CMMC Level 2 readiness, grounded in your scope, evidence and next actions.
CMMC Phase II is suspended for a 60-day government review, with no replacement start date announced. Phase I self-assessments and the underlying NIST and DFARS duties remain. Explore Valty for organizing control evidence and readiness follow-up. In a platform demo, confirm the objective mappings, evidence sources and deliverables available for your scope.
Phase II is suspended. The readiness work is not.
The government paused Phase II on July 13, 2026 and began a 60-day review. It did not announce a new start date. Phase I self-assessments and existing CUI-protection duties remain, so the useful move is to build evidence against the enduring baseline while the acquisition mechanics are reviewed.
Suspended for review
On July 13, 2026, the government suspended CMMC Phase II immediately and opened a 60-day review. The previously scheduled November start is no longer operative, and no replacement date has been announced.
July 13, 2026 · official program announcementSelf-assessments continue
During the suspension, solicitations and contracts can still designate Level 1 Self or Level 2 Self under Phase I. Contractors should read the assessment type in each acquisition rather than assume the pause removes every CMMC requirement.
Level 1 Self · Level 2 SelfStill enforceable
The suspension does not remove existing duties to protect CUI. The government said it will continue enforcing NIST SP 800-171 Revision 2 and DFARS 252.204-7012 requirements.
NIST SP 800-171 Rev. 2 · DFARS 252.204-7012Start with the evidence you hold, and make the gaps clear.
Valty brings control records, evidence and follow-up into a reviewable workflow. For CMMC readiness, begin with the company boundary and the evidence needed to explain each requirement. Use a scoped evaluation to establish which mappings, workflows and outputs support that work for your organization.
- CUI boundary, system inventory and evidence sources
- 800-171A objective mappings and remaining evidence gaps
- Requirement-level SPRS scoring assumptions and supporting evidence
- Eligible POA&M items, owners and the shared closeout deadline
- Agreed deliverables, export formats and a factual readiness status
Evaluation scope confirms available objective coverage, evidence sources and export formats. An illustrative product view does not establish a complete assessment package or an accepted OSCAL deliverable.

Connect the requirements, the evidence and the next step.
These six areas shape the readiness work. The standards define the assessment baseline; your evaluation confirms the Valty workflows and outputs available to support it.
110 requirements, 320 assessment objectives
The Level 2 baseline is NIST SP 800-171 Revision 2, assessed using SP 800-171A (June 2018). The objective count describes that baseline, not proven Valty coverage. Review the applicable mappings and evidence gaps in your evaluation.
SP 800-171 Rev. 2 requirements · SP 800-171A assessment proceduresReview the evidence behind your score
Review requirement-level scoring and supporting evidence across the 110 security requirements. The score reported to SPRS must follow the applicable assessment methodology; a planning view does not establish an official result.
Requirement-level score reviewOne closeout window, accountable owners
Track eligible items, owners and milestones against the closeout window. Section 170.21 starts the 180 days at the Conditional CMMC Status Date; opening a later item does not restart that deadline.
180-day POA&M closeout clockAgree the deliverable and format
OSCAL offers machine-readable models for system security plans, assessment plans, results and POA&M records. Confirm the artifacts and versions available in your Valty evaluation, and the formats your assessor accepts, before relying on an export.
OSCAL availability and version confirmed in scopeMake the handoff reviewable
Bring the boundary, evidence inventory, scoring assumptions and open actions into one review. Agree the deliverables with Valty and confirm assessment evidence requirements with your assessor.
Scoped readiness supportScope what is in and out
Define the CUI boundary, the systems, people, and data in scope for assessment, so evidence, scoring, and the SSP all describe the same environment the assessor will walk.
CUI boundary scopingAssessment baseline: CMMC Level 2 Assessment Guide and NIST SP 800-171A, June 2018.
Scope, review, prepare the handoff.
Keep the company boundary, evidence, scoring assumptions and open actions connected. Agree the supported handoff before the evaluation begins.

The handoff
Evidence another reviewer can follow.
A useful readiness handoff explains the scope, evidence sources, assessment assumptions and unresolved gaps. System security plans, assessment plans and results, and POA&M records may be needed. Confirm the specific deliverables and formats in your Valty evaluation, including OSCAL support where required.
Your assessor determines the evidence needed for the applicable assessment. Agree artifact and format compatibility before relying on a generated package.
Draw the CUI boundary
Define the systems, users and data in scope. Use that boundary to agree the evidence sources, supported workflows and deliverables for the evaluation.
CUI boundary definitionReview objectives and evidence
Work from the applicable 800-171A objectives. Identify the evidence already available, what needs examination or testing, and where gaps remain.
Objective and evidence reviewReview scoring and open actions
Review the score and exact requirement eligibility, then organize permitted POA&M gaps with owners and milestones. Closeout must be confirmed within 180 days of the Conditional CMMC Status Date.
SPRS review + 180-day POA&M clockPrepare the agreed handoff
Review the supported outputs against the agreed scope. If OSCAL is required, confirm the actual artifact, version and assessor compatibility before committing to the handoff.
Agreed artifacts and formatsValty is not a C3PAO.
Valty the company is not a CMMC Third-Party Assessment Organization (C3PAO), a C3PAO-accredited assessor, or a certifying body. It does not issue CMMC certifications, authorizations, or attestations of compliance.
Valty supports a scoped readiness evaluation. Confirm the objective mappings, evidence sources, workflows and deliverables available for your organization before access. A C3PAO conducts a Level 2 certification assessment; a platform demo does not establish certification.
A control catalog, illustrative screenshot or planning score does not demonstrate implementation. Missing evidence and unassessed requirements remain open questions until they are reviewed.
Know what each output supports, and what still needs review.
A useful handoff makes its evidence and limitations visible. Review these boundaries alongside the deliverables agreed for your evaluation.
Estimate your SPRS score in minutes . Free, no sign-in.
Start with the free SPRS planning estimator. Enter counts for the 107 fixed-weight requirements and see a range that leaves the two variable MFA/FIPS requirements unassessed. No account or evidence upload; no POA&M eligibility or Conditional Status is inferred.
The estimator returns an arithmetic planning range from aggregate counts. It is not a requirement-level assessment, a reportable SPRS score or a CMMC status decision.
Bring your CMMC readiness scope to a platform demo.
Explore the control evidence and readiness workflow with illustrative data. Then agree the company scope, supported objective mappings, evidence needs, deliverables and terms before evaluation access.
Valty is in the design-partner stage. Evaluation access, supported workflows, objective mappings and deliverables are agreed separately. Valty is not a C3PAO and does not issue CMMC certification or authorization.