Executive Summary
The Cybersecurity Maturity Model Certification (CMMC) program stopped being optional on November 10, 2025. That is the date the Department of Defense's final DFARS rule — 252.204-7021 — took effect, formally requiring contractors to hold a current CMMC status before contract award on applicable solicitations.1 For small and mid-size defense contractors and subcontractors, the practical challenge is rarely understanding that CMMC applies. It is building the documentation — the System Security Plan, the Plan of Action and Milestones, the evidence trail — that an assessor or a prime contractor can actually verify. This article walks through what changed with the final rule, what a C3PAO or DIBCAC assessment actually checks for, and what a readiness documentation package looks like in practice. It reflects publicly available regulatory sources and KS Tech Group's own analysis of the documentation-organization problem; it is not a substitute for a certified assessment or legal advice.
Table of Contents
- Background
- Current Landscape
- Key Challenges
- Research Findings & Analysis
- Practical Recommendations
- Key Takeaways
- FAQ
- References
Background
CMMC did not appear overnight. Its roots go back to 2016, when the DoD amended the Defense Federal Acquisition Regulation Supplement (DFARS) to require contractors handling Covered Defense Information to comply with NIST Special Publication 800-171 and to report cyber incidents.2 That requirement was largely self-attested, and the DoD grew concerned that many primes and subcontractors were not actually meeting it.2 CMMC was built to close that verification gap: instead of contractors simply attesting to compliance, an independent framework would confirm it.
The program went through a significant revision in 2021, streamlining an original five-level model down to the three-level structure known today as CMMC 2.0.6 The program rule (32 CFR Part 170) was finalized in October 2024 and took effect in December 2024, but for nearly a year afterward, DoD contracting officers were not yet authorized to write CMMC requirements into actual contracts.11 That changed with the second rule — the DFARS acquisition rule — which was published September 10, 2025 and took effect November 10, 2025.7,9 That is the date CMMC became contractually real.
Current Landscape
As of this writing, CMMC is rolling out in four phases over three years:6,10
- Phase 1 (November 10, 2025): Self-assessed Level 1 and Level 2 status begins appearing in new solicitations and contracts, with some Level 2 C3PAO assessments included at DoD's discretion.
- Phase 2 (November 10, 2026): C3PAO-assessed Level 2 status becomes required for applicable contracts; DIBCAC-assessed Level 3 may also appear.
- Phase 3 (November 10, 2027): DIBCAC-assessed Level 3 becomes required where applicable.
- Phase 4 (November 10, 2028): Full program implementation across all applicable DoD contracts.11
The three levels map to the sensitivity of the information a contractor handles:
- Level 1 applies to contractors handling Federal Contract Information (FCI) and requires the 15 basic safeguarding controls in FAR 52.204-21, verified by self-assessment.7
- Level 2 applies to contractors handling Controlled Unclassified Information (CUI) and is based on the 110 security controls in NIST SP 800-171. Most Level 2 contracts will require a third-party (C3PAO) assessment; a smaller set of non-prioritized acquisitions may allow self-assessment.10,14
- Level 3 adds 24 enhanced requirements from NIST SP 800-172 aimed at Advanced Persistent Threats, for the highest-sensitivity CUI. It is assessed by DIBCAC, a government body, rather than a commercial C3PAO.10
One detail worth flagging for anyone budgeting a readiness timeline: the assessed technical baseline right now is still NIST SP 800-171 Revision 2 (110 controls across 14 families), not the newer Revision 3 (finalized May 2024, reorganized into 97 requirements across 17 families). A DoD class deviation has kept Revision 2 in force for DFARS assessments, so contractors preparing for a near-term assessment should build their System Security Plan against Revision 2 unless their contracting officer specifies otherwise.17,18
The scale of the coming assessment wave is significant: the DoD estimates roughly 80,000 contractors in the Defense Industrial Base will need a C3PAO-assessed Level 2 certification.10 That is a large number of organizations competing for a limited pool of accredited assessors, which is itself a scheduling risk worth planning around.
Key Challenges
Documentation, not just controls, is what gets assessed. A C3PAO assessor is not simply checking whether a firewall exists. They are checking whether a System Security Plan (SSP) accurately describes the environment, whether a Plan of Action and Milestones (POA&M) exists for any gaps, and whether there is evidence — screenshots, logs, configuration exports, policy documents — tying each of the 110 controls to something verifiable. Organizations that have good technical controls but poor documentation discipline often struggle here more than organizations with modest controls and excellent records.
Enforcement risk is not theoretical. The DoD's Civil Cyber-Fraud Initiative treats a misrepresented CMMC or cybersecurity status as a potential False Claims Act violation, carrying civil penalties, treble damages, and the possibility of exclusion from future contracts.7,14 The Department of Justice reported recovering $52 million in FY2025 alone connected to cybersecurity noncompliance matters.14 That risk applies whether the misstatement was deliberate or simply the result of sloppy internal record-keeping.
Assessor capacity is a real bottleneck. With an estimated 80,000 contractors needing Level 2 certification and a finite number of accredited C3PAOs, organizations that wait until a contract award is on the line to start their readiness work may find themselves in a scheduling queue they don't control.10
Small businesses face a disproportionate documentation burden. A large prime can dedicate a compliance team to SSP maintenance. A small subcontractor is often building this documentation for the first time, without a governance, risk, and compliance function already in place — which is precisely why NIST published a small business primer alongside SP 800-171 Revision 3.20
Research Findings & Analysis
The following section reflects KS Tech Group's analysis of publicly available regulatory material, not a proprietary research study or client engagement data.
