Skip to content

Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)

Federal Register / Vol. 90, No. 173 / Wednesday, September 10, 2025 / Rules and Regulations

48 CFR Parts 204, 212, 217, and 252 Docket DARS-2020-0034 · RIN 0750-AK81

Agency: Defense Acquisition Regulations System, Department of Defense (DoD) Action: Final rule

Summary

DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) Program rule. This final DFARS rule also partially implements a section of the National Defense Authorization Act (NDAA) for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.

Effective date: November 10, 2025

For further information contact: Ms. Heather Kitchens, telephone 571-296-7152.


I. Background

  • DoD published an interim rule at 85 FR 61505 on September 29, 2020, to assess contractor implementation of cybersecurity requirements and enhance protection of unclassified information within the DoD supply chain.
  • DoD published a proposed rule at 89 FR 66327 on August 15, 2024, to implement the contractual requirements related to CMMC. Ninety-seven respondents submitted public comments.
  • Separately, a proposed rule to establish the CMMC program at 32 CFR part 170 was published at 88 FR 89058 on December 26, 2023. The final rule was published at 89 FR 83092 on October 15, 2024, and became effective December 16, 2024.

II. Discussion and Analysis

A. Summary of Significant Changes From the Proposed Rule

1. Definitions - DFARS 204.7501 adds/modifies definitions. "Current" is clarified to mean no changes in compliance with 32 CFR part 170 requirements, including as applied to Conditional CMMC Status, Final CMMC Status, and affirmation of continuous compliance. - "DoD unique identifier" renamed "CMMC unique identifier" (CMMC UID) — ten alpha-numeric characters assigned to each contractor CMMC assessment and reflected in the Supplier Performance Risk System (SPRS). - New definitions added: "Federal contract information" (FCI) (based on FAR 52.204-21), "plan of action and milestones" (POA&M) (based on 32 CFR part 170), and "CMMC status".

2. Policy - DFARS 204.7502 clarifies that for CMMC Levels 2 and 3 only, a conditional CMMC status is permitted for up to 180 days from the conditional CMMC date (32 CFR 170.21), and award can occur with conditional status. - Final CMMC status is achieved upon successful closeout of a valid POA&M.

3. Procedures - DFARS 204.7503 adds paragraph headings for clarity. - Contracting officers must check SPRS and not award a contract, task order, or delivery order to an offeror lacking a current CMMC status at the required level (or higher) in SPRS, for each CMMC UID applicable to information systems processing, storing, or transmitting FCI or CUI in contract performance. - All offerors must provide CMMC UIDs for each relevant contractor information system.

4. Clause Prescription - DFARS 204.7504 clarifies a phased implementation: - Until 3 years after the effective date: clause applies if program managers/requiring activities determine a CMMC requirement applies, excluding COTS-only awards. - Beginning 3 years and 1 day after the effective date: clause applies whenever the contractor will use contractor information systems to process, store, or transmit FCI or CUI, excluding COTS-only awards.

5. Solicitation Provision and Contract Clause - Adds a fill-in for the contracting officer to specify the required CMMC level. - Subcontract flowdown updated: subcontractors must also submit affirmations of continuous compliance and self-assessment results in SPRS. - "Affirming official" replaces "senior company official" to match 32 CFR part 170. - CMMC level terminology standardized as: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC). - Offerors must have current CMMC status and a current affirmation of continuous compliance in SPRS at proposal/award time, and must update CMMC UIDs as they change.

B. Analysis of Public Comments

DoD received extensive public comment. Below is a condensed summary of each topic area, comment theme, and DoD's response. (Full verbatim comment/response text has been paraphrased and shortened for readability — consult the original Federal Register notice for exact wording if needed for legal purposes.)

1. Clarification of "Changes"

Commenters sought clarity on what "changes" require reporting. Response: The final rule requires contractors to submit any changes in CMMC UIDs generated in SPRS throughout contract life, replacing the broader "any changes" language. A separate recommendation to remove the CO notification requirement for lapses in information security was accepted — reporting is instead handled via the existing 72-hour incident reporting requirement at DFARS 252.204-7012© and the annual affirmation of continuing compliance.

2. Clarification of "Lapses in Information Security"

Response: The requirement to notify the contracting officer of "lapses in information security" was removed from the final rule.

