The U.S. Department of Defense (DoD) is moving to revise the Defense Federal Acquisition Regulation Supplement (DFARS) by introducing new contractual obligations linked to the upcoming Cybersecurity Maturity Model Certification (CMMC) 2.0 framework. This change is part of an effort to implement aspects of the National Defense Authorization Act for Fiscal Year 2020, which mandates the development of a unified and robust cybersecurity strategy for the defense industrial base (DIB).
In a notice published in the Federal Register, the DoD is seeking input from stakeholders on this proposed rule. Comments must be submitted in writing by October 15, 2024, to influence the final rule.
The CMMC 2.0 framework aims to enhance the evaluation of contractor cybersecurity practices and safeguard unclassified information within the DoD’s supply chain. The proposed DFARS rule will further support the Secretary of Defense’s mandate to create a comprehensive cybersecurity framework for the DIB by February 1, 2020.
The CMMC 1.0 pilot program was suspended in November 2021 to pave the way for the development of CMMC 2.0. The DoD introduced the CMMC 2.0 program rule on December 26, 2023, marking the start of its formal proposal.
CMMC will be gradually implemented over a three-year period. During this rollout, the DFARS clause on ‘Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements’ will apply to solicitations and contracts requiring specific CMMC levels, except for those exclusively dealing with commercial off-the-shelf (COTS) items.
The timing of CMMC certification requirements will be determined by the program office or requiring activity, with certification requirements extending to subcontractors when they handle federal contract information (FCI) or controlled unclassified information (CUI), according to the sensitivity of the information.
Post-rollout, CMMC will be mandatory for all DoD solicitations and contracts involving the processing, storage, or transmission of FCI or CUI, except for COTS items. Contractors must have up-to-date CMMC certification or self-assessment results in the Supplier Performance Risk System (SPRS) to be considered for contract awards or extensions.
The DoD evaluated three options for the timing of CMMC certification—at proposal submission, at award, or post-award—and opted for certification at the time of award to mitigate risks associated with schedule delays and contractor readiness.
The rule will affect contracts and subcontracts valued above the micro-purchase threshold but below the Simplified Acquisition Threshold (SAT) for commercial products (excluding COTS) and services.
Initially, the rule will impact contractors only when a specific CMMC level is required. By the fourth year, the requirements will extend to all applicable solicitations and contracts involving FCI or CUI.
The rule is expected to require minimal time for contractors and the government to validate CMMC certifications and affirmations, with estimated durations of five minutes for various verification tasks.
The primary cost of compliance for contractors is associated with achieving and maintaining CMMC certification. However, the benefits include enhanced verification of cybersecurity measures and better protection of sensitive information, contributing to national security and economic stability. Although the exact benefits are still being assessed, the DoD anticipates a reduction in cyber threats and improved safeguarding of intellectual property and sensitive data.



