DoD Already Fixed CMMC’s Rev. 3 Problem. Now It’s Back.

Jacob and Jason warn that a baseline-mismatch problem the DoD deliberately solved in 2024 is now resurfacing because of the CMMC Phase 2 suspension. Their read of the DoD CIO’s own words: contractors should brace for more requirements coming out of the review, not fewer.

Key takeaways:

  • The 2024 fix is unraveling. DFARS 7012 auto-points to the latest NIST 800-171 (now Rev 3); CMMC is pinned to Rev 2. In 2024 a class deviation locked everyone to Rev 2, with a planned CMMC 3.0 rule to move everyone to Rev 3 together. That rule was on the CIO’s desk — and the suspension appears to have shredded it.
  • FAR CUI is the buzzsaw. It’s expected by year-end, requires 800-171 Rev 3, and has no phased rollout — the day the clause hits a contract, you comply. So contractors with both FAR and DFARS work could be forced to juggle Rev 3 and Rev 2 baselines for the same data.
  • Every exit is messy. Come out on Rev 3 → mismatch with the pinned CMMC program and a 12–24 month rulemaking clock. Stay on Rev 2 → mismatch with FAR CUI. Either way, the toothpaste won’t go back in the tube without the transition rule they paused.
  • Even the already-certified aren’t spared. A company with a CMMC Level 2 cert or a DIBCAC 800-171 assessment could still face the Rev 2 → Rev 3 uplift, depending on what each contract points to.
  • The DoD wants requirements beyond NIST. Quoting Kirsten Davies across 2026 (integrity + availability, OT security “from the factory floor to the tactical edge,” “table stakes… never went away”), the hosts argue the review will add obligations — OT/resilience, likely SBOMs and supply-chain items — on top of whichever 800-171 revision applies.
  • “Suspension” ≠ relief. If you read the DoD’s own statements, they want the bar to go up. Any real burden reduction would come from cutting documentation/assessment emphasis — not requirements. If it all lands as described, it’d be the biggest jump in contractor cybersecurity requirements since DFARS 7012 in 2013.

Transcript

Jacob: All right, folks. It is September of 2026. Technically, this is the first podcast of the late 2020s, according to Encyclopedia Britannica. Look it up. Anyways — back in 2024, the DoD had a major problem on their hands. DFARS 252.204-7012 was going to require compliance with NIST SP 800-171 Revision 3 requirements. Meanwhile, CMMC 2.0 was going to require proof of compliance with Revision 2 of those NIST requirements. But the DoD solved this problem with something known as a class deviation, and they pinned DFARS 7012 and CMMC together. So the future CMMC 3.0 would have a transition plan, and everything would move to 171 Revision 3 at the same time, and all was well. Well, instead of moving forward with that rule, the DoD opted to suspend CMMC Phase 2 and conduct a review of the program. And that’s a big problem, because when they come out of the review, defense contractors are almost certainly going to have more things to juggle than they did before. And that’s what we’re going to talk about today.

Jason — the DoD specifically avoided the Rev 2 / Rev 3 problem all the way back in May of 2024, but now the DoD is behind the eight-ball, and they’re specifically behind the FAR CUI rule, which is going to specify 171 Rev 3. So even if they come out this month, September of 2026, and restart CMMC 3.0 rulemaking, people are going to end up juggling multiple sets of requirements for the same data for at least some period of time.

Jason: Jacob, as Earth, Wind & Fire said — do you remember the first Sum IT Up podcast episode of September? I hope you do now, because this is what we’re going to talk about. You talked about the class deviation in the intro, and when you talked about the class deviation, it just struck a nerve for me, because it feels like we’re at that same choking point within the program, within defense security, whatever you want to call it. There was a buzzsaw coming up, because of the way regulations work — Rev 3 was going to be automatically required by 7012, because “by default, the latest edition of 800-171” is what it reads. And then they said, “We’re going to stop the buzzsaw with” — what? A class deviation. So, big old brick stops the saw blades, jams it up, whatever you want to say. And I think we’re at the same choking point now, because the FAR CUI rule has caught up. So we’re at this choking point where requirements for the DIB were going to be 800-171 Revision 2 — they saw a buzzsaw coming up, and not only the validation requirements for 800-171 Revision 2, but then the multiple frameworks being juggled, and maybe the pauses being put in there. That’s what I think, because based on everything the CIO says, this is the minimum buy-in to get in to play a hand with the DoD.