3. Editorial Changes

Various typo/wording corrections were noted. Response: Most were mooted by other final-rule changes; the suggestion to replace "or" with "and/or" (re: CMMC UIDs) was not adopted, as it could narrow the requirement's scope.

4. CMMC Level Notification and Compliance

Response: CMMC level is determined per 32 CFR 170.19 (CMMC scoping) by the program office/requiring activity (prime) or prime/next-higher-tier subcontractor (subcontract). Four CMMC levels exist: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), Level 3 (DIBCAC). DoD declined to limit CMMC inclusion in existing contracts — COs retain discretion to bilaterally modify existing contracts. A CMMC level fill-in was added to the clause. Continued compliance is required for the life of the contract.

5. COTS Item Exclusion

Response: The rule does not apply to awards exclusively for commercially available off-the-shelf (COTS) items, as defined at FAR 2.101.

6. Extending Certification Time for New Bidders

Response: Per 32 CFR part 170, contractors must have a CMMC self-assessment/certification (if required) at time of award; no delayed implementation for new bidders, though POA&Ms are allowed in certain instances under 32 CFR 170.21.

7. Flowdown When Subcontractors Use the Prime's Information System

Response: A subcontractor that does not process, store, or transmit FCI/CUI on its own systems has no CMMC assessment requirement. DoD has no automated tool giving primes visibility into subcontractor SPRS status; subcontractors may voluntarily share their scores/certificates.

8. Definitions

  • CUI — kept aligned with the definition codified at 32 CFR part 170; broader changes are out of scope for this rule.
  • FCI — a definition was added, based on FAR 52.204-21 (includes "information necessary to process payments" as an example of simple transactional information).
  • "Current" — the definition was revised in the final rule (see § 204.7501 below) to address ambiguity about assessment vs. certification dates.
  • "Data" — the term "data" was removed from the rule; it now applies only to information that is FCI or CUI.
  • Contractor information systems — clarified to mean only systems that "process, store, or transmit FCI or CUI in performance of the contract."

9. Regulatory Impact Analysis (RIA) Estimate

Commenters felt the RIA underestimated costs and the estimate of 5 information systems per contractor. Response: The RIA was revised to expand the estimated impacted-entity count to include, from year four onward, all FY2022–FY2024 DoD awardees in the Federal Procurement Data System (adjusted to exclude assumed COTS-only awards). The 5-systems-per-contractor figure remains a DoD subject-matter-expert estimate.

10. Application to Fundamental Research

Response: Fundamental research (per NSDD 189) is not FCI/CUI while it remains publicly shared, but becomes subject to CMMC once/if it becomes CUI.

11. Applicability

Response: The clause applies to solicitations issued on/after the effective date and resulting contracts; COs may include it in earlier solicitations if award occurs after the effective date, and may bilaterally add it to existing contracts (FAR 1.108(d)). Phase-in timeline confirmed (3-year threshold as above). If CMMC is required, it applies to all information systems processing/storing/transmitting FCI or CUI in contract performance. Spot checks are not permitted under 32 CFR part 170; CMMC status must be met at time of award.

12. Flowdown

Response: See 32 CFR 170.23 (CMMC application to subcontractors). Flowdown is required only when the subcontract itself requires a CMMC level. Clause paragraph (d)(1) was revised so the affirmation-of-continuous-compliance requirement also flows down to subcontractors. DoD declined to add language dictating exactly what CUI a prime may share with FCI-only subcontractors — this remains the prime's determination.

13. CMMC as an Evaluation Factor

Response: CMMC is not an evaluation/set-aside factor; it is a contract requirement — COs may not award to an offeror that fails to meet the solicitation's CMMC requirement.

14. Program Office Requirements

Response: The rule was revised so the contracting officer works with the program office/requiring activity to review the offeror's CMMC status and affirmation.

15. Clarifying When FCI Applies

Response: Not adopted — the DFARS is written for the contracting workforce; COs do not set the required CMMC level.

16. International Applicability

Response: Foreign C3PAOs are not precluded from accreditation (see 32 CFR 179). Any contract subject to NIST SP 800-171 (e.g., via DFARS 252.204-7012) requires the contractor — foreign or domestic — to secure its systems; CMMC assessments validate compliance. DoD noted an alternate Tier 3 background-investigation equivalence process for non-US C3PAO personnel.

