
CMMC Final Rule: What Changed and What Contractors Must Do
Key Takeaways
- The Cybersecurity Maturity Model Certification (CMMC)Program Rule under 32 CFR Part 170 took effect December 16, 2024, establishing the three-level certification model and the Cyber AB accreditation ecosystem.
- The Defense Federal Acquisition Regulation Supplement (DFARS)acquisition rule under 48 CFR took effect November 10, 2025, adding contract clause DFARS 252.204-7021 and solicitation provision DFARS 252.204-7025, which make CMMC status a condition of contract award.
- CMMC is rolling out in four phases through November 2028 and Phase 2, which brings mandatory Level 2 Certified Third-Party Assessment Organization (C3PAO)certification to most contracts, begins November 10, 2026.
- CMMC 2.0 collapsed the original five-level model down to three levels and anchored Level 2 directly to the 110 controls inNational Institute of Standards and Technology (NIST) SP 800-171 rather than a hybrid framework with extra CMMC-specific practices.
- Contractors must now file an annual affirmation of continuous compliance in the Supplier Performance Risk System (SPRS) and a false affirmation can trigger False Claims Act liability.
- Waiting for further rule changes is no longer a viable strategy, since the final rule is already showing up in live solicitations.
Note: As of July 13, 2026, the Department of War suspended CMMC Phase 2, along with Phases 3 and 4, pending a 60-day program review, so the November 10, 2026 dates referenced below are no longer active deadlines. Phase 1 self-assessment requirements, DFARS 252.204-7012, and annual SPRS affirmations remain fully in effect, and this is a policy pause rather than a repeal: the underlying CMMC Program rule and DFARS clauses are unchanged. Contractors already working toward Level 2 certification should keep going – a reformed requirement, and a resumed timeline, could return once the review concludes. We will update this article with accurate timelines once the review has been completed.
Government contractors have been hearing about CMMC for years, watching deadlines move while rules got proposed and comment periods dragged on. That era is over. The rule is final and it is already showing up in real solicitations, with the phased enforcement clock already running.
This article cuts through the confusion. It covers exactly what changed in the final rule, what the current phased timeline looks like and what your organization needs to do right now.
Why Did CMMC Take So Long to Finalize?
The Department of War (DoW), then Department of Defense (DoD), first introduced CMMC in 2020 as a five-level maturity model with its own certification-specific practices layered on top of NIST SP 800-171. Industry pushback over the cost and complexity of meeting that model led the DoW to pause the rollout in 2021 and announce a simplified CMMC 2.0 framework that November.
Turning that announcement into an enforceable requirement took years of formal rulemaking, including two separate regulatory processes and public comment periods. The proposed CMMC program rule appeared in December 2023, followed by lengthy interagency review before the final version reached the Federal Register in October 2024.
The 32 CFR Program Rule established the certification model itself, while a second rule under 48 CFR was needed before contracting officers could put CMMC language into solicitations. Both are now final, which is the focus of the rest of this article.
What Did the 32 CFR Program Rule Establish?
The CMMC Program Rule, codified at 32 CFR Part 170, was finalized in October 2024 and took effect December 16, 2024. It created the structure that every other CMMC requirement builds on.
The rule established the three-level certification model, defined how assessments work at each level and set up the Cyber AB accreditation ecosystem, including Certified Third-Party Assessment Organizations (C3PAOs) and Registered Provider Organizations (RPOs). It also created the CMMC status categories contractors now see in SPRS: a Final status once all requirements are met and several Conditional statuses tied to each level and assessment type when some requirements are still outstanding. For example, a conditional status moves to Final once the contractor closes out its Plan of Action and Milestones (POA&M) within the required window.
Every subsequent CMMC requirement, from who can assess a contractor to how long a certification stays valid, traces back to definitions this rule put in place. Contractors who run into a specific requirement later in their compliance work, such as a question about assessment scope or when a status expires, are ultimately looking at something this rule defined.
What the 32 CFR rule did not do is give contracting officers authority to require CMMC in a live contract. That took a second rule.
What Did the 48 CFR Rule Change?
The DFARS acquisition rule, published in the Federal Register on September 10, 2025, took effect 60 days later on November 10, 2025. This rule turned CMMC from a certification framework into a contractual reality.
