Skip to content

CMMC 2.0

In force United States (Federal) · In force Dec 16, 2024 · next deadline Nov 10, 2026 (in 47 days)

Deadlines

DateWhat happens
Dec 16, 2024CMMC Program rule (32 CFR Part 170) effective21 months ago
Nov 10, 2025DFARS rule effective; Phase 1 begins10 months ago
Nov 10, 2026Phase 2: Level 2 C3PAO certificationin 47 days
Nov 10, 2027Phase 3: Level 3 certificationin 14 months
Nov 10, 2028Phase 4: full implementationin 2.1 years

Summaries for reference, not legal advice. Check the official text.

What it does

Requires defense contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet a specified CMMC level (Level 1 self-assessment, Level 2 self- or third-party (C3PAO) assessment against NIST SP 800-171, Level 3 DIBCAC assessment against selected NIST SP 800-172 controls) as a condition of contract award. Requirements are phased into DoD solicitations over four years.

Who it applies to
DoD prime contractors and subcontractors at all tiers whose information systems process, store or transmit FCI or CUI in contract performance; excludes contracts solely for commercially available off-the-shelf (COTS) items.
Penalties
Ineligibility for award or option exercise; misrepresented affirmations can create False Claims Act and contractual liability.
Enforced by
U.S. Department of Defense (DoD CIO, contracting officers, DCMA DIBCAC); Cyber AB accredits C3PAOs
Official name
Cybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204, 212, 217, 252)
Citation
32 CFR Part 170 (89 FR 83092, Oct. 15, 2024); DFARS Case 2019-D041, 90 FR 43560 (Sept. 10, 2025)
Topics
cybersecurity
Verified 2026-09-22 federalregister.gov dodcio.defense.gov
Research notes

Phase dates computed per 32 CFR 170.3(e): Phase 1 starts on the later of the Part 170 or the 48 CFR rule effective date (November 10, 2025), each later phase one calendar year after the previous; DoD may include higher requirements earlier at its discretion. The DoD CIO site could not be fetched during verification.

Related

Questions about CMMC 2.0
What are the CMMC 2.0 compliance deadlines?
Dec 16, 2024: CMMC Program rule (32 CFR Part 170) effective. Nov 10, 2025: DFARS rule effective; Phase 1 begins. Nov 10, 2026: Phase 2: Level 2 C3PAO certification. Nov 10, 2027: Phase 3: Level 3 certification. Nov 10, 2028: Phase 4: full implementation.
When does CMMC 2.0 take effect?
CMMC 2.0 took effect on Dec 16, 2024. The next milestone is Nov 10, 2026: Phase 2: Level 2 C3PAO certification.
Who does CMMC 2.0 apply to?
DoD prime contractors and subcontractors at all tiers whose information systems process, store or transmit FCI or CUI in contract performance; excludes contracts solely for commercially available off-the-shelf (COTS) items.
What are the penalties under CMMC 2.0?
Ineligibility for award or option exercise; misrepresented affirmations can create False Claims Act and contractual liability.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.