CMMC compliance stopped being a future problem on 10 November 2025. That is the day the DFARS acquisition rule took effect and Phase 1 began — and it started a clock that most defense contractors are reading a year late.
Phase 2 begins on 10 November 2026. That is the point at which a Level 2 self-assessment stops being enough and third-party certification becomes a condition of contract award. If you handle Controlled Unclassified Information and you are relying on a self-assessment today, you have under three months.
What CMMC compliance actually is
The Cybersecurity Maturity Model Certification Program is set out in 32 CFR Part 170. It does not invent new security requirements. It is a verification regime bolted onto requirements that already existed — principally NIST SP 800-171 — because DoD concluded that self-attestation alone was not producing the security it had been paying for.
That distinction matters for how you plan. The controls are not new. What is new is that somebody else now checks them, and that a contract award can turn on the result.
The three CMMC compliance levels
| Level | Applies to | How it is assessed |
|---|---|---|
| Level 1 | Federal Contract Information (FCI) | Annual self-assessment, with an annual affirmation |
| Level 2 | Controlled Unclassified Information (CUI) | Self-assessment or C3PAO certification every three years, depending on the contract — this is the level Phase 2 changes |
| Level 3 | CUI in programs at highest risk | Assessed by DIBCAC, the government’s own assessment centre |
Most of the defense industrial base lands at Level 2. That is also where the cost and the lead time sit, because a C3PAO assessment has to be booked, paid for and passed.
The four CMMC compliance phases

32 CFR 170.3(e) sets out a four-phase rollout. Phase 1 began on the effective date of the DFARS acquisition rule; each later phase begins one calendar year after the one before it.
| Phase | Begins | What changes |
|---|---|---|
| Phase 1 | 10 November 2025 | Level 1 (Self) or Level 2 (Self) as a condition of award. Level 2 (C3PAO) at DoD’s discretion |
| Phase 2 | 10 November 2026 | Level 2 (C3PAO) as a condition of award. Level 3 (DIBCAC) at DoD’s discretion |
| Phase 3 | 10 November 2027 | Level 2 (C3PAO) for all applicable solicitations and to exercise an option period. Level 3 (DIBCAC) as a condition of award |
| Phase 4 | 10 November 2028 | Full implementation across all applicable solicitations and contracts |
Two things about that table are worth stating plainly.
The dates are derived, not published as a list. 32 CFR 170.3(e) says Phase 1 begins on the effective date of the complementary 48 CFR Part 204 acquisition rule, and that each subsequent phase begins one calendar year later. That rule is 90 FR 43560, effective 10 November 2025. Everything else follows from that one date.
“DoD intends to” is not “DoD must”. The regulation describes intent and reserves discretion throughout — DoD may include a higher requirement earlier, or defer one to an option period. Planning to the phase boundary is planning to the latest possible date, not the earliest.
Why Phase 2 is the one that bites
Phases 1, 3 and 4 broaden something already happening. Phase 2 changes the kind of evidence you need.
Under Phase 1, a Level 2 contractor can self-assess, submit the score, affirm it, and bid. Under Phase 2, DoD intends to make Level 2 (C3PAO) — an assessment by an accredited third party — a condition of award for applicable contracts.
The practical consequences are the ones organisations underestimate:
- C3PAO capacity is finite. There are far more contractors handling CUI than there are accredited assessment organisations, and every one of them faces the same date.
- You cannot pass with open POA&Ms on the wrong controls. Conditional status has a limited life and specific rules about what may remain open.
- Remediation is slower than assessment. If the assessment finds gaps, the fix is engineering work, not paperwork — and it happens after you have already waited for a slot.
What CMMC compliance requires you to have
At Level 2, the substance is NIST SP 800-171: 110 controls across fourteen families. Around that sits the CMMC-specific machinery.
- A defined CUI boundary. Which systems process, store or transmit CUI. Get this wrong and every downstream artefact describes the wrong thing.
- A System Security Plan. The single document an assessor reads first, describing how each control is met for that boundary.
- A Plan of Action and Milestones. What is not met, what is being done, by when.
- An SPRS score. Submitted and current.
- An annual affirmation by a senior official, which carries personal exposure under the False Claims Act.
- Evidence that the controls actually operate — logs, tickets, records, screenshots with dates. An assessor tests operation, not intent.
The last one is where most first assessments fail. A policy stating that access is reviewed quarterly is not evidence; four dated review records are.
The flow-down nobody budgets for
CMMC compliance follows CUI down the supply chain. If you pass CUI to a subcontractor, that subcontractor needs its own CMMC status — and § 170.23 governs how that is determined.
Two failure modes recur. Primes discover late that a critical small supplier cannot certify in time and has no plan to. And subcontractors discover that they were sent CUI they never asked for, which put them in scope without a conversation.
Both are supply chain problems with a procurement fix, and both are cheaper to solve twelve months out than three.
Where CMMC compliance sits against other frameworks
If you already run an information security programme, you are not starting from zero — but do not assume equivalence.
| If you have | What it buys you |
|---|---|
| ISO 27001 | Risk assessment, asset management, access control and incident practice that maps substantially onto 800-171 — but ISO 27001 certification is not a CMMC status and does not substitute for an assessment |
| NIST CSF | A governance structure and a common vocabulary. CSF is outcome-based; 800-171 is control-based and prescriptive |
| FedRAMP-authorised cloud | Helps where CUI sits in that cloud, and matters for the external service provider question — but does not cover your own boundary |
The gap in every case is the same: those frameworks tell you how to run security. CMMC asks you to prove a specific control set, for a specific boundary, to somebody else’s satisfaction, on a schedule.
What to do before 10 November 2026
Working backwards from Phase 2, in order:
- Confirm your level and your boundary. Do you handle CUI, or only FCI? Everything else depends on that answer, and it is a determination to be recorded, not assumed.
- Run a gap assessment against all 110 controls and be honest about which are met in practice rather than on paper.
- Book the C3PAO now if you will need Level 2 (C3PAO). Capacity is the binding constraint, not readiness.
- Close the gaps that cannot sit in a POA&M, and be clear about which those are.
- Build the evidence trail — dated records showing the controls operating, not just documents saying they should.
- Handle flow-down: identify which subcontractors receive CUI and confirm their status and their plan.
Steps 3 and 5 are the ones with lead times measured in months. Start there.
A note on dates
The phase dates in this guide are derived from 32 CFR 170.3(e) and the effective date of 90 FR 43560. They are correct as at 15 August 2026. DoD retains discretion within each phase, and acquisition rules can be amended — check the regulation before making a contractual commitment on the strength of a date.
The CMMC Toolkit provides 107 editable documents covering the Level 2 control set, the System Security Plan, the POA&M, the affirmation record and the flow-down assessment — the artefacts a C3PAO asks for, in the order they ask for them. If your programme also touches NIST SP 800-171 directly, the NIST SP 800-171 Toolkit covers the underlying control set.