Status snapshot
- Last verified:
- June 29, 2026
- Status sources:
- 32 CFR part 170; DFARS subpart 204.75; DFARS 252.204-7021; DFARS 252.204-7025; DoD CMMC official resources.
- Maintenance note:
- Reverify after any DoD CMMC rulemaking, DFARS class deviation, acquisition-policy update, or official CMMC program guidance change.
Current status
The CMMC program is codified at 32 CFR part 170. It is designed to ensure defense contractors properly safeguard FCI and CUI processed, stored, or transmitted on contractor information systems. The DFARS acquisition rule and clauses provide the contract mechanism for including CMMC requirements in applicable DoD solicitations and contracts.
Contractors should read each solicitation and contract carefully. The required CMMC status, level, assessment type, timing, and affirmation obligations depend on the procurement and the applicable phase-in rules.
What the phase-in means
The CMMC phase-in is not a general announcement that every contractor instantly needs the same certification for every DoD contract. It is a staged implementation approach that allows DoD to include CMMC requirements in applicable solicitations and contracts over time.
Under 32 CFR part 170, Phase 1 begins on the effective date of the complementary DFARS acquisition final rule. Phase 1 focuses on Level 1 self-assessment or Level 2 self-assessment requirements for applicable contracts, with DoD discretion to include Level 2 C3PAO requirements in place of Level 2 self-assessment. Later phases expand the use of Level 2 C3PAO and Level 3 DIBCAC requirements.
Why contractors should prepare before the clause appears
When a solicitation requires CMMC status as a condition of award, it may be too late to start from zero. CMMC readiness requires scope definition, control implementation, policies, procedures, evidence, assessment preparation, supplier coordination, and executive affirmation. Level 2 certification assessment capacity and remediation timelines can also affect bid strategy.
Contractors should prepare when they expect to handle FCI or CUI for DoD, even before a specific solicitation includes the CMMC clause.
What to check in each solicitation
For each DoD opportunity, contractors should check:
- whether DFARS 252.204-7025 appears as a solicitation provision;
- whether DFARS 252.204-7021 appears as a contract clause;
- what CMMC level is required;
- whether the requirement is Level 1 self, Level 2 self, Level 2 C3PAO, or Level 3 DIBCAC;
- whether the status must exist at award, option exercise, or another milestone;
- whether CUI or FCI will be processed, stored, or transmitted;
- whether subcontractors need the same or a different status;
- whether SPRS assessment information must be current; and
- whether any POA&M or conditional status is permitted under the applicable rule.
CMMC and existing DFARS obligations
CMMC does not replace existing DFARS 252.204-7012 obligations. Contractors handling covered defense information must still address safeguarding, incident reporting, malicious software submission, media preservation, damage assessment support, cloud-service requirements, and flowdowns when 7012 applies.
CMMC also does not eliminate the need for accurate SPRS information under DFARS 252.204-7019 and 252.204-7020 when those clauses apply.
Contractor planning steps
- Identify expected DoD opportunities and likely data types.
- Map FCI, CUI, covered defense information, systems, users, administrators, and suppliers.
- Define the CMMC assessment scope.
- Confirm whether the organization needs Level 1, Level 2 self, Level 2 C3PAO, or Level 3 planning.
- Build or update SSPs, policies, procedures, and evidence.
- Validate NIST SP 800-171 implementation for Level 2 environments.
- Review SPRS scores and supporting evidence.
- Remediate gaps before solicitation deadlines.
- Prepare annual affirmations and executive ownership.
- Flow requirements to subcontractors and verify supplier readiness.
Educational content only. This page provides general information for educational purposes. It does not constitute legal advice and does not create an attorney-client relationship. Contractors should consult qualified legal counsel and review official DoD sources for their specific CMMC obligations.