Jacob: Yeah. There’s a lot of irony going on here, because, like I said, this was a problem the DoD specifically avoided and harmonized, if you will. We did a whole podcast episode — we talked about this for months and months in 2024 — saying this is a real problem: DFARS 7012 says do the most current version of the NIST requirements at the time of the solicitation, but CMMC is pinned specifically to 171 Revision 2. If you don’t change DFARS 7012 to match, then you’re going to have different baselines, and everything will fall apart. They didn’t change DFARS 7012. They had a temporary change called a class deviation. We’ll link to the episode below — we specifically called that episode “crisis averted,” because this was a real crisis the DoD had to get ahead of, and they fixed it. And now we’re in a situation where the crisis, ironically, is right back on the menu, because of the actions of the DoD. And people need to be aware of it, because we don’t know what the DoD’s decision is going to be. We can only speculate, but there probably isn’t a good way for them to sync those things up in a way that’s going to be simple for everybody to handle. So, let’s just talk about the core problem here.

Jason: Wouldn’t you think that right now we’re in a situation where we’re foreshadowing crisis — or the DoW is foreshadowing crisis — and they’re averting it by pausing things?

Jacob: Well, let’s talk about how this works. Let’s talk about how the core problem plays out. So DFARS 252.204-7012 says implement the most current version of NIST SP 800-171 at the time of the solicitation. CMMC specifies NIST SP 800-171 Revision 2. Why those two things are different is a function of the different theories of rulemaking in 2016 versus 2023-2024. It’s a long story, but that’s what they say. So when NIST 171 Revision 3 came out, DFARS 7012 was automatically pointing to it. CMMC was still pointing to 171 Revision 2. Without the class deviation to fix this problem, and without simultaneous rulemaking to change 7012 and CMMC at the same time, these two things — which are inherently related — will be out of sync, and require contractors to uphold two different baselines for the same data. That’s the core of the problem they avoided in 2024.

But now here’s the bigger problem. The DoD suspended CMMC Phase 2, and as far as we can tell, has shredded the rule that was on the DoD CIO’s desk, according to the unified agenda published earlier this year. That rule that was on the desk was started in 2024, right after the CMMC 2.0 rule went into effect, and according to DoD back then, specifically has a plan to transition defense contractors from 171 Rev 2 over to 171 Rev 3. That was the plan for getting everybody synced up to Rev 3 — get the class deviation updated, there would be no issues, so on and so forth. But they’ve paused all that. They’re not moving forward with any of it. That would be fine if it were just defense contract clauses we were talking about. But now the FAR CUI rule is expected by the end of this year, and the FAR CUI rule will require NIST SP 800-171 Revision 3 — which wouldn’t have been a problem with the CMMC 3.0 rule that was in the DoD CIO’s office for months and months prior to them announcing the suspension of Phase 2. So the original plan, starting in 2024, covered this issue, was building off the averted crisis from 2024 — but then they paused it. And so now the question is: when they come out of the review, what are they going to do?

Jason: So my first question for you: by saying “shredded” — I want to assume that you’re saying, because of the pause, and because there are going to be changes recommended by the reform task force, there are going to be changes that need to be made to that rule. So it’s not completely going [away]. And so the assumption is, hopefully those changes can be worked into the rule and we don’t have to completely start from scratch.

Jacob: Well, here’s the thing we don’t know — and longtime viewers will know that rulemaking is not fast, it takes a long time. If you have a finished rule on the CIO’s desk just waiting for signatures to go over for publication, changing things in that rule has to go back through estimation. It has to go back through interagency review. It has to go back through the bureaucracy. So now you’re in a situation where you’re like, okay, is the DoD going to come out of the review and then pick up the rule they had before the review and just run with it without any changes? That would be pretty hard to believe.

Jason: But you said the FAR CUI rule is expected by the end of the year, right?

Jacob: Yeah.

Jason: And there’s an interagency review that takes place for that rule, right?

Jacob: No, that rule is going to be done, because that’s just the final rule.

Jason: No, but I’m saying, at some point an interagency review had to be there. So at some point the DoD was able to look at that rule and see what’s in it.

Jacob: DoD sits on the FAR Council, who wrote the rule.

