Page: Government Contracting Insights
Revision date: September 17, 2026
Author: Penny Marbel, JPI Worldwide
The Department of Defense issued DARS Class Deviation 2026-O0025, Revision 3, on September 3, 2026. The revision codifies the suspension of CMMC Phase 2 third-party assessment requirements.
Under the revised direction, contracting officers must remove suspended requirements from active solicitations and modify existing contracts at the next option period or administrative update, as applicable.
The pause does not eliminate the underlying cybersecurity obligations for government contractors handling Controlled Unclassified Information (CUI). Contractors must continue to address applicable requirements under DFARS 252.204-7012, maintain the NIST SP 800-171 Revision 2 baseline where required, complete self-assessments, maintain supporting records, and accurately report their status.
Quotable definition: A CMMC Phase 2 pause changes how certain cybersecurity requirements may be assessed. It does not suspend the obligation to safeguard covered defense information or accurately represent the contractor’s cybersecurity posture.
The following seven steps provide a practical response for primes and subcontractors that handle CUI.
1. Confirm which contract requirements apply
Contractors must begin with the actual contract, solicitation, and applicable flow-down provisions.
A CMMC requirement may be removed or revised from an active solicitation. An existing contract may be modified at the next option exercise or administrative update. However, the contract language currently in force remains the controlling reference until a formal modification is executed.
Review:
- DFARS 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting.”
- Any applicable DFARS assessment, scoring, or affirmation requirements.
- CMMC language in solicitations, awards, task orders, and modifications.
- Prime contract provisions that must be flowed down to subcontractors.
- The definition and location of CUI or covered defense information.
- Any contract-specific cybersecurity, incident reporting, or operationally critical support obligations.
The pause should not be treated as permission to stop performing a contract requirement. Contracting officers, legal counsel, and the prime contractor should be consulted where the requirement is unclear.
The DARS Class Deviation 2026-O0025 resource provides a public summary of the revision. Contractors should verify requirements against the applicable contract and official DoD guidance.
2. Define the CUI environment and system boundary
Cybersecurity obligations cannot be assessed accurately until the organization knows which systems, users, applications, facilities, and service providers are within scope.
A contractor should document:
- Where CUI is received, stored, processed, or transmitted.
- Which endpoints and servers can access CUI.
- Which cloud services or managed service providers support the environment.
- Which users, administrators, and subcontractors require access.
- Which network segments are included or excluded.
- How data enters and leaves the controlled environment.
- Which systems support contract performance but do not process CUI.

A poorly defined boundary can create two separate risks. The organization may assess too small an environment and omit systems that require protection. Alternatively, it may include unnecessary systems and create avoidable cost and administrative burden.
For primes, the boundary review should include subcontractor interfaces and shared technology. For subcontractors, the review should identify whether CUI is being accessed through a prime-controlled environment, a subcontractor-controlled system, or a third-party service.
3. Perform an evidence-based NIST SP 800-171 assessment
The CMMC Phase 2 pause does not remove the need to assess the applicable NIST SP 800-171 Revision 2 requirements.
The assessment should address all applicable requirements and should be supported by objective evidence. A policy statement alone may not demonstrate implementation.
Useful evidence may include:
- Approved policies and procedures.
- System Security Plans.
- Configuration records.
- Access-control and authentication records.
- Security awareness and training records.
- Vulnerability management reports.
- Incident response procedures and test results.
- Backup and recovery records.
- Media protection and sanitization records.
- Asset inventories and network diagrams.
- Physical access records.
- Supplier and managed-service documentation.
Each requirement should have a clear status. The organization should distinguish between:
- Implemented controls.
- Partially implemented controls.
- Planned controls.
- Controls that are not applicable, with a documented rationale where permitted.
A self-assessment should reflect the implemented state, not the desired future state. Inflating a score to improve proposal positioning can create material legal and contractual risk.
4. Maintain the SSP, POA&M, SPRS score, and annual affirmation
Self-assessment documentation must remain current and internally consistent.
Contractors should maintain a controlled record of:
- The assessment methodology.
- The score assigned to each applicable requirement.
- The evidence supporting each score.
- Known gaps and associated risk.
- Plans of Action and Milestones (POA&Ms), where permitted.
- Responsible personnel and target completion dates.
- The current Supplier Performance Risk System (SPRS) score.
- Annual affirmations and the basis for those affirmations.

