Dated policy review / September 7, 2026
Phase II is suspended. Read what changes in the procurement documents.
The July 2026 direction continues CMMC Phase I. It instructs contracting activities to change affected solicitations and contracts. Treating the announcement only as a delayed certification date misses that document work.
Separate the required level from safeguarding and assessment obligations applicable to the work. The permanent pause guide provides the procedural review.
01 / Three different sources
Identify what changed and who must act.
01.1
Announcement
The July 13 announcement establishes the suspension and review process. It is not a final taskforce recommendation or an amendment to every supplier's contract.
01.2
Implementation direction
The direction instructs contracting activities about level designation and changes to affected instruments. It distinguishes active solicitations from existing contracts.
01.3
Your package
Inspect the actual amendment or modification and remaining provisions. A headline cannot resolve a blank insertion, conflicting paragraphs or a proposed system's scope.
DoD CIO CMMC page and implementation attachment, linked below.
02 / Where Deep Fathom fits
Review the work that still needs evidence.
Revisit the compliance question, document version and evidence behind the proposed work. Deep Fathom's platform evaluation concerns those compliance workflows.
- 01
Locate the source
Record the incorporated version and selected level.
- 02
Check applicability
Identify the information, entity and systems contemplated for performance.
- 03
Review the support
Determine which assessment or affirmation answers the requested representation.
- 04
Preserve questions
Ask the contracting officer about blank insertions or conflicting terms.
03 / Official sources
The direction reaches the instruments.
| Source | What it establishes | What remains to check |
|---|---|---|
| DoD CIO CMMC page | Phase I continues and Phase II is suspended. | The particular instrument's terms and a supplier's status. |
| Implementation attachment | Designation restrictions, amendment and modification timing, continued 7012 requirements. | Whether the contracting activity has completed the relevant document change. |
| DFARS 7012 | Safeguarding and reporting within the clause's scope and conditions. | Whether and how the clause applies to the actual work. |
| DFARS 7019 | Current NIST assessment for relevant covered systems when applicable. | Separate CMMC status and affirmation requirements. |
04 / The review record
Preserve the changed condition and remaining work.
Record the earlier level text, the amendment changing it and the affected checkpoint. Keep unrelated technical, access and submission conditions in the review.
For an existing contract, identify the actual modification and effective terms. The policy's timing is not proof that a private contract has already changed.
The retained jack-assemblies amendment example shows why deleted text can still appear in an amendment. Read the action rather than counting words.
05 / Keep uncertainty specific
A taskforce review is not its final report.
This page does not predict recommendations or describe a company proposal as government policy. Re-read official direction when a substantive new publication appears.
Separate cybersecurity duties, assessment records and the buyer's requested status before deciding what work to pause or continue. Read the version incorporated in the actual instrument.
Platform evaluation / Compliance evidence
Bring the evidence question that remains.
Share a public requirement and describe the compliance workflow you need to examine. Our team can demonstrate the relevant platform behavior.
Do not include CUI, credentials, export-controlled data or controlled attachments in this form.
Limitations
- Dated public-source review, not an interpretation of an unseen contract.
- Phase I continues. Separate applicable cybersecurity obligations remain.
- No current market total, final taskforce report or automated contract-change capability is asserted.