The November 10 date changed
On July 13, 2026, the Department of War announced the suspension of CMMC Phase II, previously scheduled for November 10, 2026. Its current CMMC program page still describes that suspension as of this article's review date. An older rollout slide or a saved calendar reminder can therefore point to an outdated milestone.
This article reports the announced suspension. It does not announce a replacement start date or treat possible reforms as effective requirements. Recheck the official program page before acting on a future rollout date.
Read the amendment, as well as the announcement
The implementation memorandum and its attachment direct requiring activities to use Level 1 (Self) or Level 2 (Self) during the suspension. They also direct amendments to active solicitations with Level 2 (C3PAO) or Level 3 (DIBCAC) requirements, and removal of those requirements from existing contracts through modification before the next option exercise or during the next scheduled administrative modification.
The attachment says DFARS 252.204-7012 cybersecurity requirements remain in effect. It describes Level 1 safeguarding of Federal Contract Information and Level 2 alignment with NIST SP 800-171 Revision 2. The rollout pause is therefore a reason to review the applicable paperwork carefully.
For a specific award or subcontract, ask your contracting officer, prime contractor, or qualified adviser to resolve any mismatch between an announcement and your actual terms. Record the amendment or modification received and its effective date. Avoid marking an existing obligation complete solely because a general news headline changed.
Assessment and affirmation dates have different clocks
Where DFARS 252.204-7021 applies, the clause requires annual affirmation of continuous compliance in the Supplier Performance Risk System (SPRS). Its definition of current Final Level 1 (Self) status uses a one-year assessment age; Final Level 2 (Self) uses a three-year assessment age, with an affirmation no older than one year. Both include continuing-compliance conditions. Conditional status has separate requirements.
Keep the applicable assessment date and annual affirmation date as separate records. Confirm them in the official record for each relevant system with the responsible security lead and affirming official. A three-year assessment cycle does not make the associated affirmation a three-year task. A calendar reminder alone cannot establish compliance.
A practical October calendar review
The following is an organizational checklist, not a determination of your legal or cybersecurity obligations. Use it with the person responsible for interpreting your contracts.
- Find the source of each entry. Search calendars and task lists for CMMC, November 10, assessments, affirmations, and option periods. Separate a general rollout milestone from an actual contract date.
- Preserve the history. Label an old Phase II rollout reminder as suspended and retain the public source and review date. Assign someone to check official updates; do not invent a new effective date.
- Review each active opportunity. Check the current public solicitation and every amendment. Keep a pending question open until the responsible person has verified what applies.
- Separate the next actions. Track the policy-status review, contract-modification follow-up, assessment review, and affirmation preparation individually. An unresolved contract question should remain visible.
- Choose preparation reminders. Set internal lead times that leave room for document review and the authorized official's work. Label these as internal targets so they cannot be mistaken for government deadlines.
- Close with evidence. After the responsible official completes the required action, record completion in the appropriate approved system and verify the next applicable date. Keep an independent reminder for critical obligations.
Keep controlled information in approved systems
Do not upload CUI, FCI, export-controlled material, credentials, vulnerability details, system security plans, or other sensitive security evidence to Deadline Shield. Use public documents or non-sensitive administrative reminders only, consistent with your organization's policy. Keep restricted records and submission evidence in your approved environment.
Deadline Shield is not a CMMC assessment provider or a compliance certification service. This guide makes no claim that Deadline Shield is authorized to process controlled government information. It does not submit assessments or affirmations to SPRS.
Where Deadline Shield can help
For suitable public documents and ordinary business paperwork, Deadline Shield can suggest possible dates and show supporting source text. You review and approve findings before they become tracked items. You can also enter a verified, non-sensitive reminder manually. Operations adds team assignment and management visibility.
AI can miss dates or misread conditions. A document may still contain the old rollout date, so compare any suggestion with current official guidance before approving it. Deadline Shield does not automatically determine which rule governs your contract or change your dates when an agency issues new guidance.
Read the government-contractor workflow, contract deadline tracking guide, and Security Center. For team accountability, see Operations and current pricing.
Common questions
Can we delete all CMMC reminders?
Review them separately. The official notice preserves Phase I requirements, and your applicable contract, assessment, and affirmation records need their own review.
Does a reminder prove we met the requirement?
No. The authorized person must carry out and verify the required action in the appropriate system. Tracking a task is only administrative support.
General organizational information only; not legal, procurement, or cybersecurity advice. Requirements depend on the applicable contract and current official guidance. Deadline Shield is not affiliated with or endorsed by the United States Government.