CMMC Program Basics · 2 of 3
How CMMC is phased into contracts
In short
- CMMC requirements enter contracts over four phases, each a year apart.
- Award requires a current status at or above the required level.
- Some earlier DIBCAC High Assessments are credited.
1. A phased rollout
The Cybersecurity Maturity Model Certification (CMMC) Program in 32 CFR part 170 does not enter every contract at once. The Defense Department is using a phased approach to include CMMC requirements in solicitations and contracts, over four phases (32 CFR 170.3(e)). Phase 1 begins on the effective date of the complementary CMMC acquisition rule in 48 CFR part 204, the Defense Federal Acquisition Regulation Supplement (DFARS) (32 CFR 170.3(e)(1)). Each later phase begins one calendar year after the start of the one before.
CMMC statuses are named by level and by who assesses. They are Level 1 (Self), Level 2 (Self), Level 2 by a CMMC Third-Party Assessment Organization (C3PAO), and Level 3 by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) (32 CFR 170.4).
2. Phases 1 and 2
In Phase 1, the Department intends to require Level 1 or Level 2 self-assessment status for all applicable solicitations and contracts as a condition of award (32 CFR 170.3(e)(1)). At its discretion, it may also require such status as a condition of exercising an option on a contract awarded before the effective date. It may also, at its discretion, require Level 2 by a C3PAO in place of the Level 2 self-assessment.
Phase 2 begins one calendar year after Phase 1 (32 CFR 170.3(e)(2)). In addition to the Phase 1 requirements, the Department intends to require Level 2 by a C3PAO for applicable solicitations and contracts as a condition of award. It may, at its discretion, delay that requirement to an option period instead. It may also, at its discretion, include Level 3 requirements for applicable solicitations and contracts.
3. Phases 3 and 4
Phase 3 begins one calendar year after Phase 2 (32 CFR 170.3(e)(3)). The Department intends to require Level 2 by a C3PAO for all applicable solicitations and contracts, both as a condition of award and as a condition of exercising an option on a contract awarded after the effective date. It intends to require Level 3 for all applicable solicitations and contracts as a condition of award. At its discretion, it may delay the Level 3 requirement to an option period.
Phase 4, full implementation, begins one calendar year after Phase 3 (32 CFR 170.3(e)(4)). The Department will then include CMMC requirements in all applicable solicitations and contracts. That includes option periods on contracts awarded before Phase 4 begins.
4. Waivers
During Implementation Phases 1, 2 and 3, a procurement follows the CMMC requirements for the relevant phase-in period (32 CFR 170.3(c)(1)). In very limited circumstances, and in line with applicable policies, a Service Acquisition Executive or Component Acquisition Executive, or a delegate, may waive inclusion of CMMC requirements in a solicitation or contract (32 CFR 170.5(d)). In those cases, contractors and subcontractors remain obligated to comply with all applicable cybersecurity and information security requirements. The Department may also, at its discretion, waive CMMC requirements in advance of the solicitation for a single procurement or a class of procurements, under all applicable policies, procedures and approval requirements (32 CFR 170.3(c)(2)).
5. The DFARS side
DFARS subpart 204.75 prescribes how CMMC level requirements go into Defense contracts, and describes CMMC as a framework for assessing a contractor’s information security protections (DFARS 204.7500(a)). The subpart does not cancel any other requirement for protecting unclassified information, and does not affect the National Industrial Security Program (DFARS 204.7500(b)). It applies to unclassified contractor information systems (DFARS 204.7500(c)).
The contracting officer includes the required CMMC level in the solicitation, if the program office or requiring activity provides it (DFARS 204.7502(a)(1)). Contracting officers may not award a contract, task order or delivery order to an offeror without a current CMMC status at the required level (DFARS 204.7502(a)(2)). Contractors must have that status, or higher, at award for all information systems used in performance that will process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). They must keep it current throughout the life of the contract or order, if the contract requires it (DFARS 204.7502(a)(3)).
Award, or a modification exercising an option or extending performance, may proceed if the status is a recognized CMMC status equal to or higher than the required level (DFARS 204.7502(b)(1)). Levels 2 and 3 may be conditional for up to 180 days from the status date, and award may occur with a conditional level (DFARS 204.7502(b)(2)). Level 1 requires a final status for award.
Before award, contracting officers check the Supplier Performance Risk System (SPRS) for a current status at the required level, or higher, for each CMMC unique identifier (UID) the offeror provides (DFARS 204.7503(b)). Each UID applies to a contractor information system that will process, store or transmit FCI or CUI in performance of the contract. If the contractor provides new UIDs during performance, the contracting officer checks in SPRS that each newly identified system has a current status at the required level or higher (DFARS 204.7503(d)).
6. When the clause is used
Unless a waiver applies, the clause at DFARS 252.204-7021 is used on a schedule tied to dates (DFARS 204.7504(a)). Until 9 November 2028, it goes in solicitations, contracts and orders, including commercial acquisitions under Federal Acquisition Regulation (FAR) part 12, when the program office or requiring activity requires a specific CMMC level. Acquisitions solely for commercially available off-the-shelf (COTS) items are excluded in both periods. On or after 10 November 2028, it goes in when the program office or requiring activity determines that the contractor must use its information systems in performance to process, store or transmit FCI or CUI. The notice provision at DFARS 252.204-7025 goes in solicitations that include the clause (DFARS 204.7504(b)).
To avoid duplicated effort, the regulation credits some earlier DIBCAC High Assessments aligned with CMMC Level 2 scoping (32 CFR 170.20(a)). An organization that achieved a perfect score with no open plan of action from a DIBCAC High Assessment conducted before the rule’s effective date receives Final Level 2 (C3PAO) status (32 CFR 170.20(a)(1)). The scope of that Level 2 status is identical to the scope of the High Assessment, and DIBCAC identifies qualifying assessments and verifies that SPRS reflects the status. The status is valid for three years from the original assessment date, and the organization must still submit an affirmation and repeat it annually. The levels themselves are covered in how the CMMC model and its levels are built.
Key terms
| Implementation phase | One of four yearly stages by which CMMC requirements enter contracts. |
|---|---|
| C3PAO | A CMMC Third-Party Assessment Organization that conducts Level 2 certification assessments. |
| DIBCAC | The Defense Industrial Base Cybersecurity Assessment Center, which assesses Level 3. |
| Conditional status | A Level 2 or 3 status valid for up to 180 days while open items are closed. |
| Current status | A CMMC status that meets the clause’s age and affirmation tests, with no change in compliance since the status date. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Phased requirements affect when subcontractors abroad need a status in place. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.