Jason: So do you think — and the reason I’m thinking about the relationship of these rules to one another, one is a parent and one is a child of the other, correct? The FAR CUI [is the parent], in some ways. So do you think that at some point in time the contents of that rule were seen by the CIO, and they’re like, “Our rule doesn’t look like your rule, and we need to change our rule to look like your rule”?

Jacob: It’s hard to know, because the various listening sessions and the various PR campaigns and the various interviews don’t allow for people to ask the CIO, or the DoD representatives of the CIO, questions like this: how are you going to sync up the FAR CUI rule with DFARS’s requirements with whatever you’re doing with the CMMC program review?

Jason: At my listening session, I didn’t have to ask the question — she offered the answer up to us. She mentioned harmonization. She mentioned the FAR CUI rule. She mentioned 800-171 Revision 3. Some of the writing on the wall, if you look at it: the shift to PQC, the shift to certain things that are found as ODPs in 800-171 Revision 3, the mention of 800-171 again as table stakes. I don’t know — maybe my brain just doesn’t [see it]. I’m just not [sure].

Jacob: Well, let’s just think forward to the possible situations after the review, and then what that means for defense contractors. So the DoD comes out of the review and says, “Everyone go to 171 Revision 3.” First of all, I don’t know how they’re going to handle it when they say your requirements are going to expand — because 171 Rev 3, in a lot of ways, is a higher standard than 171 Rev 2, as it should be, because it’s the first time they’ve updated it in years and years. So they come out and tell everybody, “Actually, you have to do more of the NIST requirements, and you have to do 171 Revision 3.” Okay — how do they tell people to do that? Do they shred the class deviation and say DFARS 7012 now points to 171 Rev 3? Well, now you’ve got the mismatch with the CMMC program. How is that going to work? Do they go through rulemaking and say everybody go to 171 Revision 3? Do you pick up the previous rule you had before the review and go with the transition plan you had all along — that we could already have been on — or are you going to initiate a new rule, which will take you 12 to 18 to 24 months to get through the process? What about reducing cost and burden? So maybe you come out and say, “We’ll emphasize assessments less in order to move everybody to 171 Revision 3.” This still doesn’t fix the problem that if you come out and say everyone move to 171 Revision 3, now or later, the FAR CUI rule is going to come out by the end of the year. And there are many companies like this — anyone who has FAR requirements and DFARS requirements will have different baselines to juggle at the same time, which was the problem they avoided in 2024. So how do you put the toothpaste back in the tube and continue to avoid that problem, when you didn’t move forward with the previous rule that had a plan for this?

Jason: The 7012 class deviation is [in effect for an] indefinite period of time, right? Do they have to come out and say, “Hey, we’re going to lift this,” and announce a date it’s going to be lifted? Or can they just come out and be like, “It’s lifted,” and then we—

Jacob: I don’t know. I don’t know what their plan will be, because — technically, class deviations are supposed to be temporary, in lieu of future rulemaking, and the DFARS 7012 rulemaking case has been open for three years. The Under Secretary for Acquisition and Sustainment owns DFARS 7012 rulemaking, and he was all about the program review. So are they going to sync up the rulemaking? Are they going to be able to do it fast? I just don’t know how, if they come out and say everyone go to 171 Rev 3, they will sync it up with the FAR CUI rule by the end of this year. Let’s just think of a different situation. What happens if the DoD comes out and says everybody stay on 171 Revision 2? Well, now you still have the problem of the FAR CUI rule saying Rev 3 and the DFARS requirements saying Rev 2 — the exact problem we tried to avoid in 2024 by not specifying different baselines for the same data.

Jason: But the FAR CUI rule won’t come out of the gate and be like, “day one, you need to be compliant with 800-171 [Rev 3].”

Jacob: Oh yeah, it will. There is no phased rollout in the FAR CUI rule. The phased rollout for requirements is a DoD concession to the DIB. The FAR CUI rule has no phased rollout. The day that rule goes into effect and that clause shows up in a contract, that’s it.

Jason: So you could see the case where even the organizations that got CMMC Level 2 certified, or got DIBCAC 800-171 assessments done, are still having the uplift from Rev 2 to Rev 3.

Jacob: It all depends on what’s in your contract. So you might end up as a contractor with a different contract that has FAR pointing to Rev 3 and DFARS pointing to Rev 2.

Jason: Mhm.

