CMMC's Phase 2 suspension locked in with binding regulation
Gettyimages.com/ Kevin Carter / Contributor
ByNick Wakeman,
Editor-in-Chief, Washington Technology
September 9, 2026 05:10 PM ET
A new class deviation moves the pause on third-party assessments for this security standard from policy to an enforceable rule.
The Defense Department has moved beyond a simple suspension of third-party assessment requirements of the Cybersecurity Maturity Model Certification program and onto a binding regulation that essentially codifies the suspension.
A Sept. 3 memo from John Tenaglia -- DOD’s principal director for defense pricing, contracting and acquisition policy -- has directed contracting officers to comply with requirements in the Revolutionary FAR Overhaul instead of the final CMMC rule that has been in place since November 2025 for contract clauses.
The class deviation orders contracting officers to strip out from contracts any and all of CMMC’s requirements for third-party assessments.
DOD was following a phased approach to implementing CMMC with the...
Copyright of this story solely belongs to www.nextgov.com. To see the full text click HERE