Now Final: 48 CFR DFARS Rule Establishes CMMC Requirements for Defense Contractors

48 CFR and CMMC: How SPRS Scoring Determines DoD Contract Eligibility

32 CFR established what CMMC requires — the levels, the controls, the assessment types. 48 CFR is the rule that made those requirements enforceable at the point of contract award. It amended the Defense Federal Acquisition Regulation Supplement (DFARS) to give contracting officers explicit authority to name a required CMMC level in a solicitation, verify a contractor’s compliance status directly through the Supplier Performance Risk System (SPRS), and withhold the contract award if that status isn’t current.

This is the mechanism that turns CMMC from a security framework into an actual gate on winning DoD business. Understanding how it works — specifically the SPRS scoring system, the CMMC Unique Identifier, and what “current” actually means — is what determines whether your organization’s compliance status translates into contract eligibility or becomes a bid disqualifier.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Phase 1 SPRS and self-assessment requirements described below remain fully in force. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

Executive Summary

Main Idea: The 48 CFR DFARS rule — specifically clause 252.204-7021 — gives contracting officers direct authority to require a specific CMMC level in a solicitation and to withhold contract award if a contractor’s SPRS posting isn’t current. It has been in force since November 10, 2025.

Why You Should Care: This rule is where CMMC compliance stops being a security posture question and becomes a contract eligibility question. A contractor with genuinely strong cybersecurity controls but a stale or missing SPRS score can lose a bid on a procedural technicality — and contracting officers are instructed to treat an outdated posting exactly the same as no posting at all.

Key Takeaways

  1. 48 CFR gives contracting officers the authority to enforce CMMC at the point of award. The rule added DFARS clause 252.204-7021, which lets contracting officers name a required CMMC level directly in a solicitation and withhold contract award from any offeror who hasn’t achieved and maintained it.
  2. SPRS is the system of record — and a stale posting counts as no posting. Contractors must post current self-assessment scores and annual affirmations to the Supplier Performance Risk System. Contracting officers are directed to treat an out-of-date SPRS posting the same as a missing one, which can disqualify an otherwise-compliant contractor on a technicality.
  3. The CMMC Unique Identifier ties your bid directly to your compliance record. Offerors reference a CMMC UID — generated when compliance status is posted to SPRS — in their proposals, giving contracting officers a direct, verifiable link between the bid and the contractor’s actual certification status.
  4. This rule has been active and enforced since November 10, 2025 — it is not a future requirement. Phase 1 requirements under this rule are already showing up in live DoD solicitations and contracts. Contractors bidding on new DoD work today may already be required to have a current SPRS posting to be considered eligible.
  5. Subcontractors are subject to the same enforcement mechanism as primes. The flowdown requirement means a subcontractor’s SPRS status can affect a prime contractor’s ability to use them on a DoD program — making subcontractor SPRS currency a prime contractor’s problem too, not just the subcontractor’s.

How 48 CFR Fits With the Broader CMMC Rule Structure

CMMC rulemaking happened in two parts, and it’s worth understanding the distinction, since each rule does a different job. 32 CFR Part 170, finalized in late 2024, established the CMMC program itself — the three certification levels, the scoping rules, the assessment types, and the affirmation requirements. It defined what compliance means.

48 CFR — specifically the amendments to DFARS through clause 252.204-7021 — is what makes that program enforceable in the contracting process. It gives contracting officers the specific authority to name a CMMC level in a solicitation, check a contractor’s status, and act on what they find. Where 32 CFR is the rulebook, 48 CFR is the enforcement mechanism at the point of sale. For the full picture of what the underlying certification program requires, see our CMMC 2.0 Final Rule overview.

How SPRS Scoring and Contract Eligibility Actually Work

The Supplier Performance Risk System (SPRS) is where contractors post their NIST SP 800-171 self-assessment scores and annual affirmations of continued compliance. Under 48 CFR, this posting isn’t just a record-keeping formality — it’s the data source contracting officers check directly when evaluating bid eligibility.

Three things determine whether a contractor clears this gate. First, the score itself must reflect the required CMMC level for the specific solicitation — Level 1 self-assessment for FCI-only contracts, Level 2 self-assessment or C3PAO certification for CUI-handling contracts depending on program criticality. Second, the posting must be current — Level 2 self-assessments are valid for three years, but annual affirmations of continued compliance are required in between, and a missed affirmation makes an otherwise-valid score effectively stale. Third, the posting needs to be tied to the correct entity — the specific legal entity bidding on the contract, not a parent company or affiliated entity whose compliance status doesn’t transfer automatically.

