Register:Blog3 recordsSHA3-256 chainedhead sha3:665333c8169d4982f4586d02c66887f82f528fbea6c0c89da57e756096af8a43Intact
REC 0001BODYsha3-256c11af0cba690553a80f4d6e601df8d54b6286186c53a2b79003a04655c648093prev:d74ec839a241

The Clock Stopped on July 13, 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements and the pending and future implementation milestones that followed them. The planned November 10 transition is no longer the current government-wide deadline.

The release did not end CMMC or contractor cybersecurity duties. It kept all Phase I self-assessment requirements in place, named NIST SP 800-171 Rev. 2 as the interim enforcement baseline, preserved selected government-led assessments, and explicitly reaffirmed DFARS 252.204-7012.

The Current Timeline

  • November 10, 2025: Phase I began.
  • July 13, 2026: The Department suspended Phase II and pending and future implementation milestones.
  • Next 60 days: A CMMC Reform Task Force reviews the program and delivers recommendations to the Department CIO.
  • Public input: The Department says a public Request for Information will inform the review. The announcement does not include submission instructions or questions.
  • Replacement dates: None were announced in the July 13 release.

The prior Phase III and full-implementation dates should not be used as current planning anchors while future milestones are suspended.

What Still Drives Your Schedule

The absence of a government-wide Phase II date does not mean every contractor has the same amount of time. Your schedule can still be driven by:

  1. Clauses in a live solicitation or contract.
  2. A recompete or option exercise.
  3. A prime contractor's supplier review or flow-down.
  4. A selected government-led NIST assessment.
  5. An internal date for correcting or renewing the evidence behind an SPRS score.

Use the contract readiness planner to work backward from one of those dates. Add assessor lead time only when your actual path calls for it.

A Practical 60-Day Action Plan

1. Verify what applies

Inventory the relevant DFARS clauses, current solicitation language, prime direction, and dates already in writing. Do not assume the press release silently rewrote an existing instrument.

2. Revalidate the CUI boundary and SPRS score

Map every system that stores, processes, or transmits CUI. Recalculate the Rev. 2 score from current technical state and current evidence, not from the last spreadsheet.

3. Fix the operational basics

Prioritize identity, asset inventory, segmentation, logging, risk-based vulnerability management, backup, and continuous monitoring. Those areas match the Department's stated shift toward scalable, resilient security.

4. Keep the evidence current

Update the SSP, POA&M, control evidence, remediation history, and rollback records as the environment changes. The same package supports Phase I, government review, prime oversight, and a future CMMC model.

5. Prepare to respond to the RFI

Document which requirements materially reduce risk, which activities create cost without changing security, and where automation lowers burden. Submit only after the Department publishes official questions and instructions.

What to Do With a Scheduled C3PAO Assessment

Do not cancel or accelerate automatically. Ask what requirement the assessment serves, whether a live contract or prime still calls for it, what the cancellation terms are, and whether a later slot preserves value while the reform details emerge.

Technical remediation remains useful either way. Assessment spend should now follow actual contractual and business risk rather than a suspended government-wide date.

How PolicyCortex Compresses the Work That Still Matters

PolicyCortex:

  • Continuously validates the 110 NIST SP 800-171 Rev. 2 requirements against live cloud state.
  • Auto-collects evidence by requirement instead of relying on one-time screenshots.
  • Detects and remediates drift with gated, rollback-safe actions.
  • Generates SSP and POA&M updates from the technical implementation.
  • Preserves an assessment-ready package for selected government reviews and whatever model follows the reform.

The November clock is gone. The need to know what is actually true before you represent a score is not.


Take the free CMMC Readiness Assessment to see where you stand, or book a 15-minute demo to see PolicyCortex in action.

Questions on this record
When does CMMC Phase 2 start?
There is no current replacement start date. On July 13, 2026, the Department of War suspended the planned November 10 Phase II transition and pending and future CMMC implementation milestones while it conducts a 60-day review.
What happens on November 10, 2026?
November 10 is no longer the current government-wide Phase II transition date. Contractors should check the clauses in each solicitation and contract and confirm any prime-specific requirements rather than planning from the suspended milestone.
Is the November 2026 CMMC deadline a hard deadline for everyone?
No. The Department suspended that Phase II transition date. A solicitation, existing contract, recompete, or prime supplier review may still create a separate requirement, so contractors should verify the instrument that actually applies to them.
How long does it take to get CMMC certified?
Timelines depend on scope, remediation work, evidence quality, and assessor availability. During the Phase II pause, plan backward from an actual contract, prime, or internal target instead of a government-wide November date.
REC 0002RELATED RECORDSsha3-256665333c8169d4982f4586d02c66887f82f528fbea6c0c89da57e756096af8a43prev:c11af0cba690

Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

proof.state
Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
proof.change
Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
proof.agency
Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
architecture
Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Further reading in this register

Verify the record this entry describes.

Sealed
Last amended
Author
PolicyCortex Team
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000HEADd74ec839a24192a2e0217d62
REC 0001BODYc11af0cba690d74ec839a241
REC 0002RELATED RECORDS665333c8169dc11af0cba690

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:665333c8169d. The product does the same thing to your evidence.