48 CFR and CMMC: The Acquisition Rule That Changes Every DoD Contract
48 CFR and CMMC: The Acquisition Rule That Changes Every DoD Contract
On December 16, 2024, the CMMC program rule (32 CFR Part 170) became effective. Not proposed. Not finalized pending comment. Effective. Its companion acquisition rule --- amending 48 CFR, home of the Defense Federal Acquisition Regulation Supplement (DFARS) --- followed in November 2025, requiring CMMC certification as a condition of contract award through DFARS 252.204-7021. And yet, months later, a staggering number of DIB organizations still treat CMMC as a future-state problem. They assume that because Phase 1 allows self-attestation for Level 1, and because Phase 2 does not begin enforcement until November 2026, they have time.
They do not. The C3PAO assessment backlog already exceeds six months. Organizations that have not begun preparation will miss the window. And the Department of Justice has made abundantly clear through ongoing False Claims Act enforcement that the government considers inaccurate self-attestation a federal crime, not an administrative oversight.
The 48 CFR rule is not a new requirement --- it is the enforcement mechanism for a requirement that has technically existed since DFARS 252.204-7012 went live in 2017. What changed is that DoD stopped trusting self-attestation and built a verification architecture.
Why This Matters Now: The Phase 2 Clock
The CMMC phased rollout creates a false sense of safety:
Phase 1 (November 2025 - present): DoD MAY include CMMC Level 1 (self-attestation) or Level 2 (C3PAO assessment) requirements in solicitations. Key word: "may." Contracting officers have discretion.
Phase 2 (November 2026): DoD WILL include CMMC Level 2 requirements in all solicitations involving CUI. Key word: "will." The discretion disappears.
Phase 3 (November 2027): CMMC Level 3 (government-led assessment) requirements begin appearing for the most sensitive programs, with full implementation (Phase 4) following in 2028.
November 2026 is the cliff. After that date, any solicitation involving Controlled Unclassified Information will require the contractor to hold a valid CMMC Level 2 certification or be in active assessment. No certification, no bid. No exceptions. No waivers published to date.
The math is unforgiving:
- ~80,000 DIB organizations handle CUI and will need Level 2 assessment
- A limited pool of accredited C3PAOs --- far too few for the demand --- can conduct assessments
- Each assessment takes 3-6 weeks of assessor time, plus preparation
- Assessment booking backlogs already exceed six months
An organization starting today --- July 2026 --- faces this timeline: 2-3 months to remediate gaps, 1-2 months to schedule an assessment, 1-2 months for assessment execution, 1 month for adjudication. That puts certification in January-April 2027 at best, assuming no findings require remediation and re-assessment. Organizations that need to remediate significant gaps are looking at mid-2027. Contracts requiring Level 2 will be issued starting November 2026.
The DFARS Clauses: What Gets Inserted Into Your Contract
The 48 CFR rule operates through four DFARS clauses that contracting officers insert into solicitations and contracts. Understanding these clauses is essential because each carries distinct obligations:
DFARS 252.204-7012: Safeguarding Covered Defense Information
The foundational clause, effective since 2017. Requires "adequate security" for CUI systems and 72-hour cyber incident reporting to DoD via the DIBNet portal. This clause is already in virtually every DoD contract involving CUI.
Key obligation: implement the security requirements in NIST SP 800-171 on all contractor information systems that process, store, or transmit CUI.
DFARS 252.204-7019: Notice of NIST SP 800-171 DoD Assessment Requirements
Requires contractors to have a current (not older than three years) NIST 800-171 assessment on file in SPRS (Supplier Performance Risk System). The assessment must use the DoD Assessment Methodology.
Key obligation: self-assess, calculate your SPRS score, and submit it to the SPRS portal before proposal submission. A missing SPRS score is grounds for proposal rejection.
DFARS 252.204-7020: NIST SP 800-171 DoD Assessment Requirements
Enables DoD to conduct medium or high-confidence assessments of the contractor's 800-171 implementation. This is the clause that allows government assessors (or C3PAOs on their behalf) to verify what the contractor self-reported in SPRS.
Key obligation: provide access to assessors, maintain documentation that supports your SPRS score, and address findings within agreed timelines.
DFARS 252.204-7021: CMMC Requirements
The clause --- first introduced in 2020 and given teeth by the 48 CFR rule. Requires contractors to achieve and maintain the CMMC level specified in the solicitation. This is what makes CMMC a contract condition rather than a best practice.
Key obligation: hold a valid CMMC certification at the required level at time of award AND maintain it throughout contract performance. Lapsed certification is a contract compliance issue.
How the Clauses Work Together
In a typical CUI-handling contract post-Phase 2, 7012 establishes the security requirement, 7019 requires the self-assessment on file, 7020 gives the government verification rights, and 7021 requires independent C3PAO certification. All four clauses flow down to subcontractors who handle CUI. A prime cannot shield a non-compliant sub by handling CUI "on their behalf." If the sub processes CUI, the sub needs certification.