17. POA&M

Response: The "current" definition was revised to clarify that Conditional CMMC status (Levels 2 & 3 only) is valid for up to 180 days. A Final CMMC status is achieved upon successful POA&M closeout. Additional POA&M use beyond 32 CFR part 170's scoping was not adopted, except for scenarios appropriate to an "operational plan of action" under 32 CFR 170.4.

18. Subcontractor Compliance

Response: Contractors can only access their own CMMC status information in SPRS — there is no DoD tool for primes to view subcontractor status. Primes are expected to manage this the same way they manage any other flowed-down clause requirement; subcontractors may share screenshots of their own SPRS status voluntarily. Before awarding a subcontract, the prime must ensure the subcontractor has a current, appropriate CMMC status.

19. "Senior Company Official"

Response: Terminology was updated throughout the final rule to "affirming official," matching the term codified at 32 CFR part 170 (170.22) — the proposed rule had used outdated terminology due to publication timing.

20. Task Orders and Delivery Orders

Response: Task/delivery orders issued after the rule's effective date under existing IDIQ contracts may include a CMMC requirement.

21. "Covered Contractor Information Systems" vs. "Contractor Information Systems"

Response: The rule clarifies that "contractor information systems" means systems that "process, store, or transmit FCI or CUI" during contract performance — not a broader universe of systems.

22. CMMC Unique Identifiers (UIDs)

Response: A CMMC UID is issued per assessment scope (as defined by the Organization Seeking Assessment, per 32 CFR 170.19) and appears in SPRS. Organizations need a CAGE code (via SAM.gov) and a PIEE/SPRS account; non-US entities need an NCAGE code. Only prime contractors must submit CMMC UIDs to the contracting officer (which may include subcontractor UIDs obtained from those subcontractors); subcontractors themselves do not report UIDs directly to the CO. A new UID is generated whenever a new assessment score is entered (e.g., at reassessment/re-certification).

23. Creation of Exception

Response: 32 CFR part 170 does not provide an exceptional-circumstances exemption, so this DFARS rule cannot create one. DoD does not require CMMC flowdown to subcontractors that do not receive FCI/CUI.

24. Period of Performance

Response: Per 32 CFR part 170, CMMC status must be maintained for the life of the contract; COs must validate compliance before exercising options or extending performance periods.

25. Prime Contractor Protection From Subcontractor Noncompliance

Response: The Government does not establish prime/subcontractor relationships or indemnify primes, as it lacks privity of contract with subcontractors.

26. Application of CMMC to FAR Part 16 Contract Types

Response: No additional approval process was added; 32 CFR part 170 already governs CMMC applicability.

27. Acquiring Entities Without CMMC Certification

Response: Contractors must report UID list changes per clause paragraph ©(1). Adding new users to an existing system doesn't necessarily change assessment scope (see 32 CFR 170.19).

28. Applicability to Civilian Agencies

Response: This rule amends only the DFARS, so it applies only to DoD (or DoD-funded) acquisitions.

29. Provision and Clause Clarifications

Response: The clause was updated so subcontractors must enter self-assessment results into SPRS and complete an annual affirmation of continuous compliance. Subcontractors may screenshot their own SPRS status to share as needed. The phrase "unless electronically posted" was removed. Paragraph ©(1) is excluded from subcontractor flowdown (no Government privity with subcontractors), though primes are encouraged to flow down similar language voluntarily.

30. Outside the Scope of This Rule

Many comments addressed the underlying 32 CFR part 170 CMMC program itself (not this DFARS rule) and were noted as out of scope, including: CMMC level-selection guidance, Level 2 certification vs. self-assessment criteria, Morale/Welfare/Recreation exemptions, eMASS access, cost allowability, enclave scoping, reassessment policy, flowdown detail, FedRAMP/Cloud Service Provider evaluation, and others. Selected clarifications DoD did offer regardless: - CMMC level selection is made by the program office/requiring activity per 32 CFR 170.5; COs do not select it. - All CUI categories generally require at least a self-assessment; DoD Organizational Index CUI categories generally require a C3PAO assessment at minimum. - MWR/NAF procurements requiring NIST SP 800-171 safeguarding are subject to CMMC. - Waivers are established at 32 CFR 170.5 and decided before CO involvement. - Contractors do not have eMASS access (assessment-support system only); all CMMC assessments appear in SPRS.

