CMMC 2.0 Final Rule: What DoD Contractors Need to Know

The CMMC 2.0 Final Rule: What It Established and Where Things Stand Now

The Department of Defense finalized its Cybersecurity Maturity Model Certification (CMMC) 2.0 rule in September 2025, amending the Defense Federal Acquisition Regulation Supplement (DFARS). The rule took effect November 10, 2025, formally embedding mandatory cybersecurity certification requirements into DoD contracts for the first time.

Since then, the story has kept moving. Phase 1 requirements went live on schedule. Then, in July 2026, the Department of War suspended the certification program’s next phase pending a formal review. This page covers what the final rule actually established, what’s happened since, and what defense contractors need to know right now.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

Executive Summary

Main Idea: The CMMC 2.0 final rule, effective November 10, 2025, made cybersecurity certification a mandatory contractual requirement across the defense industrial base, affecting more than 337,000 contractors and subcontractors. Phase 1 self-assessment requirements are in force. Phase 2’s third-party certification requirement, originally scheduled for November 2026, is currently suspended pending a Department of War review.

Why You Should Care: “The final rule is coming” is no longer the right frame — it’s been in effect for close to a year, and it has already reshaped how DoD evaluates contractor cybersecurity. The more urgent question now is what the Phase 2 suspension means for your compliance timeline, and the answer is: less than many contractors assume.

Key Takeaways

  1. The final rule made CMMC a mandatory contractual requirement, not a future proposal. Effective November 10, 2025, the rule amended DFARS to require CMMC certification at the appropriate level as a condition of eligibility for DoD contracts and subcontracts, replacing the self-attestation model that preceded it.
  2. The rule affects the entire defense supply chain, not just prime contractors. More than 337,000 organizations are in scope, including nearly 230,000 small businesses, with mandatory flowdown requirements meaning subcontractors at every tier must also achieve the certification level appropriate to the data they handle.
  3. The rule established a three-year phased rollout — and only Phase 1 is currently active. The original schedule moved from Phase 1 self-assessment requirements in November 2025 toward full third-party certification requirements by 2028. Phase 2, which would have added mandatory C3PAO certification for prioritized programs starting November 2026, is currently suspended.
  4. The Phase 2 suspension doesn’t touch your existing DFARS or NIST 800-171 obligations. Contractors are still required to implement NIST SP 800-171’s 110 controls, maintain accurate documentation, and post current scores to SPRS. What’s paused is specifically the third-party certification mechanism — not the underlying cybersecurity standard.
  5. Readiness gaps remain widespread despite the rule being in force for nearly a year. Kiteworks’ own 2025 research found that roughly half of defense contractors were unprepared as the rule took effect, particularly small and mid-sized firms relying on legacy systems and manual compliance workflows — a gap the Phase 2 pause gives contractors a real opportunity to close before certification requirements resume.

What the Final Rule Actually Established

The CMMC 2.0 final rule amended DFARS to make cybersecurity certification a formal condition of contract eligibility across the defense industrial base. It replaced the earlier self-attestation approach — where contractors simply asserted their own compliance with NIST SP 800-171 — with a tiered, verified certification structure.

The rule established three certification levels tied to data sensitivity: Level 1 for contractors handling only Federal Contract Information, verified through annual self-assessment; Level 2 for contractors handling Controlled Unclassified Information, verified through self-assessment or third-party C3PAO certification depending on program criticality; and Level 3 for the highest-priority programs, verified through government-led assessment. For the full breakdown of what each level requires, see our CMMC compliance guide.

Critically, the rule made certification a mandatory flowdown requirement — meaning prime contractors must ensure their subcontractors, at every tier, achieve the certification level appropriate to the sensitivity of data those subcontractors handle. This extended CMMC’s practical reach well beyond direct DoD contractors to the full depth of the defense supply chain.

The Phased Timeline the Rule Established

The final rule set a three-year phased implementation, designed to give the defense industrial base time to adapt rather than requiring immediate, universal certification.

Phase 1 took effect November 10, 2025, requiring Level 1 and Level 2 self-assessment for new solicitations and contracts. This phase remains fully in force and unaffected by any subsequent developments.

