Skip to content
Deadline Shield
Home → Resources → CMMC deadline update
Deadline update · Reviewed October 1, 2026

CMMC Phase 2 suspended: which 2026 dates should you track?

The planned November 10, 2026 Phase II rollout is suspended. The official CMMC program page says Phase I self-assessment requirements remain in place. Check the source behind each calendar entry before changing it.

Read the official CMMC update

The November 10 date changed

On July 13, 2026, the Department of War announced the suspension of CMMC Phase II, previously scheduled for November 10, 2026. Its current CMMC program page still describes that suspension as of this article's review date. An older rollout slide or a saved calendar reminder can therefore point to an outdated milestone.

This article reports the announced suspension. It does not announce a replacement start date or treat possible reforms as effective requirements. Recheck the official program page before acting on a future rollout date.

Read the amendment, as well as the announcement

The implementation memorandum and its attachment direct requiring activities to use Level 1 (Self) or Level 2 (Self) during the suspension. They also direct amendments to active solicitations with Level 2 (C3PAO) or Level 3 (DIBCAC) requirements, and removal of those requirements from existing contracts through modification before the next option exercise or during the next scheduled administrative modification.

The attachment says DFARS 252.204-7012 cybersecurity requirements remain in effect. It describes Level 1 safeguarding of Federal Contract Information and Level 2 alignment with NIST SP 800-171 Revision 2. The rollout pause is therefore a reason to review the applicable paperwork carefully.

For a specific award or subcontract, ask your contracting officer, prime contractor, or qualified adviser to resolve any mismatch between an announcement and your actual terms. Record the amendment or modification received and its effective date. Avoid marking an existing obligation complete solely because a general news headline changed.

Assessment and affirmation dates have different clocks

Where DFARS 252.204-7021 applies, the clause requires annual affirmation of continuous compliance in the Supplier Performance Risk System (SPRS). Its definition of current Final Level 1 (Self) status uses a one-year assessment age; Final Level 2 (Self) uses a three-year assessment age, with an affirmation no older than one year. Both include continuing-compliance conditions. Conditional status has separate requirements.

Keep the applicable assessment date and annual affirmation date as separate records. Confirm them in the official record for each relevant system with the responsible security lead and affirming official. A three-year assessment cycle does not make the associated affirmation a three-year task. A calendar reminder alone cannot establish compliance.

A practical October calendar review

The following is an organizational checklist, not a determination of your legal or cybersecurity obligations. Use it with the person responsible for interpreting your contracts.

  1. Find the source of each entry. Search calendars and task lists for CMMC, November 10, assessments, affirmations, and option periods. Separate a general rollout milestone from an actual contract date.
  2. Preserve the history. Label an old Phase II rollout reminder as suspended and retain the public source and review date. Assign someone to check official updates; do not invent a new effective date.
  3. Review each active opportunity. Check the current public solicitation and every amendment. Keep a pending question open until the responsible person has verified what applies.
  4. Separate the next actions. Track the policy-status review, contract-modification follow-up, assessment review, and affirmation preparation individually. An unresolved contract question should remain visible.
  5. Choose preparation reminders. Set internal lead times that leave room for document review and the authorized official's work. Label these as internal targets so they cannot be mistaken for government deadlines.
  6. Close with evidence. After the responsible official completes the required action, record completion in the appropriate approved system and verify the next applicable date. Keep an independent reminder for critical obligations.
Example, using fictional records: a team has a generic November 10 Phase II rollout entry and a separate annual affirmation task based on its official record. The team updates the generic entry to show the suspension, leaves the independently verified affirmation task in place, and assigns a follow-up to check whether a contract modification has arrived. One changed milestone does not automatically update every other task.

Keep controlled information in approved systems

Do not upload CUI, FCI, export-controlled material, credentials, vulnerability details, system security plans, or other sensitive security evidence to Deadline Shield. Use public documents or non-sensitive administrative reminders only, consistent with your organization's policy. Keep restricted records and submission evidence in your approved environment.

Deadline Shield is not a CMMC assessment provider or a compliance certification service. This guide makes no claim that Deadline Shield is authorized to process controlled government information. It does not submit assessments or affirmations to SPRS.

Where Deadline Shield can help

For suitable public documents and ordinary business paperwork, Deadline Shield can suggest possible dates and show supporting source text. You review and approve findings before they become tracked items. You can also enter a verified, non-sensitive reminder manually. Operations adds team assignment and management visibility.

AI can miss dates or misread conditions. A document may still contain the old rollout date, so compare any suggestion with current official guidance before approving it. Deadline Shield does not automatically determine which rule governs your contract or change your dates when an agency issues new guidance.

Read the government-contractor workflow, contract deadline tracking guide, and Security Center. For team accountability, see Operations and current pricing.

Common questions

Can we delete all CMMC reminders?

Review them separately. The official notice preserves Phase I requirements, and your applicable contract, assessment, and affirmation records need their own review.

Does a reminder prove we met the requirement?

No. The authorized person must carry out and verify the required action in the appropriate system. Tracking a task is only administrative support.

General organizational information only; not legal, procurement, or cybersecurity advice. Requirements depend on the applicable contract and current official guidance. Deadline Shield is not affiliated with or endorsed by the United States Government.