Skip to content
    Back to Regulatory Radar
    CriticalNew RegulationDecember 26, 2023

    CMMC 2.0 Proposed Rule Published in Federal Register

    The Department of Defense published the CMMC 2.0 proposed rule (32 CFR Part 170) in the Federal Register, initiating a 60-day public comment period that closed February 26, 2024. The proposed rule formalized the three-tiered model: Level 1 (annual self-assessment, 15 security requirements from FAR 52.204-21), Level 2 (self-assessment or third-party C3PAO certification depending on contract, 110 requirements from NIST 800-171 Rev 2), and Level 3 (government-led assessment, adding 24 selected NIST 800-172 requirements on top of the Level 2 baseline). The rule established the C3PAO ecosystem, assessment methodology, and Plans of Action and Milestones (POA&M) closeout requirements.

    CMMCNIST 800-171Defense

    Key Analytics

    December 26, 2023
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    2
    Frameworks Affected

    Impact Analysis

    The proposed rule signaled that CMMC was moving from concept to enforcement, giving the defense industrial base concrete regulatory text to plan against. Organizations handling Controlled Unclassified Information (CUI) were put on notice that self-attestation under DFARS 252.204-7012 would give way to formal assessment requirements. DoD received roughly 361 public comment submissions and finalized the rule on October 15, 2024, effective December 16, 2024; the companion 48 CFR DFARS rule took effect November 10, 2025, and CMMC requirements are now phasing into DoD solicitations and contracts.

    Recommended Actions

    • Determine your organization's required CMMC level based on the type of DoD information handled (FCI vs CUI vs critical CUI)
    • Begin or accelerate NIST 800-171 implementation, as the 110 practices form the complete control set for CMMC Level 2
    • Budget for assessment costs and engage a Registered Practitioner Organization (RPO) to conduct a pre-assessment gap analysis

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant110-220 hours
    Key Workstreams
    • Gap closure against the 110 NIST 800-171 practices, largest SPRS deductions first
    • Level determination based on the FCI, CUI, and critical CUI actually handled
    • RPO pre-assessment engagement and remediation sequencing

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 110-220 hours
    Start cold under pressureMajor · 280-640 hours

    Roughly 170 to 420 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events