Cybersecurity Maturity Model Certification (CMMC) Program Proposed Rule
DoD Office of the Secretary|Proposed Rule
SupersededDW
Summary
The proposed rule for the CMMC Program published in December 2023, which was superseded by the final rule in October 2024.
On July 13, 2026, the U.S. Department of War (DoW) announced it is suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to go into effect on November 10, 2026, while Phase I self-assessment requirements remain in place.
In the interim, the Department will enforce cybersecurity compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, focused on cyber hygiene. The announcement notes that contractors remain contractually obligated to safeguard covered defense information under DFARS clause 252.204-7012 despite the suspension.
Key Dates
- Date Issued
- December 1, 2023
- Last Updated
- July 13, 2026
Topics
Relevant Roles
Research Security Officer / Export ControlIT / Cybersecurity Staff
Tags
dodcmmcproposed-rule
This document has been superseded by dod-cmmc-program
Version 2 — Updated description to reflect 7/13/2026 suspension of Phase II requirements.