Title 48 Final Rule is here: CMMC Program “Goes Live” on November 10, 2025

The wait is over. After years of uncertainty and changing rules, we finally have clarity on CMMC implementation. On September 10, 2025, the Department of Defense published the final piece of the CMMC puzzle in an update to Title 48 of the Code of Federal Regulations.

  • Bill Wootton

    Bill Wootton

    Chief Growth Officer

CMMC requirements will start appearing in DoD contracts on November 10, 2025.

Think of it this way: we now have both halves of the instruction manual. Title 32 (published in December 2024) told us what CMMC is and how it will roll out. This new Title 48 rule tells us when and how it will actually show up in contracts and procurement.

It’s been 15 years since the government established the controlled unclassified information (CUI) program and first started getting serious about requiring better cybersecurity from defense contractors. CMMC has gone through many changes since then, but now we have the final rulebook. The question for contractors is simple: Where do you stand, and what do you need to do?

This post covers the key changes in the final rule.

The CMMC timeline is set in stone

Here’s what you need to know about when CMMC requirements will begin appearing in applicable DoD solicitations and contracts. The rollout happens in four phases, each lasting one year:

Phase 1: November 10, 2025 – November 9, 2026

Self-assessment requirements beginat a minimum. New DoD solicitations may begin including CMMC Level 1 (Self) and CMMC Level 2 (Self) requirements as a condition of contract award, depending on the sensitivity of the information involved.

However, Level 2 self-assessments will be rare in practice. The DoD has stated that most contractors handling CUI will need a third-party assessment. In fact, a recent DoD memo outlined specific categories of CUI that cannot be handled under a self-assessment, and these categories represent the vast majority of CUI typically encountered in DoD contracts.

Bottom line: If your work involves CUI, especially export-controlled or critical defense information, plan on needing a third-party certification sooner rather than later — possibly even during Phase 1.

Phase 2: November 10, 2026 – November 9, 2027

CMMC Level 2 (C3PAO) certification requirements will now appear more broadly in applicable solicitations. To be eligible for awards with these requirements, contractors must have passed a formal third-party assessment conducted by a CMMC Third-Party Assessment Organization (C3PAO). This phase will continue to include Level 1 requirements where appropriate.

Phase 3: November 10, 2027 – November 9, 2028

CMMC requirements expand to contract options, and Level 3 begins. CMMC compliance may now be required not just at award, but also to exercise option periods on existing contracts. Additionally, CMMC Level 3 (DIBCAC) will start appearing in solicitations for high-priority, high-sensitivity programs.

Phase 4: November 10, 2028 and beyond

Full implementation. CMMC will be required across all new contracts and contract renewals.

Important reality check: The DoD can require a higher level of CMMC than the minimum requirement that a given phase suggests. Organizations that have delayed their CMMC efforts will quickly find themselves out of the running on valuable contracts because they attempted to “time” the market. Given C3PAO estimates of 12-18 months to implement CMMC Level 2, companies need to accelerate and prioritize their CMMC initiative if they want to be compete in early contracts.

Clarity for prime contractors and their subcontractors

The new rules make one thing crystal clear: Prime contractors are responsible for ensuring their subcontractors have proper CMMC compliance.

Here’s how it works: Unless your subcontractors only use your IT systems or don’t handle federal contract information (FCI) or CUI at all, they need their own CMMC status recorded in the government’s SPRS database. Before you can win a contract, you must verify that all your subs have the right level of CMMC compliance.

Since primes can’t predict which solicitations will require CMMC, many are already pressuring their suppliers to get certified well ahead of the official phased timeline. Lockheed Martin and other major contractors have already started requiring CMMC compliance from their subcontractor base.

Key changes you should know about

CMMC Unique Identifier (UID)

You’ll now need to include a CMMC identifier for each IT system that will handle FCI or CUI in your bid. The contracting officer will verify your CMMC status in SPRS before awarding the contract and again before exercising any options.

Fundamental Research carve-out

Basic research intended for public release is exempt from CMMC. However, there’s a catch: if that research has the potential to become CUI later, or if you handle other controlled information as part of the same contract, CMMC requirements will apply. When in doubt, clarify with the program office.

Commercial off-the-shelf (COTS) products

Pure COTS products are exempt, but be careful with the definition. If your “commercial” product requires integration, configuration, custom software, or special services, CMMC may still apply.

What you should do now

For years, many contractors have hesitated to invest in CMMC preparation because the program kept changing. That uncertainty is over. The rules are final, and the timeline is fixed. It’s time to stop waiting and start preparing.

If you expect you will need CMMC Level 2 certification, getting your environment ready for assessment should be your top priority.

Industry experts estimate that properly implementing all 320 assessment objectives for Level 2 takes an average of 12-18 months.

How C3 gets you there faster

We understand that CMMC can feel overwhelming, especially when you’re trying to run your business at the same time. That’s why we’ve designed solutions that dramatically reduce the time and effort required to achieve compliance.

Our CMMC Resource Hub breaks down everything you need to know about getting compliant and the assessment process itself. We’re continuously adding new articles, videos, and webinars to help answer the questions you have—check out some of our recent sessions:

We’ve helped hundreds of defense contractors navigate cybersecurity compliance requirements, and we’re here to help you succeed with CMMC. Learn more about our CMMC Solutions and how we can get you certified faster and with less disruption to your business.

The countdown to CMMC has begun. Let’s make sure you’re ready.

Meet the Author

Bill Wootton

Bill Wootton

Chief Growth Officer

Bill Wootton is a co-Founder and Chief Growth Officer of C3, a full-service IT provider that accelerates CMMC compliance by designing, implementing, and managing IT & cybersecurity solutions purpose-built for the U.S. Defense Industrial Base. Through its C3 Suite of CMMC Solutions, C3 delivers an expertly managed environment that brings together everything contractors require to confidently meet CMMC requirements. A graduate of Drexel University and Georgetown McDonough School of Business, Bill is passionate about bringing cyber awareness and maturity to the DIB, working with clients to help them achieve CMMC and NIST 800-171 compliance. Bill lives in Arlington with his partner Sharon and their dogs Brooks and Lemmy.