CMMC Program rule published as 32 CFR Part 170

October 15, 2024

About: CMMC

#version-updates #program-changes

On October 15, 2024, the U.S. Department of Defense published the Cybersecurity Maturity Model Certification (CMMC) Program final rule at 32 CFR Part 170. The rule took effect on December 16, 2024. It is the current CMMC 2.0 program regulation: three levels, assessments, affirmations, and the roles of self-assessment, C3PAO certification, and government-led assessment.

This item was added to the change feed at launch so followers can see the kind of program-rule update a CMMC subscription covers. It is not a new announcement.

What changed

CMMC 2.0 had existed as a program redesign since 2021. The October 2024 rule is what put that model into the Code of Federal Regulations. Level 1 remains the 15 basic safeguarding practices for Federal Contract Information (FCI). Level 2 remains the 110 NIST SP 800-171 requirements for Controlled Unclassified Information (CUI). Level 3 adds a subset of NIST SP 800-172, assessed by the government.

The companion DFARS contract rule, which actually inserts CMMC status into solicitations, took effect later (November 10, 2025) and started a phased rollout. Phase 1 self-assessment requirements from that rollout remain in force. Phase 2 third-party assessments were later paused; see CMMC Phase 2 third-party assessments put on hold.

What did not change

The underlying safeguarding duties were not invented by this rule. FAR 52.204-21 and DFARS 252.204-7012 already required FCI safeguarding and NIST SP 800-171 implementation for CUI. CMMC adds verification: scored assessments, senior-official affirmations, and, for most CUI work, an outside assessor.

What to do now

  1. Confirm which CMMC level your current and upcoming contracts actually require, in writing, with the contracting officer or prime.
  2. Identify where FCI and CUI live, and whether an enclave can contain them.
  3. If Level 2 CUI work is in scope, treat NIST SP 800-171 implementation as current work, not as something that waits on Phase 2 timing.
  4. Read the CMMC page for levels, assessment paths, and what to ask the party that set your obligation.
  5. Follow CMMC on this site for rollout, pause, and rule updates.

#version-updates#program-changes

← Back to news