CMMC 2.0
In force United States (Federal) · In force Dec 16, 2024 · next deadline Nov 10, 2026 (in 47 days)
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Requires defense contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet a specified CMMC level (Level 1 self-assessment, Level 2 self- or third-party (C3PAO) assessment against NIST SP 800-171, Level 3 DIBCAC assessment against selected NIST SP 800-172 controls) as a condition of contract award. Requirements are phased into DoD solicitations over four years.
- Who it applies to
- DoD prime contractors and subcontractors at all tiers whose information systems process, store or transmit FCI or CUI in contract performance; excludes contracts solely for commercially available off-the-shelf (COTS) items.
- Penalties
- Ineligibility for award or option exercise; misrepresented affirmations can create False Claims Act and contractual liability.
- Enforced by
- U.S. Department of Defense (DoD CIO, contracting officers, DCMA DIBCAC); Cyber AB accredits C3PAOs
- Official name
- Cybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204, 212, 217, 252)
- Citation
- 32 CFR Part 170 (89 FR 83092, Oct. 15, 2024); DFARS Case 2019-D041, 90 FR 43560 (Sept. 10, 2025)
- Topics
- cybersecurity
Research notes
Phase dates computed per 32 CFR 170.3(e): Phase 1 starts on the later of the Part 170 or the 48 CFR rule effective date (November 10, 2025), each later phase one calendar year after the previous; DoD may include higher requirements earlier at its discretion. The DoD CIO site could not be fetched during verification.
Related
Questions about CMMC 2.0
- What are the CMMC 2.0 compliance deadlines?
- Dec 16, 2024: CMMC Program rule (32 CFR Part 170) effective. Nov 10, 2025: DFARS rule effective; Phase 1 begins. Nov 10, 2026: Phase 2: Level 2 C3PAO certification. Nov 10, 2027: Phase 3: Level 3 certification. Nov 10, 2028: Phase 4: full implementation.
- When does CMMC 2.0 take effect?
- CMMC 2.0 took effect on Dec 16, 2024. The next milestone is Nov 10, 2026: Phase 2: Level 2 C3PAO certification.
- Who does CMMC 2.0 apply to?
- DoD prime contractors and subcontractors at all tiers whose information systems process, store or transmit FCI or CUI in contract performance; excludes contracts solely for commercially available off-the-shelf (COTS) items.
- What are the penalties under CMMC 2.0?
- Ineligibility for award or option exercise; misrepresented affirmations can create False Claims Act and contractual liability.