The CMMC Reform Task Force report has not been published. It was delivered to the Department of War Chief Information Officer on or about September 11th, 2026, at the end of the 60-day review that began with the suspension of CMMC Phase 2 on July 13th, 2026. Whether and when it is released publicly is the Department's decision. Reporting points to late September or October 2026.

That leaves the Defense Industrial Base in an unusual position. A document everyone is waiting for remains unpublished, while a different document, one that genuinely changes how contracting officers handle CMMC requirements, was signed on September 3rd, 2026 and received far less attention.

A significant portion of the market has read that second document as a delay of CMMC to November 2028. That reading is incorrect, and acting on it is costly. This article covers three things in order: where the report actually stands, what the class deviation actually did, and what the evidence says about the decisions contractors are making in the meantime.

Two terms used throughout this article

Level refers to an assessment tier, determined by the sensitivity of the information a contractor handles. There are three: Level 1, Level 2 and Level 3.

Phase refers to a step in the rollout calendar for the program as a whole, determining when a requirement begins appearing in contracts. There are four, with dates originally set at November 10th 2025, 2026, 2027 and 2028 under 32 CFR Part 170.3(e).

Most of the confusion described in this article comes from conflating a Phase date with a deadline that applies to a contractor today.

Where the Report Actually Stands

The Task Force was established by the same July 13th memorandum that suspended Phase 2, and was given 60 days to conduct a review and deliver recommendations. It convened in early September to consider responses to the Department's Request for Information, which closed on August 14th, 2026 and generated more than 1,100 comments.

Three points are known from on-record statements rather than from the report itself.

  1. The delivery happened. The 60-day clock from July 13th expired on September 11th, 2026, and the recommendations went to the Department CIO. Some industry trackers anchor internal delivery to September 13th. Either date places delivery in the same week.
  2. Publication is a separate decision. The report went to the CIO first, and that step is internal. Release timing is the Department's call.
  3. The CIO has characterized industry sentiment publicly. Speaking at the Billington Cybersecurity Summit on September 9th, 2026, the Department CIO indicated that more than half the RFI comments supported the Phase 2 suspension. She has separately described the existing assessment model as a burdensome, check-the-box, point-in-time view of how a company handles sensitive data.

Industry positions submitted through the RFI are public where the submitting organizations chose to publish them, and they are not uniform. The Professional Services Council framed the problem as one of execution, arguing that the solution is to improve execution rather than to postpone or weaken the requirements. Several groups raised inconsistent or improper marking of Controlled Unclassified Information as a root cause, on the basis that poor marking leads the Department and Prime contractors to flow down blanket CMMC requirements to subcontractors who will never handle CUI.

These are industry recommendations, not decisions. They indicate likely areas of focus. They do not indicate outcomes.

What Actually Changed on September 3rd

While attention was on the report, the Office of the Assistant Secretary of War for Acquisition and Sustainment issued Revision 3 of DARS Class Deviation 2026-O0025, signed by the Principal Director for Defense Pricing, Contracting, and Acquisition Policy. It supersedes Revision 2 of July 16th, 2026 and is effective immediately.

The distinction that matters is legal rather than substantive. The CMMC language in Revision 3 is carried forward from Revision 2 largely unchanged. What changed is the instrument.

Instrument What it is What it takes to undo
The July 13th memorandum A policy decision issued by the Department CIO, announced with a 60-day review attached and no contract language of its own. It can be reversed by the office that issued it.
Class Deviation 2026-O0025, Revision 3 Binding acquisition regulation. It directs contracting officers to apply a revised FAR Part 40 and DFARS Part 240 in place of the codified text, and to remove third-party CMMC requirements from solicitations and contracts. It remains in effect until rescinded or incorporated into the FAR and DFARS. Undoing it requires regulatory action.

In practical terms, the pause moved from a press release into the rulebook that contracting officers actually work from. A pause that lives in the rulebook behaves differently from one that lives in a memorandum.

What the deviation directs

  • Contracting officers are directed to remove or revise CMMC third-party assessment requirements in new and existing solicitations, and to amend contracts at the next option exercise or scheduled administrative modification.
  • CMMC Level 1 and Level 2 requirements may be satisfied through self-assessment while the deviation is in effect.
  • Baseline compliance with NIST SP 800-171 Revision 2 is explicitly preserved under DFARS 252.204-7012 in every applicable contract.
  • A clause at DFARS 252.240-7997 preserves the Government's authority to conduct Medium and High assessments on covered contractor systems, with results posted to the Supplier Performance Risk System (SPRS).
  • DFARS 240.371 appears in full, including definitions of CMMC status and the currency standards for conditional and final assessments. Clause 252.204-7021 and solicitation provision 252.204-7025 both remain printed in the deviation text.
  • Award eligibility is unchanged. A contracting officer checks SPRS and cannot award to an offeror without a current CMMC status at the required level.

The program rule at 32 CFR Part 170 has not been revoked. The Department retains assessment authority and continues to exercise it.

