Insights · CMMC & NIST SP 800-171
C3PAO wasn’t removed. Read the status list.
Both C3PAO statuses survive in the revised DFARS text — and requiring activities have been directed not to designate them. Two true statements that only look contradictory.
Since Class Deviation 2026-O0025, Revision 3 landed, the same four questions have been arriving in my inbox. Is CMMC being rolled back? Is Level 2 certification gone? Are C3PAO assessments finished? Can we stop preparing?
The answer is more interesting than four noes.
C3PAO was not removed from the CMMC framework. And during the current suspension, Program Managers and requiring activities have been directed not to designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments in procurement requirements.
Both of those are true at the same time. Understanding why is the difference between planning well and planning badly for what comes next.
Section one
What Revision 3 actually says
Revision 3 was signed on September 3, 2026, superseding Revision 2 from July 16. The memorandum describes its own purpose plainly: it implements several statutory requirements and corrects definitions.
That is worth sitting with, because it means Revision 3 is not primarily a CMMC action. Much of it deals with other things entirely — a court order affecting how Alibaba is treated under one statutory prohibition, semiconductor restrictions under section 853 of the FY2025 NDAA, protections for DoD employee data, unmanned aircraft prohibitions, and corrections to the definitions of “covered lobbyist” and “Chinese military company.”
The CMMC portion implements the July 13 CIO direction suspending advancement to Phase 2. During the suspension, procurement requirements are limited to Level 1 (Self) and Level 2 (Self). Baseline compliance with NIST SP 800-171 Revision 2 remains required where DFARS 252.204-7012 applies. The planned November 2026 Phase 2 transition is suspended. And the Department has directed action on procurements that already contain the affected requirements: active solicitations are to be amended, and for existing contracts, contracting officers are to remove those requirements by modification before the next option period or through the next scheduled administrative modification.
For CMMC, then, the significance of Revision 3 is continuity rather than another reversal. The latest DoD CIO guidance continues to describe CMMC implementation as paused in Phase 1, with Phase 1 self-assessment requirements remaining in place.
That is what most people were actually asking.
Section two
The part that answers the C3PAO question
Read into the attached DFARS Part 240 text and you find section 240.371, still titled Cybersecurity Maturity Model Certification, still describing CMMC as a framework for assessing contractor information-security protections, and still establishing award eligibility. Where a solicitation requires a CMMC level, the revised text provides that the contracting officer must not award to an offeror lacking a current status at that level.
Then there is the status list.
| CMMC level | Statuses retained in the revised text | Assessed by |
|---|---|---|
| Level 1 | Final Level 1 (Self) | The contractor |
| Level 2 | Conditional Level 2 (Self) Final Level 2 (Self) | The contractor |
| Level 2 | Conditional Level 2 (C3PAO) Final Level 2 (C3PAO) | Authorized third party |
| Level 3 | Conditional Level 3 (DIBCAC) Final Level 3 (DIBCAC) | Government |
Both C3PAO statuses are there. The revised contractual framework continues to recognize CMMC Level 2 (C3PAO) as a level, and the solicitation language itself retains Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC) as possible CMMC levels within the framework.
That answers one question definitively: C3PAO was not deleted from CMMC.
But the second half of the answer matters just as much. The July 13 implementation direction provides that during the suspension, Program Managers and requiring activities may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments. DoD’s current CMMC guidance reflects the same operational position: the program is paused in Phase 1 and may currently require self-assessments at Level 1 or Level 2.
So this is not “C3PAO exists, therefore assessments proceed as usual.” And it is not “Phase 2 is suspended, therefore C3PAO is gone.” The actual position sits between them: C3PAO remains in the underlying architecture while its use as a procurement designation is suspended during the Phase 1 pause.
That distinction has been lost in much of what I have read on this. One statement concerns the architecture of the program. The other concerns how the Department is implementing that architecture right now.
The fact that the revised framework continues to contain C3PAO statuses, C3PAO solicitation language, and related contractual machinery is significant. It tells us that third-party assessment has not been deleted from the regulatory structure. It does not, by itself, tell us when or in what form DoD will use that structure again. That part remains an implementation question.
Section three
Two questions that are not the same question
This is where I watch contractors go wrong, and the error is structural rather than careless.
Do I need a C3PAO assessment for this procurement?
That answer moves. Procurement policy shifts, phasing changes, solicitations get amended, contracts get modified.
Do I have a contractual obligation to implement NIST SP 800-171?
That answer comes from the applicable contract clauses, and the Phase 2 suspension did not suspend it.
DoD’s current CMMC guidance expressly states that pausing implementation in Phase 1 does not eliminate the requirement for companies to protect information in accordance with DFARS 252.204-7012. During this period, the Department says it will enforce NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments. The revised DFARS also retains the assessment framework, including the Government’s ability to conduct Medium or High assessments of covered contractor information systems required to comply with NIST SP 800-171 under 252.204-7012.
