
DoD Class Deviation Ends Self-Attestation
This episode breaks down the end of contractor self-attestation under the 2026 DoD class deviation, explaining how government-led assessments now replace SPRS-based assumptions. It also tackles the subcontracting fallout, showing why primes must verify data scope and flowdowns before pushing CMMC requirements onto lower-tier suppliers.
Chapter 1
The Death of Self Attestation Under Class Deviation 2026 O0025
Eric Marquette
Wait, so on February 1st of 2026, when the Department of Defense issued Class Deviation 2026 O0025 under the Revolutionary FAR Overhaul, a lot of contractors thought it was just, you know, administrative cleanup. Like shifting numbers around on a spreadsheet.
Paul Netopski
Yeah, and, and, and that assumption is flat out dangerous. Firsthand testimony, not commentary here. People saw FAR 52.204 21 move to FAR 52.240 93, or DFARS 252.204 7020 become DFARS 252.240 7997, and they figured, okay, paper shuffle. But they missed the main event. DFARS 252.204 7019 was completely eliminated. The contractor basic self assessment is dead.
Eric Marquette
Wait, wait, it is gone? So the self reported score you just type into the Supplier Performance Risk System, SPRS, that doesn't count as a basic assessment anymore?
Paul Netopski
The term basic assessment does not even exist in the text of 252.240 7997. The DoD erased it. Now, the clause only defines two things: Medium Assessments and High Assessments. Both of them are government led, using NIST SP 800 171A procedures. The government isn't taking your word for it on paper anymore. They wrote direct validation authority straight into the contract clause.
Eric Marquette
I was talking to a mid tier defense supplier last week, and they were, uh, they were totally convinced that as long as they had a positive score sitting in SPRS, they were safe from anyone knocking on their door until full CMMC rolled around. They thought the SPRS score was an umbrella.
Paul Netopski
It is not an umbrella, it never was. CMMC dictates your eligibility for certification, but DFARS 252.240 7997 dictates contract enforcement authority right now. The second that clause hits a solicitation or flowdown, the Defense Contract Management Agency or DIBCAC has full legal standing to walk into your physical facility, inspect your server room, and interrogate your staff on your System Security Plan.
Eric Marquette
So if an auditor walks in, what are they actually looking at? Is it mostly technical IT setups, or...
Paul Netopski
Look, compliance labor in the defense industrial base is always 75% documentation and 25% technical controls. Always. You can have the best firewalls on the planet, but if your System Security Plan doesn't match operational reality, or if your policies are aspirational templates you bought online, a Medium or High assessment will tear you to shreds. They validate evidence, not promises.
Chapter 2
Mandatory Flowdowns CMMC Enforcement and the Subcontract Trap
Eric Marquette
That brings up a massive issue I am seeing everywhere right now. Prime contractors are seeing these new clause numbers and panic flowing them down. I am hearing about tier three machine shops, guys making simple metal brackets, getting emails from primes saying they need full CMMC Level 2 and a third party C3PAO assessment or they lose the contract.
Paul Netopski
It is a complete operational breakdown, and it comes down to one fundamental problem: scope is being driven by the marking, not by the information. Prime contracting officers are taking routine Federal Contract Information, basic specifications for a bolt, automatedly tagging it as Controlled Unclassified Information, and dumping CUI requirements on companies that shouldn't touch CUI at all.
Eric Marquette
So because an email header got auto tagged with CUI, a small five person machine shop is suddenly expected to drop fifty thousand dollars on NIST SP 800 171 implementation?
Paul Netopski
Exactly. And it is crushing the lower tiers of the supply chain. What primes need to do, and what we teach, is the CDI Determination Workflow. You have to follow the actual data flow, step by step, across people, technology, and locations. Is this data Federal Contract Information, or is it actual Covered Defense Information? If it is just FCI, the flowdown is FAR 52.240 93, fifteen basic safeguarding controls. You don't need a C3PAO, you don't need a 110 control audit, you just need the brilliant basics.
Eric Marquette
So instead of just blindly forwarding every DFARS clause down to every sub, procurement teams actually have to audit what data they are handing over.
Paul Netopski
If they don't, they are going to lock out their own critical suppliers before award gates hit. Right now, every defense contractor needs to perform an immediate crosswalk of their internal clause matrices. Map your legacy 7020 references to 252.240 7997, clean up your contract flowdowns, and verify your actual data markings today. Because when the government comes to validate, paper promises won't save your contract.