Why the Timeline Question Keeps Coming Up
Every defense supplier I talk to asks some version of the same question: when does CMMC actually hit my contracts? It's a fair question, and it's harder to answer than it should be, because CMMC 2.0 isn't one rule. It's two, and they move on different clocks.
The first rule, 32 CFR Part 170, is the program rule. It defines what CMMC is: three assessment levels, what each level requires, how assessments work, how long a Plan of Action and Milestones (POA&M) can stay open, and what the annual affirmation obligation looks like. That rule went final on October 15, 2024, and took effect December 16, 2024. It exists. It's law. But by itself, it doesn't put a CMMC requirement into a single contract.
The second rule is the one that does that work: the DFARS acquisition rule, which adds clause 252.204-7021 to Title 48 of the CFR. This is the mechanism contracting officers use to write a CMMC level requirement into a solicitation. Until this clause is in your contract, your CMMC obligation is contractual intent, not contractual fact.
I have come to think this two-rule structure is the single most misunderstood part of CMMC 2.0. Suppliers hear "CMMC is final" and assume the clock started. What actually started is the definition of the program. The rollout clock starts when the acquisition rule goes into effect and DoD begins inserting the clause into new solicitations, and that rollout itself is staged across four phases over three years — not a single flip-the-switch date.
The Two Rules, in Plain Terms
| Rule | CFR citation | What it does | Status as of this writing |
|---|---|---|---|
| CMMC Program Rule | 32 CFR Part 170 | Defines the three levels, assessment types, POA&M rules, affirmation requirement | Final; effective December 16, 2024 |
| CMMC Acquisition Rule | 48 CFR 252.204-7021 | Puts a specific CMMC level into a specific contract or solicitation | Governs the phased rollout once effective |
If you only read one of these, read the second one for your own contracts — check your solicitation and any active contract modifications for whether 252.204-7021 has actually been inserted, and at what level. That's the fact that controls your deadline, not a general industry timeline.
The Three Levels, Briefly
You can't plan a timeline without knowing what you're planning for.
- Level 1 (Foundational) — 17 practices drawn from FAR 52.204-21, covering Federal Contract Information (FCI). Annual self-assessment, no third party required.
- Level 2 (Advanced) — 110 practices aligned to NIST SP 800-171 Rev 2, covering Controlled Unclassified Information (CUI). Some contracts allow self-assessment; others require a third-party assessment from a certified C3PAO (CMMC Third-Party Assessment Organization). Reassessment is required at least once every three years, with an annual affirmation in between.
- Level 3 (Expert) — Level 2 plus a subset of additional practices from NIST SP 800-172. Assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a government body, not a commercial C3PAO.
The level named in your contract's 252.204-7021 clause is the one you're held to — not the level you assume based on the type of work you do.
The Four-Phase Rollout, Structurally
Here's the part worth understanding even before you know your own contract's status, because it tells you what's coming and roughly when. DoD structured the rollout in four phases anchored to the effective date of the acquisition rule, with each subsequent phase beginning approximately one year after the last:
| Phase | Timing (relative to 48 CFR effective date) | What gets added to new solicitations |
|---|---|---|
| Phase 1 | Effective date | Level 1 and Level 2 self-assessment requirements begin appearing in applicable contracts |
| Phase 2 | ~1 year later | Level 2 third-party (C3PAO) certification requirement begins appearing where CUI flows |
| Phase 3 | ~1 year after Phase 2 | Level 3 requirement (DIBCAC-assessed) begins appearing for the highest-sensitivity work |
| Phase 4 | ~1 year after Phase 3 | Full implementation — CMMC requirements applied across all applicable DoD solicitations and contracts, including option-year exercises on existing contracts |
DoD retains discretion to include a level requirement in any contract earlier than its phase mandates it, and can also delay a specific phase's application to a specific contract. That discretion is written into the rule itself, which is exactly why a generic industry timeline can't substitute for reading your own contract.
The practical consequence: if you supply FCI-only information and never touch CUI, Phase 1 may be the only phase that ever touches you, and it only requires a self-assessment. If you handle CUI on a program DoD considers high-value, you should assume Phase 2 or Phase 3 requirements will reach you within the three-year window, and plan the C3PAO assessment lead time now rather than after the clause shows up.