A company that hears “Phase 2 suspended” and concludes it can stop implementing 800-171 has answered the second question using information that only bears on the first.
Section four
What the suspension does not fix
An assessment date can move. A network does not become compliant because it moved.
If you handle CUI, the questions underneath the certification schedule are unchanged. Where is the CUI, which systems process it, and where does it rest. How does it move, and who can reach it. Which accounts hold privileged access. Which cloud services and external providers sit inside the boundary. Whether logs are being generated, and whether anyone reads them. Whether the SSP describes the environment that exists today or the one that existed when it was written.
In practice the failure is almost always the same shape. The SSP says one thing, the firewall says another, the identity provider shows a third, and the administrator describes a process that appears in no procedure. Four accounts of the same control, and an assessor finds all four eventually. The certification calendar has nothing to do with it.
That is the case for treating this as breathing room rather than an exit.
What the time is actually for
- Scope. Define the CUI boundary correctly and cut scope that was never necessary — often one of the largest cost levers available, and one contractors reach for surprisingly late.
- Architecture. Fix what was going to fail testing anyway, while there is no assessment date forcing the shortcut.
- Evidence. Build collection that produces artifacts rather than assurances.
- Response. Exercise incident response before you need it rather than during.
- Access. Clean up decisions made years ago for reasons nobody remembers.
- Providers. Confirm what your external service providers can actually reach.
Compliance programs are hard to restart once organizational momentum is gone. Budget that gets released is difficult to re-request. Staff assigned to a paused initiative get reassigned. And much of the underlying security work may already be required under applicable DFARS clauses and NIST SP 800-171 obligations regardless of whether a C3PAO was expected in November.
Section five
Start with the contract, not the announcement
Revision 3 directs the Government to amend affected solicitations and modify affected contracts. That instruction matters more than the headline — and it cuts both ways.
The direction runs to the acquisition workforce. It does not authorize a contractor to rewrite its own contract. For an active solicitation, look for the required amendment. For an existing contract containing an affected C3PAO or Level 3 requirement, look for the modification the contracting officer has been directed to issue. If your procurement documents do not match the current direction, that is something to resolve through the contracting process, not a reason to quietly disregard language you are still signed up to.
The sequence I would follow for any contractor
- Identify the applicable DFARS clauses.
- Determine whether the work involves processing, storing, or transmitting FCI or CUI.
- Find what CMMC level the solicitation or contract actually specifies.
- Look for an amendment or modification issued as a result of the July 13 direction and Revision 3.
- Then decide what any of it means for your assessment schedule.
A government-wide announcement is news. A solicitation amendment or contract modification is what happened to your procurement.
Section six
What I think comes next
This is the part I would separate clearly from what the documents require today. What follows is my assessment of the direction of travel, not a prediction of what the final CMMC model will look like.
There are several reasons I would not build a compliance strategy around the assumption that third-party verification has disappeared permanently.
The policy is still moving
Revision 3 superseded Revision 2 less than two months after the July revision, and DoD now says it is conducting a comprehensive review of CMMC while implementation remains paused in Phase 1. Class deviations also allow the Department to implement acquisition policy on a different timetable from ordinary final-rule development. For contractors, the practical point is simple: procurement requirements can move faster than an eighteen-month compliance budget or technical remediation program.
The architecture was preserved
The Department suspended the current procurement designation of C3PAO and Level 3 assessments but retained the underlying CMMC architecture containing both C3PAO statuses and Level 3 DIBCAC statuses.
I would not treat that as proof that C3PAO will return unchanged. But I also would not treat the present suspension as evidence that independent verification is gone permanently. The Department’s own description of CMMC still centers on obtaining assurance that contractors have implemented required cybersecurity protections. How DoD chooses to obtain that assurance after its review is the open question.
The broader federal CUI framework is moving too
This deserves careful wording because it is separate from Revision 3.
The FAR Council published the proposed government-wide CUI rule — FAR Case 2017-016 — on January 15, 2025. The proposal addresses government-wide handling of CUI in federal contracts and reflects NIST’s publication of SP 800-171 Revision 3. It also includes a general CUI incident-reporting requirement of eight hours after discovery for suspected or confirmed CUI incidents.
That proposed rule matters because it demonstrates that CUI protection is not exclusively a DoD or CMMC issue. But it is still a proposed FAR rule. Contractors should not describe its requirements as current contractual obligations unless and until applicable final requirements are issued and incorporated into their contracts. What it does show is that the federal government continues to work toward a broader, more standardized CUI protection regime beyond the Defense Industrial Base.
Read together, I do not see a substantive security requirement disappearing. I see the Government reconsidering how compliance should be verified while the obligation to protect the information remains. The exact verification model that comes out of that process is not yet something we can state as fact.
