ITAR Registration Code:
M49438 / Cage Code: 94U86

CMMC Revision 3 Explained: Phase 2 Suspension, the 2028 Date, and What Contractors Need to Know

Table of Contents

DARS Class Deviation 2026-O0025, Revision 3 suspends the planned November 2026 CMMC Phase 2 transition and establishes November 10, 2028, as an important date for how the CMMC clause is applied. Here’s what defense contractors need to know.

The Short Answer

The Cybersecurity Maturity Model Certification (CMMC) program has not gone away.

DARS Class Deviation 2026-O0025, Revision 3 suspends the planned November 2026 CMMC Phase 2 transition. It also establishes November 10, 2028, as an important date for the application of the CMMC clause to solicitations and contracts.

Until November 9, 2028, the CMMC clause may still be included when the program office or the requiring activity determines that a contractor must have a specific CMMC level. Beginning November 10, 2028, the condition changes to whether contractor information systems will be used to process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), subject to the exception for acquisitions solely for commercially available off-the-shelf (COTS) items.

So, while you may hear that “CMMC has been delayed until 2028,” that description does not tell the whole story.

Key Takeaways

  • November 2026: The planned CMMC Phase 2 transition is suspended.
  • Before November 10, 2028: The CMMC clause can still be included when the program office or requiring activity determines that a contractor needs a specific CMMC level.
  • November 10, 2028: Revision 3 does not describe this as a universal CMMC certification deadline. Instead, it changes the condition for including the CMMC clause.
  • NIST SP 800-171 remains important: Revision 3 requires baseline compliance with NIST SP 800-171 Revision 2 in accordance with DFARS 252.204-7012.

What Is DARS Class Deviation 2026-O0025, Revision 3?

DARS Class Deviation 2026-O0025, Revision 3 provides revised acquisition direction affecting CMMC requirements.

The CMMC portion directs contracting officers to collaborate with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts in accordance with a July 13, 2026, Department of War Chief Information Officer memorandum titled “Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements.”

The deviation identifies several specific actions associated with that memorandum. It permits requiring activities to include CMMC Level 1 (Self) or Level 2 (Self) assessments, requires baseline compliance with NIST SP 800-171 Revision 2 under DFARS 252.204-7012, and suspends the November 2026 CMMC Phase 2 transition.

Did CMMC Phase 2 Get Delayed?

Revision 3 specifically says that the November 2026 CMMC Phase 2 transition is suspended.

That wording is important.

The document does not say that the entire CMMC program has been canceled. It also does not state that CMMC cannot be required before November 2028.

Instead, Revision 3 changes how CMMC requirements are handled during this period.

Can CMMC Still Be Required Before November 2028?

Yes, under the conditions established in Revision 3.

Until November 9, 2028, the CMMC clause in DFARS 252.204-7021 is included when the program office or requiring activity determines that the contractor must meet a specific CMMC level.

The provision applies to solicitations and contracts, task orders, and delivery orders, including those using FAR Part 12 procedures for commercial products and commercial services. The deviation provides an exception for acquisitions of COTS items only.

This is an important point for defense contractors.

The November 2028 date should not automatically be interpreted as meaning:

“CMMC does not matter until 2028.”

Revision 3 provides a mechanism for CMMC requirements to continue appearing before that date.

What Changes on November 10, 2028?

Beginning November 10, 2028, the condition for including the CMMC clause changes.

On or after that date, the clause is included when the program office or requiring activity determines that the contractor is required to use contractor information systems during contract performance to process, store, or transmit FCI or CUI.

The exception for acquisitions solely for COTS items remains.

The distinction can be summarized this way:

Until November 9, 2028: The focus is on whether the program office or the requiring activity determines that the contractor must have a specific CMMC level.

On or after November 10, 2028: The focus is whether the program office or requiring activity determines that contractor information systems will be used to process, store, or transmit FCI or CUI during contract performance.

This is why describing November 10, 2028, simply as the “new CMMC deadline” can be misleading.

Does NIST SP 800-171 Still Apply?

Revision 3 specifically requires baseline compliance with NIST SP 800-171 Revision 2 in accordance with DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.

The CMMC program materials also explain the relationship between CMMC and existing cybersecurity requirements. They identify NIST SP 800-171 Revision 2 as the cybersecurity standard associated with CMMC Level 2 and note that it is required by DFARS 252.204-7012 for applicable covered contractor information systems.

This distinction is important:

A change to the CMMC rollout does not automatically mean that underlying contractual cybersecurity requirements disappear.