Jacob: Like, I don’t know. What’s the answer? How will they handle this?

Jason: In addition to that, we know that all the other requirements — the “brilliant at the basics” subset of things — those aren’t all covered in the 800-171 baseline. So how does that play into this?

Jacob: Yeah. So we’ve got the NIST baseline mismatch problem. If the DoD comes out and says Rev 3, you’ve got problems. They come out and say Rev 2, you’ve got problems. Mostly because these are timing problems. But the DoD has been signaling for quite a while — actually, if you go back and look at the quotes — that they want additional requirements on top of the confidentiality requirements in SP 800-171. So if the DoD comes out of the review and says either 171 Rev 2 or 171 Rev 3, but also these other new requirements that we want, you’ve got an even bigger problem. Even if they were to fix the FAR/DFARS mismatch, now you’ve got this other third thing to juggle.

So let’s talk about what the DoD, in their own words, has said about new or current requirements versus potential requirements. This is a quote from Kirsten Davies in February of 2026 — it’s on the LinkedIn page for her office, you can go watch the video yourself, we’ll link it below. At the Defense Tech Leadership Summit — remember, this is months before the suspension — she said, “It’s so critical that in the world of technology risk resilience initiatives, we don’t just look at the confidentiality of data, that we’re also looking at the integrity of data.” And this is a pattern through her statements throughout 2026: that the requirements NIST has created, tied specifically to data confidentiality, don’t go far enough. So in July of 2026, in the CMMC Phase 2 suspension announcement video on the DoD CIO’s web page, she says, “Safeguarding covered defense information remains a non-negotiable legal requirement. In the coming days, we will launch a ‘brilliant at the basics’ cybersecurity campaign, where we will provide streamlined, practical guidance designed to reduce cyber risk to both your IT and OT — operational technology — environments. We’ve worked hand in hand with experts and industry partners to distill these vital cybersecurity best practices into clear, actionable steps.” This is a pattern where she’s talking about not just IT requirements, not just data confidentiality requirements, but also integrity, availability, and OT requirements.

And then last month, in August of 2026, in the article we talked about in last week’s episode, an unknown representative from the DoD CIO’s office, in an interview with National Defense Magazine, said, “The critical machinery used to design, produce, and maintain our weapon systems relies on operational technology that, if compromised, could halt national defense production. The practices in the operational technology top 10 ‘brilliant at the basics’ list ensure that when critical systems are delivered to our warfighters, they are secure from the factory floor to the tactical edge, shifting the focus from checking compliance boxes to establishing a defensible, threat-resistant operational architecture.” The current requirements don’t go far enough.

And then just the other week — also last month, in August, at the DIBEX conference — Kirsten Davies, on stage, said, “As we look at the CMMC reform, I’ve been vocal about the fact that protecting federal data — that’s table stakes. That’s bread and butter for your IT division, your information security folks. That’s still required. That requirement never went away.” She went on to say, “In my opinion — and fortunately my opinion counts in my leadership role — we need to be thinking about how you think about the resilience and readiness of your manufacturing lines. That’s OT security. This is where we’re looking to see what a reform actually looks like, to get after things that help you re-industrialize, increase output, and help us with the arsenal of freedom.” They are going to come out of this review and they are going to try and increase people’s requirements, for better or for worse, to include things outside of just data confidentiality, and things beyond just the NIST 171 Rev 2 or Rev 3 baseline. They’ve been saying it all of 2026, every time they come out. Now, I’m not disagreeing that that would create better security. But let’s just say they are able to fix the 171 Rev 2 / 171 Rev 3 mismatch problem. Then they’re going to come out and do what? Have these other—

Jason: I assume, requirements. So people will have to juggle different baselines.

Jacob: Even if they were to press a magic button and just delete NIST requirements entirely — which they can’t and won’t do — if you had a FAR contract with the data, you would have 171 Rev 3 and then whatever these OT cyber-resilience requirements are that the DoD comes up with. I don’t know what’s going to come out of the review, but based off of reading — not even between the lines, reading their own lines — they clearly have an appetite to have an additional set of requirements on top of the NIST requirements, outside of the revision issue.

Jason: Yeah. Listening to everything they’ve said — the lines she said, and when I’ve been present, the lines she said that I’ve seen her say that are printed in any publication — that’s 100% what I think is going to happen. The thing that’s up in the air right now is: how are those going to work? How do we transition to that? And which one of these requirements that isn’t in the “brilliant at the basics” can’t be absorbed into NIST 800-171 Revision 3 and some ODP, and has to be added on as an included factor?

