CMMC Compliance Deadlines: The Complete Phase-by-Phase Guide (2025–2028)
June 14, 2026
The CMMC phased rollout began November 10, 2025 and follows a four-phase schedule through 2028. This guide covers every CMMC phased rollout deadline and what DoD contractors must do before Phase 2.
CMMC Implementation · Active Since November 10, 2025
On September 10, 2025, the DoD published the final 48 CFR CMMC Acquisition Rule in the Federal Register. Sixty days later, on November 10, 2025, the rule became effective and Phase 1 began. CMMC is no longer a future requirement — it is a present contractual obligation for every DoD contractor and subcontractor handling FCI or CUI.
The rollout follows a four-phase schedule spanning November 2025 through November 2028. Each phase expands the scope and stringency of required assessments. The phased schedule does not grant a grace period — CMMC requirements are already appearing in new solicitations today, and contracting officers cannot make awards to contractors without a current CMMC status in SPRS at the required level.
✓ Not sure if your Level 1 documentation is in place? Download the free readiness checklist →
Quick reference: the four phase dates
November 10, 2025 – November 9, 2026
Active Now
DFARS 252.204-7021 becomes enforceable. Contracting officers begin inserting CMMC requirements into applicable new solicitations and contracts.
- Level 1 (FCI): Annual self-assessment against FAR 52.204-21’s 15 basic safeguarding requirements. Score and affirmation must be entered in SPRS prior to award. POA&Ms are not permitted at Level 1.
- Level 2 Self (CUI): Full NIST SP 800-171 Rev. 2 self-assessment covering all 110 requirements. Results entered in SPRS every 3 years with annual affirmations. A Conditional CMMC Status via POA&M is permitted but must be closed within 180 days.
- Level 2 C3PAO at DoD discretion: Contracting officers retain discretion to require a Level 2 C3PAO certification even in Phase 1 for select high-sensitivity programs. Do not assume self-assessment is sufficient for every contract.
- SPRS posting requirement: Contracting officers shall not award, extend, or exercise options without a verified current CMMC status posting at the required level. The affirmation must be entered in SPRS alongside the assessment results.
- Subcontractor flow-down: Prime contractors must ensure subcontractors handling FCI or CUI meet the applicable CMMC level as a condition of the subcontract.
November 10, 2026 – November 9, 2027
⚠️ 5 Months Away
This is the most consequential phase for contractors handling CUI. Mandatory third-party C3PAO assessments become the standard for Level 2. Self-assessments will no longer be sufficient for most CUI-handling contractors.
- Level 2 C3PAO required for new awards: Organizations handling CUI must obtain certification from an accredited C3PAO as a condition of award. Results are entered into CMMC eMASS. The certificate must reflect Final CMMC Status — not Conditional.
- Certificate validity: CMMC Level 2 C3PAO certificates are valid for 3 years from the assessment date. Annual affirmations of continued compliance must be submitted in SPRS each year within that window. Failure to annually affirm lapses the assessment.
- POA&M limitations: A Conditional CMMC Status with open POA&M items may allow award in limited cases, but all items must be closed within 180 days of the Conditional Status Date via a formal POA&M closeout assessment by the C3PAO.
- C3PAO capacity constraint: The DoD estimates approximately 8,350 DIB entities require Level 2 C3PAO assessments. With limited authorized C3PAO capacity, organizations should engage C3PAOs 8–12 months before their contract deadlines. Do not wait.
November 10, 2027 – November 9, 2028
Upcoming
Level 2 certification requirements expand to cover contract option exercises. Level 3 DIBCAC assessments are formally introduced for programs involving the most sensitive CUI and advanced persistent threat exposure.
- Level 2 C3PAO required for option exercises: Organizations without a current Final CMMC Status at Level 2 cannot have options exercised on applicable contracts awarded after November 10, 2025.
- Level 3 (DIBCAC) required for applicable new awards: CMMC Level 3 assessments, conducted by DCMA’s Defense Industrial Base Cybersecurity Assessment Center, are required for programs involving the most sensitive CUI. A Final Level 2 C3PAO certification for the same assessment scope is a prerequisite.
- Level 3 requirements — 134 total: All 110 NIST SP 800-171 Rev. 2 requirements plus 24 selected requirements from NIST SP 800-172, for a total of 134 security requirements.
November 10, 2028 onward
Full Implementation
Full CMMC program implementation. All applicable DoD solicitations and contracts must include the appropriate CMMC level as a condition of award.
- Universal applicability: CMMC requirements apply to all DoD solicitations above the micro-purchase threshold where the contractor processes, stores, or transmits FCI or CUI. The only exclusion remains contracts solely for COTS items.
- Continuous compliance: CMMC is not a one-time checkpoint. Annual affirmations, ongoing implementation, and three-year reassessments are permanent obligations across all levels.
What this means for your organization today
Organizations that handle CUI and have not yet completed a gap assessment, built an SSP aligned to NIST SP 800-171 Rev. 2, and begun active remediation are already behind the timeline required to achieve Final CMMC Status before Phase 2 solicitations begin requiring C3PAO certification.
The CMMC Program Office has made clear there will be no across-the-board waivers. Waivers are determined at the acquisition program level and are not granted ad hoc to individual contractors. If your contract requires CMMC certification and you do not have it, you are ineligible for award.
Free Resource — CMMC Level 1
Not sure if your Level 1 documentation is in order?
Download the free CMMC Level 1 Readiness Checklist — the same gap analysis tool KyberStorm uses with advisory clients. Covers all 15 FAR 52.204-21 practices, shows exactly which documents you are missing, and gives you a starting point for your SPRS submission.
Gap analysis worksheet
Documentation checklist
100% free
Ready to Get Compliant? KyberStorm Can Help.
Whether you need to complete your Level 1 self-assessment this week or prepare for a Level 2 C3PAO assessment before Phase 2, KyberStorm has the resources and expertise to get you there.
CMMC Level 1 · Instant Download
CMMC Level 1 Documentation Kit — $897
All 12 documents you need to support your Level 1 SPRS submission — System Security Plan, POA&M template, Control Tracker, and all required policies — in editable Word format. Built by a CISSP-certified GRC professional. One-time purchase, instant download.
CMMC Level 2 · Advisory Services
Level 2 Gap Assessment, Documentation & C3PAO Preparation
With Phase 2 less than six months away and C3PAO scheduling backlogs growing, organizations handling CUI need to start preparation now. KyberStorm provides full Level 2 advisory services — gap assessments aligned to NIST SP 800-171 Rev. 2, SSP development, POA&M management, and C3PAO readiness across the Greater DMV area.
Security Validation
Penetration Testing & Red Teaming
Validate your security controls before a formal assessment with penetration testing and red team exercises built specifically for defense contractors. Identify gaps before your C3PAO or DIBCAC assessor does.
Sources & References
32 CFR Part 170 (CMMC Program Rule, effective December 16, 2024) · 48 CFR Parts 204, 212, 217, and 252 (DFARS CMMC Acquisition Rule, effective November 10, 2025) · DFARS 252.204-7021 · NIST SP 800-171 Rev. 2 · NIST SP 800-172 · NIST SP 800-172A · dodcio.defense.gov/CMMC/About/
All phase dates derive from 32 CFR § 170.3(e). This post reflects the program as of June 2026. Questions? info@kyberstorm.com