A POA&M does not automatically cure a missing control or authorize a contractor to represent full implementation. Its use, acceptance, and effect depend on applicable requirements and contract terms.
Management should also establish change control. A new application, cloud service, remote-access method, subcontractor, or network connection may change the system boundary and invalidate an older assessment.
The assessment record should be understandable to an independent reviewer who did not prepare it. That standard helps reduce ambiguity during a prime contractor review, government inquiry, or government-led assessment.
5. Preserve operational compliance, including incident reporting
DFARS 252.204-7012 continues to establish important operational duties for covered contractors.
Where the clause applies, contractors must implement the required security protections for covered contractor information systems and maintain procedures for cyber incident response. The clause also requires rapid reporting of qualifying cyber incidents. “Rapidly report” generally means reporting within 72 hours of discovery, subject to the specific clause and applicable reporting process.
The organization should maintain:
- A documented incident response plan.
- Defined escalation responsibilities.
- A method for determining whether CUI or a covered system was affected.
- A clock for tracking the 72-hour reporting period.
- Procedures for preserving relevant forensic information.
- Contact and coordination procedures for the prime contractor and government.
- Periodic exercises that test decision-making and reporting readiness.
Technical controls and reporting procedures should be tested together. A contractor may have a written plan but still be unable to identify who must act, what information must be preserved, or how a report is initiated.
The current DFARS clause text is available through Acquisition.gov. Contractors should review the version incorporated into the applicable contract.
6. Align every representation with the implemented environment
Cybersecurity representations must be consistent across proposals, contract certifications, SPRS submissions, annual affirmations, subcontractor questionnaires, and internal management reports.
A contractor should establish a review process before submitting any statement that:
- Claims compliance with DFARS 252.204-7012.
- Describes a CMMC level or self-assessment status.
- Identifies a specific SPRS score.
- States that all required controls are implemented.
- Describes a system as capable of handling CUI.
- Confirms compliance on behalf of a subcontractor or service provider.
Legal, contracts, information security, and program personnel should use the same source documentation. Differences between a proposal statement and the current assessment record should be investigated before submission.
The False Claims Act creates potential exposure where a contractor knowingly or recklessly submits materially inaccurate information or conceals noncompliance. The risk does not require a third-party CMMC assessment to exist. Self-assessments and affirmations may still be relevant to responsibility, award, payment, and contract performance.
A prudent contractor should not make a broader claim than the evidence supports.
7. Prepare for review by the government, the prime, or an independent assessor
The government retains authority to conduct its own assessment. A government assessment may take precedence over a contractor-provided self-assessment score.
Contractors should therefore maintain assessment readiness even while third-party Phase 2 requirements are paused.
Preparation should include:
- A current system boundary diagram.
- A complete and indexed evidence repository.
- A responsible owner for each control area.
- A record of open findings and remediation status.
- A process for responding to information requests.
- Controlled access to sensitive assessment materials.
- Coordination procedures with prime contractors.
- A method for documenting corrective actions.

The pause may reduce a near-term third-party assessment requirement. It does not remove the need for disciplined cybersecurity governance. Contractors that maintain accurate records and operational controls will be better positioned for contract modifications, future rule changes, government review, and prime contractor oversight.
What does the CMMC Phase 2 pause change?
The September 3, 2026 revision changes the immediate treatment of certain third-party CMMC assessment requirements. Contracting officers are directed to remove or revise those requirements in applicable solicitations and contracts, subject to the stated modification process.
It may permit Level 1 Self or Level 2 Self assessment approaches where the revised procurement documents allow them.
What does the pause not change?
The pause does not, by itself, remove:
- Applicable DFARS 252.204-7012 obligations.
- The NIST SP 800-171 Revision 2 baseline where required.
- Self-assessment and SPRS reporting obligations.
- Annual affirmation requirements.
- Cyber incident reporting responsibilities.
- Prime contractor flow-down requirements.
- Government assessment authority.
- Potential False Claims Act consequences for inaccurate representations.
For additional background, contractors may review the DoD CIO CMMC resources and the NIST SP 800-171 Revision 2 publication.
How JPI Worldwide can reduce compliance friction
JPI Worldwide supports government agencies, prime contractors, and subcontractors with cybersecurity services, network infrastructure, technology integration, and operational support.
As a subcontractor and technology infrastructure partner, JPI can help organizations:
- Review technology environments that support contract performance.
- Document system boundaries and infrastructure dependencies.
- Organize assessment evidence and remediation priorities.
- Support secure network configuration and monitoring.
- Coordinate technical requirements across prime and subcontractor teams.
- Improve operational readiness for remote, CONUS, and OCONUS environments.
- Reduce avoidable friction between contracts, security, and technical personnel.
JPI Worldwide does not provide a legal determination of compliance. Contract-specific obligations should be reviewed with qualified contracts and legal professionals.
Government contractors, primes, and subcontractors may contact JPI Worldwide to discuss how cybersecurity services and infrastructure support may help address current assessment, documentation, and operational requirements.

