CMMC 2.0 · Deadlines

What Defense Contractors Need to Know

If your company handles Department of Defense work, cybersecurity certification is now a condition of doing business.

The final CMMC 2.0 rule took effect November 10, 2025.
DoD contracts now carry certification requirements that will determine eligibility.

What changed

  • For years, defense contractors could largely self-attest to their cybersecurity practices. CMMC 2.0 essentially ends that.
  • The framework now requires verified assessments and pushes accountability down through the entire supply chain — because the threats targeting defense contractors have grown faster than many contractors’ defenses.
  • Published September 10, 2025 and effective 60 days later, the rule makes certification a prerequisite for contract award.
  • If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), this affects how you secure, store, and move that data across every system you run.

The four-phase rollout

  • The DoD is phasing in CMMC over three years, with each phase tightening requirements and widening the pool of contracts affected.
  • Benchmark where you are in your CMMC journey and avoid a gap that could cost you an award.
01
Phase 1

Nov 10, 2025 – Nov 9, 2026

  • DoD begins writing Level 1 and Level 2 requirements into new solicitations, and self-assessment is enough to satisfy both levels for now.
  • You still have to complete that assessment before a contract can be awarded.
02
Phase 2

Specified Date on Hold and Awaiting Government Guidance

  • The bar rises for Level 2.
  • Contracts at that level now demand a third-party assessment from a certified C3PAO.
  • Level 1 can still self-assess.
  • Because C3PAO assessments take real lead time — and assessor availability is limited — anyone handling CUI should be building toward C3PAO readiness at least six months before this phase opens.
03
Phase 3

Specified Date on Hold and Awaiting Government Guidance

  • CMMC spreads across a much broader set of contracts and enforcement gets stricter.
  • This is also where supply-chain responsibility bites: before a supplier can touch CUI, you’re expected to confirm their CMMC status.
04
Phase 4

Specified Date on Hold and Awaiting Government Guidance

  • Full implementation.
  • CMMC applies to every applicable DoD contract and solicitation, with no exceptions and no waivers.
  • Expect ongoing monitoring and periodic re-certification, and full accountability throughout your supply chain.

At this point compliance is an operating requirement you maintain, and one you’re responsible for enforcing on your suppliers.

Questions about your CMMC timeline?
Contact Us