It also added two new pieces to the DFARS. Contract clause DFARS 252.204-7021 establishes the ongoing compliance obligations for contractors and subcontractors, including maintaining current CMMC status and filing annual affirmations. Solicitation provision DFARS 252.204-7025 requires contracting officers to specify the CMMC level a solicitation requires, using one of four standard fill-in options:
- Level 1 (Self): Annual self-assessment against the 15 requirements in FAR 52.204-21
- Level 2 (Self): Self-assessment against the 110 NIST SP 800-171 controls, permitted for a subset of lower-risk contracts
- Level 2 (C3PAO): Third-party certification against the same 110 controls, required for most contracts handling controlled unclassified information (CUI)
- Level 3 (DIBCAC): Government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), reserved for the most sensitive programs
The rule also replaced the earlier term “senior company official” with “affirming official,” matching the terminology in the 32 CFR rule and requires every contractor information system handling FCI or CUI to carry a CMMC Unique Identifier (UID) in SPRS. Contracting officers cannot move forward on the contract, whether that means a new award or a later option period, unless SPRS reflects a current CMMC status and a current affirmation at the required level.
What Is the Phased Rollout Timeline?
The DoW is not flipping a single switch on CMMC enforcement. The rule spreads full implementation across four phases over three years, with each phase widening what contracting officers can require.
| Phase | Timeframe | What Changes |
|---|---|---|
| 1 | November 10, 2025 to November 9, 2026 | Level 1 and Level 2 self-assessment become standard; the DoW may still require Level 2 C3PAO certification for specific contracts |
| 2 | November 10, 2026 to November 9, 2027 | Level 2 C3PAO certification becomes the standard requirement for most applicable contracts; Level 3 DIBCAC assessment becomes available at the DoW’s discretion |
| 3 | November 10, 2027 to November 9, 2028 | Level 2 C3PAO certification extends to option period exercises on existing contracts; Level 3 DIBCAC assessment becomes standard for applicable solicitations |
| 4 | November 10, 2028 forward | Full implementation applies across every applicable DoW solicitation and contract, including option periods |
Phase 2 deserves particular attention, since it is now roughly four months away and shifts most Level 2 contracts from self-assessment to mandatory third-party certification. A C3PAO assessment typically takes six to twelve months of preparation once you identify compliance gaps, so contractors who have not started an assessment against the CMMC timeline are running out of runway before that shift takes effect.
Contracts awarded during Phase 1 under self-assessment terms are not automatically exempt from stricter requirements down the road. Many DoW contracts run in stages, an initial period followed by optional renewal years the government can choose to exercise instead of rebidding the work and Phase 3 requires Level 2 C3PAO certification when the government renews a contract into one of those renewal years, not just when it awards a brand new contract.
What Changed from CMMC 1.0 to CMMC 2.0?

CMMC 1.0 organized requirements into five maturity levels, each layering additional CMMC-specific practices and formal process maturity scoring on top of NIST SP 800-171. Level 3 under the original model, for example, required 130 practices, the 110 controls in NIST SP 800-171 plus 20 CMMC-only practices that existed nowhere else.
CMMC 2.0 eliminated that hybrid approach entirely. The model now uses just three levels and Level 2 maps directly to the 110 controls in NIST SP 800-171 with no additional CMMC-specific practices layered on top. The formal process maturity scoring from CMMC 1.0 is gone as well, replaced by a simpler focus on whether the security practices themselves are in place.
Two other changes matter for day-to-day compliance work. CMMC 2.0 reintroduced limited use of POA&Ms, which the original model did not allow, giving contractors a documented path to close specific gaps without losing their eligibility entirely. It also opened self-assessments for Level 1 and for a subset of lower-risk Level 2 contracts, where CMMC 1.0 had required broad third-party assessment across nearly every level.
The practical effect is a framework that costs less to prepare for and is far simpler to interpret. A contractor reading NIST SP 800-171 today knows that meeting those 110 controls satisfies Level 2 in full, without needing to track down a separate CMMC-specific practices document that no longer exists under the current model.
Why Does the False Claims Act Matter Now?
