Federal Policy
DoD Implements CMMC Cybersecurity Requirements
March 20, 2026
The Department of Defense (DoD) began enforcing the Cybersecurity Maturity Model Certification (CMMC) program as a regulatory requirement starting November 10, 2025, marking a significant shift in defense contractor cybersecurity obligations. The phased rollout extends through 2028, with increasing levels of mandatory cybersecurity assessments for contractors and subcontractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Prime contractors are accelerating compliance timelines for their supply chains to mitigate risks, requiring subcontractors to obtain CMMC certification earlier than the DoD's baseline schedule. This transition emphasizes verified cybersecurity postures over self-attestation, increasing demand for third-party assessments and continuous governance.
- Why this matters: Defense contractors must prioritize obtaining CMMC certification to maintain eligibility for DoD contracts, as primes are enforcing stricter supply chain requirements.
- The phased implementation includes self-assessments starting November 2025, mandatory third-party Level 2 assessments from November 2026, and government-led Level 3 assessments beginning November 2027 for sensitive programs.
- Procurement professionals should incorporate CMMC compliance status into vendor evaluations and contract award decisions to reduce supply chain cybersecurity risks.
- Organizations providing cybersecurity assessment services may see increased demand due to the growing need for verified certifications and continuous compliance monitoring.
If your prime contractor asks for your CMMC status today and you don’t have an SPRS score or a clear path to certification, they may (and often will) move your work to a competitor who does.
— Robert McVay
Self-attestation has repeatedly failed to produce durable cybersecurity outcomes. Verification is therefore inevitable, and it is quickly becoming the standard currency of trust.
— Ryan Heidorn, Chief Technology Officer at C3 Integrated Solutions
Agencies
Department of Defense
Contracts
, ,
Locations
Sources
- When is My CMMC Assessment Supposed to Happen? · Smithers · Mar 17
- COMMENTARY: The First 100 Days of CMMC, And What Comes Next · National Defense Magazine · Mar 20