- Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
- AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
- Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
- Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.
Last Updated on September 11, 2026
BLUF
DARS Class Deviation 2026-O0025, Revision 3, dated September 3, 2026, does not establish a new CMMC policy. Revision 3 carries forward the CMMC direction in Revision 2, which implemented the Department’s July 13, 2026 decision to suspend advancement to CMMC Phase 2 requirements. Revision 3 does not repeal CMMC or remove the safeguarding obligations in DFARS 252.204-7012. When that clause applies, contractors must continue to protect covered defense information and implement NIST SP 800-171 Revision 2.
For CMMC, Revision 3 confirms the position established in July. Its principal new changes address other information-security and supply-chain requirements. Contractors should continue required remediation and evidence collection, but they should evaluate the timing of a voluntary C3PAO assessment against contract requirements and business need.
What Revision 3 Actually Does
The primary purpose of Revision 3 is to provide implementation direction to the Department of Defense acquisition workforce. The memorandum is addressed to acquisition executives, procurement leaders, and contracting organizations across the Department. It instructs contracting officers how to apply revised DFARS Part 240 requirements and how to implement existing Department policy.
With respect to CMMC, the memorandum directs contracting officers to remove or revise CMMC requirements in solicitations and contracts in accordance with the July 13, 2026 memorandum issued by the Department Chief Information Officer. Specifically, the memorandum states that the July policy:
- Permits CMMC Level 1 (Self) assessments.
- Permits CMMC Level 2 (Self) assessments.
- Requires baseline compliance with NIST SP 800-171 Revision 2 through DFARS 252.204-7012.
- Suspends the November 2026 CMMC Phase 2 transition.
- Requires updates to active solicitations.
- Requires modification of existing contracts that contain affected CMMC requirements.
Revision 2 already contained this CMMC direction. Revision 3 carries the direction forward. The memorandum primarily tells contracting officers how to execute the existing policy decision.
The Relationship Between Revision 3, Revision 2, and the July 13 CIO Memorandum
To understand Revision 3, it is important to view it as part of a sequence of actions.
Step 1: July 13, 2026 CIO Memorandum
The Department Chief Information Officer issued the memorandum titled “Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements.” This memorandum established the policy decision to suspend advancement to Phase 2 and allow self-assessment approaches while maintaining NIST SP 800-171 compliance requirements.
Step 2: Revision 2
Revision 2 incorporated the July 13 CIO direction into the class deviation and instructed contracting officers to remove or revise affected CMMC requirements in solicitations and contracts. Revision 2 already contained the core CMMC suspension concepts that contractors have been discussing since July.
Step 3: Revision 3
Revision 3 supersedes Revision 2. It adds or revises requirements for prohibited sources, covered semiconductor products and services, unmanned aircraft systems, and the transfer of covered DoD employee data. These changes do not modify the CMMC direction established in Revision 2.
In practical terms, Revision 3 confirms that the Department continues to operate under the July 13 policy direction. Revision 3 continues the suspension of the November 2026 Phase 2 transition. It does not establish a new CMMC implementation model.
What Revision 3 Does Not Do
Many contractors immediately ask whether Revision 3 means that CMMC has been canceled. The memorandum does not support that conclusion.
Revision 3 does not:
- Repeal the CMMC program.
- Remove CMMC Levels 1, 2, or 3 from revised DFARS Part 240.
- Remove DFARS 252.204-7012 from the revised DFARS text.
- Remove the requirement to implement NIST SP 800-171 Revision 2 when DFARS 252.204-7012 applies.
- Remove the SPRS-related requirements retained in the revised DFARS text.
- Remove the Government assessment provisions retained in the revised DFARS text.
Revised DFARS Part 240 retains the CMMC provisions, definitions, and assessment structure while the Phase 2 transition remains suspended. A suspension is not a repeal.
What Revision 3 Does Not Answer
Although Revision 3 provides implementation guidance to the acquisition workforce, it does not answer several questions that are important to defense contractors.
Revision 3 does not indicate:
- Whether the Department intends to reinstate the Phase 2 rollout after completion of the CIO review.
- Whether CMMC Level 2 (Self) will become a long-term alternative to C3PAO assessments.
- Whether future solicitations or contracts will require CMMC Level 2 (C3PAO) after the suspension ends or the Department issues new direction.