That uncertainty is itself the reason not to dismantle the underlying program. The organizations that use this period to align contracts, documentation, systems, controls, and evidence will have substantially less work to do whichever verification model follows. The organizations that stop will eventually have to rebuild that work if the requirement returns in another form.
Section seven
What I would tell you today
Do not make a compliance decision on the strength of two words in a headline.
Find out what changed in your solicitation or contract. If the Government removes a near-term C3PAO requirement from your procurement, reconsidering assessment timing is reasonable — that is a business and contract decision. Abandoning NIST SP 800-171 implementation is a different decision and does not follow from the same facts.
Build an environment that survives scrutiny. Make the SSP match the system, make the system match the security requirements, make the policies match what people actually do, and hold evidence for all three.
Because whoever asks next — your own team, a future C3PAO, DIBCAC, a Government assessment team, a contracting officer looking into a compliance issue, or someone investigating an incident — the question is the one it has always been. Can you show that the requirements applicable to your environment were implemented?
Additional time is genuinely useful. It is not the same thing as the requirement going away. And in this case the distinction is visible in the Government’s own documents.
| Where CMMC stands today | Status |
|---|---|
| C3PAO within the CMMC framework | Retained |
| C3PAO and Level 3 procurement designations | Suspended during the pause |
| Level 1 and Level 2 self-assessment | In place |
| NIST SP 800-171 Rev. 2 under applicable 252.204-7012 contracts | In place |
| November 2026 Phase 2 transition | Suspended |
Read together — not any one of them alone — those statements describe where CMMC actually stands today.
References
Primary sources for this brief
- Class Deviation 2026-O0025, Revision 3 — Revolutionary FAR Overhaul Part 40, DFARS Part 240, signed 3 September 2026
- Department of War CIO memorandum, Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements, 13 July 2026
- DoD CIO current CMMC implementation guidance — Phase 1 pause and comprehensive program review
- Revised DFARS 240.370 and 240.371, as attached to Revision 3
- DFARS 252.204-7012 — safeguarding covered defense information and cyber incident reporting
- 32 CFR Part 170 — CMMC Program, including CMMC status definitions
- FAR Case 2017-016 — proposed government-wide CUI rule, published 15 January 2025
FAQ
Common questions
Has CMMC been cancelled?
No. Section 240.371 remains in the revised DFARS text, CMMC award eligibility remains, and the CMMC status list is intact. What was suspended is the planned November 2026 advancement to Phase 2.
Can a contracting officer still require a Level 2 (C3PAO) assessment?
The framework still permits it, but during the current suspension Program Managers and requiring activities have been directed not to designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments. If your solicitation or contract still contains such a requirement, the contracting officer has been directed to amend or modify it — look for that action rather than assuming it has already happened.
Our contract still names Level 2 (C3PAO). What do we do?
Raise it through the contracting process. The direction in Revision 3 runs to the acquisition workforce, not to contractors, and it does not authorize you to disregard language you are still signed up to. Until an amendment or modification issues, your contract says what it says.
Can we pause our NIST SP 800-171 work?
Not on the basis of the Phase 2 suspension. Where DFARS 252.204-7012 applies, the safeguarding obligation is unchanged, and the Department has said it will enforce Revision 2 compliance through self-assessments and selected government-led assessments during this period.
Does the suspension affect our SPRS score or annual affirmation?
The suspension addresses the advancement to Phase 2 assessment requirements. Obligations arising under your existing clauses — including the accuracy of what you have submitted — are a separate question, and one worth reviewing against your own contracts rather than against a policy announcement.
Should we cancel a scheduled C3PAO assessment?
That is a business and contract decision, and it should follow from what your procurement documents say after amendment, not from the headline. Given that the architecture was preserved and a comprehensive review is underway, I would be cautious about treating a cancellation as permanent relief.
Not sure what your contract actually requires right now?
We read the clauses in your solicitations and contracts, identify what the July 13 direction and Revision 3 change for your specific procurements, and tell you plainly what still applies.
Book a scope call. Thirty minutes, no charge. Or take the self-check first.
This series
- 01 · C3PAO wasn’t removed. Read the status list. (you are here)
- 02 · What moved to DFARS Part 240, and what your documents still cite — forthcoming
- 03 · Reading a class deviation: what binds and what doesn’t — forthcoming
Related briefs
This brief reflects published guidance as of 9 September 2026. Class Deviation 2026-O0025 has been revised three times since issuance and remains in effect until rescinded or incorporated into the FAR, DFARS and DFARS PGI — verify the current revision before relying on it. CMMC Level 2 is assessed against NIST SP 800-171 Rev. 2; references to Rev. 3 concern NIST’s current publication and the proposed FAR CUI rule, not the CMMC assessment baseline. Advisory content, not legal advice. Contract-specific obligations should be evaluated against the applicable solicitation, contract clauses, amendments, modifications, and current Government guidance.
Cyber DSC · Insights · CMMC Regulatory Brief 01 · 09 Sep 2026
