Skip to content
CMMC

CMMC Level 2 readiness, grounded in your scope, evidence and next actions.

CMMC Phase II is suspended for a 60-day government review, with no replacement start date announced. Phase I self-assessments and the underlying NIST and DFARS duties remain. Explore Valty for organizing control evidence and readiness follow-up. In a platform demo, confirm the objective mappings, evidence sources and deliverables available for your scope.

Prepared by ValtyUpdated
Design partner
Request a platform demo
Current program status

Phase II is suspended. The readiness work is not.

The government paused Phase II on July 13, 2026 and began a 60-day review. It did not announce a new start date. Phase I self-assessments and existing CUI-protection duties remain, so the useful move is to build evidence against the enduring baseline while the acquisition mechanics are reviewed.

Phase II status

Suspended for review

On July 13, 2026, the government suspended CMMC Phase II immediately and opened a 60-day review. The previously scheduled November start is no longer operative, and no replacement date has been announced.

July 13, 2026 · official program announcement
Phase I remains

Self-assessments continue

During the suspension, solicitations and contracts can still designate Level 1 Self or Level 2 Self under Phase I. Contractors should read the assessment type in each acquisition rather than assume the pause removes every CMMC requirement.

Level 1 Self · Level 2 Self
Baseline duties

Still enforceable

The suspension does not remove existing duties to protect CUI. The government said it will continue enforcing NIST SP 800-171 Revision 2 and DFARS 252.204-7012 requirements.

NIST SP 800-171 Rev. 2 · DFARS 252.204-7012
Read the July 2026 program update
Readiness support

Start with the evidence you hold, and make the gaps clear.

Valty brings control records, evidence and follow-up into a reviewable workflow. For CMMC readiness, begin with the company boundary and the evidence needed to explain each requirement. Use a scoped evaluation to establish which mappings, workflows and outputs support that work for your organization.

  • CUI boundary, system inventory and evidence sources
  • 800-171A objective mappings and remaining evidence gaps
  • Requirement-level SPRS scoring assumptions and supporting evidence
  • Eligible POA&M items, owners and the shared closeout deadline
  • Agreed deliverables, export formats and a factual readiness status

Evaluation scope confirms available objective coverage, evidence sources and export formats. An illustrative product view does not establish a complete assessment package or an accepted OSCAL deliverable.

Control and Evidence Review product surface
Control and Evidence ReviewActual Valty control-catalog view with illustrative data. Review the CMMC objective mappings and evidence sources available for your scope during the demo.Open full-size product view ↗
Readiness foundations

Connect the requirements, the evidence and the next step.

These six areas shape the readiness work. The standards define the assessment baseline; your evaluation confirms the Valty workflows and outputs available to support it.

Assessment objectives

110 requirements, 320 assessment objectives

The Level 2 baseline is NIST SP 800-171 Revision 2, assessed using SP 800-171A (June 2018). The objective count describes that baseline, not proven Valty coverage. Review the applicable mappings and evidence gaps in your evaluation.

SP 800-171 Rev. 2 requirements · SP 800-171A assessment procedures
SPRS scoring

Review the evidence behind your score

Review requirement-level scoring and supporting evidence across the 110 security requirements. The score reported to SPRS must follow the applicable assessment methodology; a planning view does not establish an official result.

Requirement-level score review
POA&M lifecycle

One closeout window, accountable owners

Track eligible items, owners and milestones against the closeout window. Section 170.21 starts the 180 days at the Conditional CMMC Status Date; opening a later item does not restart that deadline.

180-day POA&M closeout clock
Assessment artifacts

Agree the deliverable and format

OSCAL offers machine-readable models for system security plans, assessment plans, results and POA&M records. Confirm the artifacts and versions available in your Valty evaluation, and the formats your assessor accepts, before relying on an export.

OSCAL availability and version confirmed in scope
Assessment preparation

Make the handoff reviewable

Bring the boundary, evidence inventory, scoring assumptions and open actions into one review. Agree the deliverables with Valty and confirm assessment evidence requirements with your assessor.

Scoped readiness support
CUI boundary

Scope what is in and out

Define the CUI boundary, the systems, people, and data in scope for assessment, so evidence, scoring, and the SSP all describe the same environment the assessor will walk.

CUI boundary scoping

Assessment baseline: CMMC Level 2 Assessment Guide and NIST SP 800-171A, June 2018.