C. Other Changes

  • DFARS 204.7500 was updated to remove a web address, replacing it with a reference to 32 CFR part 170.
  • Clarified throughout that a higher CMMC level than required is always permissible.
  • The term "CMMC status" was added and defined throughout (204.75, clause 252.204-7021, provision 252.204-7025), clarifying that awards may proceed with a current Final Level 1 (Self), Conditional/Final Level 2 (Self), or Conditional/Final Level 2 (C3PAO) status.

III. Applicability to Contracts at/Below the Simplified Acquisition Threshold (SAT), Commercial Products (incl. COTS), and Commercial Services

  • Clause 252.204-7021 is prescribed at DFARS 204.7504:
  • Until November 9, 2028: applies to solicitations/contracts/orders (including FAR part 12 commercial acquisitions), excluding COTS-only awards, when the program office/requiring activity determines a specific CMMC level is required.
  • On/after November 10, 2028: applies whenever the contractor must use contractor information systems to process, store, or transmit FCI or CUI, excluding COTS-only awards.
  • Provision 252.204-7025 is prescribed at DFARS 204.7504(b) for use in solicitations containing the 252.204-7021 clause.
  • DoD applies NDAA FY2020 §1648 to contracts at/below the SAT, commercial products (excluding COTS), and commercial services (FAR 2.101).

IV. Expected Impact of the Rule

A. Background

CMMC self-assessments and third-party assessments verify a contractor's compliance with information system security requirements for systems that process, store, or transmit FCI or CUI (per 32 CFR part 170, final rule at 89 FR 83092, October 15, 2024).

New DFARS solicitation/contract requirements: - Post CMMC Level ½ self-assessment results to SPRS before award, option exercise, or period-of-performance extension. - Maintain the required CMMC status for the life of the contract. - Have an affirming official complete an annual (or status-change-triggered) affirmation of continuous compliance in SPRS for each applicable CMMC UID. - Identify contractor information systems in scope by providing SPRS-generated CMMC UIDs before award, option exercise, or performance extension.

(Technical assessment costs themselves are addressed in the 32 CFR part 170 rule, not this DFARS rule.)

B. Summary of Impact

  • Phase-in (years 1–3): Applies only where the solicitation/contract specifically requires a CMMC level.
  • Year 4 onward: Applies to any contract/order requiring FCI/CUI processing, storage, or transmission on contractor systems (excluding COTS-only awards).

Estimated impacted entities (Year 4+), based on FY2022–FY2024 Federal Procurement Data System data:

Metric Value
Unique entities awarded above micro-purchase threshold 32,756
...of which, awarded via commercial procedures only 18,370
Assumed COTS-only awardees (25% of the above) 4,592
Entities remaining after COTS exclusion 28,164
Assumed offerors per solicitation 2
Total prime offerors (28,164 × 2) 56,328
Assumed subcontractors per prime offer 5
Total estimated impacted entities (primes + subs) 337,968
Estimated small entities (68%) 229,818

Estimated time burdens (per contractor information system):

Offerors/contractors: - ~5 minutes to post self-assessment results in SPRS - ~5 minutes to complete the required affirmation in SPRS - ~5 minutes to retrieve and submit CMMC UIDs

Government: - ~5 minutes to validate CMMC level/currency for all offerors pre-award, and for contractors pre-option/extension - ~5 minutes to validate a current affirmation per applicable system - ~5 minutes to validate status/affirmation when CMMC UIDs change during performance

Benefits: Verification of DIB contractors' cybersecurity posture, extending beyond DFARS 252.204-7012's self-attestation model by adding third-party assessment verification. The rule cites Council of Economic Advisors estimates that malicious cyber activity cost the U.S. economy $57–109 billion in 2016 (equating to an estimated \(400B–\)929B over 10 years depending on discount rate), and GAO/Treasury reporting that ransomware-related incidents reached $886 million in 2021.

10-Year Cost Summary (3% discount rate):

Public Government Total
Present Value $329,097,922 $15,812,069 $344,909,991
Annualized Costs $38,580,316 $1,760,303 $40,340,619

10-Year Cost Summary (7% discount rate):

Public Government Total
Present Value $254,756,766 $11,533,649 $266,290,415
Annualized Costs $36,271,632 $1,642,132 $37,913,764

V. Executive Orders 12866 and 13563

This is a significant regulatory action, subject to review under E.O. 12866 § 6(b), as amended.

