Top story
With the 60-day review closed on September 11, the defense industry is waiting on the task force's recommendations. Professional Services Council president Stephanie Kostro told Federal News Network on September 15: "This is not the death knell of CMMC. In no way, shape or form does this class deviation say CMMC is dead." She described what the deviation does: "It suspends the Phase 2 transition, where you would start going towards this level 2 by an outside assessor." To companies that already paid for an assessment: "If you have undertaken an outside review, an outside assessment of your approach to cybersecurity, that was money well spent."
Rules and policy
- The CMMC wording didn't change between revisions. Fortreum's September 14 analysis finds that "the CMMC language in Class Deviation 2026-O0025 remained unchanged between Revision 2 (July 16, 2026) and Revision 3." It also notes the task force "has 15 days to respond" after the review closed. (Fortreum dates Revision 3 September 4. The deviation memo shows it was signed September 3.) Why it matters: Revision 3 changed clause numbering and added other requirements, not the CMMC policy.
- FAR overhaul proposals published. On September 18 the Federal Register published three proposed FAR overhaul rules: Parts 9, 27 and 47; Parts 14, 28, 36 and 52; and Parts 16, 17 and 35. As CMMC.com noted when this batch cleared OMB, "CMMC is not in the FAR." Why it matters: the FAR rewrite is moving on its own track. CMMC changes will come through 32 CFR Part 170 and the DFARS.
Industry and enforcement
- No new DOJ cyber-fraud settlements were announced this week. The most recent is Honeywell Aerospace ($2,042,518, September 1).
Still on the radar
- Kostro expects "another memo from the Department of War CIO." None had been issued by September 18.
Watch list
- The task force recommendations, expected about 15 days after the review closed.
- Any Phase 2 restart date, or proposed changes to 32 CFR Part 170.
What to do this week
- Keep your SPRS score and annual affirmations accurate.
- If you've already been through a C3PAO assessment, keep your evidence current and your annual affirmation on schedule.
- Keep closing NIST SP 800-171 gaps. They are required under DFARS 252.204-7012 either way.
Sources
- As the Pentagon rethinks CMMC, cybersecurity isn't pausing (Federal News Network, Sept. 15, 2026)
- Second Batch of Revolutionary FAR Overhaul Clears OMB (CMMC.com, Sept. 4, 2026)
- CMMC Update: What DoD Class Deviation 2026-O0025 Means (Fortreum, Sept. 14, 2026)
- Revolutionary FAR Overhaul Parts 9, 27, and 47 (Federal Register, Sept. 18, 2026)
- Revolutionary FAR Overhaul Parts 14, 28, 36, and 52 (Federal Register, Sept. 18, 2026)
- Revolutionary FAR Overhaul Parts 16, 17, and 35 (Federal Register, Sept. 18, 2026)
- Honeywell Aerospace Inc. Agrees to Pay Over $2M (U.S. Department of Justice, Sept. 1, 2026)
This briefing summarizes public sources for general awareness. It is not legal advice. Check the linked primary sources before acting on any item.