DoW published the final CMMC rule on September 10, 2025, ref. 90 Federal Register (FR) 43560, with an effective date of November 10, 2025.
Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement[s]) to address new CMMC post-award requirements. DoW will implement CMMC in four phases:
- Phase 1 begins on November 10, 2025.
- Phase 2 begins on November 10, 2026.
- Phase 3 begins on November 10, 2027.
- Phase 4, the final phase, begins on November 10, 2028.
Recommended Contractor Actions Now:
- Ensure your current cybersecurity posture aligns with contractual requirements related to NIST SP 800‑171 controls.
- Follows all steps to use Procurement Integrated Enterprise Environment (PIEE) applications, to secure access to the Supplier Performance Risk System (SPRS) module, and post a current self-assessment score in SPRS.
- Monitor updates from DoD, DPCAP, and SAM.gov for USACE Special Notices, official timelines and certification requirement updates.
- Comply with current DFARS 252.204-7012 requirements to report cyber incidents to DoD within 72 hours of discovery, using DoD’s Cyber Crime Center (DC3) portal at: https://dibnet.dod.mil.
Important Disclaimers:
- This notice is for INFORMATION ONLY and does not impose new requirements.
- This notice does not create any rights/benefits enforceable by law against the U.S. Government.