The 48 CFR Final Rule: CMMC Is Now in Defense Contracts — Here's the Rollout Timeline

The waiting is over. The CMMC acquisition rule — the 48 CFR final rule, published September 10, 2025 — took effect on November 10, 2025. Since that date, the contract clause DFARS 252.204-7021 has been appearing in applicable new DoD solicitations, and contractors must hold the required CMMC status to be eligible for award. There is no grace period once the clause is in a solicitation: if you cannot show the required status, you cannot win the work.

The rule did not change any of the underlying CMMC requirements — those were set by the CMMC Program rule (32 CFR Part 170), which took effect December 16, 2024. What the 48 CFR rule did was operational: it put the clause into the acquisition system, authorized contracting officers to use it, and started the official phased rollout across the defense industrial base.

The Four-Phase Rollout

  • Phase 1 (November 10, 2025 – November 9, 2026). Applicable new solicitations require CMMC Level 1 or Level 2 self-assessments, with DoD discretion to require a third-party (C3PAO) assessment in select procurements.
  • Phase 2 (begins November 10, 2026). Applicable new solicitations begin requiring Level 2 C3PAO certification as a condition of award, with DoD discretion to defer the requirement to an option period. This is the step change for most CUI-handling contractors.
  • Phase 3 (begins November 10, 2027). Requirements extend further — including to option periods of contracts awarded earlier in the rollout — and Level 3 (DIBCAC) assessment requirements enter applicable solicitations.
  • Phase 4 (begins November 10, 2028). Full implementation: CMMC requirements appear in all applicable DoD solicitations and contracts, including option periods of contracts awarded before the rollout began.

The practical takeaway: "when does CMMC apply to me?" now depends on when your next solicitation drops and what information you handle. FCI alone points to Level 1; CUI points to Level 2; a small set of programs will require Level 3.

Is Your Organization CMMC Ready?

If your organization holds or plans to bid on DoD contracts, the certification question is no longer hypothetical — the clause is live today, and its reach widens every November through 2028. For organizations that have not yet earned Level 2 certification, a CMMC readiness assessment is the first step.

With 110 security requirements — more than seven times Level 1's 15 — Level 2 is vastly more complex. Certification assessments are conducted by a CMMC Third-Party Assessment Organization (C3PAO) and are valid for three years, with an annual affirmation of continuing compliance in SPRS; "significant changes" to your environment can trigger reassessment sooner.

The most important planning metric is the procurement administrative lead time (PALT) — the window between solicitation and contract award. If your customer typically awards three to four months after a solicitation, you must already hold the required status inside that window to accept the award. Waiting for the solicitation to start is unwise: C3PAO calendars are booked months out, and pre-assessment remediation routinely takes longer than the assessment itself.

Many contractors discover issues too late — sometimes during the assessment itself. A readiness assessment reveals the gaps while they are still fixable on your schedule, not the assessor's.

The Bottom Line

The 48 CFR rule is in effect, the rollout clock is running, and Phase 2's C3PAO requirement arrives in new solicitations on November 10, 2026. Essendis provides comprehensive CMMC readiness assessments that cover all requirements — including critical documentation and contracts — accelerating compliance timelines and improving your chances of acing the C3PAO assessment.

Connect with a CMMC advisor today to start your journey.

Related reading

Talk to a Cloud Cybersecurity Expert

Thank you for contacting Essendis. Our team is reviewing your submission and will be in touch shortly. 
We look forward to assisting with your cybersecurity and cloud computing needs. 

Continue Exploring Essendis’ Offerings

Return to Essendis
Oops! Something went wrong while submitting the form.