In this piece
Class Deviation 2026-O0025, Revision 3 directs contracting officers to remove or revise affected CMMC requirements while retaining the stated NIST SP 800-171 Rev. 2 baseline. For a contractor, the immediate task is to review the solicitation amendment or contract modification that applies to your work. The instructions appear in paragraph (b) of the deviation memo.
Our earlier CMMC Phase II article covers the July policy announcement.
What does Revision 3 say about CMMC?
The memo, digitally signed September 3, 2026, supersedes Revision 2, issued July 16. It directs contracting officers to use revised FAR Part 40, the attached DFARS Part 240, and revised PGI 240. It remains effective until rescinded or incorporated into those rules and guidance; see the cover memo, pages 1–4.
Paragraph (b) carries forward instructions tied to the CIO’s July 13 memorandum. It suspends the November 2026 Phase 2 transition and permits requiring activities to include Level 1 (Self) or Level 2 (Self) assessments in procurement requests and requirement documents. It also requires baseline NIST SP 800-171 Rev. 2 compliance in accordance with DFARS 252.204-7012.
The practical distinction is between the assessment requirement being revised and the safeguarding work supporting contract performance. Read both against the systems and information involved. Keep the memo’s CMMC instructions with that review.
Check the document that changes your requirement
For active solicitations, program managers and requiring activities must initiate amendments and send them to the responsible contracting officer. The officer must issue the corresponding amendments as soon as practicable. For existing contracts containing the affected requirements, removal occurs by modification before the next option exercise or through the next scheduled administrative modification; see memo pages 2–3.
Use a short review record for each opportunity or contract:
| Situation | Document to request | Decision to record |
|---|---|---|
| Preparing a bid | Latest solicitation and amendments | Assessment level and evidence requested |
| Performing an existing contract | Applicable modification | Requirements changed and effective date |
| Approaching an option | Option schedule and planned modification | Timing confirmed with the contracting officer |
| Revising security plans | Current clauses and system scope | Safeguarding work and responsible owners |
If the solicitation still contains assessment language you expect to change, raise the specific provision with the contracting officer. Ask which amendment addresses it and how the change affects your submission. Keep the written response with the proposal record.
How should you read the 2028 dates?
Attachment 1, section 240.371-5, retains a clause-prescription distinction around November 10, 2028. Before that date, it describes inserting DFARS 252.204-7021 when the program office or requiring activity determines that a specific CMMC level is required. From that date, the stated trigger concerns contractor systems processing, storing, or transmitting FCI or CUI, subject to the listed exceptions.
The 2028 dates govern when contracting officers insert the CMMC clause. Read them alongside the cover memo’s suspension and amendment directions. The relevant text is on Attachment 1, printed pages 15–16.
Track changes against the security plan
For each amendment or modification, mark the affected entry in your contract review record. Have the security lead identify which assessment plans need revision and which safeguarding tasks remain open. Keep the previous requirement with the change record so the team can explain why its plans changed.
If that review identifies a collaboration gap, request a defense pilot around the affected workflow with IRONKEEP. Use the specific gap to define the evaluation. Review deployment suitability and contractual requirements before introducing controlled information.
Put an owner on the next contract review
Choose one active solicitation or upcoming option and bring its latest documents to the contracts and security leads. Record the applicable assessment language, the amendment or modification status, and the safeguards your team must maintain. Assign an owner and a follow-up date to each unresolved question.
Use the Honeywell settlement review to examine whether contract statements match the evidence from the relevant network. Keep that evidence with the revised contract record so future reviewers can follow both the requirement and its implementation.
Plan your CMMC workspace.
Request a defense pilot and get the Level 2 readiness checklist: 39 prompts across 11 assessment areas.