CMMC 2.0 Is Officially Here: What Every DoD Contractor Needs to Know Right Now

Return to Top

Published on:

Wed, Nov 26, 2025

Categories:

Legal Guide
Share This Post:

On October 15, 2024, the Department of Defense published the long-awaited final CMMC rule in the Federal Register (89 Fed. Reg. 83092). Thirty days later—November 10, 2025—the program became contractually enforceable. For the first time, a specific CMMC level is now a go/no-go condition for award on an increasing number of DoD solicitations.

If your company (or any of your subcontractors) touches Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), this is no longer a “get ready someday” exercise. It’s here.

Who Actually Has to Comply — and Who Doesn’t

CMMC only applies when a contract or task order requires the contractor to receive, store, process, or generate FCI or CUI. That scope is broader than many realize: if you get export-controlled technical data, operations security plans, or even contract-specific funding documents marked “CUI,” you’re in scope.

Clear exemptions remain:

  • Pure COTS contracts (think buying a laptop off GSA Advantage)

  • Facilities support, janitorial, or landscaping contracts with no sensitive data

  • Contracts awarded under the “micro-purchase” threshold that truly involve zero FCI/CUI

Everything else? Assume you’re covered until proven otherwise.

The Three Levels — Simplified but Not Simple

Level

What It Protects

Number of Controls

Assessment Path

Real-World Impact

1

FCI only

15 (FAR 52.204-21)

Annual self-attestation in SPRS

Mostly small suppliers; low burden

2

CUI

110 (NIST SP 800-171 Rev 2)

Self or C3PAO (third-party) depending on risk

80–90 % of the DIB will land here

3

Highest-priority DoD programs

Level 2 + 24 selected NIST 800-172 controls

DoD DIBCAC assessment only

Relatively few contractors (think missile defense, nuclear enterprise)

The big change from CMMC 1.0: the confusing five-level model is gone. DoD listened to industry and aligned Level 2 directly with the 110 controls everyone has been scoring in SPRS since DFARS 252.204-7012 went into effect in 2017.

The Four-Phase Rollout You Can’t Ignore

DoD is using a deliberate, escalating approach:

Phase

Starts

What Changes

1

Nov 10, 2025

Level 1 and Level 2 (self or C3PAO) start appearing in RFIs and solicitations

2

Nov 10, 2026

Most Level 2 contracts will require third-party (C3PAO) certification

3

Nov 10, 2027

Level 3 government assessments begin

4

Nov 10, 2028

Full enforcement — no applicable contract awarded without final CMMC status

Contracting officers have flexibility in Phases 1–3, but by Phase 4 there are no waivers.

POA&Ms Are Allowed — But on a Very Short Leash

Good news: limited Plans of Action & Milestones are permitted during the rollout. Bad news: they are far more restrictive than the old 7012 interim scoring:

  • Only certain high-weighted controls can remain open

  • Maximum 180 days to close

  • Must be approved and tracked in SPRS

  • After October 1, 2027, new awards generally require full compliance (no open POA&M items)

Close your gaps early or risk being locked out of 2027–2028 opportunities.

Prime Contractors: Your Subcontractors Are Now Your Problem (Legally)

The final rule reaffirms that prime contractors bear full responsibility for flow-down and verification. Expect DFARS 252.204-7021 (the new CMMC clause) to appear in contracts starting Q1 2026.

Practically, this means:

  • Confirm every subcontractor’s CMMC status

    before

    they touch data

  • Maintain audit-ready evidence (screenshots from the CMMC portal, certificates, affirmations)

  • Insert explicit flow-down language and reporting requirements

The Department of Justice’s Civil Cyber-Fraud Initiative has already brought multiple False Claims Act cases for inadequate subcontractor oversight. CMMC just gave them a sharper tool.

Immediate Next Steps (Don’t Overthink — Just Start)
  • Scope your environment — draw the boundary around systems that handle CUI

  • Run (or refresh) your NIST 800-171 self-assessment scorecard

  • Upload your current score and senior official affirmation to SPRS — even if it’s not perfect

  • Build a realistic POA&M for any “Met/No” controls

  • Map your supply chain and start asking subs for their CMMC plan

  • Budget for a C3PAO if your programs are likely Level 2 certified

We’ve Been Doing This Since the Pilot Days

At MDRXLaw, our Government Contracts and Cybersecurity practice works with DoD contractors and subcontractors on exactly these issues: CMMC scoping and boundary decisions, NIST 800-171/172 gap assessments, POA&M strategy, SPRS submissions, C3PAO preparation, and airtight subcontractor flow-down provisions.

We also represent companies under DoD OIG audits or DOJ Civil Cyber-Fraud Initiative investigations when compliance breakdowns occur — which gives us a clear view of what actually holds up under scrutiny and what doesn’t.

Whether you need:

  • A quick, accurate determination of which of your contracts trigger Level 2 (or Level 3)

  • Help cleaning up your SPRS score and drafting a defensible POA&M

  • Review and strengthening of your subcontractor clauses before the new DFARS 252.204-7021 clause drops

  • Or ongoing compliance support on a predictable fixed-fee or subscription basis

…we can get you there efficiently and with documentation that will actually protect you if things are ever questioned.

Have questions or want to talk through where you stand? Give us a call at (212) 668-0200 or email info@mdrxlaw.com.

The clock is running. The work you do (or start) in the next 6–12 months will determine which contracts you’re still eligible for when full enforcement arrives in 2028. Let’s make sure you’re ready.