiver procedures — all of which were scheduled to begin rolling out starting November 10, 2026 (Secureframe, 2026). That rollout would have required a growing share of defense contractors to prove compliance through outside assessors rather than their own attestation, and it's that specific transition — not the underlying security requirements themselves — that remains on hold while the Department of Defense's CMMC Reform Task Force finishes its review.

What Do Contractors Still Have to Do Right Now?

Contractors remain fully obligated under DFARS 252.204-7012, the safeguarding clause requiring NIST SP 800-171 Rev 2 implementation that's been in effect since 2017, along with CMMC Level 1 and Level 2 self-assessments under the CMMC Program Rule (32 CFR Part 170), accurate SPRS score submissions with annual executive-signed affirmations, and existing DFARS cyber incident reporting obligations (Secureframe, 2026). None of that requires a third-party assessor — but it does require the same underlying security controls CMMC was built to verify, which means the pause changes who checks your work, not what work needs to get done.

Is Self-Attestation Actually Being Enforced?

Yes, and the enforcement mechanism is the False Claims Act rather than CMMC itself. Two recent settlements make the point concrete: contractor Logzone paid roughly $500,000 in June 2026 after falsifying its self-assessment score (Nextgov/FCW, 2026), and Honeywell Aerospace settled for $2 million in September 2026 over compliance misrepresentation (Secureframe, 2026). A paused assessment program doesn't pause the legal risk of an inaccurate SPRS submission — if anything, self-attestation without a third-party check behind it puts more weight on getting the assessment right the first time.

What Should Contractors Do During the Pause?

The Department of Defense's own reform task force review — which closed around September 11, 2026 after receiving over 1,100 public comments totaling more than 11,000 pages, largely concerned with compliance costs the SBA estimates at $250,000-$500,000 over three years for small contractors — makes clear the pause is about fixing CMMC's rollout, not questioning whether the underlying security requirements matter (Secureframe, 2026). Contractors should use the pause to define their controlled unclassified information (CUI) scope precisely — overmarking and inconsistent CUI handling was the single most common complaint in the industry feedback — migrate CUI-touching systems to FedRAMP-authorized infrastructure, implement FIPS 140-2 cryptography and MFA where required, and run an honest NIST 800-171A gap analysis rather than treating the pause as a reason to wait.

Frequently Asked Questions

Is CMMC Phase II canceled?

No. Phase II — the transition to mandatory third-party and government-led assessments — is paused, not canceled, and a September 2026 class deviation made that pause harder to reverse by converting it into binding regulation rather than a simple policy suspension.

Do defense contractors still need to comply with NIST 800-171?

Yes. NIST SP 800-171 Rev 2 compliance under DFARS 252.204-7012 has been mandatory since 2017 and is unaffected by the CMMC Phase II pause — self-assessment and SPRS score submission obligations remain fully in effect.

What happens if a contractor's self-assessment is inaccurate?

Inaccurate self-assessments can trigger False Claims Act liability. Recent settlements include Logzone paying roughly $500,000 in June 2026 and Honeywell Aerospace paying $2 million in September 2026 over compliance misrepresentation.

When was CMMC Phase II supposed to start?

Third-party and government-led assessments under Phase II were scheduled to begin rolling out starting November 10, 2026, before the Department of Defense suspended the transition in July 2026.

What should contractors do while CMMC Phase II is paused?

Contractors should use the pause to define their CUI scope accurately, migrate CUI-touching systems to compliant infrastructure, implement required controls like MFA and FIPS 140-2 cryptography, and conduct a genuine NIST 800-171A gap analysis — the underlying security requirements haven't gone away even though third-party verification has.