- Whether the Department intends to revise CMMC assessment requirements.
- Whether future DFARS rulemaking will permanently alter the current implementation schedule.
The memorandum preserves the CMMC framework while implementing the July 13 suspension. As a result, contractors should avoid drawing conclusions that are not expressly supported by the available guidance.
Organizations should monitor future CIO memoranda, DFARS class deviations, solicitation changes, and proposed rulemaking activity for additional direction.
Questions Contractors Should Ask
Does this mean I can stop pursuing CMMC certification?
Not necessarily. Revision 3 does not prohibit a contractor from continuing preparations for a C3PAO assessment. However, the contractor should evaluate whether a current or expected contract requirement supports the cost and timing of that assessment. The contractor should consider expected solicitation requirements, customer requirements, subcontract obligations, readiness, cost, and schedule. The contractor must continue required NIST SP 800-171 remediation even if the contractor delays a voluntary C3PAO assessment.
Does Revision 3 change an existing SPRS assessment result?
Revision 3 does not state that an existing SPRS assessment result will be removed, invalidated, or automatically changed. Contractors should verify that each submitted assessment remains accurate and current under the applicable contract requirements. The SSP, POA&M, and retained evidence should support the submitted result.
Can the Government still assess me?
Yes. The Phase 2 suspension does not remove the Government assessment provisions retained in the revised DFARS text. Contractors must remain prepared to support a Government Medium or High NIST SP 800-171 DoD Assessment when the applicable contract includes that requirement.
Will new contracts still contain cybersecurity requirements?
Yes. Revision 3 does not remove cybersecurity requirements from all DoD solicitations and contracts. It directs contracting officers to remove or revise affected CMMC requirements in accordance with the July 13 CIO memorandum. It retains DFARS 252.204-7012 and the requirement to implement NIST SP 800-171 Revision 2 when that clause applies. Contractors must review each solicitation and contract to identify the applicable requirements.
What Should Contractors Watch For Next?
Revision 3 does not identify whether the Department will publicly release a review report or issue other documents related to the review. However, the following public sources could show future changes.
Future CIO Memoranda
A future CIO memorandum could provide additional direction about the Department’s approach to CMMC. Revision 3 identifies the July 13 CIO memorandum as the source of the current suspension direction.
Additional DFARS Class Deviations
A future class deviation could provide implementation instructions if the Department changes the requirements before permanent rulemaking is complete.
Solicitation Language
Contractors should pay close attention to actual RFPs and RFQs. Solicitation amendments and contract modifications can provide insight into how contracting activities implement the suspension. Revision 3 directs contracting officers to amend affected solicitations and modify affected contracts. The memorandum specifically directs contracting officers to perform those actions.
Formal DFARS Rulemaking
The memorandum states that the deviation remains effective until rescinded or incorporated into the FAR, DFARS, or DFARS PGI. Contractors should monitor the Federal Register and official FAR and DFARS publication sites for proposed rules, final rules, and implementation notices.
Advice for Defense Contractors
Defense contractors should not treat the Phase 2 suspension as a suspension of the underlying safeguarding requirements. Contractors should:
- Maintain an accurate CUI scope.
- Implement the applicable NIST SP 800-171 Revision 2 requirements.
- Maintain an accurate SSP.
- Maintain an accurate POA&M and track remediation activities to completion.
- Collect and retain objective evidence.
- Keep applicable SPRS assessment information accurate and current.
- Review each solicitation and contract for specific cybersecurity requirements.
- Evaluate the timing of a voluntary C3PAO assessment against contractual requirements, business need, cost, and readiness.
Revision 3 does not remove DFARS 252.204-7012 or the requirement to protect covered defense information when that clause applies. A contractor that stops required remediation can increase contractual and assessment risk.
Final Thoughts
For CMMC, Revision 3 continues the direction in Revision 2 and the July 13 CIO memorandum. The November 2026 Phase 2 transition remains suspended. The safeguarding requirements in DFARS 252.204-7012 remain in effect, including NIST SP 800-171 Revision 2 when the clause applies.
Contractors should maintain required safeguards, support submitted assessment information with evidence, and review each solicitation and contract for applicable cybersecurity requirements. Contractors should also monitor official Department publications for additional CMMC direction.