The consequence of getting any of this wrong is direct: contracting officers are instructed to treat an outdated or missing SPRS posting the same as no compliance at all, regardless of how strong a contractor’s actual cybersecurity posture is. A contractor with excellent technical controls but a lapsed annual affirmation can lose a bid on a procedural gap that has nothing to do with their actual security.

The CMMC Unique Identifier

The CMMC UID is generated when a contractor posts their assessment results to SPRS, and it functions as the link between a specific compliance record and a specific bid. Offerors reference their CMMC UID in proposals, giving contracting officers a direct way to verify that the compliance status being claimed in a bid actually matches what’s on file in SPRS — closing a gap where a contractor might otherwise assert compliance in a proposal without it being independently verifiable at the point of evaluation.

Keeping this identifier and its underlying SPRS record current is now a practical part of business development for any organization bidding on DoD work, not just a compliance department responsibility handled separately from the contracts team.

What This Means for Subcontractors

The flowdown requirement extends this enforcement mechanism through the full supply chain. Prime contractors are responsible for ensuring their subcontractors hold the CMMC level appropriate to the CUI or FCI those subcontractors will handle — which means a subcontractor’s stale SPRS posting can become the prime’s problem, potentially jeopardizing the prime’s own ability to perform on a contract if a required subcontractor can’t demonstrate current compliance.

This has made subcontractor SPRS status a due diligence item for prime contractors managing their supply chains, not just an internal compliance question for each individual subcontractor.

How Kiteworks Supports SPRS-Relevant Compliance Evidence

Kiteworks doesn’t manage SPRS submissions directly, but the platform provides the underlying evidence base that makes an accurate, defensible self-assessment score possible to produce and maintain. A unified Data Policy Engine consolidates access controls, encryption, and audit logging across every channel where CUI moves — secure email, secure file sharing, managed file transfer, and SFTP — supporting nearly 90% of CMMC 2.0 Level 2 requirements out of the box.

A single, consolidated, immutable audit trail across all of these channels gives contractors current, exportable evidence to support their SPRS score and annual affirmation, rather than requiring a scramble to reconstruct documentation each time an affirmation comes due. That consistency is what keeps a compliance posture — and the SPRS record built on it — genuinely current rather than technically compliant on paper but stale in practice.

To see how Kiteworks supports the compliance evidence behind your SPRS posting, schedule a custom demo.

Frequently Asked Questions

The 48 CFR rule amended DFARS to add clause 252.204-7021, which gives contracting officers explicit authority to require a specific CMMC certification level in a solicitation and to verify a contractor’s compliance status directly through the Supplier Performance Risk System (SPRS) before awarding a contract. It has been in effect since November 10, 2025. Where the earlier 32 CFR rule established what CMMC certification requires, 48 CFR is what makes that requirement enforceable at the point of contract award.

Contracting officers are directed to treat an outdated SPRS posting the same as a missing one — meaning a contractor can be disqualified from a bid even if their underlying cybersecurity controls are genuinely strong, simply because their self-assessment score or annual affirmation isn’t current. Level 2 self-assessment scores are valid for three years, but require an annual affirmation of continued compliance in between; missing that annual affirmation is enough to make an otherwise valid score effectively stale for contract eligibility purposes.

A CMMC Unique Identifier is generated when a contractor posts assessment results to SPRS, and it’s referenced by offerors in DoD contract proposals to link a specific bid to a specific, verifiable compliance record. It closes a gap where a contractor might otherwise assert compliance in a proposal that a contracting officer couldn’t easily verify — the UID gives them a direct way to confirm the claimed status matches what’s actually on file in SPRS.

Both. Mandatory flowdown requirements mean prime contractors are responsible for ensuring subcontractors at every tier hold the CMMC level appropriate to the CUI or FCI they’ll handle. A subcontractor with a stale or missing SPRS posting can jeopardize the prime contractor’s own ability to perform on a contract, which has made subcontractor SPRS status a supply chain due diligence responsibility for primes managing their contractor networks, not solely an internal compliance matter for each individual subcontractor.

No. The Phase 2 suspension announced by the Department of War in July 2026 paused the requirement for mandatory third-party C3PAO certification, which was scheduled to take effect in November 2026. The Phase 1 requirements enforced under 48 CFR and DFARS clause 252.204-7021 — self-assessment, SPRS posting, annual affirmations, and contracting officer authority to withhold awards — took effect November 10, 2025 and remain fully in force, unaffected by the Phase 2 pause.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks