The Department of Defense published the final CMMC Program rule, 32 CFR Part 170, on October 15, 2024. It takes effect on December 16, 2024. The rule sets out three CMMC levels, who assesses each one, strict limits on open gaps (POA&Ms), and a requirement for a senior official to affirm compliance every year. It doesn't put CMMC into your contracts by itself, though. That depends on a separate DFARS rule, which DoD proposed in August 2024 and hasn't yet finalized.

If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for DoD, the rules of the program are now settled. The start date isn't, but the preparation work is the same either way.

What is the CMMC 2.0 final rule?

CMMC is implemented through two separate rules:

  • The program rule (32 CFR Part 170) defines the CMMC levels, the assessment process, scoring, POA&Ms, affirmations and the roles of assessors. This is the rule that became final on October 15, 2024.
  • The acquisition rule (48 CFR, DFARS Case 2019-D041) puts CMMC requirements into solicitations and contracts. DoD published it as a proposed rule on August 15, 2024, and the comment period closed on October 15, 2024.

The program rule tells you what CMMC compliance looks like. The acquisition rule will tell contracting officers when to require it. You can read the full final program rule in the Federal Register.

What are the three CMMC levels?

Level Protects Requirements Assessment Frequency
Level 1 (Self) FCI 15 requirements from FAR 52.204-21 Self-assessment Annual
Level 2 (Self) CUI 110 requirements from NIST SP 800-171 Rev. 2 Self-assessment Every 3 years
Level 2 (C3PAO) CUI 110 requirements from NIST SP 800-171 Rev. 2 Certified Third-Party Assessment Organization Every 3 years
Level 3 (DIBCAC) CUI in higher-priority programs Level 2 plus 24 selected requirements from NIST SP 800-172 Government assessment by DCMA's DIBCAC Every 3 years

Every level also requires an affirmation of compliance, which we cover below.

Level 1

Level 1 covers the 15 basic safeguarding requirements already in FAR 52.204-21. You assess yourself every year and post the result in the Supplier Performance Risk System (SPRS). No POA&Ms are allowed: all 15 requirements must be met.

Level 2

Level 2 is where most of the effort lies for contractors handling CUI. It aligns with the 110 security requirements of NIST SP 800-171 Revision 2.

NIST published Revision 3 of SP 800-171 in May 2024, but the CMMC rule is tied to Revision 2. Don't rebuild your program around Rev. 3 for CMMC purposes.

Level 3

Level 3 applies to CUI in DoD's highest-priority programs. It adds 24 requirements selected from NIST SP 800-172. You must already hold Final Level 2 (C3PAO) status for the same assessment scope before you can seek Level 3.

Self-assessment or C3PAO: which one do you need?

You don't choose. The solicitation will specify the level and assessment type, based on the information involved in the contract.

  • Level 2 (Self): You assess yourself against the 110 requirements and post your score in SPRS.
  • Level 2 (C3PAO): An authorized C3PAO assesses you, and the results are recorded in DoD's CMMC eMASS system.

Treat a self-assessment with the same rigor as a third-party one. The requirements are identical, and a senior official will be affirming the result.

How do POA&Ms work under the final rule?

A Plan of Action and Milestones (POA&M) lets you achieve a conditional status while you close a small number of gaps. The final rule allows them only within tight limits.

Level 1

No POA&Ms. All requirements must be fully met.

Level 2

You can hold Conditional Level 2 status with a POA&M only if all of the following are true:

  • Your score is at least 80 percent of the maximum, which works out to 88 of 110 points.
  • Every requirement on the POA&M has a point value of 1. The one exception is CUI encryption (SC.L2-3.13.11), which can go on a POA&M if you use encryption that isn't FIPS-validated.
  • None of the following is on the POA&M:
  • AC.L2-3.1.20 (external connections)
  • AC.L2-3.1.22 (control public information)
  • CA.L2-3.12.4 (system security plan)
  • PE.L2-3.10.3 (escort visitors)
  • PE.L2-3.10.4 (physical access logs)
  • PE.L2-3.10.5 (manage physical access)

Level 3

The same 80 percent threshold applies to the Level 3 requirements, and seven specific Level 3 requirements can't be placed on a POA&M.

The 180-day closeout

Conditional status lasts 180 days. Within that window you must close every open item and pass a POA&M closeout assessment, performed by whoever did the original assessment. If you don't close out in time, your conditional status expires.

The practical lesson is to treat POA&Ms as a small safety margin, not a plan. Any requirement worth more than one point has to be fully in place on assessment day.

What are CMMC annual affirmations?

Every CMMC level requires an affirmation of continuing compliance, submitted in SPRS by an Affirming Official. That's a senior person in your organization who is responsible for CMMC compliance and has the authority to affirm it.

