Strengthening Cybersecurity in the Defense Supply Chain: CMMC Final Rule Update
The US Department of War Defense Federal Acquisition Regulation System has issued a final rule updating the supplement to integrate requirements for the Cybersecurity Maturity Model Certification (CMMC) program. This update strengthens protections for unclassified information in the defense supply chain by ensuring contractor compliance with robust security standards. The rule builds on an interim version from 2020 and a proposed update in 2024, incorporating feedback from 97 public submissions. It partially fulfills directives from the National Defense Authorization Act for Fiscal Year 2020, which called for a unified framework to bolster cybersecurity across the US defense industrial base.
Key Takeaways:
- The final rule updates the CMMC program's requirements, clarifying definitions such as "current" for compliance status and "CMMC unique identifier" for tracking assessments in the Supplier Performance Risk System.
- The rule introduces allowances for conditional CMMC statuses at levels 2 and 3, valid up to 180 days with a plan of action and milestones, enabling awards during that window.
- The rule requires contracting officers to verify CMMC statuses in the system before awards, option exercises, or extensions, affecting contracts involving processing, storing, or transmitting federal contract information or controlled unclassified information.
- A phased rollout spans three years, after which it extends to all relevant solicitations and contracts, with offerors required to submit CMMC unique identifiers and maintain affirmations of ongoing compliance annually.
- Public input led to refinements, including removal of some reporting obligations deemed redundant with existing incident protocols and adjustments to clarify terms like "changes" and "lapses in information security."
- Concerns over costs and small business burdens were noted, though primary economic analysis resides in the related 32 CFR rule.
- Expected impacts include enhanced assurance against cyber threats, potentially curbing economic losses from malicious activities estimated at billions annually.
Statistics:
- The final rule projects annualized public costs around $38 million at a 3 percent discount rate over 10 years.
- The rule affects up to 338,000 entities by year four, with 68 percent small businesses.
- The update incorporates feedback from 97 public submissions.
- The rule builds on an interim version from 2020 and a proposed update in 2024.
- The National Defense Authorization Act for Fiscal Year 2020 called for a unified framework to bolster cybersecurity across the US defense industrial base.
Sources:
- United States Department of War Defense Federal Acquisition Regulation System (2025, September 10). Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Maturity Model Certification [Notices: 2025-17359]. Federal Register.
- Jaymar Talang, Targeted News Service.