The Misreading: No, CMMC Was Not Delayed to 2028

This is what contractors are actually doing about the Task Force report, and it is the most consequential behavior in the market right now.

Revision 3 is a 71-page document. On its clause prescription pages, at DFARS 240.371-5, it retains a distinction built around a date of November 10th, 2028. Before that date, contracting officers insert clause 252.204-7021 when a program office or requiring activity determines that a specific CMMC Level is required. On or after that date, insertion is triggered by any contractor information system that will process, store or transmit Federal Contract Information or Controlled Unclassified Information, subject to listed exceptions including contracts solely for commercial off-the-shelf items.

Within a week of publication, a substantial part of the defense supply chain had concluded that this meant CMMC had been pushed to November 2028.

Why that reading is wrong

The November 10th, 2028 date is the original Phase 4 date. Under 32 CFR Part 170.3(e), the phased rollout was set at Phase 2 on November 10th 2026, Phase 3 on November 10th 2027, and Phase 4 on November 10th 2028. Phase 4 is the point at which the clause applies universally, without program office discretion. That date has been in the clause since November 2025. Revision 3 did not create it, extend it or move it. It reprinted text that was already there.

The shared "10th of November" across every phase date is most of why the two are confused.

The correct reading is narrower and less comfortable. The deviation changed who verifies a contractor's compliance. It did not change whether a contractor has to be compliant. Third-party certification is not being written into new solicitations while the deviation is in effect, and there is no fixed date for when it returns.

What a contractor owes today, unchanged

None of the following was altered by the July memorandum, by Revision 2, or by Revision 3.

  • DFARS 252.204-7012, including adequate security and cyber incident reporting within 72 hours.
  • Implementation of the 110 security requirements in NIST SP 800-171 Revision 2.
  • A current self-assessment score posted in SPRS, required under DFARS 252.204-7019 since November 2020 and independent of the CMMC clause.
  • The annual affirmation of continuous compliance, signed by a senior official.
  • Flow-down obligations from Prime contractors, which are set by subcontract terms rather than by Department memorandums.
  • Government-led Medium and High assessments, preserved under DFARS 252.240-7997, whose results take precedence over a contractor's own self-reported status.

The Cost of Standing Down

Two categories of exposure follow from treating the current period as a reprieve. The first is legal and is active now. The second is commercial and arrives later.

Enforcement did not pause

The Department of Justice settled two cybersecurity False Claims Act matters during the review window. Neither depended on the CMMC program operating.

Settlement Amount What it establishes
LOGZONE Inc. June 2026 $507,144 The contractor had posted a self-assessment score of 110 out of 110. A later Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessment produced a score of negative 170. The matter was not whistleblower-driven; it arose from the Government's own assessment process.
Honeywell Aerospace Inc. September 1st, 2026 $2,042,518 Allegations covered April 2020 through December 2023 and concerned NIST SP 800-171 non-compliance on one network. The case originated in a 2022 whistleblower complaint. No security breach was alleged. The allegations remain allegations, with no determination of liability.

The relevant point for the current period is structural. Removing the third-party assessment removed the mechanism that would have identified an overstated self-assessment in a controlled setting. The affirmation signature remains where it was. Self-assessment is now the only attestation operating, and self-assessment is where score inflation occurs.

A contractor whose posted score is optimistic was not protected by the suspension. The exposure was concentrated, not reduced.

The commercial position in 2028

The second cost is competitive. Phase 4 remains on the books at November 10th, 2028, and no plausible outcome of the reform review removes NIST SP 800-171 as the underlying standard. The stated purpose of the review was to reduce compliance cost and administrative burden, particularly for small and non-traditional companies, not to lower the security bar.

An organization that suspends remediation now will be conducting compressed remediation later, under time pressure, while organizations that continued are bidding. Remediation compressed into a short window costs more than the same work spread across available time, and it produces weaker evidence.

What to Do While the Report Is Pending

Four actions are correct under every plausible outcome of the review, whether third-party certification returns as designed, returns narrowed, is replaced by an enhanced self-attestation model, or is not reinstated.

  1. Identify which clause set each contract actually carries. Contracts awarded at different points now sit under different clause sets, and the deviation directs amendment at the next option exercise rather than immediately. The obligation is in the contract, not in the news.
  2. Confirm the SPRS score still describes the environment. A score that was accurate when submitted may no longer be accurate after eighteen months of system change. Correcting an inaccurate score is substantially less costly than having the discrepancy identified by an assessment or a whistleblower.
  3. Keep the evidence trail running. Evidence supporting the posted score, the System Security Plan and the Plan of Action and Milestones is required today and is the foundation of any future assessment model.
  4. Watch for the correct instruments. A task force report is advice. Contractual obligations change only through a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170. The September 3rd deviation is an example of the kind of instrument that constitutes real change; the report, when published, will not be one.

The one-sentence summary

The report is not public, the class deviation is, it did not delay anything to 2028, and the obligations a contractor carries today are the same ones it carried in June.

