For most of its existence, the Cybersecurity Maturity Model Certification (CMMC) program lived in the future tense: something defense contractors would eventually need to address. That changed on November 10, 2025, when the Department of Defense began including CMMC requirements in contracts.
CMMC is now operational. Enforcement mechanisms are active, and a March 2026 federal watchdog report provides a candid assessment of where implementation could still face pressure. The message for defense contractors is not to panic. It is to prepare before a certification requirement appears in a solicitation.
The DoD is implementing CMMC through a four-phase rollout spanning roughly three years. Each phase expands the set of contracts that carry an assessment or certification requirement.
Phase 1 began on November 10, 2025. It introduced Level 1 and Level 2 self-assessment requirements, along with required affirmations in the Supplier Performance Risk System (SPRS), into applicable solicitations and contracts.
During this phase, contracting officers began identifying contracts that require a specific CMMC status as a condition of award. Contractors should expect their self-assessment scores and affirmations to be treated as material representations to the government.
Phase 2 begins on November 10, 2026. It expands the use of accredited CMMC Third-Party Assessment Organizations (C3PAOs) for many Level 2 contracts involving Controlled Unclassified Information (CUI).
This is the critical shift for organizations that handle CUI:
Phase 3 is expected to introduce Level 3 assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center and broaden certification conditions. Phase 4, expected on or after November 10, 2028, represents full implementation across applicable DoD solicitations and contracts above the micro-purchase threshold involving Federal Contract Information or CUI, excluding commercial off-the-shelf purchases.
The practical takeaway is that CMMC does not arrive on one universal deadline. It reaches contractors one contract at a time, based on the opportunities they pursue and the requirements attached to those awards.
CMMC did not create the underlying obligation to protect CUI. Contractors have been required to implement the 110 controls in NIST SP 800-171 Revision 2 through DFARS clause 252.204-7012 for years. CMMC adds verification, and verification changes the enforcement calculus by making compliance representations easier to test.
The Department of Justice has used the False Claims Act (FCA) to pursue cybersecurity misrepresentations. Two 2025 settlements illustrate the risk.
In March 2025, MORSECORP agreed to pay $4.6 million to resolve FCA allegations tied to its work for the Army and Air Force. According to the DOJ, the company submitted an SPRS score of 104 in early 2021, while a later third-party gap analysis calculated a score of negative 142. The government alleged that the company did not promptly correct the score after learning it was inaccurate.
The matter also originated with a whistleblower: the company's former head of security. The case demonstrates that an SPRS score is not a static filing. Contractors must keep it aligned with the actual condition of their environment.
In July 2025, Aero Turbine and its private equity owner, Gallant Capital Partners, agreed to pay $1.75 million to resolve alleged cybersecurity noncompliance on an Air Force contract. The settlement was reported as the first FCA cybersecurity matter to name a private equity firm as a party.
Across these cases, the enforcement pattern is consistent:
On March 12, 2026, the Government Accountability Office published Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation (GAO-26-107955). The audit found that DoD had addressed six of seven key elements of a comprehensive implementation strategy, including goals, responsibilities, milestones, and resources.
The GAO's central criticism was narrower: DoD had not systematically assessed and documented external factors that could impede the rollout. Four issues matter directly to contractors.
CMMC relies on a private-sector ecosystem, overseen by Cyber AB, to provide enough C3PAOs and certified assessors. As of December 2025, approximately 92 C3PAOs had been authorized to serve a defense industrial base of roughly 200,000 companies. Tens of thousands are expected to require Level 2 certification.
That mismatch creates a foreseeable risk of assessment backlogs and longer lead times.
The GAO warned that certification cost and complexity could push some companies, especially small businesses, out of the defense market. For contractors, delayed preparation can make compliance costs more disruptive by compressing technical work, documentation, and assessment scheduling into the proposal window.
DoD officials indicated that assessment requirements could be waived when capacity is constrained. The GAO cautioned that overreliance on waivers could weaken the program's purpose: verifying that contractors meet federal cybersecurity requirements.
A potential waiver is not a sound readiness strategy.
CMMC is currently anchored to the 2021 edition of NIST SP 800-171 Revision 2, although NIST published a newer revision in 2024. A future standards transition would affect requirements, assessor training, and exam materials, adding another moving part for contractors to manage.
The work that reduces CMMC risk begins before an assessor arrives. Defense contractors should prioritize the following actions:
Accurate CUI identification drives every downstream decision: the assessment boundary, required controls, evidence collection, licensing costs, and the SPRS score an executive affirms. Over-scoping increases cost. Under-scoping leaves gaps that may surface during an assessment or enforcement inquiry.
Maintaining an accurate CUI footprint is difficult when sensitive information accumulates across cloud platforms, shared drives, endpoints, images, and technical file formats. Manual inventories and assumptions quickly become stale.
Teramis helps organizations identify and continuously monitor CUI across complex repositories. That evidence can support more accurate self-assessments, tighter CUI boundaries, and better-informed remediation priorities. Technology is only one input; process discipline, documentation, and qualified assessment guidance remain essential.
CMMC has moved from anticipated to operational. The rollout is phased, SPRS affirmations and contract clauses create enforceable representations, and the GAO has identified real capacity and readiness pressures.
The contractors best positioned to compete will know where their CUI resides, scope accurately, document thoroughly, keep affirmations current, and enter the assessment queue before a contract forces the issue.
Use Teramis to identify CUI at scale, strengthen the evidence behind your compliance posture, and focus remediation where it matters most.