CMMC Phase 2 Suspension Is Now Permanent: What Texas Defense Contractors Must Still Do (2026)

DoD locked the CMMC Phase 2 assessment suspension into binding regulation on September 3, 2026. Self-attestation and False Claims Act risk did not go away.
Introduction
For more than a year, Texas defense subcontractors were told a hard deadline was coming: a mandatory third-party CMMC Level 2 assessment before certain DoD solicitations could be awarded. On September 3, 2026, the Department of Defense made that deadline disappear — not with a memo that could quietly reverse at the next policy meeting, but with a binding class deviation ordering contracting officers to strip third-party CMMC assessment requirements out of active and upcoming contracts. For Houston-area manufacturers, engineering firms, and IT vendors sitting anywhere in the federal supply chain, the assessment clock has stopped. The underlying compliance obligation has not, and treating this as "CMMC is over" is the mistake that will show up in your next flow-down review or, worse, a False Claims Act inquiry.
What the September 3 Class Deviation Actually Changed
The directive came from John Tenaglia, DoD's principal director for defense pricing and acquisition policy, and it did something policy memos rarely do: it converted a temporary pause into an enforceable regulation. Contracting officers are now ordered to strip out any and all CMMC third-party assessment requirements from contracts — eliminating the mandatory third-party evaluation that had been scheduled to begin rolling out in November 2026. Because the suspension now runs through a class deviation rather than informal guidance, reversing it requires DoD to go back through a formal regulatory process, not just change its mind. That is a meaningfully higher bar than the original suspension announced back in July, when the Pentagon first paused Phase 2 and launched a CMMC Reform Task Force to review the program.
What is suspended is narrow and specific: the third-party assessment requirement and the phased rollout timeline behind it. Nothing in the class deviation touches the underlying security standard your business is still expected to meet.
Self-Attestation to NIST 800-171 Is Still Mandatory
If your company handles Controlled Unclassified Information (CUI) under a federal contract, DFARS clause 252.204-7012 still obligates you to implement the 110 controls in NIST SP 800-171 and to self-certify your score in the Supplier Performance Risk System (SPRS). That requirement never moved. Our guide to NIST 800-171 control mapping walks through scoping CUI and building the control map an assessor or a prime contractor's audit team would actually accept. If you have not pulled your SPRS score recently, LayerLogix's CMMC self-assessment tool is the fastest way to see where the gaps sit before anyone else asks.
The False Claims Act Risk Did Not Pause With the Assessments
This is the part getting lost in the "CMMC is dead" narrative circulating among smaller contractors. The Department of Justice's Civil Cyber-Fraud Initiative has already pursued contractors under the False Claims Act for submitting NIST 800-171 self-assessment scores that did not match their real environment. Removing the third-party check does not remove the incentive for DOJ to keep using whistleblower and audit-driven enforcement against inflated self-attestations — if anything, self-attestation without a third-party backstop puts more scrutiny on whether the number you reported to SPRS is honest. A Texas SMB that lets its documentation lapse because "the assessment got cancelled" is walking into exactly the exposure this regulation was not designed to create.
What the CMMC Reform Task Force Review Signals for What Comes Next
The task force that grew out of July's initial suspension had a 60-day review window that closed around September 11, 2026. Its recommendations now sit with DoD Chief Information Officer Kirsten Davies, who will decide whether to release them publicly and how they reshape CMMC requirements going forward. Nothing here suggests the program disappears — the working signal from federal contracting counsel and trade press is reform, not repeal. Firms that treat this as a multi-month reprieve to shore up their control environment will be in a far better position than firms that treat it as a reason to stop investing. A practical roadmap for the control families likely to survive any rewrite is the same one behind CIS Controls implementation groups: access, logging, and vulnerability management carry the most weight in every version of this framework the DoD has floated.
How a Texas Defense Supply Chain SMB Should Respond Right Now
Nothing about your actual security posture should change because of a procedural suspension. What should change is how closely you watch three things:
- Your SPRS score's accuracy. If it reflects an aspirational environment rather than your real one, fix the score or fix the environment before DOJ or a prime's audit team asks.
- Flow-down language from primes. Some prime contractors are keeping contractual CMMC language even where DoD has removed the third-party requirement — read your renewals carefully rather than assuming the suspension trickles down automatically.
- Any public release from the CMMC Reform Task Force. Whatever DoD CIO Davies decides to publish will be the clearest signal yet of what CMMC 3.0, or whatever it becomes, actually requires.
Where to Start
This week, pull your current SPRS score and compare it line by line against what your environment actually does — not what your POA&M says you plan to do eventually. If you do not have a current System Security Plan and POA&M, start one now while the third-party assessment clock is paused; that pause is a runway, not a reason to stop. LayerLogix's CMMC compliance services and cybersecurity services cover both the documentation and the technical controls behind an honest self-attestation, and our SOC 2 readiness work builds evidence you can reuse across every framework a prime or an insurer asks about.
Geographic Coverage
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.