Jacob: And I just can’t imagine that this level of sustained emphasis on OT security — I mean, this is the flag they have planted: “we need the OT security requirements.” And I don’t disagree, but they have planted this flag, and they have foot-stomped this point all year. And okay, I just don’t see them coming out of the review and then being like, “We politely suggest that you do these things.” I mean, they clearly know that if they want people to do these things, they have to be requirements. But if you want them to be requirements, you have to go through rulemaking.

Jason: I don’t think you’re going to pause something with a purpose — and the purpose here is small business and innovators were struggling to get in — create a pause, create a reform task force, and come out of this and be like, “I really hope that you do these things for us now.” No. If it were me, and I’m putting forward all this effort to make exceptions for you or make things more accessible for you, I don’t think I’m going to make it a recommendation.

Jacob: I agree with you 100% there. We talked about this with the PQC requirements in the episode we did on that, which was also pre-suspension, pre-review. So listen, I’m not trying to confuse everybody or scare anybody. I’m just saying that if you have taken the news of the CMMC Phase 2 suspension as a signal that your cybersecurity requirements as a defense contractor will decrease, I would urge you to go and look at these quotes. Look at the sources we’re going to link in the notes below. That’s not what they’re saying. They’re saying that they want the requirements to go up.

Jacob: If you don’t want to listen to the way that we summarize it, then just listen to the way that she says it. It’s like that National Defense article — basically, in my interpretation of what they are saying, they seem to be saying that if there were less costly assessments, or fewer assessments, or less emphasis on the assessments, then people could get back to the work of cybersecurity and resiliency — and we think that cybersecurity and resiliency is all of these other requirements that you’ve never had before. And I just think people are going to get caught by surprise. Because they’re saying the NIST requirements are non-negotiable table stakes that are absolutely vital and haven’t changed. So to me, it seems like they’re going to come out and say 171 Rev 2 at a minimum, probably 171 Rev 3 shortly thereafter. “Oh, and by the way, also this other stuff.” Isn’t everybody happy?

Jason: Yeah. And then with other things needing like SBOMs, other things completely down the supply-chain line that are coming — other regulatory actions — you can see what’s on the writing on the wall.

Jacob: Yeah. When you get the statements, and you get reports back from the listening sessions, and the DoD is saying that 171 doesn’t go far enough, I just don’t see how you come out of the review with less than what’s currently in 171. And I don’t see how you get those turned into requirements without rulemaking. So whatever they announce at the end of this review is probably going to make a big splash. Let us know in chat — are we misinterpreting what they’re saying? Are you guys hearing something different from these quotes? Because if they were to do the things they’re saying, it would be the largest increase in cybersecurity requirements on defense contractors since DFARS 7012 was created in 2013.

Jason: But how do you offset the burden of that? You eliminate unnecessary burden in other places. And where’s that unnecessary burden right now? If you read RFI responses, it’s in heavy documentation. It’s on assessments, and “too many assessors.”

Jacob: I mean, let’s say — like I said, if the assessments were free and automated, but your requirements go up, are you in a better position?

Jason: Maybe.

Jacob: Well, I don’t know.

Jason: From a security posture, probably.

Jacob: 100% from a security posture. But I don’t think that’s how a lot of contractors are going to interpret it. If you don’t validate it, how will we ever know? So, we’ll see. We don’t know, folks. We’re hoping they’re going to come out with something in the report sometime this month. We don’t know exactly when it’s going to be. What do you think is going to be in the report? What have you heard? How do you interpret what the DoD is saying? I think they’re going to say, “Stay with NIST” — there’s going to be a mismatch with the FAR CUI rule — “oh, and by the way, we’re going to implement a bunch of new requirements on top of it.” Do you think that’s going to happen? You think the burden’s going to go up? You think it’s going to go down? Nobody knows. But like and subscribe, because we’re definitely going to cover it whenever the news breaks. And I cannot wait to see what they say, because I don’t think it’s going to be what people think.

Jason: No, me either. I don’t believe it’s what some people think.

Jacob: That’s true. All right. See you next week.

Jason: See you next week.

[End of recording]

Contact

Speak With Our Team

Scroll to Top