The final rule requires an affirming official, typically a senior company executive, to submit an annual affirmation of continuous compliance in SPRS for every covered information system. That affirmation is not a formality. It is a statement to the federal government that the contractor’s environment meets the CMMC level required by its contracts.
A false or careless affirmation creates real legal exposure. The Department of Justice has made cybersecurity compliance misrepresentations an enforcement priority under its Civil Cyber-Fraud Initiative and a knowingly inaccurate affirmation of continuous compliance can trigger False Claims Act liability, which carries treble damages and per-claim penalties. It’s a meaningfully different risk profile from the self-attestation era, when an inaccurate compliance claim rarely faced this level of legal scrutiny.
Contractors should treat the annual affirmation with the same rigor as a financial certification. Before an affirming official signs, someone should verify that the environment described in the SSP still matches reality and that no material changes have gone undocumented since the last assessment. A new system brought into scope, a vendor change affecting a control’s implementation or even a lapsed configuration can all turn a previously accurate affirmation into one that no longer reflects the truth.
What Must Contractors Do Now, by Level?
The specific work ahead depends heavily on which CMMC level your contracts require and that level depends on what kind of information your systems handle rather than the size of your contract. A small subcontractor receiving CUI from a prime contractor, the company holding the direct DoW contract, needs Level 2 protections regardless of its own contract value, so checking information type first prevents scoping the wrong level of effort entirely.
- Level 1 contractors, who handle only Federal Contract Information (FCI), need to complete an annual self-assessment against the 15 requirements in FAR 52.204-21 and file the corresponding affirmation in SPRS. No POA&Ms are permitted at this level, so all 15 requirements must be fully met before affirming compliance.
- Level 2 contractors, who handle CUI, need a documented gap assessment against the 110 NIST SP 800-171 controls, a current SSP, an active POA&M for anything still in progress and either a self-assessment or C3PAO certification depending on what the specific contract requires.
- Level 3 contractors, who handle the most sensitive CUI on the highest priority programs, need everything Level 2 requires plus the additional practices from NIST SP 800-172, along with a government-led assessment through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
Contractors should also check every active solicitation and contract for the CMMC level fill-in language at DFARS 252.204-7025, since that single line determines exactly what your organization needs to have in place before award.
What Misconceptions Should Contractors Correct?
A few persistent misunderstandings tend to slow contractors down at exactly the wrong moment, often because they were true or partly true, earlier in CMMC’s long rulemaking history. Correcting them early avoids wasted effort later.
- CMMC is not a paperwork exercise. A policy binder alone won’t satisfy an assessor. Assessors expect to see evidence that documented controls operate day to day in practice, not just that a policy describing them exists.
- The same firm cannot both prepare you and certify you. Federal rules under 32 CFR Part 170 prohibit an assessor from grading work it helped produce, since that would be an inherent conflict of interest. This separation is enforced at the level of the individual client relationship, so a firm can hold both RPO and C3PAO accreditation if it never serves both roles for the same organization.
- Waiting for a “final” rule is no longer a viable strategy. That rule has already arrived and is already showing up in live solicitations. The phased enforcement clock does not pause for contractors who are still waiting to start.
Getting Ahead of the Final Rule
The CMMC final rule ends years of uncertainty about whether and when, these requirements would apply to real contracts. They apply now and the phased implementation timeline only tightens from here.
Contractors who treat Phase 2’s arrival in November 2026 as a distant deadline are the ones most likely to find themselves scrambling for C3PAO scheduling slots or discovering gaps too late to close them in time. Assessment wait times are already stretching toward a year in some regions and that window will only shrink as more contractors reach their own Phase 2 deadlines at the same time. Understanding CMMC 2.0’s specific requirements at the level your contracts require is the fastest way to figure out exactly where your organization stands today.
Red River helps defense contractors assess their environment against NIST SP 800-171, close the gaps that matter most and prepare for whatever assessment path their contracts require. Contact Red River to talk through where your organization stands under the final rule and what a realistic path forward looks like.
Frequently Asked Questions
written by
Corrin Jones
Corrin Jones is the Director of Digital Demand Generation. With over ten years of experience, she specializes in creating content and executing campaigns to drive growth and revenue. Connect with Corrin on LinkedIn.
