POLICY UPDATE // JUL 13, 2026

CMMC Phase II is suspended. The security baseline is not.

The Department of War paused the November Phase II transition while it runs a 60-day reform review. Phase I self-assessments remain in force, and contractors handling covered defense information still have to meet their DFARS safeguarding obligations.

PHASE II
SUSPENDED
Transition and future milestones paused
PHASE I
ACTIVE
Self-assessment requirements remain
CONTRACT DUTY
DFARS 7012
Covered defense information still protected
INTERIM BASELINE
NIST REV. 2
110 requirements · government checks continue
INSIGHTS // CMMC

CMMC Phase II Timeline Suspended: What the 60-Day Review Changes

BY POLICYCORTEX TEAM·PUB Mar 3, 2026·UPD Jul 13, 2026· 10 MIN· CMMC Phase 2 timeline defense contractors certification 2026

The Department of War suspended the November 2026 Phase II transition and future milestones. Here is the current timeline, what remains active, and what contractors should do during the review.

The Clock Stopped on July 13, 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements and the pending and future implementation milestones that followed them. The planned November 10 transition is no longer the current government-wide deadline.

The release did not end CMMC or contractor cybersecurity duties. It kept all Phase I self-assessment requirements in place, named NIST SP 800-171 Rev. 2 as the interim enforcement baseline, preserved selected government-led assessments, and explicitly reaffirmed DFARS 252.204-7012.

The Current Timeline

  • November 10, 2025: Phase I began.
  • July 13, 2026: The Department suspended Phase II and pending and future implementation milestones.
  • Next 60 days: A CMMC Reform Task Force reviews the program and delivers recommendations to the Department CIO.
  • Public input: The Department says a public Request for Information will inform the review. The announcement does not include submission instructions or questions.
  • Replacement dates: None were announced in the July 13 release.

The prior Phase III and full-implementation dates should not be used as current planning anchors while future milestones are suspended.

What Still Drives Your Schedule

The absence of a government-wide Phase II date does not mean every contractor has the same amount of time. Your schedule can still be driven by:

  1. Clauses in a live solicitation or contract.
  2. A recompete or option exercise.
  3. A prime contractor's supplier review or flow-down.
  4. A selected government-led NIST assessment.
  5. An internal date for correcting or renewing the evidence behind an SPRS score.

Use the contract readiness planner to work backward from one of those dates. Add assessor lead time only when your actual path calls for it.

A Practical 60-Day Action Plan

1. Verify what applies

Inventory the relevant DFARS clauses, current solicitation language, prime direction, and dates already in writing. Do not assume the press release silently rewrote an existing instrument.

2. Revalidate the CUI boundary and SPRS score

Map every system that stores, processes, or transmits CUI. Recalculate the Rev. 2 score from current technical state and current evidence, not from the last spreadsheet.

3. Fix the operational basics

Prioritize identity, asset inventory, segmentation, logging, risk-based vulnerability management, backup, and continuous monitoring. Those areas match the Department's stated shift toward scalable, resilient security.

4. Keep the evidence current

Update the SSP, POA&M, control evidence, remediation history, and rollback records as the environment changes. The same package supports Phase I, government review, prime oversight, and a future CMMC model.

5. Prepare to respond to the RFI

Document which requirements materially reduce risk, which activities create cost without changing security, and where automation lowers burden. Submit only after the Department publishes official questions and instructions.

What to Do With a Scheduled C3PAO Assessment

Do not cancel or accelerate automatically. Ask what requirement the assessment serves, whether a live contract or prime still calls for it, what the cancellation terms are, and whether a later slot preserves value while the reform details emerge.

Technical remediation remains useful either way. Assessment spend should now follow actual contractual and business risk rather than a suspended government-wide date.

How PolicyCortex Compresses the Work That Still Matters

PolicyCortex:

  • Continuously validates the 110 NIST SP 800-171 Rev. 2 requirements against live cloud state.
  • Auto-collects evidence by requirement instead of relying on one-time screenshots.
  • Detects and remediates drift with gated, rollback-safe actions.
  • Generates SSP and POA&M updates from the technical implementation.
  • Preserves an assessment-ready package for selected government reviews and whatever model follows the reform.

The November clock is gone. The need to know what is actually true before you represent a score is not.

Take the free CMMC Readiness Assessment to see where you stand, or book a 15-minute demo to see PolicyCortex in action.

FREQUENTLY ASKED
When does CMMC Phase 2 start?
There is no current replacement start date. On July 13, 2026, the Department of War suspended the planned November 10 Phase II transition and pending and future CMMC implementation milestones while it conducts a 60-day review.
What happens on November 10, 2026?
November 10 is no longer the current government-wide Phase II transition date. Contractors should check the clauses in each solicitation and contract and confirm any prime-specific requirements rather than planning from the suspended milestone.
Is the November 2026 CMMC deadline a hard deadline for everyone?
No. The Department suspended that Phase II transition date. A solicitation, existing contract, recompete, or prime supplier review may still create a separate requirement, so contractors should verify the instrument that actually applies to them.
How long does it take to get CMMC certified?
Timelines depend on scope, remediation work, evidence quality, and assessor availability. During the Phase II pause, plan backward from an actual contract, prime, or internal target instead of a government-wide November date.
READY TO AUTOMATE?

Replace 4 tools with one platform.

See how PolicyCortex consolidates compliance, security, AI governance, and cost — autonomously.