in effect
This is a final rule from the Department of Defense that updates the Defense Federal Acquisition Regulation Supplement (DFARS) to make the Cybersecurity Maturity Model Certification (CMMC) program a formal requirement in defense contracts. It translates the existing CMMC program rules (already codified separately at 32 CFR part 170) into binding contract language that contracting officers and defense suppliers must follow.
Defense contractors must now have a current, verified CMMC certification or self-assessment on file in the government’s Supplier Performance Risk System (SPRS) before they can be awarded a DoD contract, task order, or delivery order that involves handling federal contract information (FCI) or controlled unclassified information (CUI). For the first three years after the rule’s effective date of November 10, 2025, program managers decide which contracts require CMMC; after that three-year window, CMMC applies automatically to any contract where the contractor’s systems will process, store, or transmit FCI or CUI. Contracts are assigned one of four certification levels — Level 1 (Self), Level 2 (Self), Level 2 (third-party assessed), or Level 3 (government-assessed) — and the required level is stated directly in the solicitation. A contractor with a conditional CMMC status (meaning they have a plan of action to close remaining gaps) may still receive an award, but only for Levels 2 and 3 and only for up to 180 days. Contracts exclusively for commercially available off-the-shelf (COTS) products are excluded from the requirement entirely.
Any company that bids on or holds DoD contracts where their computer systems will handle federal contract information or controlled unclassified information must obtain and maintain the appropriate CMMC certification level before award. Subcontractors are also affected: prime contractors must flow the CMMC requirement down to any subcontractor whose own systems will process, store, or transmit FCI or CUI during performance, and those subcontractors must likewise enter their assessment results and annual compliance affirmations into SPRS.