Register:Blog3 recordsSHA3-256 chainedhead sha3:6f0140d4ec22a5f0bcfaf895865efa35a3720d7ddcfd3abf5da5334add9029ebIntact
REC 0001BODYsha3-256ea0f120d1e654f78fafec6f73a0c73cc7f401370497711b65b74f96462cf5204prev:bd98bbeaa03c

July 13, 2026 update: The Department of War suspended the Phase II transition and pending and future implementation milestones. The numbers below are a dated May 2026 capacity snapshot, not a reason to plan against November 10 as a current deadline.

The Numbers, As of the Latest Cyber AB Town Hall

Every month the Cyber AB publishes ecosystem numbers at its Town Hall. The May 2026 figures show the assessment ecosystem immediately before the Phase II suspension:

MetricNumberSource
Organizations needing L2 C3PAO certification (DoD estimate)76,59832 CFR Part 170 rulemaking analysis
Final Level 2 certifications issued1,391 (+14% month-over-month)May 2026 Cyber AB Town Hall
Conditional Level 2 certifications47May 2026 Cyber AB Town Hall
Assessments in progress~140May 2026 Cyber AB Town Hall
Authorized C3PAOs~100–103Cyber AB Marketplace, March 2026
New certifications per month (recent pace)~178March 2026 Town Hall data
Typical C3PAO booking lead time6–9 monthsAssessor and industry reporting, mid-2026

The snapshot showed why the Department viewed cost and scalability as program-level problems. It should not be extrapolated as a current demand forecast after the suspension; assessment demand, authorizations, and policy may change during the reform review.

What the Suspension Changes

Precision matters here, because both the panic version and the “nothing applies” version are wrong.

What paused: The Department suspended the November Phase II transition and pending and future CMMC implementation milestones while a task force conducts a 60-day review.

What remains: Phase I self-assessment requirements, NIST SP 800-171 Rev. 2 enforcement through self-assessments and selected government reviews, and DFARS 252.204-7012 safeguarding obligations.

What may still create a date: A live solicitation, existing contract, recompete, planned voluntary assessment, or prime supplier requirement. Get that requirement in writing and plan from it.

Replace the Phase Date With a Real Target

The former day-one work-back schedule is no longer current. A useful schedule now begins with the date and assessment path that actually apply to your business:

MilestonePlan fromWhy
Confirm contract / prime requirementNowEstablish whether a third-party assessment is actually required
Validate CUI boundary and Rev. 2 scoreTarget date minus scope timeDetermines remediation and evidence scope
Remediation completeBefore evidence freezeLive technical state must match the claimed score
SSP + evidence package currentBefore review or assessmentStale documentation creates an avoidable mismatch
C3PAO assessmentOnly when applicableUse a current assessor quote, not a pre-suspension market average
SPRS / contract deliverableActual required dateFollow the solicitation, contract, or prime instruction

Re-plan around three facts:

  1. Technical remediation survives the policy change. Closing real security gaps remains useful under Phase I, government review, and any revised model.
  2. Assessment spend should follow an actual requirement. A pre-suspension booking assumption is not a substitute for contract analysis.
  3. Evidence still decays. Keep the SSP and control evidence synchronized with the environment even if a third-party assessment moves.

Use the free CMMC contract readiness planner with your own contract, prime, or internal date. C3PAO lead time is optional.

Where the Months Actually Go (and How to Get Them Back)

Across the DIB, the 12–18 month typical timeline breaks down roughly like this: scoping and gap assessment (1–2 months), remediation (4–8 months), documentation and evidence (2–4 months), then the assessment queue. The queue is fixed. The middle two phases are not.

The documentation and evidence phase is the most compressible — and the most commonly botched. Assessors consistently report that documentation gaps, not technical gaps, drive failed assessments: SSPs that don't match the live environment, evidence that's months stale, controls that are implemented but unprovable. Teams burn hundreds of hours screenshotting configurations by hand, and the output starts decaying the day it's collected.

This is the phase PolicyCortex collapses. The platform continuously maps your actual cloud environment against all 110 NIST 800-171 controls, remediates drift autonomously, and emits assessor-ready evidence as a byproduct of operation — so the SSP and evidence bundle reflect the environment as it is, not as it was last quarter. The 30-day CMMC pilot ($15,000 flat) takes a contractor from unknown posture to a C3PAO-ready OSCAL evidence bundle inside one month, which is the difference between booking your assessment with confidence and booking it on hope.

The Bottom Line

  • 1,391 of 76,598 required certifications exist. The ecosystem certifies ~178 companies a month.
  • The pre-suspension 6–9 month lead-time range is a dated market snapshot, not a current scheduling promise.
  • The government-wide November Phase II date is suspended.
  • Your real planning date comes from a contract, solicitation, prime instruction, selected government review, or internal assurance target.

Start with the free readiness assessment to locate your gaps, price the effort with the cost calculator, and run the date that actually applies through the contract readiness planner.

Questions on this record
How long is the C3PAO wait time in 2026?
Before the July 13 Phase II suspension, industry reports commonly cited 6–9 month booking lead times. Demand and schedules may change during the reform review, so contractors should get a current quote from a selected C3PAO instead of treating the pre-suspension range as a live guarantee.
How many defense contractors are CMMC certified?
As of the May 2026 Cyber AB Town Hall, 1,391 organizations held final Level 2 certifications — under 2% of the roughly 76,598 that DoD estimates will need it. The ecosystem is certifying about 178 companies per month, which is why full DIB coverage is not projected before 2029 at the current pace.
Do I still need CMMC certification by November 2026?
There is no current government-wide Phase II certification deadline on November 10. The Department suspended that transition on July 13, 2026. Check the clauses in your actual solicitation or contract and confirm any prime-specific requirement in writing.
What is the CMMC work-back schedule?
Working backward from a target date: certification and SPRS affirmation must post by the deadline; the C3PAO assessment happens when both your slot arrives and prep is complete; before that comes a readiness review, then SSP and evidence, then remediation (12–16 weeks typical), then scoping and gap assessment. Use a work-back calculator to map these milestones against your own dates and current wait times.
REC 0002RELATED RECORDSsha3-2566f0140d4ec22a5f0bcfaf895865efa35a3720d7ddcfd3abf5da5334add9029ebprev:ea0f120d1e65

Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

proof.state
Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
proof.change
Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
proof.agency
Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
architecture
Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Further reading in this register

Verify the record this entry describes.

Sealed
Last amended
Author
PolicyCortex Team
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000HEADbd98bbeaa03cdfa3a3085ff0
REC 0001BODYea0f120d1e65bd98bbeaa03c
REC 0002RELATED RECORDS6f0140d4ec22ea0f120d1e65

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:6f0140d4ec22. The product does the same thing to your evidence.