CIO - About CMMC (original) (raw)

Phased Implementation of CMMC Requirements Has Begun!
CMMC Phase 1 Implementation (Nov 10, 2025 - Nov 9, 2026) to focus primarily on CMMC Level 1 and Level 2 self-assessments
**Reminder to submit AFFIRMATIONS with your CMMC assessments in SPRS**

Cybersecurity is a top priority for the Department of War (DoW or Department). The defense industrial base (DIB) faces increasingly frequent and complex cyber-attacks. To strengthen DIB cybersecurity and better protect DoW information, the Department developed the Cybersecurity Maturity Model Certification (CMMC) Program. CMMC assesses defense contractor compliance with existing information safeguarding requirements for federal contract information (FCI) and controlled unclassified information (CUI).

Overview of the CMMC Program

Level 3 = model 134 requirements; assessment DIBCAC certification assessment every 3 years and annual affirmation; Level 2 = model 110 requirements aligned with NIST SP 800-171 R2; assessment C3PAO certification assessment every 3 years, or self assessment every 3 years for select programs and annual affirmation; Level 1 = model 15 requirements aligned with FAR 52.204-21; assessment annual self assessment and annual affirmation; opens larger image of the CMMC Model

The CMMC Program aligns with the Department’s existing information safeguarding requirements for the DIB. The program provides the DoW with increased assurance that prospective contractors and subcontractors have implemented contractually required cybersecurity standards for nonfederal information systems that will process, store, or transmit FCI or CUI during contract performance.

Key features of the CMMC Program:

Protected Information

The CMMC model is designed to enforce the protection of FCI and CUI.

Overview of Assessments

The CMMC Program provides assessments at three levels, each incorporating security requirements from existing regulations and guidelines.

Level 1: Basic Safeguarding of FCI

Level 2: Broad Protection of CUI

Level 3: Higher-Level Protection of CUI Against Advanced Persistent Threats

CMMC Status Source & Number of Security Reqts. Assessment Reqts. Plan of Action & Milestones (POA&M) Reqts. Affirmation Reqts.
Level 1 (Self) 15 required by FAR clause 52.204-21 Conducted by Organization Seeking Assessment (OSA) annually Results entered into the Supplier Performance Risk System (SPRS) Not permitted After each assessment Entered into SPRS
Level 2 (Self) 110 NIST SP 800-171 R2 required by DFARS clause 252.204-7012 Conducted by OSA every 3 years Results entered into SPRS CMMC Status will be valid for three years from the CMMC Status Date as defined in § 170.4 Permitted as defined in 32 CFR § 170.21(a)(2) and must be closed out within 180 days Final CMMC Status will be valid for three years from the Conditional CMMC Status Date After each assessment and annually thereafter Assessment will lapse upon failure to annually affirm Entered into SPRS
Level 2 (C3PAO) 110 NIST SP 800-171 R2 required by DFAR clause 252.204-7012 Conducted by C3PAO every 3 years Results entered into CMMC Enterprise Mission Assurance Support Service (eMASS) CMMC Status will be valid for three years from the CMMC Status Date as defined in 32 CFR § 170.4 Permitted as defined in 32 CFR § 170.21(a)(2) and must be closed out within 180 days Final CMMC Status will be valid for three years from the Conditional CMMC Status Date After each assessment and annually thereafter Assessment will lapse upon failure to annually affirm Entered into SPRS
Level 3 (DIBCAC) 110 NIST SP 800-171 R2 required by DFARS clause 252.204-7012 24 selected from NIST SP 800-172 Feb2021, as detailed in table 1 to 32 CFR § 170.14(c)(4) Pre-requisite CMMC Status of Level 2 (C3PAO) for the same CMMC Assessment Scope, for each Level 3 certification assessment Conducted by DIBCAC every 3 years Results entered into CMMC eMASS CMMC Status will be valid for three years from the CMMC Status Date as defined in 32 CFR § 170.4 Permitted as defined in 32 CFR § 170.21(a)(3) and must be closed out within 180 days Final CMMC Status will be valid for three years from the Conditional CMMC Status Date After each assessment and annually thereafter Assessment will lapse upon failure to annually affirm Level 2 (C3PAO) affirmation must also continue to be completed annually Entered into SPRS

CMMC Post-Assessment Remediation: Plans of Actions and Milestones

The CMMC Program allows limited use of Plans of Action and Milestones (POA&Ms).

A POA&M closeout assessment is a CMMC assessment that evaluates only the NOT MET requirements identified in the initial assessment. The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within this timeframe, the Conditional CMMC Status for the information system will expire.

CMMC Implementation

The first phase of CMMC implementation began on November 10, 2025. CMMC assessment requirements will be implemented using a four-phase plan over three years. The phases add CMMC Level requirements incrementally, starting with self-assessments in Phase 1, and ending with full implementation of program requirements in Phase 4. This phased approach allows time to train assessors and for companies to understand and implement CMMC assessment requirements.

Graphic shows the four phases of CMMC implementation. PHASE 1 - Initial Implementation - Begins 10 Nov 2025 Where applicable, solicitations will require Level 1 or 2 self-assessment. PHASE 2 Begins 10 Nov 2026 Where applicable, solicitations will require Level 2 Certification
DoW may opt to delay the Level 2 certification requirement in a contract to an option period. PHASE 3 Begins 10 Nov 2027 Where applicable solicitations will require Level 3 Certification DoW may opt to delay the Level 3 certification requirement in a contract to an option period. PHASE 4 - Full Implementation - Begins 10 Nov 2027 Where applicable solicitations will require Level 3 Certification. DoW may opt to delay the Level 3 certification requirement in a contract to an option period

DoW may implement CMMC Level 2 (C3PAO) requirements in some Phase 1 procurements or Level 3 requirements in some Phase 2 procurements, which may limit competitors or drive cost