Skip to content

CMMC Program

Cybersecurity Maturity Model Certification program for defense-related research.

DoD Office of the Secretary|
SupersededDW

The proposed rule for the CMMC Program published in December 2023, which was superseded by the final rule in October 2024. On July 13, 2026, the U.S. Department of War (DoW) announced it is suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to go into effect on November 10, 2026, while Phase I self-assessment requirements remain in place. In the interim, the Department will enforce cybersecurity compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, focused on cyber hygiene. The announcement notes that contractors remain contractually obligated to safeguard covered defense information under DFARS clause 252.204-7012 despite the suspension.

Department of Defense|
ActiveDW

In the September 10, 2025, Federal Register, the Department of Defense (DoD) issued a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) program rule. The new rule formalizes the ability of the DoD to include CMMC requirements as a condition of contract award, to include either Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or both.