Readiness workflow

Scope, review, prepare the handoff.

Keep the company boundary, evidence, scoring assumptions and open actions connected. Agree the supported handoff before the evaluation begins.

Evidence Package Review product surface
Evidence Package ReviewActual Valty proof-pack view with illustrative data. This shows package organization, not an OSCAL export. Confirm available deliverables and formats before evaluation.Open full-size product view ↗

The handoff

Evidence another reviewer can follow.

A useful readiness handoff explains the scope, evidence sources, assessment assumptions and unresolved gaps. System security plans, assessment plans and results, and POA&M records may be needed. Confirm the specific deliverables and formats in your Valty evaluation, including OSCAL support where required.

Your assessor determines the evidence needed for the applicable assessment. Agree artifact and format compatibility before relying on a generated package.

01

Draw the CUI boundary

Define the systems, users and data in scope. Use that boundary to agree the evidence sources, supported workflows and deliverables for the evaluation.

CUI boundary definition
02

Review objectives and evidence

Work from the applicable 800-171A objectives. Identify the evidence already available, what needs examination or testing, and where gaps remain.

Objective and evidence review
03

Review scoring and open actions

Review the score and exact requirement eligibility, then organize permitted POA&M gaps with owners and milestones. Closeout must be confirmed within 180 days of the Conditional CMMC Status Date.

SPRS review + 180-day POA&M clock
04

Prepare the agreed handoff

Review the supported outputs against the agreed scope. If OSCAL is required, confirm the actual artifact, version and assessor compatibility before committing to the handoff.

Agreed artifacts and formats
Readiness, not authorization

Valty is not a C3PAO.

Valty the company is not a CMMC Third-Party Assessment Organization (C3PAO), a C3PAO-accredited assessor, or a certifying body. It does not issue CMMC certifications, authorizations, or attestations of compliance.

Valty supports a scoped readiness evaluation. Confirm the objective mappings, evidence sources, workflows and deliverables available for your organization before access. A C3PAO conducts a Level 2 certification assessment; a platform demo does not establish certification.

A control catalog, illustrative screenshot or planning score does not demonstrate implementation. Missing evidence and unassessed requirements remain open questions until they are reviewed.

Evidence and boundaries

Know what each output supports, and what still needs review.

A useful handoff makes its evidence and limitations visible. Review these boundaries alongside the deliverables agreed for your evaluation.

ClaimObjective mapping and evidence
SourceApplicable SP 800-171A objectives and the evidence available for your scope
ConfidenceConfirm coverage in the evaluation; a catalog entry is not evidence of implementation
FreshnessReview when scope, controls or source evidence change
ClaimSPRS score
SourceRequirement-level assessment and applicable DoD assessment methodology
ConfidenceA planning aid does not establish a reportable assessment result
FreshnessReview after evidence or scope changes
ClaimPOA&M item
SourceRequirement eligibility, owner, milestone and supporting evidence
ConfidenceEligibility must be assessed; closure requires evidence
FreshnessCloseout is due within 180 days of the Conditional CMMC Status Date
ClaimAssessment artifacts and OSCAL
SourceThe actual outputs and formats agreed for your Valty evaluation
ConfidenceConfirm supported artifacts, version and assessor acceptance; no blanket export promise
FreshnessReview outputs again when the underlying evidence or scope changes
ClaimCMMC certification / authorization
SourceThe applicable assessment and affirmation process, outside this platform evaluation
ConfidenceValty is not a C3PAO and does not issue CMMC certification or authorization
FreshnessDetermined through the applicable assessment process
Free tool

Estimate your SPRS score in minutes . Free, no sign-in.

Start with the free SPRS planning estimator. Enter counts for the 107 fixed-weight requirements and see a range that leaves the two variable MFA/FIPS requirements unassessed. No account or evidence upload; no POA&M eligibility or Conditional Status is inferred.

The estimator returns an arithmetic planning range from aggregate counts. It is not a requirement-level assessment, a reportable SPRS score or a CMMC status decision.

Bring your CMMC readiness scope to a platform demo.

Explore the control evidence and readiness workflow with illustrative data. Then agree the company scope, supported objective mappings, evidence needs, deliverables and terms before evaluation access.

Valty is in the design-partner stage. Evaluation access, supported workflows, objective mappings and deliverables are agreed separately. Valty is not a C3PAO and does not issue CMMC certification or authorization.