Contractors should therefore avoid treating the Phase 2 suspension as a reason to stop work associated with applicable NIST SP 800-171 requirements.

What Happens to Active Solicitations and Existing Contracts?

Revision 3 also provides instructions for CMMC requirements already appearing in solicitations and contracts.

For affected active solicitations, program managers and requiring activities must initiate amendments and provide them to the cognizant contracting officer. Contracting officers are then required to issue the corresponding solicitation amendments as soon as practicable.

For existing contracts containing the affected requirements, contracting officers are directed to remove them through a modification before exercising the next option period or through the next scheduled administrative modification.

For contractors, this makes the actual solicitation, contract, amendment, or modification especially important.

A general announcement about CMMC does not replace the need to review the requirements contained in the specific procurement or contract.

Why Is There So Much Confusion About the 2028 Date?

Much of the confusion comes from two separate changes appearing together.

The planned November 2026 Phase 2 transition is suspended, while November 10, 2028 establishes a different condition for the inclusion of the CMMC clause.

Combining those provisions into the statement “CMMC is delayed until 2028” oversimplifies what Revision 3 says.

What Should Defense Contractors Do Now?

Contractors should continue to pay close attention to the cybersecurity and CMMC requirements in their specific solicitations and contracts.

Revision 3 allows CMMC requirements under the conditions described above before November 2028, while also requiring baseline compliance with NIST SP 800-171 Revision 2 under DFARS 252.204-7012. CMMC Level 1 (Self) and CMMC Level 2 (Self) requirements still apply when required by contract.

The practical takeaway is simple:

Do not treat November 2028 as permission to stop preparing.

Instead, review your applicable contractual requirements, monitor solicitation amendments and contract modifications, and continue addressing the cybersecurity requirements that apply to your organization.

Frequently Asked Questions

Was CMMC canceled?

No. Revision 3 does not state that CMMC has been canceled. It suspends the planned November 2026 CMMC Phase 2 transition and provides revised direction for CMMC requirements.

Was CMMC Phase 2 delayed?

Revision 3 specifically states that the November 2026 CMMC Phase 2 transition is suspended. Using the word “suspended” most closely follows the language of the document.

Can CMMC still be required before November 2028?

Yes. Until November 9, 2028, the CMMC clause can be included when the program office or requiring activity determines that the contractor is required to have a specific CMMC level, subject to the applicability language and COTS exception in Revision 3.

Is November 10, 2028 the new universal CMMC certification deadline?

Revision 3 does not describe November 10, 2028 as a universal CMMC certification deadline. It establishes that date as the point when the condition for including the CMMC clause changes. CMMC Level 1 (Self) and CMMC Level 2 (Self) requirements still apply when required by contract.

The Bottom Line

CMMC has not disappeared, but the rollout has changed.

The planned November 2026 CMMC Phase 2 transition is suspended. Before November 10, 2028, CMMC can still be required under the conditions established in Revision 3. Beginning November 10, 2028, the condition for including the CMMC clause changes to whether contractor information systems will be used to process, store, or transmit FCI or CUI, subject to the stated COTS exception.

At the same time, Revision 3 requires baseline compliance with NIST SP 800-171 Revision 2 under DFARS 252.204-7012.

For defense contractors, the key message is:

The CMMC rollout changed. The responsibility to understand and meet applicable cybersecurity requirements did not disappear.

Schedule a free consultation with the Brea Networks team to review your current environment, identify compliance risks, and determine the steps required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.

About Brea Networks

Brea Networks is a cybersecurity and compliance-focused IT partner dedicated to supporting Defense Industrial Base (DIB) contractors. We help organizations understand and implement the security requirements outlined in FAR 52.204-21, DFARS 252.204-7012, and the CMMC framework from Level 1 self-assessments to Level 2 and Level 3 readiness. Our team works alongside contractors to strengthen system security, define assessment scope, prepare documentation such as System Security Plans (SSPs) and POA&Ms, and build sustainable cybersecurity programs that protect FCI and CUI. Whether you are preparing for a self-assessment or simply improving your security posture. Brea Networks provides practical guidance and technical expertise to help you move forward with confidence.

Redirecting to Download Full Offline Documents

Redirecting to Download GCC High Buyer`s Guide

Redirecting to ITAR Compliance Checklist

Redirecting to CMMC Level 2 Audit Checklist

Redirecting to CMMC Level 1 Audit Checklist

Redirecting to Discovery Call