POLICY UPDATE // JUL 13, 2026

CMMC Phase II is suspended. The security baseline is not.

The Department of War paused the November Phase II transition while it runs a 60-day reform review. Phase I self-assessments remain in force, and contractors handling covered defense information still have to meet their DFARS safeguarding obligations.

PHASE II
SUSPENDED
Transition and future milestones paused
PHASE I
ACTIVE
Self-assessment requirements remain
CONTRACT DUTY
DFARS 7012
Covered defense information still protected
INTERIM BASELINE
NIST REV. 2
110 requirements · government checks continue
SOLUTIONS // CMMC COMPLIANCE

Defensible now. Ready for what follows.

CMMC Phase II is suspended, but Phase I self-assessments and DFARS 252.204-7012 remain. PolicyCortex validates your live cloud against all 110 NIST SP 800-171 Rev. 2 requirements, closes technical gaps, and produces the evidence behind your SPRS score — while preserving a clean handoff for any future CMMC assessment.

Current PolicyCortex compliance workspace showing framework posture and prioritized policy findings in the production demo tenant
Current product · /governance/compliance · demo tenant
MISSION READINESS
PHASE II
SUSPENDED
TRACKED
REV. 2
110 / 110
MAPPED
OUTPUT
SSP · POAM · OSCAL
AUTO
ENGAGEMENT
30 DAYS
FIXED
CMMC PHASE II // SUSPENDEDAnnounced 2026-07-13Scope: Phase I self-assessments + DFARS safeguards remain active
LIVE OPS // SAMPLE TENANT
STREAM
14:22:09okremediation.applied target=storage/cui-archive control=AC-3 action=disable-public
14:22:11infocmmc.evidence.captured control=AC-2(7) status=PASS hash=4b3a…ce19
14:22:14warndrift.detected resource=vnet/prod-east severity=HIGH cui-scope=YES
14:22:15okremediation.applied target=vnet/prod-east action=tighten-nsg gates=3/3
14:22:18infossp.section.regenerated family=AC controls=22 format=docx
14:22:21okpoam.closed item=POAM-0118 closure-evidence=auto retention=7y
CAPABILITIES
  1. CAP-01
    110 requirements baselinedNIST SP 800-171 Rev. 2 — the interim baseline named by DoW.
  2. CAP-02
    Drift < 5sContinuous validation, not point-in-time scans.
  3. CAP-03
    C3PAO handoff packageSSP · POA&M · OSCAL · auditor ZIP, organized by control objective.
  4. CAP-04
    CUI boundary awareScope auto-derived. GovCloud + GCC High native.
  5. CAP-05
    Auto-remediationRollback contract on every action. Type-checked.
  6. CAP-06
    Cleared founder engagementDoD Secret + DoE Q. Runs the pilot personally.
OPERATIONS · 30-DAY PILOT
  1. 01
    ConnectAzure Government · AWS GovCloud · GCC High. Discovery in minutes.
  2. 02
    BaselineAll 110 controls validated. Findings with AI confidence.
  3. 03
    Hand offOSCAL bundle + auditor ZIP your C3PAO can review, select from, and use for eMASS submission.
FIELD-TESTED · FOUNDER OPERATED AT
  1. DOE National LabActive consultant
  2. MITRECybersecurity engineering
  3. USAAFinancial-grade ops
  4. FrontierProduction cloud architecture
CLEARANCES · PATENTS
DoD SECRETDoE Q

Founder runs every engagement personally. 4 U.S. patent applications filed.

FAQ

Did the Department of War cancel CMMC?

No. On July 13, 2026, the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. All Phase I self-assessment requirements remain in place.

What remains enforceable during the pause?

The Department says NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments. DFARS 252.204-7012 safeguarding obligations also remain contractually binding.

L2 vs L3 — which do we need?

Most contractors need L2 (handles CUI). L3 is required for organizations supporting high-priority programs. PolicyCortex covers both with the same engine.

What does the $15K pilot include?

Full CMMC L2 baseline, automated gap closure, SSP, POA&M, C3PAO-ready evidence bundle (OSCAL + ZIP), CUI boundary analysis, 30-day platform access, final readiness review with the founder. Flat fee — no overages.

Does PolicyCortex submit to CMMC eMASS?

No. Your C3PAO controls the official assessment package and eMASS submission. PolicyCortex prepares the control-mapped evidence, remediation history, SSP, POA&M, OSCAL bundle, and audit ZIP so the assessor can review, select, and submit with less manual cleanup.

Can we use a different C3PAO?

Yes. PolicyCortex output is C3PAO-agnostic — the OSCAL package and audit ZIP work with any C3PAO. We don't lock you to an assessor.

What about CMMC 2.0 vs 3.0?

Current CMMC final rule (32 CFR Part 170) defines 3 maturity levels. We support L1 (self-attestation), L2 (C3PAO assessment), L3 (DIBCAC assessment). Future revisions tracked automatically.

PROCUREMENT · NEXT STEP

Know what you can defend. $15K flat.

Connect a cloud account, validate the 110-requirement baseline, close technical gaps, and walk away with the evidence behind your SPRS score. Cleared founder runs the engagement.