Copyright i3solutions. All Rights Reserved.
Email aski3@i3solutions.com - Phone 703.652.8966
Privacy Policy | Sitemap
The requirement does not arrive as an announcement. It arrives inside a solicitation or an option year, printed in a clause, and by the time you read it there you need an answer rather than a project. What applies to your organization is not decided by your company size or by a single deadline on a calendar. It is decided by the kind of information your contracts require you to handle and by the clause each contract carries. That is knowable now, before the clause shows up, which is the whole point of reading this before you have to.
This is guidance on how the Cybersecurity Maturity Model Certification requirement is structured so you can locate yourself inside it. It is not legal or contractual advice, and where a regulatory date is still moving we say so rather than commit you to a number that ages badly.
Quick Answer
CMMC applicability is determined by the type of information a contract requires you to handle and by the clause that contract carries, not by company size or by a general deadline. Determine the information type in scope, identify the level that follows from it, confirm what the phase-in stage requires at the point your contracts renew or new work is bid, and work backward from the earliest contract date rather than from the program’s outermost date. The organizations that get caught are the ones that planned to the latest date rather than to their own first affected contract.
How CMMC Reaches You: The Clause, Not the Calendar
CMMC does not apply to you because a general deadline passed. It applies because a specific contract tells it to. The mechanism is a contract clause. The Department of Defense finalized the CMMC Program in a rule at 32 CFR Part 170, published in the Federal Register on October 15, 2024 and effective December 16, 2024 (32 CFR Part 170, Federal Register doc 2024-22905). That rule defines the program: the levels, the assessment types, and the rollout. It does not by itself put a requirement into your contract.
The requirement lands through acquisition. The DFARS clause 252.204-7021, “Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements,” obligates a contractor to have and maintain a current CMMC status at the level the contracting officer specifies, for the duration of that contract (DFARS 252.204-7021, acquisition.gov). So the practical trigger is not a date you circle. It is the moment that clause appears in a solicitation you want to bid or in an option year you want to exercise. If you hold or pursue DoD contracts that involve Federal Contract Information or Controlled Unclassified Information, your job is to know which level that clause will carry before you see it, not after.
What the “final rule” means for you, then, is narrow and useful: the program is settled, the levels are fixed, and the countdown to seeing the clause in your contracts has started. It does not mean every contract carries it today.
Determining Your Level: What the Information You Handle Decides
The level is a function of the data, not of your revenue or headcount. Under 32 CFR Part 170 the program defines three levels, and the information type in scope points to one of them (32 CFR Part 170, Federal Register doc 2024-22905):
- Level 1 covers Federal Contract Information and is met through an annual self-assessment against the 15 security requirements in FAR clause 52.204-21.
- Level 2 covers Controlled Unclassified Information and is measured against the 110 security requirements of NIST SP 800-171 Revision 2. Depending on what the contract specifies, Level 2 is met either by self-assessment or by a certification assessment conducted by a Certified Third-Party Assessment Organization.
- Level 3 applies to the subset of programs handling CUI under the highest risk, adds 24 selected requirements drawn from NIST SP 800-172 on top of the Level 2 baseline, and is assessed by the government’s Defense Industrial Base Cybersecurity Assessment Center.
To place yourself, answer one question first: does any contract you hold or intend to bid require you to receive, store, or transmit CUI? If yes, you are in Level 2 territory at minimum, and 110 controls is your working number. If your contracts involve only Federal Contract Information and never CUI, Level 1 is the likely ceiling. Level 3 is reserved and will be named explicitly in the contract when it applies. The determination you can make today is which category your data falls into, because that is the input the clause will read from.
The Microsoft-environment question that usually follows, whether your Microsoft 365 tenant can hold the data at the level you need, is a separate decision with its own page. If that is where your uncertainty is, see whether Office 365 can be CMMC compliant.
The Phase-In Stages and What Each One Requires
The program does not switch on for everyone at once. 32 CFR Part 170 lays out a four-phase rollout, and each phase begins one calendar year after the phase before it (32 CFR Part 170, Federal Register doc 2024-22905). In broad terms the phases escalate what a contracting officer may require in a solicitation:
- Phase 1 introduces Level 1 and Level 2 self-assessment requirements into applicable solicitations.