How KSG Approaches This Period

Kaizen Solutions Group has secured federal and state government systems since 2016. We are an SBA 8(a)-certified small disadvantaged business, ISO 27001:2022, ISO 9001:2015 and ISO 20000-1:2018 certified, and we hold GSA HACS designations across all five categories: Risk and Vulnerability Assessment, High Value Asset assessment, Penetration Testing, Incident Response, and Cyber Hunt.

Our position has not changed since the suspension was announced, because the work we scope was never certification work. Control implementation against NIST SP 800-171 is required today, it is what the enforcement activity of the past year has turned on, and it underpins every version of the program that could emerge from the reform review.

Where we typically begin

  • Contract clause and obligation review: We identify which clause set each contract carries, which requirements have been amended, and which flow-down obligations remain active under subcontract terms.
  • SPRS score reconciliation and gap assessment: We assess the environment against all 110 NIST SP 800-171 controls and reconcile the result against the posted score. Where those two figures disagree, we address that first.
  • System Security Plan and POA&M development: We produce documentation that describes the environment, the boundary and the deficiencies accurately enough to hold up under a Government-led assessment.
  • Risk Management and POA&M analytics: We deliver continuous monitoring, vulnerability and patch management, Cybersecurity Supply Chain Risk Management, and Key Risk Indicator and Key Performance Indicator dashboards so that remediation progress is visible to leadership.
  • Security operations and remediation delivery: We support Security Operations Center monitoring, SIEM and SOAR, penetration testing, incident response, Identity and Access Management, endpoint detection and response, and DevSecOps.
  • Governance, Continuous ATO and Continuous Monitoring: For contractors that also carry FISMA and Assessment and Authorization obligations on the civilian side of their portfolio.

A useful place to begin

For most contractors the shortest high-value conversation is a comparison between the score currently posted in SPRS and the environment as it exists today. Where those two disagree, that gap is the live exposure, and it is unaffected by anything the Task Force recommends.

Talk to our team · Download our capability statement · Explore CMMC Level 2* readiness

Frequently Asked Questions

Has the CMMC Reform Task Force report been published?

No. The report was delivered to the Department of War Chief Information Officer on or about September 11th, 2026, at the end of the 60-day review that began with the July 13th, 2026 suspension of CMMC Phase 2. Publication is a separate decision by the Department, and reporting points to late September or October 2026. Any analysis of the report's contents circulating now is speculation.

Has CMMC been delayed to November 2028?

No. This is the most common current misreading. The November 10th, 2028 date in Class Deviation 2026-O0025 Revision 3 is the original Phase 4 date from 32 CFR Part 170.3(e), which has been in the clause since November 2025. The deviation reprinted it; it did not create or extend it. Phase 4 is the point at which the CMMC clause applies universally without program office discretion. It is not a deadline that relieves a contractor of obligations owed today.

What did Class Deviation 2026-O0025 Revision 3 actually change?

It converted the Phase 2 suspension from a policy memorandum into binding acquisition regulation. Signed September 3rd, 2026, it directs contracting officers to apply a revised FAR Part 40 and DFARS Part 240 in place of the codified text, to remove third-party CMMC requirements from solicitations and contracts, and to amend existing contracts at the next option exercise or scheduled administrative modification. It permits Level 1 and Level 2 to be satisfied by self-assessment. The CMMC language itself is carried forward from Revision 2 of July 16th, 2026 largely unchanged.

Why does it matter whether the pause is a memo or a class deviation?

Because of what it takes to reverse. A memorandum can be withdrawn by the office that issued it. A class deviation remains in effect until it is rescinded or incorporated into the FAR and DFARS, which requires regulatory action. The pause now lives in the rulebook contracting officers work from rather than in a policy announcement.

Does DFARS 252.204-7012 still apply?

Yes, fully. Revision 3 explicitly preserves baseline compliance with NIST SP 800-171 Revision 2 under DFARS 252.204-7012 in every applicable contract. That includes the obligation to provide adequate security on covered contractor information systems and to report cyber incidents within 72 hours.

What is DFARS 252.240-7997?

It is the clause preserving the Government's authority to conduct Medium and High NIST SP 800-171 assessments on covered contractor systems, with results posted to SPRS. Where a Government-led assessment is performed, its results take precedence over a contractor's self-reported status. Government assessment authority did not pause with the third-party certification requirement.

Can a contractor pause CMMC preparation while the report is pending?

Separate the question. Pausing a voluntary third-party assessment that no customer currently requires is defensible on timing grounds. Pausing NIST SP 800-171 control implementation is not, because those controls are required today under DFARS 252.204-7012 and are the basis of the enforcement activity of the past year. If an organization cannot distinguish certification-related spend from control implementation-related spend, resolving that distinction is the first step.

What should contractors watch for next?

Three instruments constitute genuine legal change: a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170. The report itself, when published, will be advice rather than regulation. Contractors holding civilian federal work should separately track the FAR Controlled Unclassified Information rule folded into the June 23rd, 2026 rulemaking, which is unaffected by the CMMC suspension.