The CMMC Rule is Final & Posted by the DoD

Here’s a concise overview of the recent developments regarding the Cybersecurity Maturity Model Certification (CMMC) Program.


Welp, it’s official— and Phase 1 is now in effect. If you’re a defense contractor and you haven’t started preparing for CMMC requirements, you’re already behind. Now’s the time to ensure compliance and protect your eligibility for DoD contracts. Proactive steps include reviewing current contracts to determine the required CMMC level, implementing necessary cybersecurity controls, and planning for the appropriate assessments.

If you aren’t familiar with CMMC, you can check out our blog, What Phase 2 Means and How to Get Ready, where we outline what it is, why you’ll have to do it, why you should work with a cybersecurity consultant, and the tools for compliance.

Final Rule Publication and Effective Date:

  • The U.S. Department of Defense (DoD) published the final rule for CMMC 2.0 on October 15, 2024
  • This rule will become effective on December 16, 2024.

The CMMC 2.0 Framework Levels:

  • Level 1 (Foundational): Focuses on 15 basic cyber hygiene practices for handling Federal Contract Information (FCI). Organizations are required to conduct annual self-assessments.
  • Level 2 (Advanced): Aligns with the 110 controls outlined in NIST SP 800-171 to protect Controlled Unclassified Information (CUI). Depending on the contract, this may require self-assessment or third-party certification every three years.
  • Level 3 (Expert): Designed for the most sensitive contracts, incorporating additional NIST SP 800-172 controls. Requires both third-party certification and government-led assessment every three years.


In our webinar, “How to Streamline CMMC 2.0 Compliance,we outlined what manufacturers need to be CMMC 2.0 compliant, including how to budget for it and when. The big takeaway is that CMMC 2.0 is necessary for all organizations in the DoD’s supply chain that handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

The CMMC Levels for Manufacturers
Disclaimer: Level 1 has been updated to 15 controls with the release of the final rule on CMMC 2.0 in October 2024.
© Datanomix & Carbide. All Rights Reserved.


If you’re curious about your software vendors, CMMC 2.0 is necessary for all vendors in the DoD’s supply chain that handle FCI and CUI, whether in the cloud or on-premise. If they do touch CUI, ask whether they comply with the 110 requirements of DFARS 252.204-7012/NIST SP 800-171 and whether they have any third-party certifications such as SOC 2, ISO 27001, or FedRAMP (if they sell to any federal agencies).

The CMMC 2.0 Implementation Timeline—Key Dates to Know

The CMMC 2.0 implementation is being rolled out in phases, giving manufacturers time to prepare.

Update (July 2026): On July 13, 2026, the Department of War suspended CMMC Phase 2 — the November 10, 2026 deadline — along with all pending and future CMMC rollout milestones, and opened a 60-day review of the program. Phase 1 self-assessment requirements remain firmly in place. For Level 1 shops, this changes almost nothing: Level 1 was always self-assessed, never third-party assessed, so your path is intact. You still self-assess against the 15 requirements below.

Here’s where each phase stands now:

  • Phase 1 — November 10, 2025 (in effect): CMMC clauses appear in new DoD solicitations and contract awards. Level 1 and Level 2 self-assessments are required as a condition of award for applicable contracts. This is the piece that’s still live.
  • Phase 2 — was November 10, 2026 (suspended): Would have made third-party (C3PAO) Level 2 the default for CUI contracts and stopped self-assessments from counting. Suspended July 13, 2026, pending the reform review. No replacement date has been set.
  • Phase 3 — was November 10, 2027 (suspended): Would have made C3PAO Level 2 a condition for option exercises on existing contracts, and made Level 3 (DIBCAC) mandatory in applicable solicitations. Swept up in the suspension of future milestones.
  • Phase 4 — was November 10, 2028 (suspended): Full implementation across all applicable DoD contracts above the micro-purchase threshold. Also on hold.

What applies in the meantime: During the review, the DoW is enforcing cybersecurity through NIST SP 800-171 Rev 2 self-assessments and DFARS 252.204-7012 — the safeguarding obligation that never went away. A CMMC Reform Task Force will report to the DoW CIO within 60 days, drawing on a public request for information due August 14, 2026.

You can visit the official DoD CMMC program page for more detailed information and resources.

The G-code piece of your CMMC plan. Traceability, compliance, and control — all in a GovCloud-hosted platform.

The G-code piece of your CMMC plan. Traceability, compliance, and control — all in a GovCloud-hosted platform.

Similar Posts