Top story
DFARS Class Deviation 2026-O0025, Revision 3, was signed September 3 and supersedes Revision 2 of July 16. It directs contracting officers to "remove or revise the Cybersecurity Maturity Model Certification (CMMC) requirements in new and existing solicitations and contracts," per the DoW CIO's July 13 suspension memo. That memo permits Level 1 (Self) or Level 2 (Self), requires baseline NIST SP 800-171 Rev. 2 compliance under DFARS 252.204-7012, and suspends the November 2026 Phase 2 transition.
Rules and policy
- New clause numbers. Revision 3 has contracting officers use the revised FAR Part 40 and the attached DFARS Part 240 and PGI 240. In DFARS Part 240, the NIST SP 800-171 DoD assessment clause is 252.240-7997 (FEB 2026), which covers government-led Medium and High assessments. Where a contract includes Level 1 (Self) or Level 2 (Self), 252.204-7021 still requires posting a current self-assessment in SPRS. Why it matters: your next modification may carry clause numbers you haven't seen before.
- More than CMMC. Revision 3 also implements section 853 of the FY2025 NDAA, barring DoD purchases from entities that knowingly supply covered semiconductor products to Huawei, and the FY2024 and FY2025 NDAA bans on selling covered DoD personnel data. Why it matters: read the whole modification, not just the CMMC language.
Industry and enforcement
- Honeywell Aerospace pays $2,042,518. DOJ announced on September 1 that Honeywell Aerospace Inc., headquartered in Phoenix, agreed to settle allegations that "from April 2020 through December 2023, a business unit of Honeywell International Inc. submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, with respect to one of Honeywell's networks, as required by the contract and regulation." The case began with a whistleblower suit by a former employee, who receives $375,823. Assistant Attorney General Brett A. Shumate: "Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards." DOJ notes that the claims "are allegations only and there has been no determination of liability." Why it matters: it follows the LOGZONE settlement in June. False Claims Act exposure doesn't depend on Phase 2.
Still on the radar
- The Reform Task Force's 60-day review ends about September 11.
Watch list
- The task force report, expected late September or early October.
- Contract modifications implementing Revision 3.
What to do this week
- Compare your SPRS score against your actual implementation. An inflated score is what False Claims Act cases are built on.
- Make sure employees have an internal channel to raise compliance concerns, and that someone acts on them.
- Flag Revision 3 for whoever signs your contract modifications.
Sources
- Class deviations list, including 2026-O0025, Revision 3 (Defense Pricing, Contracting, and Acquisition Policy)
- Understanding the Impact of Class Deviation 2026-O0025 Revision 3 (Fortreum, Sept. 14, 2026)
- Honeywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense Contract (U.S. Department of Justice, September 1, 2026)
- Alabama Defense Contractor Agrees to Pay $507,144 (U.S. Department of Justice, June 18, 2026)
This briefing summarizes public sources for general awareness. It is not legal advice. Check the linked primary sources before acting on any item.