---
title: "Tag: CMMC"
description: "11 blog entries tagged CMMC, newest first, each with sealed and amended dates."
url: https://policycortex.com/blog/tags/cmmc
sealed: 2025-11-20
amended: 2026-07-13
register: blog/tags/cmmc
records: 3
digest: sha3:68e39160624b8d1901ad205cd1834fa89675431b5c53b706f77ce5b32bd0b4e2
---

# Blog entries tagged CMMC

Register / Blog / Tag: CMMC

Every blog entry tagged CMMC, newest first. Tags group the register by subject so a reader working one requirement can follow it across entries as the rules change. Each entry is sealed on the date shown and amended in place when it is updated; the full register is at the blog index.

11 entries · Latest sealed 2026-07-13

## Entries, newest first

| Sealed | Entry | Reading |
|---|---|---|
| 2026-07-13 | [CMMC Phase II Is Suspended: What Defense Contractors Still Have to Do](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now): The Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place. | 7 min |
| 2026-07-01 | [The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act Evidence](https://policycortex.com/blog/logzone-false-claims-act-sprs-score): DOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment. | 9 min |
| 2026-06-29 | [The C3PAO Capacity Math After the CMMC Phase II Suspension](https://policycortex.com/blog/c3pao-backlog-2026-cmmc-work-back-schedule): The Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans. | 10 min |
| 2026-03-17 | [CMMC Level 2 Requirements in 2026: The Complete Guide for Defense Contractors](https://policycortex.com/blog/cmmc-level-2-requirements-2026-complete-guide): CMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active. | 14 min |
| 2026-03-17 | [The Safety Sandwich: How PolicyCortex Gives AI Safe Write Access to Cloud Environments](https://policycortex.com/blog/safety-sandwich-ai-cloud-access): Giving AI autonomous write access to production cloud environments sounds dangerous. | 9 min |
| 2026-03-10 | [CMMC Level 2 Compliance Costs: The Complete Breakdown for 2026](https://policycortex.com/blog/cmmc-compliance-cost): Most defense contractors budget for the C3PAO assessment and forget about everything else. | 10 min |
| 2026-03-10 | [NIST 800-171 Cloud Compliance: The Practical Guide for AWS, Azure, and GCP](https://policycortex.com/blog/nist-800-171-cloud-compliance-guide): Implementing NIST 800-171 in cloud environments is fundamentally different from on-premises. | 12 min |
| 2026-03-04 | [The Alert Queue That Never Empties: Why CSPM Visibility Isn't Enough](https://policycortex.com/blog/cloud-alerts-vs-remediation): Your CSPM tool is finding everything. Your queue is growing anyway. | 8 min |
| 2026-03-03 | [CMMC Phase II Timeline Suspended: What the 60-Day Review Changes](https://policycortex.com/blog/cmmc-phase-2-timeline-defense-contractors): The Department of War suspended the November 2026 Phase II transition and future milestones. | 10 min |
| 2026-02-18 | [The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)](https://policycortex.com/blog/cmmc-level-2-self-assessment): Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk. | 9 min |
| 2025-11-20 | [CMMC 2.0: What Defense Contractors Need to Know](https://policycortex.com/blog/cmmc-2-what-defense-contractors-need-to-know): The CMMC program is officially active with assessments underway. | 2 min |

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Read the entries. Then verify the record they describe. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 238e488f53ab | 126cfbf35b46 |
| REC 0001 | ENTRIES | 016dc35e1230 | 238e488f53ab |
| REC 0002 | RELATED RECORDS | 68e39160624b | 016dc35e1230 |

Head sha3:68e39160624b8d1901ad205cd1834fa89675431b5c53b706f77ce5b32bd0b4e2. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
