The CMMC phased rollout began November 10, 2025 and follows a four-phase schedule through 2028. This guide covers every CMMC phased rollout deadline and what DoD contractors must do before Phase 2.

CMMC Implementation · Active Since November 10, 2025

On September 10, 2025, the DoD published the final 48 CFR CMMC Acquisition Rule in the Federal Register. Sixty days later, on November 10, 2025, the rule became effective and Phase 1 began. CMMC is no longer a future requirement — it is a present contractual obligation for every DoD contractor and subcontractor handling FCI or CUI.

The rollout follows a four-phase schedule spanning November 2025 through November 2028. Each phase expands the scope and stringency of required assessments. The phased schedule does not grant a grace period — CMMC requirements are already appearing in new solicitations today, and contracting officers cannot make awards to contractors without a current CMMC status in SPRS at the required level.

✓  Not sure if your Level 1 documentation is in place? Download the free readiness checklist →

Quick reference: the four phase dates

Phase 1
Nov 10, 2025
Self-assessments begin in applicable solicitations

✅ Active Now

Phase 2
Nov 10, 2026
Mandatory C3PAO certification for Level 2

⚠️ 5 Months Away

Phase 3
Nov 10, 2027
Level 3 DIBCAC assessments introduced

Upcoming

Phase 4
Nov 10, 2028
Full enforcement across all applicable contracts

Upcoming

Phase 1
November 10, 2025 – November 9, 2026
Active Now
Self-assessment · Initial implementation of DFARS 252.204-7021

DFARS 252.204-7021 becomes enforceable. Contracting officers begin inserting CMMC requirements into applicable new solicitations and contracts.

  • Level 1 (FCI): Annual self-assessment against FAR 52.204-21’s 15 basic safeguarding requirements. Score and affirmation must be entered in SPRS prior to award. POA&Ms are not permitted at Level 1.
  • Level 2 Self (CUI): Full NIST SP 800-171 Rev. 2 self-assessment covering all 110 requirements. Results entered in SPRS every 3 years with annual affirmations. A Conditional CMMC Status via POA&M is permitted but must be closed within 180 days.
  • Level 2 C3PAO at DoD discretion: Contracting officers retain discretion to require a Level 2 C3PAO certification even in Phase 1 for select high-sensitivity programs. Do not assume self-assessment is sufficient for every contract.
  • SPRS posting requirement: Contracting officers shall not award, extend, or exercise options without a verified current CMMC status posting at the required level. The affirmation must be entered in SPRS alongside the assessment results.
  • Subcontractor flow-down: Prime contractors must ensure subcontractors handling FCI or CUI meet the applicable CMMC level as a condition of the subcontract.

Phase 2
November 10, 2026 – November 9, 2027
⚠️ 5 Months Away
Mandatory C3PAO certification · Self-attestation no longer sufficient for most Level 2 contracts

This is the most consequential phase for contractors handling CUI. Mandatory third-party C3PAO assessments become the standard for Level 2. Self-assessments will no longer be sufficient for most CUI-handling contractors.

  • Level 2 C3PAO required for new awards: Organizations handling CUI must obtain certification from an accredited C3PAO as a condition of award. Results are entered into CMMC eMASS. The certificate must reflect Final CMMC Status — not Conditional.
  • Certificate validity: CMMC Level 2 C3PAO certificates are valid for 3 years from the assessment date. Annual affirmations of continued compliance must be submitted in SPRS each year within that window. Failure to annually affirm lapses the assessment.
  • POA&M limitations: A Conditional CMMC Status with open POA&M items may allow award in limited cases, but all items must be closed within 180 days of the Conditional Status Date via a formal POA&M closeout assessment by the C3PAO.
  • C3PAO capacity constraint: The DoD estimates approximately 8,350 DIB entities require Level 2 C3PAO assessments. With limited authorized C3PAO capacity, organizations should engage C3PAOs 8–12 months before their contract deadlines. Do not wait.

Phase 3
November 10, 2027 – November 9, 2028
Upcoming
Level 3 DIBCAC assessments introduced · Option period enforcement begins

Level 2 certification requirements expand to cover contract option exercises. Level 3 DIBCAC assessments are formally introduced for programs involving the most sensitive CUI and advanced persistent threat exposure.

  • Level 2 C3PAO required for option exercises: Organizations without a current Final CMMC Status at Level 2 cannot have options exercised on applicable contracts awarded after November 10, 2025.
  • Level 3 (DIBCAC) required for applicable new awards: CMMC Level 3 assessments, conducted by DCMA’s Defense Industrial Base Cybersecurity Assessment Center, are required for programs involving the most sensitive CUI. A Final Level 2 C3PAO certification for the same assessment scope is a prerequisite.
  • Level 3 requirements — 134 total: All 110 NIST SP 800-171 Rev. 2 requirements plus 24 selected requirements from NIST SP 800-172, for a total of 134 security requirements.

Phase 4
November 10, 2028 onward
Full Implementation
All applicable DoD contracts fully enforced

Full CMMC program implementation. All applicable DoD solicitations and contracts must include the appropriate CMMC level as a condition of award.

  • Universal applicability: CMMC requirements apply to all DoD solicitations above the micro-purchase threshold where the contractor processes, stores, or transmits FCI or CUI. The only exclusion remains contracts solely for COTS items.
  • Continuous compliance: CMMC is not a one-time checkpoint. Annual affirmations, ongoing implementation, and three-year reassessments are permanent obligations across all levels.

⚠️  False Claims Act exposure: Submitting an inaccurate SPRS score or annual affirmation — whether intentionally or through willful ignorance — carries federal False Claims Act liability. Penalties include treble damages and civil monetary penalties per false claim. DoJ whistleblower programs are actively monitoring the Defense Industrial Base.

What this means for your organization today

~60
The average SPRS score across the Defense Industrial Base — well below the 110 required for Level 2 Final status. With Phase 2 less than six months away, that gap is a direct contract eligibility risk for every CUI-handling contractor that has not yet begun formal remediation.

Organizations that handle CUI and have not yet completed a gap assessment, built an SSP aligned to NIST SP 800-171 Rev. 2, and begun active remediation are already behind the timeline required to achieve Final CMMC Status before Phase 2 solicitations begin requiring C3PAO certification.

The CMMC Program Office has made clear there will be no across-the-board waivers. Waivers are determined at the acquisition program level and are not granted ad hoc to individual contractors. If your contract requires CMMC certification and you do not have it, you are ineligible for award.


Free Resource — CMMC Level 1

Not sure if your Level 1 documentation is in order?

Download the free CMMC Level 1 Readiness Checklist — the same gap analysis tool KyberStorm uses with advisory clients. Covers all 15 FAR 52.204-21 practices, shows exactly which documents you are missing, and gives you a starting point for your SPRS submission.

All 15 practices
Gap analysis worksheet
Documentation checklist
100% free

Ready to Get Compliant? KyberStorm Can Help.

Whether you need to complete your Level 1 self-assessment this week or prepare for a Level 2 C3PAO assessment before Phase 2, KyberStorm has the resources and expertise to get you there.

📋

CMMC Level 1 · Instant Download

CMMC Level 1 Documentation Kit — $897

All 12 documents you need to support your Level 1 SPRS submission — System Security Plan, POA&M template, Control Tracker, and all required policies — in editable Word format. Built by a CISSP-certified GRC professional. One-time purchase, instant download.

Get the Kit →

🛡️

CMMC Level 2 · Advisory Services

Level 2 Gap Assessment, Documentation & C3PAO Preparation

With Phase 2 less than six months away and C3PAO scheduling backlogs growing, organizations handling CUI need to start preparation now. KyberStorm provides full Level 2 advisory services — gap assessments aligned to NIST SP 800-171 Rev. 2, SSP development, POA&M management, and C3PAO readiness across the Greater DMV area.

Learn More →

🔍

Security Validation

Penetration Testing & Red Teaming

Validate your security controls before a formal assessment with penetration testing and red team exercises built specifically for defense contractors. Identify gaps before your C3PAO or DIBCAC assessor does.

Contact Us →


Sources & References

32 CFR Part 170 (CMMC Program Rule, effective December 16, 2024) · 48 CFR Parts 204, 212, 217, and 252 (DFARS CMMC Acquisition Rule, effective November 10, 2025) · DFARS 252.204-7021 · NIST SP 800-171 Rev. 2 · NIST SP 800-172 · NIST SP 800-172A · dodcio.defense.gov/CMMC/About/

All phase dates derive from 32 CFR § 170.3(e). This post reflects the program as of June 2026. Questions? info@kyberstorm.com