Skip to content
CMMC-Timeline

CMMC Timeline, News & Regulatory Updates

Complete CMMC implementation timeline from 2020 through 2028. Phase 1 active now. Phase 2 mandatory C3PAO certification begins November 2026.

Where CMMC Stands Today

CMMC Phase 1 is active now. Since November 2025, DFARS 252.204-7021 has appeared in DoD solicitations. Self-assessments required. C3PAO assessments at contracting officer discretion. Phase 2 begins November 2026. Mandatory C3PAO certification at award. ~80 C3PAOs serve 16,000+ organizations.
This page tracks every CMMC milestone from inception through 2028. Bookmark and check back quarterly. Quzara delivers CMMC services: advisory, Cybertorch MDR (cybertorch.com), and NISTCompliance.ai (nistcompliance.ai).

CMMC Phase 2 Countdown

Phase 2 begins November 2026. Mandatory C3PAO certification at contract award. The clock is running.
Compliance Advisory 32 CFR Part 170 — CMMC Final Rule
Published December 2024. Three-level certification framework and four-phase implementation timeline through 2028.  
Managed Security DFARS 252.204-7021 — Contract Clause
Effective November 2025. All CMMC assessment obligations consolidated under this single contract clause.  
Cloud Security C3PAO Assessment Ecosystem
~80 C3PAOs currently authorized for Level 2 assessments. Scaling but remains a bottleneck for 16,000+ organizations.  
Security Analytics NIST SP 800-171 & SPRS Scoring
110 security requirements for CMMC Level 2. SPRS scores range from -203 to +110.  

Start Your CMMC Journey

Description. Lorem ipsum dolor sit amet, consetetur sadipscing elitr, sed diam nonumy eirmod tempor invidunt ut labore et

The Complete CMMC Regulatory Timeline

**Every major CMMC milestone from inception to full implementation**
  • 2020 — CMMC 1.0 Published

    • DoD published CMMC 1.0 with five maturity levels
    • Third-party assessments required above Level 1
    • CMMC-AB (now The Cyber AB) established
  • 2021 — CMMC 2.0 Announced

    • Streamlined from five levels to three
    • Level 1: 15 controls, self-assessment
    • Level 2: 110 NIST 800-171 controls, C3PAO assessment
    • Level 3: NIST 800-172, DoD-led assessment
  • 2023 — Proposed Rule Published

    • Proposed rule 32 CFR Part 170 published
    • Over 2,000 public comments received
    • C3PAO authorizations began
    • CMMC ecosystem training launched
  • 2024 — Final Rule Published

    • Final rule published December 16, 2024
    • Four-phase timeline established
    • DFARS 7019 deleted, 7020 renumbered
    • Obligations consolidated under DFARS 7021
  • 2025 — Phase 1: CMMC Takes Effect

    • Phase 1 begins November 10, 2025
    • DFARS 252.204-7021 in solicitations
    • Self-assessments required
    • ~80 C3PAOs authorized
    • GAO report GAO-26-107955 published
  • 2026 — Phase 2: Mandatory

    • Phase 2 begins November 2026
    • Mandatory C3PAO certification at award
    • No cert means no contract
    • Assessment backlog expected
  • 2027 — Phase 3: Options & Level 3

    • Phase 3 begins November 2027
    • Cert required at option exercise
    • Level 3 DoD-led assessments begin
    • NIST 800-172 enhanced requirements
  • 2028 — Phase 4: Full Implementation

    • Phase 4 begins November 2028
    • Full CMMC across ALL DoD contracts
    • No exceptions or waivers
    • Annual affirmation required
Show more

Technology Partners

Ready to Start Your CMMC Certification Journey?

Contact Quzara for your CMMC journey.