What a C3PAO Assessment Actually Examines
Most organizations underestimate the depth of a CMMC Level 2 assessment because they have only experienced self-attestation. The gap between "we believe we implement this control" and "prove to an independent assessor that this control operates effectively" is where most organizations fail.
A C3PAO assessment evaluates all 110 NIST 800-171 security requirements across three dimensions:
Implementation: Is the control technically implemented? Configuration evidence, system screenshots, architecture diagrams.
Documentation: Is there a policy, procedure, and plan that governs this control? Are they current, approved, and communicated?
Operation: Is the control actually functioning in production? Logs showing enforcement, records of reviews, evidence of monitoring, proof of response to violations.
The third dimension --- operational evidence --- is where self-assessed organizations consistently fail. They have a policy and perhaps even a configuration, but they cannot demonstrate that the control operates day-to-day. A firewall rule exists but the logs show it has not blocked anything because traffic routes around it. An MFA policy exists but exception requests are rubber-stamped. Access reviews are scheduled but the last completed review is 18 months old.
Common Assessment Failures
Based on publicly available C3PAO findings and DoD assessment data, the most common failures cluster in predictable families:
| Control Family | Common Failure | Why It Happens |
|---|---|---|
| Access Control (AC) | No evidence of periodic access reviews | Reviews scheduled but not completed or documented |
| Audit & Accountability (AU) | Audit logs exist but no evidence of review | SIEM deployed but nobody reads the dashboards |
| Configuration Management (CM) | No documented baselines for CUI systems | Servers configured ad-hoc; no standard captured |
| Identification & Authentication (IA) | MFA exceptions for service accounts | "It breaks automation" used as permanent excuse |
| System & Communications Protection (SC) | CUI boundary not defined or enforced | Data flows to personal devices via email |
| Risk Assessment (RA) | No vulnerability scanning on schedule | Scanner purchased but not configured for full coverage |
The False Claims Act: Why SPRS Scores Are Now Legal Exposures
This is the enforcement mechanism that gives 48 CFR its teeth, and it is the reason organizations should not submit inflated SPRS scores as a stopgap:
When a contractor submits a SPRS score to the government, that score is a representation to the federal government about the state of their cybersecurity. Under 31 U.S.C. 3729 (the False Claims Act), knowingly submitting false information to the government in connection with a claim for payment is subject to treble damages and per-claim penalties.
The Department of Justice's Civil Cyber-Fraud Initiative, launched in October 2021, explicitly targets cybersecurity misrepresentations in government contracting. DOJ has publicly stated:
- SPRS scores constitute certifications to the government
- Inflated scores that overstate compliance are actionable
- Qui tam (whistleblower) lawsuits are actively encouraged
- Investigations are underway across the DIB
In 2026 alone, DOJ has settled multiple False Claims Act cases involving cybersecurity misrepresentation by defense contractors. Penalties in the published settlements ranged from $500K to several million dollars, plus suspension and debarment referrals.
The implication is clear: submitting a SPRS score of 90 when your actual assessed score is -30 is not a "compliance gap." It is potential fraud.
The Contrarian Take: CMMC Is Not About Security
Here is the opinion that will generate pushback from both the compliance industry and DoD: CMMC as a program is not primarily about improving security. It is about creating accountability for a requirement that has existed since 2017 and been systematically ignored.
DFARS 252.204-7012 required NIST 800-171 implementation eight years ago. The vast majority of DIB organizations ignored it because there was no verification. Self-attestation with no audit is not a compliance framework --- it is an honor system. The honor system failed.
CMMC exists because DoD needed a forcing function. The 110 security requirements did not change. The standard did not change. What changed is that someone now checks. The entire $5-10 billion CMMC ecosystem --- C3PAOs, consultants, tools, training --- exists because the defense industrial base would not do what it contractually agreed to do absent verification.
This matters because it reframes how organizations should approach CMMC. It is not a new requirement to satisfy. It is an old requirement to finally implement honestly. Organizations that approach it as "what do we need to pass the assessment" rather than "how do we actually secure CUI" will spend more money, face more rework, and still fail --- because assessors are trained to distinguish performative compliance from operational security.
Preparation Roadmap: What to Do Before Phase 2
Step 1: Define Your CUI Boundary (Month 1-2)
Before anything else, define where CUI lives. This is simultaneously the most important and most neglected step. Every 800-171 control applies only within the CUI boundary. A well-scoped boundary means fewer systems to protect, assess, and maintain.
Common boundary-scoping approaches:
- Enclave model: Isolate all CUI processing into a dedicated network segment with controlled entry/exit points
- System-wide model: Apply 800-171 controls across the entire enterprise (simpler to describe, much more expensive to implement)
- Hybrid model: CUI enclave for processing/storage, controlled access from enterprise systems with enhanced protections
The boundary definition must be documented in a System Security Plan that identifies every component within scope.
Step 2: Honest Self-Assessment (Month 2-3)
Conduct a gap assessment against all 110 NIST 800-171 requirements. Score honestly:
- MET: Control is implemented, documented, AND operating with evidence
- NOT MET: Control has gaps in implementation, documentation, or operational evidence
- NOT APPLICABLE: Control genuinely does not apply (rare --- most do)
Calculate your SPRS score using the DoD Assessment Methodology. Accept the number. If it is negative, that is information. An honest -30 is better than a fraudulent 90.