Phase 2 was scheduled to add mandatory third-party C3PAO certification requirements for Level 2 programs involving the most critical information, beginning November 10, 2026. This is the phase the Department of War suspended in July 2026, pending a 60-day review by a CMMC Reform Task Force examining the cost and operational burden the certification requirement places on contractors, particularly smaller ones.

Phases 3 and 4 were planned to extend certification requirements further and add Level 3 government-led assessment for the highest-priority programs, with full implementation across the DIB expected by 2028. These phases are also currently on hold as part of the same suspension.

What Hasn’t Changed

The suspension is narrower than headlines about it often suggest. DFARS 252.204-7012 — the clause requiring defense contractors to implement NIST SP 800-171 and report cyber incidents — predates CMMC and is untouched by the pause. Contractors must continue implementing all 110 required controls, maintaining a current System Security Plan, tracking remediation through a Plan of Action and Milestones, and posting accurate scores to the Supplier Performance Risk System.

The Department of Justice’s Civil Cyber-Fraud Initiative also continues pursuing False Claims Act cases against contractors who misrepresent their cybersecurity compliance, entirely independent of where the certification program stands. The verification mechanism changed. The underlying security obligation didn’t.

What Defense Contractors Should Do Now

Treat the current period as an opportunity rather than a reprieve. Contractors who use the Phase 2 pause to fully close their NIST SP 800-171 gaps — rather than deprioritizing the work because certification enforcement is paused — will be substantially better positioned whenever the CMMC Reform Task Force’s findings translate into resumed requirements.

Kiteworks’ own research heading into the rule’s effective date found that roughly half of defense contractors were unprepared, particularly smaller firms relying on legacy systems and manual compliance processes. If that described your organization in late 2025, the current pause is real runway to close that gap before certification requirements resume — not a reason to set the work aside. For a structured approach to using this time well, see our CMMC 2.0 Roadmap and CMMC 2.0 Compliance Checklist.

How Kiteworks Supports Final Rule Compliance

Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box, consolidating the channels through which CUI and FCI typically flow — secure email, secure file sharing, managed file transfer, and SFTP — onto a single governed platform with AES-256 encryption, FIPS 140-3 validated cryptographic modules, and customer-owned encryption keys.

Every access event across every channel is logged to a single, immutable, consolidated audit trail — the evidence base that supports both self-assessment documentation today and third-party certification whenever Phase 2 requirements resume. Kiteworks also holds FedRAMP Moderate Authorization, independently assessed since June 2017, giving contractors documented control inheritance that compresses assessment scope regardless of which verification path applies to their program.

To see how Kiteworks supports your organization’s compliance with the final rule’s current and upcoming requirements, schedule a custom demo.

Frequently Asked Questions

The CMMC 2.0 final rule, amending DFARS, took effect November 10, 2025. It formally established mandatory cybersecurity certification as a condition of eligibility for DoD contracts, replacing the earlier self-attestation model, and initiated a phased rollout intended to extend full requirements across the defense industrial base by 2028.

No. The final rule itself remains in effect, and Phase 1 self-assessment requirements are fully active. What was suspended in July 2026 is specifically Phase 2 — the requirement for mandatory third-party C3PAO certification, which was scheduled to begin November 10, 2026. The Department of War suspended that specific requirement pending a 60-day review, but the final rule’s underlying framework, and contractors’ DFARS 252.204-7012 and NIST SP 800-171 obligations, remain fully in force.

The rule affects more than 337,000 organizations across the defense industrial base, including nearly 230,000 small businesses, due to mandatory flowdown requirements that extend certification obligations to subcontractors at every tier of the supply chain, not just prime contractors holding direct DoD contracts.

Continue implementing and documenting the underlying NIST SP 800-171 controls as though certification requirements remain on the original timeline. The suspension pauses the third-party verification mechanism, not the security obligations themselves, and research has found that a substantial share of defense contractors remain unprepared even with the final rule in force for nearly a year. Contractors who use the current period to close genuine gaps — rather than treating the pause as a reason to deprioritize the work — will be better positioned whenever Phase 2 requirements resume in some form.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks