No, CMMC Wasn’t Pushed to 2028

A new DFARS class deviation is making the rounds, and it's easy to misread as CMMC enforcement getting delayed to November 2028. It didn't - here's what Revision 3 actually changed, and why your CMMC timeline hasn't moved.

Risk Level

Read Time

The Department of War (DoW) issued Revision 3 of the class deviation implementing the Revolutionary FAR Overhaul's Part 40 and its DFARS companion, Part 240. It's a 71-page document, effective immediately, and page 16 is easy to misread as CMMC enforcement getting pushed back to November 2028. It doesn't say that, and if your organization is reading it that way, it's worth clearing up before it changes how you plan for CMMC.

“Ok, so what actually changed in Revision 3?”

Every page of the deviation carries the same note in the header: changes are marked with a change bar in the right-hand margin. That makes it easy to see exactly what Revision 3 touched, and none of it is CMMC.

The change bars cluster around a handful of items. They correct the definitions of “Chinese military company” and “covered lobbyist.” That includes a temporary carve-out for Alibaba Group Holding Limited and Alibaba Group (U.S.) Inc. from both definitions, to comply with a federal court order. They add a brand-new section, 240.374, prohibiting contractors from transferring certain personal data on DoW employees to third parties. They also expand the list of covered foreign countries under the existing unmanned aircraft systems prohibition. Lastly, there's a handful of clause cross-reference corrections scattered through the attachments.

That's the entire scope of Revision 3. Section 240.371, the part of DFARS Part 240 that governs CMMC, doesn't have a single change bar next to it. That holds from the definitions section through the solicitation clause requirements. Revision 3 didn't touch it.

“Then why does page 16 read like CMMC got delayed?”

Page 16 lays out when contracting officers have to insert the CMMC clause, 252.204-7021, into a solicitation. It reads:

“...until November 9, 2028...if the program office or requiring activity determines that the contractor is required to have a specific CMMC Level.”

“...on or after November 10, 2028...if the program office or requiring activity determines that the contractor is required to use contractor information systems in performance of a contract, task order, or delivery order to process, store, or transmit FCI or CUI.”

Neither paragraph has a change bar next to it. That's the tell: this is the exact language that's been in the DFARS clause prescription all along, carried forward untouched. Revision 3 isn't announcing a new CMMC timeline. It's reprinting the phased rollout that's already in effect today.

Today, and until November 9, 2028, a program office or requiring activity can decide, contract by contract, that a specific CMMC level is required. If they decide it is, the clause goes in. Starting November 10, 2028, that determination stops being optional: if the contractor's information systems will process, store, or transmit FCI or CUI in performance of the contract, the clause goes in automatically. November 2028 isn't when CMMC starts. It's when the requirement stops depending on a program office's discretion and applies across the board.

“So what does this mean for my CMMC timeline?”

Nothing about it has moved. Program offices can require CMMC today, and plenty of them already do. You may remember in another ACT post that the DoW separately paused the CMMC Phase 2 milestone while a task force reviews the program. That pause is a different action entirely, and Revision 3 doesn't touch it either. It's mentioned again on page 2 of this deviation, exactly as it stood before.

If your organization is treating November 2028 as a deadline to start CMMC preparation, that's the risk here. A solicitation asking for a specific CMMC level can show up in your inbox well before then. And by the time 2028 arrives, it applies to every contract touching FCI or CUI, regardless of whether a program office singled it out. Waiting is a bet against your own contracting officers making that call sooner.

If a memo like this one crosses your desk, don’t assume it changes your compliance posture. Confirm it before you act. 


Ready to find out where your organization stands?


 

Follow us - stay ahead.

Next
Next

The AI Test That Broke Its Own Rules