None
EN
DoD Finalizes Cybersecurity Maturity Model Certification Rule: What Defense Contractors Need to Know
[]
Recent Contributors to The National Law Review
The CMMC is a cybersecurity framework designed to ensure DoD contractors implement adequate measures to protect federal contract information (FCI) or controlled unclassified information (CUI) processed on contractor-owned information systems.
Previously, the CMMC was an accreditation program through the DoD chief information officer.
But beginning November 10, 2025, contractors will need to achieve and maintain a specified CMMC level as a condition of contract award, option exercise, or extension.
Key Compliance ObligationsThe final rule establishes a three-year phased implementation period, during which time CMMC requirements will be included in select contracts as determined by DoD program offices.
By November 2028, CMMC compliance will become mandatory for all contracts that require the handling of FCI or CUI, unless an exception applies.
['rule'
'embeds'
'level'
'contracts'
'contract'
'information'
'fci'
'final'
'cmmc'
'assessments'
'contractors'
'dod'
'compliance'
'defense'
'cui']