- Phase 2, one year later, begins to require Level 2 certification assessments where the contract calls for them.
- Phase 3, one year after that, begins to require Level 3 certification assessments where applicable.
- Phase 4, the following year, is full implementation, at which point CMMC requirements apply to all applicable DoD solicitations and contracts, including option years.
The date that matters is when the clock starts. Under the rule, Phase 1 begins on the effective date of the 32 CFR program rule or of the companion 48 CFR CMMC Acquisition rule, whichever occurs later (32 CFR Part 170, Federal Register doc 2024-22905). The 32 CFR rule has been effective since December 16, 2024. The 48 CFR acquisition rule that actually puts the clause into contracts is the gating event, and its effective date has moved during rulemaking. Rather than print a number that may already be stale by the time you read this, confirm the current 48 CFR effective date and the resulting Phase 1 start against the official source before you plan to it: the DFARS text and status live at acquisition.gov, and the DoD CMMC program office publishes the current schedule at dodcio.defense.gov/CMMC.
Two honest points follow from this. First, schedules in this program have shifted before, so any single date is a planning input, not a guarantee. Second, the shifting outer date is exactly the trap: the phase-in ceiling is not your deadline. Your deadline is set by your own first affected contract, and that can land well inside the phase-in window.
Flow-Down: What This Means If You Are a Subcontractor
Most subcontractors underestimate this, because they assume the requirement stops at the prime. It does not. DFARS 252.204-7021 requires the prime to insert the substance of the clause into subcontracts and other contractual instruments whenever the subcontract involves processing, storing, or transmitting Federal Contract Information or Controlled Unclassified Information, and to flow down the correct CMMC level to those subcontracts consistent with 32 CFR 170.23 (DFARS 252.204-7021, paragraphs (f)(1) and (d)(1)(ii), acquisition.gov).
The practical consequence is that responsibility for compliance sits with the entity that handles the data, not only with the entity that signed the prime contract. If you are a subcontractor who touches CUI, you may need your own Level 2 status even though you never see the government contract directly. Do not wait for a prime to tell you your level. If you handle CUI on defense work, assume flow-down reaches you, and confirm the level with the prime rather than discovering it when an award is contingent on it.
Working Backward From Your First Affected Contract
The sequencing question is not “when is the deadline,” it is “when is my first affected contract.” Build the timeline from that date, not from the program’s outer edge. The steps in order:
- List the DoD contracts and target solicitations that involve FCI or CUI, and note each one’s renewal, option-year, or expected bid date.
- For each, determine the level the data implies (Level 1 for FCI only, Level 2 for CUI).
- Find the earliest of those dates. That is your real deadline, because being ineligible to bid or non-compliant on a held award is the exposure, not the program’s final phase.
- Subtract the time your level’s assessment path actually takes. A Level 2 certification assessment through a third-party organization is a scheduled event with lead time, not a same-week action, so the work has to be done before the assessment, and the assessment before the clause bites.
There is an honest case for waiting, and it is worth stating plainly. If your earliest affected contract is genuinely far out, or if you are still confirming whether you handle CUI at all, spending on a certification assessment today can be premature. But waiting is a decision that comes with work, not a decision to do nothing. While you wait you should confirm your information type in scope, define your CUI boundary if you have one, and close the highest-risk gaps against NIST SP 800-171 Revision 2 so that when your first contract date resolves, the assessment is a confirmation rather than a scramble. The organizations that wait well are the ones that use the time; the ones that get caught are the ones that planned to the latest date and treated the interval as free.
What Has to Be True Before You Can Bid
By the time the clause appears in a solicitation you want, a specific set of things has to already be true. The clause requires a current CMMC status at the specified level for the duration of the contract, which means the status has to exist at award, not be in progress (DFARS 252.204-7021, acquisition.gov). Concretely, before you can bid you need:
- Your information type in scope settled, and the level that follows from it identified.
- The applicable assessment completed at that level, whether a Level 1 or Level 2 self-assessment or a Level 2 or Level 3 certification assessment.
