People searching for “the CFR CMMC Rule” are usually looking for one of two different rules, and confusing them is a common and consequential mistake. 32 CFR Part 170 is the rule that created the CMMC program — the levels, the controls, the assessment types. 48 CFR, through DFARS clause 252.204-7021, is the rule that made that program enforceable in DoD contracting — giving contracting officers authority to require a specific CMMC level and verify it before awarding a contract.

They’re both final, both in effect, and both essential to understand — but they answer different questions, and a resource written about one won’t tell you much about the other. This page is a short orientation to both, with links to the detailed guide for whichever one you actually need.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Both rules described below remain in effect; the pause applies specifically to the certification timeline. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

CFR CMMC Rule

Executive Summary

Main Idea: “The CFR CMMC Rule” isn’t one rule — it’s shorthand people use for either 32 CFR (which establishes the CMMC program itself) or 48 CFR (which makes that program enforceable in DoD contract awards). Both are final and in effect. Knowing which one you’re actually asking about determines whether you need to understand certification levels and controls, or acquisition and bidding mechanics.

Why You Should Care: If you’re trying to figure out what CMMC level applies to your organization, you want 32 CFR. If you’re trying to figure out why a bid was rejected over an SPRS posting, you want 48 CFR. Looking in the wrong place wastes time and can leave you missing the specific requirement that actually affects you.

Key Takeaways

  1. 32 CFR Part 170 created the CMMC program itself. Finalized in October 2024 and effective December 16, 2024, it establishes the three certification levels, the required controls at each level, assessment types, and scoping rules — the substance of what CMMC compliance means.
  2. 48 CFR made CMMC enforceable in the contracting process. Through DFARS clause 252.204-7021, effective November 10, 2025, it gives contracting officers authority to require a specific CMMC level in a solicitation and to verify compliance status through SPRS before awarding a contract.
  3. 32 CFR answers “what does compliance require”; 48 CFR answers “how is compliance enforced at the point of award.” They’re sequential and complementary — one defines the standard, the other makes it a condition of doing business — not competing or overlapping regulations.
  4. Both rules are final and in effect, regardless of the Phase 2 pause. The July 2026 suspension paused the timeline for mandatory third-party certification under Phase 2 — it did not unwind either 32 CFR or 48 CFR, both of which remain the governing rules for CMMC’s structure and enforcement.
  5. Most practical questions about “the CFR CMMC Rule” are actually questions about one rule specifically, not both at once. If your question is about levels, controls, or what you need to implement, you want 32 CFR. If it’s about bidding, contract eligibility, or SPRS, you want 48 CFR.

32 CFR Part 170: The Rule That Defines CMMC

32 CFR Part 170 is the Department of Defense rule that formally established the CMMC program within Title 32 (National Defense) of the Code of Federal Regulations. Published to the Federal Register in October 2024 and effective December 16, 2024, it’s the rule that answers the question “what does CMMC compliance actually require.”

This rule defines the three certification levels — Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert) — and ties each to the sensitivity of the data an organization handles. It specifies which controls apply at each level, drawing on NIST SP 800-171 for Level 2 and NIST SP 800-172 for Level 3 enhancements. It defines the assessment types available at each level, including the criteria for accredited C3PAOs conducting third-party certification. And it establishes scoping rules that determine which systems and data within an organization actually fall under CMMC’s requirements.

If your question is about which level applies to your organization, what controls you need to implement, or how the assessment process works, 32 CFR is the rule you’re actually asking about. For the full detail, see our 32 CFR Requirements guide, and for a level-by-level breakdown, see our CMMC Level 2 guide.

48 CFR: The Rule That Enforces CMMC in Contracting

48 CFR governs federal acquisition regulations, and the amendments relevant to CMMC — specifically DFARS clause 252.204-7021 — are what make 32 CFR’s requirements enforceable at the point of contract award. This rule took effect November 10, 2025.

Where 32 CFR defines what compliance means, 48 CFR gives contracting officers the specific mechanism to act on it: naming a required CMMC level directly in a solicitation, checking a contractor’s certification status against the Supplier Performance Risk System (SPRS), and withholding contract award if that status isn’t current. It also introduced the CMMC Unique Identifier, which ties a specific bid to a specific, verifiable SPRS record.

If your question is about bidding, contract eligibility, why a contracting officer is asking about your SPRS score, or what happens if your compliance posting lapses, 48 CFR is the rule you’re actually asking about. For the full detail, including exactly how SPRS scoring and contract eligibility work in practice, see our 48 CFR and CMMC guide.

Why the Confusion Happens

Both rules are commonly referred to in casual conversation as “the CMMC rule” or “the CFR rule,” without the specific citation attached — which is understandable, since most people encounter them through secondary discussion (webinars, news coverage, vendor content) rather than the Federal Register text itself. The confusion is compounded by timing: 32 CFR and 48 CFR were finalized roughly a year apart but are frequently discussed together, since together they form the complete regulatory picture — one defining the standard, the other enforcing it.

The practical fix is simple: when you encounter “the CFR CMMC Rule” in an article, webinar, or conversation, check whether the specific citation (32 CFR or 48 CFR) is given, and if it isn’t, consider which underlying question is actually being discussed — compliance requirements, or contract enforcement — since that usually reveals which rule is meant.

How Kiteworks Supports Compliance With Both Rules

Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box — directly addressing what 32 CFR requires — through a unified Data Policy Engine that consolidates access controls, encryption, and audit logging across secure email, secure file sharing, managed file transfer, and SFTP. AES-256 encryption with FIPS 140-3 validated cryptographic modules and a single, consolidated, immutable audit trail give organizations current, exportable evidence for both self-assessment and C3PAO certification under 32 CFR.

That same evidence base is what supports an accurate, defensible SPRS posting under 48 CFR — helping ensure the compliance status a contracting officer checks against SPRS reflects a genuinely current, well-documented security posture rather than one reconstructed under deadline pressure.

To see how Kiteworks supports your organization’s compliance with both rules, schedule a custom demo.

Frequently Asked Questions

32 CFR Part 170 established the CMMC program itself — the three certification levels, required controls, and assessment types. It answers what compliance requires. 48 CFR, through DFARS clause 252.204-7021, made that program enforceable in DoD contracting by giving contracting officers authority to require a specific CMMC level and verify it through SPRS before awarding a contract. It answers how compliance is enforced at the point of bidding and award. Both rules are final and in effect; they’re complementary, not competing or overlapping.

32 CFR Part 170. It’s the rule that ties certification level to the type of data your organization handles — Federal Contract Information for Level 1, Controlled Unclassified Information for Level 2, and the most sensitive national security information for Level 3 — and defines the specific controls required at each level.

48 CFR, specifically DFARS clause 252.204-7021. This is the rule that gives contracting officers authority to check a contractor’s compliance status against SPRS and withhold contract award if that status isn’t current — including treating a stale SPRS posting the same as no posting at all, even if the underlying cybersecurity controls are genuinely strong.

No. The Phase 2 suspension announced in July 2026 paused the requirement for mandatory third-party C3PAO certification, which was scheduled to expand starting November 2026. Both 32 CFR (which defines the program) and 48 CFR (which enforces it through Phase 1 self-assessment and SPRS requirements) remain fully in effect. The pause is narrower than “CMMC is suspended” — it applies specifically to the certification timeline under Phase 2, not to the underlying regulatory structure either rule established.

Back to Risk & Compliance Glossary

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks