CMMC Certification Pauses, but 7012 Doesn't
DoD's class deviation suspends third-party assessments without touching the underlying DFARS safeguarding clause, the NIST 800-171 baseline, or the annual affirmation requirement, and conflating the two is how contractors lose their seat at the table.
TL;DR
The Pentagon issued a class deviation suspending CMMC third-party certification requirements (no more C3PAO assessments for Level 2, no Level 3) but left every underlying cybersecurity obligation intact. DFARS 252.204-7012 safeguarding requirements remain. NIST SP 800-171 Revision 2 controls remain. SPRS scoring remains. And contractors must still file annual affirmations of continuous compliance. Contracting officers have been instructed to update active solicitations to reflect the changes. The Phase 2 transition toward mandatory outside assessments, originally set to ramp up, is now on hold while DoD's 60-day top-to-bottom review of the program concludes.

The Defense Department has drawn a line that every contractor needs to see clearly: CMMC certification is paused. Cybersecurity compliance is not.
The class deviation, issued days after the CMMC comment window closed, suspends third-party assessments, the C3PAO-led certifications that were supposed to become the standard for Level 2 contractors handling controlled unclassified information. Level 3 assessments are suspended as well. What remains are self-assessments at Levels 1 and 2, which took effect last November under Phase 1 and are not affected by the pause.
But the deviation does not touch DFARS 252.204-7012, the safeguarding clause that has anchored defense contractor cybersecurity obligations for years. It does not touch NIST SP 800-171 Revision 2. It does not touch the Supplier Performance Risk System scoring that determines how a contractor looks to the government. And it does not touch the annual affirmation, the requirement that a senior official certify, every year, that the company is meeting those controls.
Stephanie Kostro, president of the Professional Services Council, put it bluntly in an interview with Federal News Network: "This is not the death knell of CMMC. In no way, shape, or form does this class deviation say CMMC is dead." What it says, she explained, is that the outside-assessment piece is gone for now, not the underlying obligations.
That distinction matters because the contractor base appears to be splitting. Some companies, early C3PAO-certified, view their certification as a sunk cost and a competitive signal. Others are hitting pause, waiting to see what the permanent framework looks like before spending on an assessment. Both positions are defensible. Neither relieves a contractor of 7012 compliance or the annual affirmation.
What's less defensible is treating the class deviation as a compliance holiday. The review is still underway, DoD CIO Kirsten Davies's July memo launched a 60-day process that should be wrapping up now, with listening sessions and an RFI already in the rearview. No permanent redesign has been announced. Contracting officers have been told to update active solicitations line-in, line-out, and the deviation runs more than 80 pages. The building is not treating this casually, and contractors shouldn't either.
One open question the deviation doesn't resolve: whether the suspension applies retroactively to already-awarded contracts that contain CMMC Level 2 certification clauses, or only to new solicitations going forward. Until that's clarified, a contractor holding a Level 2 requirement in an existing contract should assume it still bites.
Published ·Deep Fathom