Skip to content

Cybersecurity Maturity Model Certification (CMMC) Program Proposed Rule

DoD Office of the Secretary|Proposed Rule
SupersededDW

Summary

The proposed rule for the CMMC Program published in December 2023, which was superseded by the final rule in October 2024. On July 13, 2026, the U.S. Department of War (DoW) announced it is suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to go into effect on November 10, 2026, while Phase I self-assessment requirements remain in place. In the interim, the Department will enforce cybersecurity compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, focused on cyber hygiene. The announcement notes that contractors remain contractually obligated to safeguard covered defense information under DFARS clause 252.204-7012 despite the suspension.
View Source Document

Key Dates

Date Issued
December 1, 2023
Last Updated
July 13, 2026

Topics

Relevant Roles

Research Security Officer / Export ControlIT / Cybersecurity Staff

Tags

dodcmmcproposed-rule

This document has been superseded by dod-cmmc-program

Version 2Updated description to reflect 7/13/2026 suspension of Phase II requirements.