On September 10, 2025, the Department of Defense (DoD) issued a long-awaited final rule related to the implementation of the Cybersecurity Maturity Model Certification (CMMC) program. The final rule goes into effect on November 10, 2025, but we are unlikely to see CMMC requirements appear overnight in every DoD contract. Instead, there will be a three-year phased implementation. Initially, only select contracts will require CMMC; after three years, it will apply broadly to all contracts involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) [1] , except for those solely for commercially available off-the-shelf (COTS) items. Contractors will register CMMC status in the Supplier Performance Risk System (SPRS) and will be assigned a “CMMC unique identifier
What the Department of Defense Final Rule ‘Assessing Contractor Implementation of Cybersecurity Requirements’ Means for Government Contractors’ Information Security Systems

143