Affirmations are required:

  • After each assessment
  • Annually after that
  • After a POA&M closeout

An affirmation is a formal representation to the government. The official signing it needs real evidence that controls are still operating, which means continuous monitoring, not a scramble before the anniversary.

When will CMMC requirements appear in contracts?

The final rule describes four phases. Phase 1 begins on the effective date of the 32 CFR rule or the 48 CFR DFARS rule, whichever is later. Because the DFARS rule isn't final yet, the Phase 1 start date isn't fixed.

Phase Starts What DoD intends to include in solicitations
Phase 1 Later of the two rules' effective dates Level 1 (Self) and Level 2 (Self)
Phase 2 One year after Phase 1 starts Adds Level 2 (C3PAO)
Phase 3 One year after Phase 2 starts Adds Level 3 (DIBCAC)
Phase 4 One year after Phase 3 starts Full implementation across applicable solicitations and contracts

DoD has discretion to require a higher level in some solicitations earlier in the rollout. Don't assume you'll get the full phase-in period.

What would the proposed DFARS rule require?

As proposed, the DFARS rule would require contractors to:

  • Have a current CMMC status at the required level, or higher, in SPRS before award.
  • Maintain a current affirmation of continuous compliance.
  • Provide DoD unique identifiers for the information systems that will process, store or transmit FCI or CUI during the contract.
  • Notify the contracting officer of changes to those information systems.

The proposal describes a three-year phase-in during which CMMC appears only in solicitations where the program office requires it, followed by broad application to contracts involving FCI or CUI. The final text may change after DoD reviews public comments.

What about subcontractors and cloud providers?

CMMC requirements flow down. The final rule sets the minimum level a subcontractor needs based on the prime's requirement and the information the subcontractor handles.

Prime contract requirement Subcontractor handling FCI only Subcontractor handling CUI
Level 1 (Self) Level 1 (Self) Not applicable
Level 2 (Self) Level 1 (Self) Level 2 (Self)
Level 2 (C3PAO) Level 1 (Self) Level 2 (C3PAO)
Level 3 (DIBCAC) Level 1 (Self) Level 2 (C3PAO)

If you use a cloud service provider to handle CUI, you need to confirm it meets the FedRAMP Moderate baseline or equivalent. Other external service providers, such as managed IT providers, fall within your assessment scope when their services touch FCI or CUI. Get their responsibilities in writing.

How should defense contractors prepare now?

The requirements are settled even if the start date isn't. Here's where we'd focus:

  1. Find your FCI and CUI. Map where it enters, where it's stored, how it moves and who touches it. This determines your likely level.
  2. Shrink your scope. A well-defined CUI environment is cheaper to secure and faster to assess than an entire corporate network.
  3. Write or update your System Security Plan. CA.L2-3.12.4 can't go on a POA&M, so an assessment without a current SSP fails.
  4. Run an honest self-assessment. Score yourself against all 110 requirements using DoD's assessment methodology, and make sure your SPRS score is current. The existing DFARS clauses 252.204-7019 and 252.204-7020 already require one for contracts covered by 252.204-7012.
  5. Fix the high-value gaps first. Anything worth more than one point, and the six requirements that can't be deferred, must be fully in place.
  6. Talk to your supply chain. Tell subcontractors what level they'll need. Get written confirmation from cloud and managed service providers about their responsibilities.
  7. Name your Affirming Official. Agree on what evidence that person needs to see before signing, and how often.
  8. Plan for a C3PAO if you expect one. Assessor capacity is limited, so if your contracts involve CUI that will likely require Level 2 (C3PAO), start planning well ahead of Phase 2.

Frequently asked questions

Will CMMC be in our contracts on December 16, 2024?

Not automatically. December 16 is when the program rule takes effect. Phase 1 can't start until the DFARS acquisition rule is also final and effective.

Do we need to implement NIST SP 800-171 Revision 3?

Not for CMMC. The final rule ties Level 2 to the 110 requirements of Revision 2.

How long does a CMMC Level 2 status last?

Three years, for both self-assessments and C3PAO assessments. You still need an affirmation every year, and you'll need a new assessment at the end of the three years.

Can we pass with some gaps still open?

Only at Levels 2 and 3, and only within the POA&M limits above. You'd receive conditional status and have 180 days to close every gap and pass a closeout assessment.

Key takeaways

  • The 32 CFR Part 170 final rule was published October 15, 2024, and takes effect December 16, 2024.
  • Level 1 is an annual self-assessment of 15 requirements. Level 2 covers the 110 requirements of NIST SP 800-171 Rev. 2, assessed by you or a C3PAO. Level 3 adds 24 requirements from SP 800-172.
  • POA&Ms are narrow: not allowed at Level 1, and at Levels 2 and 3 they require an 80 percent score, apply only to certain requirements and must close within 180 days.
  • A senior Affirming Official must affirm compliance after each assessment and every year.
  • Contract requirements will phase in over four phases once the separate DFARS rule is final.