Don’t do SECURITY. Do business SECURELY.

CMMC requirements begin appearing in US defence contracts

The DFARS rule implementing CMMC takes effect, allowing US Department of Defense contracts to require CMMC status as a condition of award.

The DFARS rule implementing the Cybersecurity Maturity Model Certification (CMMC) takes effect today, allowing CMMC requirements to be included in US Department of Defense solicitations and contracts.

Key points

  • Phase 1 of the rollout begins, focused initially on Level 1 and Level 2 self-assessments.
  • Contractors must have their CMMC status recorded in the Supplier Performance Risk System before award.
  • Requirements flow down to subcontractors handling federal contract information or controlled unclassified information.
  • Third-party Level 2 assessments will become a requirement in later phases.

UK organisations in the US defence supply chain should expect primes to ask for evidence of CMMC status and NIST SP 800-171 compliance.

Source: DFARS CMMC final rule (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights