The final CMMC Program rule published in October 2024 by the DoD Office of the Secretary establishing the Cybersecurity Maturity Model Certification framework for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in the defense supply chain.
CMMC Program
Cybersecurity Maturity Model Certification program for defense-related research.
Supplemental summary document and press release from DoD announcing the final CMMC Program rule.
The proposed rule for the CMMC Program published in December 2023, which was superseded by the final rule in October 2024. On July 13, 2026, the U.S. Department of War (DoW) announced it is suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to go into effect on November 10, 2026, while Phase I self-assessment requirements remain in place. In the interim, the Department will enforce cybersecurity compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, focused on cyber hygiene. The announcement notes that contractors remain contractually obligated to safeguard covered defense information under DFARS clause 252.204-7012 despite the suspension.
Joint comments submitted by ACE, AAU, APLU, COGR, and EDUCAUSE on February 26, 2024 in response to the proposed CMMC rule.
In the September 10, 2025, Federal Register, the Department of Defense (DoD) issued a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) program rule. The new rule formalizes the ability of the DoD to include CMMC requirements as a condition of contract award, to include either Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or both.