# DoD Implements CMMC Compliance Requirements

The Department of Defense (DoD) has initiated phased implementation of the Cybersecurity Maturity Model Certification (CMMC) program starting November 10, 2025, mandating defense contractors and subcontractors to comply with cybersecurity standards for Controlled Unclassified Information (CUI) protection. Initial phases emphasize self-assessments at Levels 1 and 2, with third-party assessments required by November 2026 for higher levels. Compliance is based on NIST SP 800-171 Revision 2, with future updates to Revision 3 anticipated. Contractors must carefully evaluate CMMC requirements, including assessment scope, handling of virtual desktop infrastructure endpoints, and the applicability of penetration testing, which is not mandated at lower levels but may be relevant at higher levels or under specific NIST standards. Industry providers like iboss offer FedRAMP Moderate Authorized Zero Trust SASE platforms to support accelerated compliance through mapped controls and continuous monitoring.

- **Why this matters:** DoD contract awards increasingly require verified CMMC compliance, impacting contractor eligibility and subcontractor flow-down obligations.
- Contractors and subcontractors handling CUI must align cybersecurity practices with evolving CMMC levels and NIST standards to maintain contract eligibility.
- Procurement professionals should incorporate CMMC verification timelines into acquisition planning, noting the transition from self-assessments to third-party validations by late 2026.
- Security service providers offering pre-mapped NIST controls and audit-ready documentation can facilitate contractor compliance and certification readiness.
- Contact points such as support@cyberab.org and CAICO support (+1-855-549-2047) provide resources for certification application inquiries and program guidance.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** May 08, 2026

### Government Entities
- Department of War (DoW)
- Cybersecurity Maturity Model Certification Accreditation Body (Cyber AB)
- Cybersecurity Assessor and Instructor Certification Organization (CAICO)
- Department of Defense (DoD)
- Cybersecurity and Infrastructure Security Agency (CISA)

### Vendors
- iboss (security platform provider)

### Key Quotes
> "CMMC requirements will flow down to subcontractors as outlined in 32 Code of Federal Regulations 170.23. The required CMMC level is based on the type of data1 Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)1 that will be processed, stored, or transmitted."
> — Original poster

### Sources
- [Virtual clients and CUI](https://www.reddit.com/r/CMMC/comments/1t5agqt/virtual_clients_and_cui) - reddit-cmmc
- [Is penetration testing needed for CMMC?](https://www.reddit.com/r/CMMC/comments/1t6o3f0/is_penetration_testing_needed_for_cmmc) - reddit-cmmc
- [Need CMMC compliance? 
Learn More: https://t.co/wvQcYWG7Jq https://t.co/vzwdnc5dxi](https://x.com/ibossCloud/status/2052867483103621486) - twitter-govtech