VI. Executive Order 14192

The rule is exempt from E.O. 14192 as it concerns a national security function — implementing CMMC is deemed urgently needed to protect DoD information and the defense industrial base's intellectual property against cyber exfiltration.

VII. Congressional Review Act

DoD will submit the rule to Congress and the Comptroller General per 5 U.S.C. 801-808. The Office of Information and Regulatory Affairs determined this is not a major rule under 5 U.S.C. 804(2).

VIII. Regulatory Flexibility Act

A final regulatory flexibility analysis was prepared. Key points:

Requirements for CMMC-affected offerors/contractors: 1. Post current CMMC status in SPRS for each applicable CMMC UID (self-assessments not already covered by C3PAO/DIBCAC). 2. Maintain the required CMMC status for the life of the contract. 3. Provide CMMC UID(s) to the contracting officer, with updates as needed. 4. Maintain a current affirmation of continuous compliance in SPRS for each CMMC UID.

Phased small-entity impact estimates:

Year Estimated Small Entities Affected
Year 1 1,104
Year 2 5,565
Year 3 18,554
Year 4+ 229,818

Anticipated Year 4+ mix of CMMC statuses:

CMMC Level % Small Entities Large Entities Total Entities
Level 1 Self-assessment 62% 142,487 67,053 209,540
Level 2 Self-assessment 2% 4,596 2,163 6,759
Level 2 Certificate 35% 80,436 37,853 118,289
Level 3 Certificate 1% 2,298 1,082 3,380
Total 100% 229,818 108,150 337,968

DoD found no viable alternative that meets the statutory objective while reducing small-entity burden further, beyond the phased rollout and the COTS-only exclusion.

IX. Paperwork Reduction Act

This rule's information collection requirements are approved under the PRA (44 U.S.C. chapter 35), OMB Control Number 0750-0008 (DFARS Part 204, Contractor Implementation of Cybersecurity Requirements).


List of Subjects in 48 CFR Parts 204, 212, 217, and 252: Government procurement.

Kimberly R. Ziegler, Editor/Publisher, Defense Acquisition Regulations System.

The interim rule (48 CFR parts 204, 212, 217, and 252), originally published at 85 FR 61505 on September 29, 2020, is adopted as final with the changes below.

Authority: 41 U.S.C. 1303 and 48 CFR chapter 1.


Regulatory Text

PART 204 — Administrative and Information Matters

Subpart 204.75 — Cybersecurity Maturity Model Certification

Table of Contents - 204.7500 Scope of subpart. - 204.7501 Definitions. - 204.7502 Policy. - 204.7503 Procedures. - 204.7504 Solicitation provision and contract clause.


204.7500 Scope of subpart.

(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor's information security protections.

(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.

© This subpart applies to unclassified contractor information systems.

204.7501 Definitions.

As used in this subpart—

Controlled unclassified information means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).

Current means—

  1. With regard to Conditional CMMC Status
  2. (i) Not older than 180 days for Conditional Level 2 (Self) and Conditional Level 2 (C3PAO) assessments, with:
    • (A) No changes in compliance with 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16, 170.17); and
    • (B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and
  3. (ii) Not older than 180 days for Conditional Level 3 (DIBCAC) assessments, with:

    • (A) No changes in compliance since the Conditional CMMC Status date (see 32 CFR 170.18); and
    • (B) A corresponding affirmation of continuous compliance.
  4. With regard to Final CMMC Status

  5. (i) Not older than 1 year for Final Level 1 (Self), with no compliance changes since the Final CMMC Status date (32 CFR 170.15) and a corresponding affirmation (≤1 year old);
  6. (ii) Not older than 3 years for Final Level 2 (Self)/(C3PAO), with no compliance changes since the Final CMMC Status date (32 CFR 170.16, 170.17) and a corresponding affirmation (≤1 year old); and
  7. (iii) Not older than 3 years for Final Level 3 (DIBCAC), with no compliance changes since the Final CMMC Status date (32 CFR 170.18) and a corresponding affirmation (≤1 year old).

  8. With regard to affirmation of continuous compliance (32 CFR 170.22): not older than 1 year with no changes in compliance.

