Skip to main content
IAMRoadmapIAMRoadmap
Back to Compliance
Security Standard

CMMC 2.0

Cybersecurity Maturity Model Certification Program

United States
Effective: December 16, 2024
Updated: November 10, 2025

Overview

The Cybersecurity Maturity Model Certification (CMMC) Program is how the U.S. Department of Defense verifies that defense contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The program rule (32 CFR Part 170) took effect on December 16, 2024, and the acquisition rule that places CMMC requirements in contracts (DFARS, 48 CFR) took effect on November 10, 2025. Requirements are being phased into solicitations over three years, and from November 10, 2028 they apply to all applicable contracts. There are three levels: Level 1 (the 15 requirements of FAR 52.204-21), Level 2 (the 110 requirements of NIST SP 800-171 Revision 2) and Level 3 (24 additional requirements selected from NIST SP 800-172). Access control and identification and authentication are two of the requirement families assessed.

IAM Requirements

Access Control (NIST SP 800-171 R2, 3.1)

  • Limit system access to authorized users, processes acting on behalf of authorized users, and devices (3.1.1)
  • Limit system access to the types of transactions and functions that authorized users are permitted to execute (3.1.2)
  • Separate the duties of individuals to reduce the risk of malevolent activity without collusion (3.1.4)
  • Employ the principle of least privilege, including for specific security functions and privileged accounts (3.1.5)
  • Use non-privileged accounts or roles when accessing nonsecurity functions (3.1.6)
  • Limit unsuccessful logon attempts (3.1.8) and monitor and control remote access sessions (3.1.12)

Identification and Authentication (NIST SP 800-171 R2, 3.5)

  • Identify system users, processes acting on behalf of users, and devices (3.5.1)
  • Authenticate the identities of users, processes, or devices before allowing access to organizational systems (3.5.2)
  • Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts (3.5.3)
  • Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts (3.5.4)
  • Prevent reuse of identifiers for a defined period and disable identifiers after a defined period of inactivity (3.5.5, 3.5.6)
  • Enforce minimum password complexity, prohibit password reuse for a specified number of generations, and store and transmit only cryptographically protected passwords (3.5.7, 3.5.8, 3.5.10)

Levels and Assessment

  • Level 1 (Self): annual self-assessment against the 15 FAR 52.204-21 requirements; no POA&Ms are permitted
  • Level 2 (Self) or Level 2 (C3PAO): assessment against the 110 NIST SP 800-171 R2 requirements every three years
  • Level 3 (DIBCAC): requires a Final Level 2 (C3PAO) status first, then assessment by DCMA DIBCAC
  • An affirming official affirms continuing compliance in SPRS after every assessment and annually thereafter
  • Conditional status at Levels 2 and 3 lasts no more than 180 days
  • Multifactor authentication is scored separately: 3 points are deducted if it covers only remote and privileged users, 5 points if it is not implemented for any users

Level 3 Identity Requirements (NIST SP 800-172)

  • Restrict access to systems and system components to information resources that are owned, provisioned, or issued by the organization (AC.L3-3.1.2e)
  • Identify and authenticate systems and system components before establishing a network connection, using bidirectional authentication that is cryptographically based and replay resistant (IA.L3-3.5.1e)
  • Prohibit system components from connecting unless they are known, authenticated, in a properly configured state, or in a trust profile (IA.L3-3.5.3e)

Implementation Phases

  • Phase 1, from November 10, 2025: Level 1 (Self) or Level 2 (Self) as a condition of award in applicable solicitations
  • Phase 2, one year after Phase 1 (November 10, 2026): Level 2 (C3PAO) in applicable solicitations
  • Phase 3, one year after Phase 2 (November 10, 2027): Level 2 (C3PAO) also for option periods, and Level 3 (DIBCAC) in applicable solicitations
  • Phase 4, one year after Phase 3 (November 10, 2028): CMMC requirements in all applicable solicitations and contracts

Compliance Checklist

1
Identify which information systems process, store or transmit FCI or CUI
2
Determine the CMMC level required by current and expected contracts
3
Limit system access to authorized users, processes and devices
4
Apply least privilege and separate privileged from non-privileged accounts
5
Separate conflicting duties
6
Deploy multifactor authentication for privileged accounts and for network access by all users
7
Set identifier and password rules, including disabling inactive identifiers
8
Monitor and control remote access sessions
9
Complete the self-assessment or schedule a C3PAO assessment and post results in SPRS
10
Close any POA&M items within 180 days
11
Submit the annual affirmation of continuing compliance
12
Confirm that subcontractors hold the CMMC status their work requires

Penalties for Non-Compliance

The CMMC rules set no fines. Contracting officers must not award a contract, task order or delivery order to an offeror that lacks a current CMMC status in SPRS at the level the solicitation requires.

Quick Facts

Region
United States
Effective Date
December 16, 2024
Enforcing Body
U.S. Department of Defense (Office of the Chief Information Officer); assessments by C3PAOs and DCMA DIBCAC

Related Regulations & Frameworks