POLICY UPDATE // JUL 13, 2026

CMMC Phase II is suspended. The security baseline is not.

The Department of War paused the November Phase II transition while it runs a 60-day reform review. Phase I self-assessments remain in force, and contractors handling covered defense information still have to meet their DFARS safeguarding obligations.

PHASE II
SUSPENDED
Transition and future milestones paused
PHASE I
ACTIVE
Self-assessment requirements remain
CONTRACT DUTY
DFARS 7012
Covered defense information still protected
INTERIM BASELINE
NIST REV. 2
110 requirements · government checks continue
INSIGHTS // C3PAO

The C3PAO Capacity Math After the CMMC Phase II Suspension

BY POLICYCORTEX TEAM·PUB Jun 29, 2026·UPD Jul 13, 2026· 10 MIN· C3PAO CMMC backlog CMMC assessment scheduling defense contractors

The Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans. Here is how to use the dated 2026 market snapshot without planning from a suspended milestone.

July 13, 2026 update: The Department of War suspended the Phase II transition and pending and future implementation milestones. The numbers below are a dated May 2026 capacity snapshot, not a reason to plan against November 10 as a current deadline.

The Numbers, As of the Latest Cyber AB Town Hall

Every month the Cyber AB publishes ecosystem numbers at its Town Hall. The May 2026 figures show the assessment ecosystem immediately before the Phase II suspension:

MetricNumberSource
Organizations needing L2 C3PAO certification (DoD estimate)76,59832 CFR Part 170 rulemaking analysis
Final Level 2 certifications issued1,391 (+14% month-over-month)May 2026 Cyber AB Town Hall
Conditional Level 2 certifications47May 2026 Cyber AB Town Hall
Assessments in progress~140May 2026 Cyber AB Town Hall
Authorized C3PAOs~100–103Cyber AB Marketplace, March 2026
New certifications per month (recent pace)~178March 2026 Town Hall data
Typical C3PAO booking lead time6–9 monthsAssessor and industry reporting, mid-2026

The snapshot showed why the Department viewed cost and scalability as program-level problems. It should not be extrapolated as a current demand forecast after the suspension; assessment demand, authorizations, and policy may change during the reform review.

What the Suspension Changes

Precision matters here, because both the panic version and the “nothing applies” version are wrong.

What paused: The Department suspended the November Phase II transition and pending and future CMMC implementation milestones while a task force conducts a 60-day review.

What remains: Phase I self-assessment requirements, NIST SP 800-171 Rev. 2 enforcement through self-assessments and selected government reviews, and DFARS 252.204-7012 safeguarding obligations.

What may still create a date: A live solicitation, existing contract, recompete, planned voluntary assessment, or prime supplier requirement. Get that requirement in writing and plan from it.

Replace the Phase Date With a Real Target

The former day-one work-back schedule is no longer current. A useful schedule now begins with the date and assessment path that actually apply to your business:

MilestonePlan fromWhy
Confirm contract / prime requirementNowEstablish whether a third-party assessment is actually required
Validate CUI boundary and Rev. 2 scoreTarget date minus scope timeDetermines remediation and evidence scope
Remediation completeBefore evidence freezeLive technical state must match the claimed score
SSP + evidence package currentBefore review or assessmentStale documentation creates an avoidable mismatch
C3PAO assessmentOnly when applicableUse a current assessor quote, not a pre-suspension market average
SPRS / contract deliverableActual required dateFollow the solicitation, contract, or prime instruction

Re-plan around three facts:

  1. Technical remediation survives the policy change. Closing real security gaps remains useful under Phase I, government review, and any revised model.
  2. Assessment spend should follow an actual requirement. A pre-suspension booking assumption is not a substitute for contract analysis.
  3. Evidence still decays. Keep the SSP and control evidence synchronized with the environment even if a third-party assessment moves.

Use the free CMMC contract readiness planner with your own contract, prime, or internal date. C3PAO lead time is optional.

Where the Months Actually Go (and How to Get Them Back)

Across the DIB, the 12–18 month typical timeline breaks down roughly like this: scoping and gap assessment (1–2 months), remediation (4–8 months), documentation and evidence (2–4 months), then the assessment queue. The queue is fixed. The middle two phases are not.

The documentation and evidence phase is the most compressible — and the most commonly botched. Assessors consistently report that documentation gaps, not technical gaps, drive failed assessments: SSPs that don't match the live environment, evidence that's months stale, controls that are implemented but unprovable. Teams burn hundreds of hours screenshotting configurations by hand, and the output starts decaying the day it's collected.

This is the phase PolicyCortex collapses. The platform continuously maps your actual cloud environment against all 110 NIST 800-171 controls, remediates drift autonomously, and emits assessor-ready evidence as a byproduct of operation — so the SSP and evidence bundle reflect the environment as it is, not as it was last quarter. The 30-day CMMC pilot ($15,000 flat) takes a contractor from unknown posture to a C3PAO-ready OSCAL evidence bundle inside one month, which is the difference between booking your assessment with confidence and booking it on hope.

The Bottom Line

  • 1,391 of 76,598 required certifications exist. The ecosystem certifies ~178 companies a month.
  • The pre-suspension 6–9 month lead-time range is a dated market snapshot, not a current scheduling promise.
  • The government-wide November Phase II date is suspended.
  • Your real planning date comes from a contract, solicitation, prime instruction, selected government review, or internal assurance target.

Start with the free readiness assessment to locate your gaps, price the effort with the cost calculator, and run the date that actually applies through the contract readiness planner.

FREQUENTLY ASKED
How long is the C3PAO wait time in 2026?
Before the July 13 Phase II suspension, industry reports commonly cited 6–9 month booking lead times. Demand and schedules may change during the reform review, so contractors should get a current quote from a selected C3PAO instead of treating the pre-suspension range as a live guarantee.
How many defense contractors are CMMC certified?
As of the May 2026 Cyber AB Town Hall, 1,391 organizations held final Level 2 certifications — under 2% of the roughly 76,598 that DoD estimates will need it. The ecosystem is certifying about 178 companies per month, which is why full DIB coverage is not projected before 2029 at the current pace.
Do I still need CMMC certification by November 2026?
There is no current government-wide Phase II certification deadline on November 10. The Department suspended that transition on July 13, 2026. Check the clauses in your actual solicitation or contract and confirm any prime-specific requirement in writing.
What is the CMMC work-back schedule?
Working backward from a target date: certification and SPRS affirmation must post by the deadline; the C3PAO assessment happens when both your slot arrives and prep is complete; before that comes a readiness review, then SSP and evidence, then remediation (12–16 weeks typical), then scoping and gap assessment. Use a work-back calculator to map these milestones against your own dates and current wait times.
READY TO AUTOMATE?

Replace 4 tools with one platform.

See how PolicyCortex consolidates compliance, security, AI governance, and cost — autonomously.