Cybersecurity Maturity Model Certification (CMMC) status means the result of meeting or exceeding the minimum required score for the corresponding assessment. Potential statuses: 1. Final Level 1 (Self) 2. Conditional Level 2 (Self) 3. Final Level 2 (Self) 4. Conditional Level 2 (C3PAO) 5. Final Level 2 (C3PAO) 6. Conditional Level 3 (DIBCAC) 7. Final Level 3 (DIBCAC)

Cybersecurity Maturity Model Certification unique identifier (CMMC UID) means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in SPRS for each contractor information system.

Federal contract information (FCI) means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information the Government provides to the public (e.g., on public websites) or simple transactional information (e.g., information necessary to process payments).

204.7502 Policy.

(a) Award eligibility. 1. The contracting officer shall include the required CMMC level in the solicitation, if provided by the program office/requiring activity. 2. COs shall not award a contract, task order, or delivery order to an offeror lacking a current CMMC status at the required level. 3. Contractors must achieve, at time of award, the required CMMC status (or higher) for all information systems processing, storing, or transmitting FCI or CUI, and must maintain it throughout the contract's life.

(b) CMMC status. 1. COs may award a contract, task order, delivery order, or modification (to exercise an option/extend performance) if the offeror's/contractor's CMMC status is listed in the "CMMC status" definition and is equal to or higher than required. 2. CMMC Levels 2 and 3 can be in conditional status for up to 180 days from the CMMC status date (32 CFR 170.21), and award can occur with conditional status. CMMC Level 1 requires final status for award.

204.7503 Procedures.

(a) CMMC level. The CO shall include the required CMMC level (32 CFR 170.19) in the solicitation provision and contract clause prescribed at 204.7504.

(b) Award. COs shall check SPRS and not award to an offeror lacking a current CMMC status posted in SPRS at the required level (or higher) for each CMMC UID provided, applicable to systems that will process, store, or transmit FCI or CUI in contract performance.

© Option exercise or period-of-performance extension. COs shall check SPRS and not exercise an option or extend performance unless the contractor has a current CMMC status at the required level (or higher) for each applicable CMMC UID.

(d) CMMC UIDs. If the contractor provides new CMMC UIDs during performance, the CO shall verify in SPRS that the contractor has a current CMMC status at the required level for each newly identified system.

204.7504 Solicitation provision and contract clause.

(a) Unless the requirements at 32 CFR 170.5(d) are met, use clause 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements: 1. Until November 9, 2028 — in solicitations/contracts/orders (including FAR part 12 commercial acquisitions), excluding COTS-only awards, if the program office/requiring activity determines a specific CMMC level is required. 2. On/after November 10, 2028 — in solicitations/contracts/orders (including FAR part 12 commercial acquisitions), excluding COTS-only awards, if the contractor will be required to use contractor information systems to process, store, or transmit FCI or CUI.

(b) Use provision 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements, in solicitations that include the 252.204-7021 clause.


PART 212 — Acquisition of Commercial Products and Commercial Services

Amend 212.301 by: - In paragraph (f)(ii)(L), replacing "204.7503 (a) and (b)" with "204.7504(a)"; and - Adding paragraph (f)(ii)(P):

(P) Use the provision at 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements, as prescribed in 204.7504(b).


PART 217 — Special Contracting Methods

Revise 217.207 — Exercise of options.

© In addition to FAR 17.207© requirements, exercise an option only after—

  1. Determining the contractor's SAM.gov record is active and its unique entity identifier, CAGE code, name, and physical address are accurately reflected in the contract document (see PGI 217.207 re: cost/price analysis of spare parts before exercising firm-fixed-price options with spare parts); and

  2. Working with the program office/requiring activity to verify in SPRS (https://piee.eb.mil) that—

  3. (i) The summary-level score of a current NIST SP 800-171 DoD Assessment (not more than 3 years old, unless the solicitation specifies less) is posted for each relevant covered contractor information system (see 204.7303); and
  4. (ii) If a CMMC status at a specific level is required, the contractor has a current CMMC status at that level (or higher) for each applicable CMMC UID (see 204.7503©).

