logo

CMMC enforcement begins after eight years of warnings

ID: bea4c516-dd90-520d-b86e-a55a8c298580

STIX ID: report--bea4c516-dd90-520d-b86e-a55a8c298580

Feed Name: Nextgov Cybersecurity

Date Published: 2025-11-10

Date Updated: 2026-04-22

Author: Nick Wakeman

...
...

The report details the Department of Defense’s CMMC rollout: Level 1 self-certification for basic NIST SP 800-171 controls begins now, Level 2 third-party assessments will be required by Nov. 10, 2026, and Level 3 may be mandated from 2027. Enforcement is market-driven—no contract award without the appropriate certification—with legal risk under the False Claims Act for false attestations. With an estimated 70,000 contractors needing Level 2 and only ~85 3PAOs and ~450 organizations currently certified, assessor capacity is a bottleneck, underscoring the need for defense contractors to accelerate compliance efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.