Step 3: Remediation (Month 3-8)
Address gaps in priority order:
- Critical gaps that could result in immediate CUI exposure (boundary failures, no MFA, no encryption in transit)
- High-value gaps that assessors consistently flag (access reviews, audit log review, configuration baselines)
- Documentation gaps where controls exist technically but lack policy/procedure/evidence
- Operational gaps where controls are implemented but not monitored or enforced
For findings that cannot be remediated before assessment, document them in a Plan of Action & Milestones. C3PAOs can assess organizations with open POA&Ms if the residual risk is managed and timelines are credible.
Step 4: Evidence Collection and C3PAO Engagement (Month 6-8)
Start evidence collection now --- not the week before the assessor arrives. Automate wherever possible: configuration screenshots, log excerpts showing enforcement, policy documents with approval signatures, training records, and vulnerability scan reports. Simultaneously, select a C3PAO from the Cyber-AB marketplace and schedule your assessment. Book early --- assessment slots are constrained and demand will spike as Phase 2 approaches.
What Happens After Certification
CMMC Level 2 certification is valid for three years with annual affirmation by the responsible senior official. Material changes to the CUI boundary or security architecture may trigger reassessment. Subcontractor flow-down requirements remain active throughout --- a subcontractor's lapsed certification becomes the prime's problem. Certification is not a one-time event. It is an ongoing operational commitment that requires continuous monitoring of control effectiveness.
Key Takeaways
- The CMMC program rule (32 CFR Part 170) has been effective since December 16, 2024, and the 48 CFR acquisition rule since November 2025. Phase 2 mandatory inclusion in CUI solicitations begins November 2026.
- Assessment backlogs exceed six months. Organizations that have not started preparation are already at risk of missing the Phase 2 window.
- Four DFARS clauses (7012, 7019, 7020, 7021) work together to establish, verify, and certify cybersecurity compliance. All flow down to subcontractors.
- The False Claims Act makes inflated SPRS scores a legal liability, not just a compliance gap. DOJ enforcement is active and escalating.
- CMMC Level 2 assesses 110 NIST 800-171 requirements across implementation, documentation, AND operation. Self-assessment experience does not predict assessment outcomes.
- Define CUI boundaries, assess honestly, remediate gaps, collect evidence continuously, and book C3PAO engagement early.
- Certification is valid for three years with annual affirmation and continuous monitoring obligations.
Frequently Asked Questions
Can we bid on contracts before achieving CMMC Level 2 certification?
During Phase 1 (current), contracting officers MAY include CMMC requirements --- check each solicitation. During Phase 2 (November 2026 forward), solicitations involving CUI WILL require certification. You cannot submit a compliant proposal without holding the required level or being in active assessment with the C3PAO. Some solicitations may accept a POA&M-based conditional authorization, but this is not guaranteed.
What happens if our certification lapses during contract performance?
DFARS 252.204-7021 requires maintaining the specified CMMC level throughout contract performance. Lapsed certification is a contract compliance issue that the contracting officer must address --- typically through a cure notice with a defined remediation window. Persistent non-compliance can result in contract termination for default. Maintain awareness of your three-year certification expiration and schedule reassessment well in advance.
Do subcontractors need the same CMMC level as the prime?
Subcontractors need the CMMC level appropriate to the information they handle. If a sub processes CUI, they need Level 2. If a sub only handles Federal Contract Information (not CUI), Level 1 self-attestation suffices. Primes should map information flows to subcontractors and communicate required levels early --- subcontractor certification failures will delay program execution.
How much does a C3PAO assessment cost?
Assessment costs vary by organization size and boundary complexity. A small organization (under 100 users, simple boundary) can expect $30,000-$60,000. A mid-tier organization (100-500 users, moderate complexity) typically faces $60,000-$150,000. Large organizations with multiple boundaries, enclaves, and facilities can exceed $200,000. These figures exclude remediation costs --- only the assessment itself. Budget separately for gap remediation, which typically exceeds assessment cost by 3-5x.
Is CMMC reciprocal with FedRAMP or other certifications?
CMMC and FedRAMP are complementary but not reciprocal. A FedRAMP-authorized CSP may satisfy certain inherited controls, but the contractor still needs their own CMMC assessment. ISO 27001 demonstrates maturity but does not satisfy CMMC. The only path to Level 2 is a C3PAO assessment against NIST 800-171.
How Advisedly Helps
Advisedly maps your current security posture against all 110 NIST 800-171 requirements, calculates an honest SPRS score, identifies gaps by priority, and generates the operational evidence that C3PAO assessors demand --- policy documents, configuration evidence, audit logs, and access review records collected continuously rather than assembled in a pre-assessment panic. The platform supports 500+ compliance frameworks with automated crosswalking, so CMMC preparation simultaneously advances your FedRAMP, ISO 27001, and NIST 800-53 posture. begin@advisedly.ai
<!-- LI hook: November 2026 is closer than your C3PAO booking backlog. -->