PART 252 — Solicitation Provisions and Contract Clauses

252.204-7021 — Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements (NOV 2025)

As prescribed in 204.7504(a), use the following clause:

(a) Definitions. (Same definitions as DFARS 204.7501 above: Controlled unclassified information, Current, Cybersecurity Maturity Model Certification (CMMC) status, CMMC unique identifier (CMMC UID), Federal contract information (FCI) — plus:)

Plan of action and milestones means a document identifying tasks to be accomplished, detailing required resources, milestones, and scheduled completion dates, as defined in NIST Special Publication 800-115 (32 CFR 170.21).

(b) Framework. CMMC is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170).

© Duplication. CMMC assessments will not duplicate other comparable DoD assessments, except in rare circumstances requiring reassessment (e.g., indications of cybersecurity or CMMC-compliance issues).

(d) Requirements. The Contractor shall—

  1. (i) Have and maintain, for the contract's duration, a current CMMC status at the level specified by the Contracting Officer — CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC) — or higher, for all information systems processing, storing, or transmitting FCI or CUI in contract performance; and (ii) Consult 32 CFR 170.23 regarding flowdown, and flow down the correct CMMC level to subcontracts and other contractual instruments;
  2. Only process, store, or transmit FCI or CUI on contractor information systems that meet the required CMMC status level, or higher;
  3. Complete on an annual basis, and maintain as current, an affirmation by the affirming official (32 CFR 170.4) of continuous compliance in SPRS (https://piee.eb.mil) for each applicable CMMC UID;
  4. Ensure all subcontractors/suppliers complete, prior to subcontract award and maintain annually, an affirmation of continuous compliance for each applicable subcontractor information system; and
  5. If the Contractor's CMMC Status is Conditional, successfully close out a valid POA&M (32 CFR 170.21) to achieve Final status.

(e) Reporting. The Contractor shall—

  1. Submit to the Contracting Officer—
  2. (i) The CMMC UID(s) issued by SPRS for applicable contractor information systems; and
  3. (ii) Any changes in CMMC UIDs generated in SPRS throughout contract life, if applicable;
  4. Enter into SPRS the results of a current self-assessment for each applicable CMMC UID not covered by a C3PAO or DIBCAC assessment; and
  5. Complete in SPRS, annually, and maintain as current, an affirmation of continuous compliance by the affirming official for each self-assessment, C3PAO assessment, or DIBCAC assessment required.

(f) Subcontracts. The Contractor shall—

  1. Insert the substance of this clause (including paragraph (f), excluding paragraph (e)(1)) in subcontracts and other contractual instruments — including for commercial products/services, but excluding COTS items — if the subcontract will involve processing, storing, or transmitting FCI or CUI; and
  2. Prior to awarding a subcontract or other contractual instrument, ensure the subcontractor has a current CMMC certificate/status at the level appropriate to the information being flowed down (per 32 CFR 170.23).

(End of clause)


252.204-7025 — Notice of Cybersecurity Maturity Model Certification Level Requirements (NOV 2025)

As prescribed in 204.7504(b), use the following provision:

(a) Definitions. As used in this provision, controlled unclassified information (CUI), current, Cybersecurity Maturity Model Certification (CMMC) status, CMMC unique identifier (CMMC UID), Federal contract information (FCI), and Plan of action and milestones have the meanings given in the DFARS 252.204-7021 clause of this solicitation.

(b) 1. CMMC level. The CMMC level required by this solicitation is: ___ [CO to insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]. This level (or higher, per 32 CFR part 170) is required prior to award for each contractor information system that will process, store, or transmit FCI or CUI during contract performance. 2. The Offeror will not be eligible for award if it lacks, for each applicable contractor information system— - (i) A current CMMC status entered in SPRS (https://piee.eb.mil) at the required level; and - (ii) A current affirmation of continuous compliance with 32 CFR part 170 security requirements in SPRS.

© Plan of action and milestones. If the Offeror's CMMC Status is Conditional, the Offeror shall successfully close out a valid POA&M (32 CFR 170.21) to achieve Final status.

(d) CMMC unique identifiers. The Offeror shall provide, in its proposal, the CMMC UID(s) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI during contract performance, and shall update this list as new UIDs are generated. CMMC UIDs are provided in SPRS after the Offeror enters self-assessment results for each such system.

(End of provision)


[FR Doc. 2025-17359 Filed 9-9-25; 8:45 am] — Billing Code 6001-FR-P