Reviewing the structure of the final rule and the documentation expectations built into DFARS 252.204-7021 and 252.204-7025 suggests a few patterns worth naming directly:
- The SSP is the anchor document. Nearly every other artifact — the POA&M, the evidence repository, the SPRS score — exists to support or verify claims made in the System Security Plan. Organizations that treat the SSP as a living document, updated as the environment changes, tend to have a much shorter path to assessment than organizations that write it once and let it drift out of sync with reality.
- SPRS submission is a prerequisite most contractors underestimate. DFARS 252.204-7019 and 252.204-7020 require a current NIST SP 800-171 assessment score on file in the Supplier Performance Risk System before award eligibility.14,17 An organization that has never submitted an SPRS score has a documentation gap before it even reaches the C3PAO conversation.
- Organization-Defined Parameters (ODPs) add a compliance dimension that is easy to miss. Revision 3 introduces ODPs — fields where an organization or governing agency must specify a concrete value (a frequency, a threshold) rather than relying on vague language like "periodically." The DoD published mandatory values for 88 ODPs in April 2025.21 Even though Revision 2 remains the current assessed baseline, this is a strong signal of where documentation specificity is heading, and organizations building an SSP today benefit from writing concrete, auditable parameters rather than generic language.
- Readiness work and acquisition-support work overlap more than they first appear to. Building a defensible evidence package is fundamentally a documentation and process-organization problem, not purely a technical one — which is why acquisition support and compliance documentation functions often sit closer together operationally than an org chart might suggest.
Practical Recommendations
- Start with a gap assessment against NIST SP 800-171 Revision 2, not Revision 3, unless a specific contract vehicle instructs otherwise. Confirm this with your contracting officer if there is any ambiguity.
- Treat the SSP as version-controlled documentation, not a one-time deliverable. Every change to your environment — a new cloud service, a new remote-access tool — should trigger an SSP review.
- Build your evidence repository alongside the SSP, not after it. For each of the 110 controls, keep a corresponding artifact (screenshot, config export, policy document, log sample) so that responding to an assessor's request is a retrieval exercise, not a scramble.
- Submit or refresh your SPRS score early. This is a documented prerequisite, not a formality, and it surfaces gaps before a C3PAO conversation.
- If you will need a C3PAO assessment, start scheduling conversations now. With an estimated 80,000 contractors needing Level 2 certification against a limited assessor pool, timeline risk is real.
- If cloud services touch Controlled Unclassified Information, confirm FedRAMP Moderate baseline compliance for that cloud service provider, as required under DFARS 252.204-7012.9
- Never submit a CMMC or NIST 800-171 status you cannot fully support with documentation. The Civil Cyber-Fraud Initiative treats misrepresentation as a False Claims Act matter, independent of intent.7,14
Key Takeaways
- CMMC has been contractually enforceable since November 10, 2025, and is rolling out in phases through November 2028.
- The current assessed technical baseline is NIST SP 800-171 Revision 2 (110 controls), not the newer Revision 3.
- Most Level 2 contracts will require third-party (C3PAO) assessment, not self-assessment.
- Documentation quality — the SSP, POA&M, and evidence trail — is frequently the deciding factor in assessment readiness, not just technical controls.
- Misrepresenting CMMC status carries real False Claims Act exposure, with active DOJ enforcement.
FAQ
Is CMMC certification mandatory yet?
Yes, as of November 10, 2025, under the DFARS final rule (252.204-7021), in a phased rollout running through November 2028.7,9
Do I need a C3PAO assessment or can I self-assess?
It depends on your level and contract. Level 1 is always self-assessed. Most Level 2 contracts handling CUI will require a C3PAO assessment; a smaller set of non-prioritized acquisitions may permit self-assessment. Level 3 requires a government-led DIBCAC assessment.10
Which NIST 800-171 revision applies right now?
Revision 2 remains the current assessed baseline. Revision 3 was finalized in May 2024 and is expected to eventually apply, but a DoD class deviation currently keeps Revision 2 in force for DFARS assessments.17,18
References
- Arnold & Porter, "CMMC Final Rule: Key Takeaways for Defense Contractors" (Sept. 2025)
- Davis Wright Tremaine, "Department of Defense Issues Final Rule to Implement CMMC Program" (2025)
- Morgan Lewis, "DOD Finalizes CMMC Rules, Adding Cybersecurity and False Claims Act Compliance Risks" (Oct. 2025)
- Secureframe, "The CMMC 2.0 Timeline: When Will CMMC 2.0 Go Into Effect?"
- Godlan, "CMMC 2.0 Deadlines and Rules: Your Complete 2025 Compliance Guide"
- Elevate Consult, "CMMC 2.0 Certification: DoD Contractor Guide for 2026"
- Intersec, "Federal Contractor's Guide to CMMC 2.0"
- Ryan & Wetmore, "New CMMC Rule: Crucial Cybersecurity Changes for Defense Contractors"
- Summit 7, "What is NIST 800-171? Six Things to Know about Revision 3"
- PreVeil, "Understand NIST 800-171 Compliance & How to Achieve It"
- Isora GRC, "NIST SP 800-171: Complete Guide [2026]"
- ComplianceForge, "NIST 800-171 Rev 3 Compliance Resource Center"
- NIST CSRC, "Small Business Primer for Protecting CUI" (2025)
- ISI Defense, "What Are the NIST 800-171 Requirements? Understanding Rev3 Changes"
Note: hyperlinks are omitted in favor of source citations above; readers are encouraged to verify current requirements directly against NIST and DoD primary sources, as guidance in this area continues to evolve.
Further Reading
- NIST SP 800-171 Rev. 2 and Rev. 3, published by NIST CSRC
- 32 CFR Part 170 (CMMC Program Rule) and DFARS 252.204-7021 (Federal Register)
- SPRS (Supplier Performance Risk System) documentation, DoD Procurement Toolbox
Related Articles
Research by KS Tech Group.