CMMC became a hard condition of contract award for the first time on November 10, 2025, the effective date of DoD's DFARS 252.204-7021 final rule. The next deadline that changes what shows up in solicitations is November 10, 2026, when DoD's phase-in plan calls for Level 2 third-party certification to become the standard condition of award, rather than a discretionary substitute for self-assessment. In between, plenty of contractors are still fuzzy on what each level requires, what "affirmation" means versus "assessment," and which phase-in date actually applies to them. The program itself is codified at 32 CFR Part 170, effective December 16, 2024, and it sorts contractors into three tiers based on what they touch: Federal Contract Information (FCI), or the more sensitive Controlled Unclassified Information (CUI).
CMMC replaces an honor-system regime that DoD had run since a 2020 interim rule let contractors self-attest to NIST SP 800-171 compliance with no outside check. That approach produced years of self-reported scores DoD had no reliable way to verify. CMMC's answer is a tiered structure where the level assigned to your contract — driven by whether you'll touch FCI, CUI, or nothing sensitive at all — determines whether a self-assessment is still enough or whether an outside assessor has to sign off.
The Three Levels
Level 1 (Foundational) applies if you process, store, or transmit FCI and nothing more sensitive. It carries 15 basic safeguarding requirements pulled directly from FAR 52.204-21(b)(1) — things like limiting system access to authorized users and sanitizing media before disposal. You self-assess annually, score yourself in the Supplier Performance Risk System (SPRS), and there is no partial credit: 32 CFR 170.15 explicitly bars Plans of Action and Milestones (POA&Ms) at Level 1. You either meet all 15 or you don't have a CMMC Status.
Level 2 (Advanced) is where CUI work lives, and it is exactly the 110 security requirements in NIST SP 800-171 Revision 2 — not a CMMC-specific rewrite of them. Depending on what the contract's clause fill-in specifies, you achieve this either through self-assessment (Level 2 Self) or a paid certification assessment from a CMMC Third-Party Assessment Organization, a C3PAO (Level 2 C3PAO). Unlike Level 1, a limited POA&M is allowed for unmet requirements, but it has to close out — remediated and re-verified — within 180 days of your Conditional status date, or the status expires. Whichever route you take, the underlying assessment is valid for three years before you have to redo it.
Level 3 (Expert) is reserved for DoD's most sensitive programs and stacks 24 additional requirements, selected from NIST SP 800-172, on top of everything in Level 2 — 134 total. Unlike Level 2, there's no self-assessment or commercial C3PAO option: Level 3 is assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a government team, and it runs on a three-year reassessment cycle. It also has a prerequisite most contractors don't expect — you need a Final Level 2 (C3PAO) status on the same assessment scope before DIBCAC will even start a Level 3 evaluation.
The Phase-In Timeline
DoD is not flipping CMMC on for every contract at once. 32 CFR 170.3(e) lays out four phases, each beginning one calendar year after the last:
- Phase 1 (Nov. 10, 2025): Level 1 (Self) or Level 2 (Self) becomes a condition of award for applicable solicitations. DoD can substitute Level 2 (C3PAO) at its discretion, but isn't required to yet.
- Phase 2 (Nov. 10, 2026): DoD's stated plan is for Level 2 (C3PAO) to become a condition of award, though the rule preserves discretion to push it to a later option period instead. DoD also gains discretion to add a Level 3 (DIBCAC) requirement.
- Phase 3 (Nov. 10, 2027): Level 2 (C3PAO) applies to all applicable contracts and to exercising options on contracts awarded after the rule took effect. Level 3 (DIBCAC) becomes a condition of award where applicable.
- Phase 4 — full implementation (Nov. 10, 2028): CMMC requirements apply to all applicable DoD solicitations and contracts, including option periods on contracts awarded before Phase 4 began.
Two carve-outs matter here: the requirement only attaches above the micro-purchase threshold, and awards made exclusively for commercially available off-the-shelf (COTS) items are excluded entirely, regardless of level.
Assessment vs. Affirmation — the Part People Conflate
The assessment cadence differs by level and by path — annual for Level 1, three years for a Level 2 or Level 3 certification. Affirmation does not follow that clock. Under 32 CFR 170.22, a designated senior "Affirming Official" at your company must submit a signed statement in SPRS attesting to continuing compliance annually, at every level, regardless of when your underlying assessment is due for renewal. Affirmation is also required immediately after achieving a Conditional or Final status and again after any POA&M closeout. It's entirely possible to be current on your three-year Level 2 certification and still be out of compliance because nobody filed this year's affirmation.
What It Means for Contractors
- Confirm the clause fill-in in your solicitation or contract before assuming CMMC applies — no FCI or CUI in scope, or an award that's exclusively COTS items, means no CMMC requirement regardless of level.
- If you're pursuing CUI work, treat Level 2 as the level to plan around now. Self-assess this year even if your current contracts only specify Level 1 — Phase 2 is when DoD plans to make C3PAO certification the default on applicable awards, and certification bodies book out.
- Subcontractors aren't exempt: primes are required to flow the appropriate CMMC level down to subs that will handle FCI or CUI, per 32 CFR 170.23. Check your subcontract terms now, not after a prime asks for your SPRS score.
- Put your annual affirmation on a separate calendar reminder from your assessment renewal date — they run on different clocks, and missing the affirmation alone is enough to lose your CMMC Status.
- If you self-assess at Level 2 and land on a POA&M, the 180-day closeout clock starts on your Conditional status date, not when you notice the gap. Start remediation immediately.
- Contracting officers check CMMC Status in SPRS before award, not after — an incomplete or expired affirmation there is a contract-eligibility problem, not a paperwork footnote you can clean up post-award.
Sources
- eCFR — 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (current as of July 2026)
- Federal Register — Cybersecurity Maturity Model Certification (CMMC) Program, final rule (Oct. 15, 2024; effective Dec. 16, 2024)
- Federal Register — DFARS: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041), final rule (Sept. 10, 2025; effective Nov. 10, 2025)
- Acquisition.gov — DFARS 252.204-7021, Contractor Compliance With the CMMC Level Requirements
- Acquisition.gov — FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems