The wait is over: The CMMC Final Rule (48 CFR), was published in the Federal Register on September 10, 2025, and CMMC requirements can be added to contracts, RFPs, and RFIs starting November 10, 2025.

CMMC Background

Defense contractors handling controlled unclassified information (CUI) have been required to meet the 110 controls of NIST 800-171 since 2017. CMMC will validate compliance with NIST 800-171 through independent assessments conducted by a C3PAO (CMMC Third-Party Assessor Organization).

CMMC will enter contracts starting in on Nov 10, 2025. This US Army Corp of Engineers solicitation already requires CMMC(and there are many more). Here’s what Matt Travis, CEO of Cyber AB, warned at PreVeil’s CMMC Summit:

The Latest CMMC Timeline

cmmc timeline

The CMMC Final Rule (CFR 32) became effective on Dec 16, 2024, and CMMC assessments started on Jan 2, 2025.

CMMC Compliance Deadline: When will it be in contracts?

Here’s the latest on the CFR 48 CMMC Final Rule, which enables DoD contracting officers to add CMMC requirements to new DoD solicitations and contracts.

  • July 23: DoD sent CFR 48 to the OMB (Office of Management & Budget)
  • Aug 29: CFR 48 cleared regulatory review.
  • Sept 10: CFR 48 published in the Federal Register.
  • Nov 10: CFR 48 will be effective and from this date forward, CMMC requirements can be added to any DoD contract, RFP or RFI.

Here’s the link to the Federal Register page about the CMMC Final Rule.

Note that NIST 800-171, which CMMC is based on, is already required today. Further, Primes are already beginning to require their subcontractors meet CMMC requirements, ahead of the rule. Here’s what Leidos CISO JR Williamson said on a PreVeil panel,

Defense contractors who are not yet meeting all 110 NIST 800-171 controls should prioritize this immediately if they wish to continue bidding on defense contracts.

Behind the Curve? How to Fast-Track CMMC

Given that CMMC will be in contracts on Nov 10, 2025, you need to get started on your compliance preparations now, as it takes 6-12 months for the average defense contractor to get assessment ready. Doing nothing is not an option. Here’s what Matt Travis said:

If you’re not sure where to start, read our CMMC Guide. For convenience, here are a few ways to expedite your compliance journey:

  1. Use Pre-filled Documentation: Protecting CUI is at the core of NIST and CMMC compliance. However, you also must provide detailed documentation to your CMMC Assessor to prove that you’re compliant. PreVeil offers pre-filled, assessment-validated documentation that covers all 110 controls, including a System Security Plan (SSP). 
  2. Limit POA&MS: Plans of Actions & Milestones (POAMs) describe your plan to meet any controls that are currently unmet. Make sure you are taking steps to address any POAMs and specifying the technologies and procedures you will need to close those gaps. C3PAOs will allow for only a limited use of POAMs at the time of assessment and then only for the least critical controls. You will need a minimum score of 80% (88/110) to be eligible for a conditional certification so we do not recommend relying on POAMs to pass CMMC.
  3. Leverage Partners: If you get stuck, or don’t have the time or expertise to complete the steps required, you can take advantage of PreVeil’s preferred network of Assessors, Consultants, and Service Providers. They offer a variety of services to help accelerate your compliance journey, and you can have confidence that they were vetted and recommended by the PreVeil compliance team.

According to the current letter of the law, NIST 800-171A, you are already responsible for meeting all of the security standards included in CMMC. If you are not yet fulfilling this obligation, the time to act is now.

Get Caught Up with PreVeil

If your organization wishes to stay in the Defense Industrial Base, then you will need to become CMMC compliant. PreVeil can help.

PreVeil is used by over 1,800 defense contractors and provides a comprehensive solution to expedite CMMC compliance. It includes:

  • Technology Platform: Our Email and Drive platform protects CUI with end-to-end encryption and meets FedRAMP Moderate Equivalent, FIPS 140-2 and DFARS 7012 c-g.
  • Compliance Accelerator: We provide pre-filled CMMC documentation, assessor-validated videos and 1×1 support from our compliance experts.
  • Partner Network: We support your organization through the entire compliance journey – from prep to assessment – with our network of CMMC consultants and auditors.The goal for defense contractors is to not only remain eligible to win defense contracts, but also to minimize business risk and protect CUI from our country’s adversaries. By getting started on your organization’s compliance journey, you can achieve these objectives and ensure your company is ready for ramped-up federal enforcement of cybersecurity regulations.
preveil cmmc compliance help

The goal for defense contractors is to not only remain eligible to win defense contracts, but also to minimize business risk and protect CUI from our country’s adversaries. By getting started on your organization’s compliance journey, you can achieve these objectives and ensure your company is ready for ramped-up federal enforcement of cybersecurity regulations.

PreVeil’s proven solution has been used by 35 defense contractors and C3PAOs to achieve perfect 110 scores in CMMC assessments.

To learn more, summarize in AI: