The US Department of Defense has issued the final rule for the Cybersecurity Maturity Model Certification (CMMC) 2.0, establishing a rigid compliance timeline for the Defense Industrial Base (DIB). Effective immediately, all new contracts involving Controlled Unclassified Information (CUI) will require Level 2 certification.
The most significant update is the flow-down requirement: prime contractors are now legally responsible for verifying the compliance status of their entire supply chain before contract award. This move is expected to trigger a wave of audits across the tier 2 and tier 3 supplier base.
'Self-attestation is no longer sufficient for critical programs,' warned the DoD CIO. 'We are moving to a trust-but-verify model.' The announcement has spurred a surge in demand for third-party assessment organizations (C3PAOs), with waitlists already extending into mid-2026.