- Your affirmation on file. Under 32 CFR Part 170 an Affirming Official must affirm continuing compliance in the Supplier Performance Risk System upon completing the assessment and annually after the Final CMMC Status Date (32 CFR Part 170, Federal Register doc 2024-22905). This is a recurring obligation, not a one-time filing.
If you do not meet the level the clause specifies, the consequence is contractual, not abstract: you are ineligible to be awarded that work, and on an award you already hold, a lapse in status is a compliance failure against the contract. That is why the timeline works backward from the contract date. When your uncertainty shifts from “which level and when” to “how do we get assessment-ready without disrupting operations,” that is a different job, and it lives on our guide to CMMC audit preparation.
Key Takeaways
- CMMC applies through a contract clause, DFARS 252.204-7021, not through a general deadline. The trigger is the clause appearing in a solicitation or option year.
- Your level follows from the data you handle: Level 1 for Federal Contract Information (15 requirements), Level 2 for Controlled Unclassified Information (110 requirements from NIST SP 800-171 Revision 2), Level 3 for the highest-risk CUI (an added 24 requirements from NIST SP 800-172).
- The rollout is four phases, each one year apart. Phase 1 starts on the later of the 32 CFR effective date (December 16, 2024) and the companion 48 CFR acquisition rule. Confirm the current 48 CFR date at acquisition.gov, since it has moved.
- Flow-down reaches subcontractors that handle FCI or CUI. If you touch the data, assume the requirement reaches you.
- Plan backward from your earliest affected contract, not from the program’s outer date. Waiting is only safe if you use the interval to scope, bound CUI, and close 800-171 gaps.
Frequently Asked Questions
Is CMMC compliance mandatory?
It is mandatory when a contract requires it. CMMC is not a blanket obligation on every company; it becomes mandatory for a given contractor through DFARS clause 252.204-7021, which requires a current CMMC status at the level the contracting officer specifies for the duration of that contract (DFARS 252.204-7021, acquisition.gov). As the phase-in proceeds under 32 CFR Part 170, that clause appears in progressively more DoD solicitations, so for organizations handling FCI or CUI on defense work it becomes effectively unavoidable over time.
Which DFARs clause requires CMMC?
DFARS clause 252.204-7021, “Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements,” is the clause that carries the CMMC requirement into a contract and specifies the level (acquisition.gov). It is distinct from the older DFARS 252.204-7012 safeguarding clause; 252.204-7021 is the one that ties the contract to a CMMC status.
Does CMMC only apply to DoD contracts?
The CMMC Program as established under 32 CFR Part 170 and implemented through the DFARS applies to Department of Defense contracts and to the subcontracts beneath them (32 CFR Part 170). It reaches an organization when it holds or pursues DoD work involving Federal Contract Information or Controlled Unclassified Information, including as a subcontractor through flow-down. It is not a general federal-wide certification imposed outside that acquisition path.
What companies need to be CMMC certified?
Companies in the defense supply chain that receive, store, or transmit Controlled Unclassified Information on DoD contracts are the ones that need a Level 2 certification assessment when their contract specifies it; companies handling only Federal Contract Information generally need a Level 1 self-assessment, which is affirmation rather than third-party certification. The determinant is the data and the clause, not the company’s size. Subcontractors are included where the requirement flows down under DFARS 252.204-7021 (acquisition.gov).
How often must an affirmation of CMMC compliance be submitted?
Under 32 CFR Part 170, the Affirming Official must submit an affirmation in the Supplier Performance Risk System upon completing the relevant self-assessment, certification assessment, or plan-of-action closeout, and annually thereafter following the Final CMMC Status Date (32 CFR Part 170, Federal Register doc 2024-22905). It is an annual, recurring obligation, not a one-time submission.
Schedule a 30-minute scoping call to confirm which CMMC level your contracts carry and build the timeline backward from your first affected award.
Related Reading
Once you know which level applies and when, the natural next questions are budget and execution: see what CMMC compliance actually costs, how a CMMC technology readiness assessment scopes the gap, and when to bring in CMMC technology consultants.