What "Self-Assessment" Actually Obligates You To Do
A self-assessment isn't a lighter version of paperwork you can defer. Under 32 CFR Part 170, a Level 1 or Level 2 self-assessment still requires:
- Scoring your environment against the applicable practice set and posting the score to the Supplier Performance Risk System (SPRS)
- Maintaining a System Security Plan (SSP) that documents how each practice is implemented
- An annual affirmation from a senior company official attesting to continued compliance, submitted through SPRS
That affirmation requirement is not cosmetic. It puts a named individual's attestation on the record annually and after every assessment — which means the "self" in self-assessment doesn't mean informal.
The POA&M Rule Most Suppliers Get Wrong
32 CFR Part 170 allows a limited number of unimplemented practices to be carried on an open Plan of Action and Milestones for up to 180 days after the assessment, rather than requiring 100% implementation before the assessment closes. That's real flexibility — but it comes with two limits people miss:
- A defined set of practices is POA&M-ineligible, meaning those specific controls must be fully implemented at the time of assessment with no grace period.
- The 180-day clock runs from the assessment date, not from when you notice the gap. A supplier who discovers a gap on day 150 of their own internal review has 30 days left on a clock they didn't know was running.
If you're planning your timeline around "we'll fix it during the POA&M window," build in the discovery lag, not just the remediation lag.
What to Do Regardless of Which Phase Applies to You
I tell clients the same thing whether their contract has 252.204-7021 in it yet or not: the work underneath CMMC — the SSP, the SPRS score, the POA&M discipline — is worth doing on its own timeline, because NIST SP 800-171 compliance is already a standing DFARS obligation for anyone handling CUI, independent of CMMC's contract-by-contract rollout. Waiting for the clause to appear before starting the underlying security work is the single most common planning mistake I see, because a Level 2 C3PAO assessment is not a same-quarter engagement — evidence collection, gap remediation, and scheduling with an accredited C3PAO all take lead time that a newly-inserted contract clause doesn't wait for.
Suppliers who've built an information security management system around ISO/IEC 27001 already have a head start on the documentation discipline CMMC expects — the control families overlap more than they don't, even though the two frameworks aren't formally mapped to each other. If ITAR-controlled technical data is also part of your environment, the two compliance obligations run in parallel rather than substituting for one another, and it's worth having both mapped against the same system boundary rather than treating them as separate projects.
Common Timeline Mistakes
Assuming the program rule's effective date is your deadline. December 16, 2024 started the program. It did not start your contract obligation. Your obligation starts when 252.204-7021 lands in your paperwork.
Assuming your level based on your product, not your contract. The clause in your solicitation names the level. Two suppliers doing similar work can be held to different levels because of different CUI flows on different programs.
Treating the 180-day POA&M window as a planning buffer rather than a deadline. It's a deadline with a fixed number of ineligible items that must already be done.
Waiting for the phase to reach you before starting the SSP. The SSP, the SPRS score, and the underlying NIST SP 800-171 implementation are worth having in place before a solicitation forces the question, because a C3PAO assessment slot and a remediation sprint both take longer than most suppliers assume when they start the clock.
FAQ
Does CMMC 2.0 apply to every DoD contractor? Only contracts and solicitations that include DFARS clause 252.204-7021 carry a CMMC requirement. A contractor with no FCI or CUI exposure may never see the clause; one handling CUI on a sensitive program should expect it well before the four-year rollout completes.
What's the difference between Phase 1 and Phase 2 for a Level 2 supplier? Phase 1 allows a Level 2 self-assessment for many contracts. Phase 2 begins requiring a third-party C3PAO certification for Level 2 work where the contract calls for it, replacing the self-assessment option on those solicitations.
Can I lose a contract for not having CMMC certification yet? Only if the applicable solicitation or contract already contains 252.204-7021 at the level you can't meet. Check the clause list in your specific contract rather than relying on a general timeline.
How long does a Level 2 C3PAO assessment take to schedule? Lead time varies by C3PAO availability and your own readiness, but evidence collection and gap remediation before the assessment date typically take longer than the assessment itself — which is why starting after the clause appears in your contract is usually too late.
Does the annual affirmation replace the need for reassessment? No. The affirmation is a yearly attestation of continued compliance between assessments. A full reassessment is still required at least once every three years for Level 2.
If you're trying to figure out where your own contract sits in this rollout, or you need the underlying NIST SP 800-171 documentation built before a C3PAO assessment becomes unavoidable, that's the kind of gap analysis worth doing with someone who reads DFARS clauses for a living. My team at ISO/IEC 27001 information security consulting and ITAR compliance consulting works with defense suppliers on exactly this overlap — feel free to reach out if you want a second set of eyes on your timeline.
Last updated: 2026-09-06
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.