Skip to content
    Back to Regulatory Radar
    CriticalDeadlineNovember 10, 2025

    CMMC Phase 1 Begins as DFARS Final Rule Takes Effect

    The DFARS final rule for CMMC (DFARS Case 2019-D041, published September 10, 2025) took effect on November 10, 2025, starting Phase 1 of the CMMC phased implementation. From this date, DoD includes clause DFARS 252.204-7021 in applicable solicitations and contracts, requiring CMMC Level 1 (self-assessment) or Level 2 (self-assessment) as a condition of award, with program offices holding discretion to require Level 2 certification assessments in some procurements. Phase 1 is intentionally limited in scope to allow the assessment ecosystem to scale, but it establishes the contractual mechanism for mandatory cybersecurity certification in defense procurement.

    CMMCDefense

    Key Analytics

    November 10, 2025
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Defense contractors responding to solicitations issued during Phase 1 must be able to demonstrate the required CMMC level at time of contract award. Even though Phase 1 centers on self-assessment levels, the documentation and evidence requirements are rigorous, including a complete System Security Plan, a current SPRS score submission, and a senior official affirmation of continuous compliance. Organizations that treated NIST SP 800-171 compliance as a checkbox exercise will find that CMMC's assessment methodology demands substantive, verifiable control implementations, and inaccurate self-assessments or affirmations create False Claims Act exposure.

    Recommended Actions

    • Monitor SAM.gov and agency-specific procurement portals for solicitations containing CMMC DFARS clauses to understand which contracts are in scope for Phase 1
    • Validate your SPRS score accuracy and ensure it reflects your current implementation state, as material discrepancies create False Claims Act exposure
    • Complete your CMMC Level 2 self-assessment using the CMMC Assessment Guide methodology; Phase 2 third-party assessment requirements were suspended by DoD in July 2026, so monitor DoD announcements before committing to a certification timeline

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant120-240 hours
    Key Workstreams
    • Self-assessment against the CMMC Assessment Guide, closing the objectives that fail
    • SPRS score validation and correction so the posted score matches implementation
    • System security plan and evidence updates supporting each claimed practice
    • Solicitation monitoring on SAM.gov for DFARS 252.204-7021 clause appearances

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 120-240 hours
    Start cold under pressureMajor · 300-700 hours

    Roughly 180 to 460 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events