top of page

CMMC Enforcement in 2026: What the Phased Rollout and Recent Government Reports Mean for Defense Contractors

  • Jul 7
  • 7 min read

For most of its existence, the Cybersecurity Maturity Model Certification (CMMC) program lived in the future tense, something defense contractors would eventually need to worry about. That changed on November 10, 2025, when the Department of Defense began writing CMMC requirements into contracts. The program is now operational, enforcement mechanisms are live, and a March 2026 federal watchdog report has added a candid assessment of where the rollout could still stumble.

The message emerging from official sources is not one of alarm. It is one of preparation. Contractors who understand the timeline, the enforcement signals, and the program's known pressure points are in a good position to compete; those who wait for a certification requirement to appear in a solicitation are the ones most likely to be caught short.


The Phased Rollout Is Underway


CMMC is being implemented gradually rather than all at once. The DoD's final acquisition rule, effective November 10, 2025, establishes a four-phase rollout spread across roughly three years, with each phase widening the set of contracts that carry a certification requirement.


Phase 1 (beginning November 10, 2025) introduced Level 1 and Level 2 self-assessment requirements, along with the associated affirmations in the Supplier Performance Risk System (SPRS), into applicable solicitations and contracts. During this window, contracting officers began flagging contracts that require a specific CMMC status as a condition of award.


Phase 2 (beginning November 10, 2026) expands the use of third-party certification, requiring assessments by an accredited CMMC Third-Party Assessment Organization (C3PAO) for many Level 2 contracts involving Controlled Unclassified Information (CUI). This is the shift from "attest to your own compliance" to "have an independent assessor verify it," and it is the change most contractors handling CUI should be planning around now.


Two further phases follow. Phase 3, roughly a year later, brings Level 3 assessments (conducted by the government's Defense Industrial Base Cybersecurity Assessment Center) into scope and broadens certification conditions. Phase 4, expected on or after November 10, 2028, marks full implementation, at which point CMMC requirements are expected to appear in essentially all applicable DoD solicitations and contracts above the micro-purchase threshold that involve Federal Contract Information or CUI, excluding commercial off-the-shelf purchases.


The practical takeaway is that the requirement does not arrive on a single deadline. It phases in contract by contract, which means a given company's first mandatory assessment depends on which contracts it pursues and when, not on a universal date.


CMMC Enforcement Signals: From Self-Attestation to Verified Liability


CMMC did not create the underlying cybersecurity obligations. Contractors handling CUI have been contractually required to implement the 110 controls in NIST SP 800-171 Revision 2 for years, through DFARS clause 252.204-7012. What CMMC adds is verification, and verification changes the enforcement calculus, because a documented status and affirmation create a clear, checkable representation to the government.


The clearest enforcement signal comes from the Department of Justice's use of the False Claims Act (FCA) to pursue cybersecurity misrepresentations. In fiscal year 2025, DOJ recovered more than $52 million across nine cybersecurity-related FCA settlements, and it has publicly described cybersecurity fraud as a continuing enforcement priority.


One 2025 settlement illustrates the specific risk that SPRS scores now carry. In March 2025, defense contractor MORSECORP agreed to pay $4.6 million to resolve FCA allegations tied to its work for the Army and Air Force. According to the DOJ, the company submitted a near-perfect self-assessment score of 104 to SPRS in early 2021, but a later third-party gap analysis put its actual score at negative 142 (reflecting implementation of only about 22% of the required controls), and the company did not promptly correct the figure. The case was notable as the first FCA settlement built on a contractor's failure to update an inaccurate SPRS score after learning it was wrong, and it originated from a whistleblower, the company's own head of security, who received roughly 18.5% of the recovery.


A second 2025 case widened the circle of potential liability. Defense contractor Aero Turbine and its private equity owner, Gallant Capital Partners, agreed to pay $1.75 million over alleged cybersecurity noncompliance on an Air Force contract, reported as the first FCA cybersecurity settlement to name a private equity firm as a party. For contractors, the throughline across these cases is consistent: the government treats compliance representations, self-assessment scores, and annual affirmations as material statements, and inaccuracies in them, especially knowing or uncorrected ones, can carry treble damages, whistleblower exposure, and the risk of suspension or debarment.


What the March 2026 GAO Report Adds


On March 12, 2026, the Government Accountability Office published Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation (GAO-26-107955), an audit that Congress directed through the FY2025 National Defense Authorization Act. It is worth reading precisely because it is neither a vendor pitch nor a DoD press release. It is an independent evaluation of whether the program can deliver at scale.


The GAO's overall verdict is measured. It found that DoD had addressed six of seven key elements of a comprehensive implementation strategy, including defining program goals, responsibilities, milestones, and resources. Its central criticism is narrower: DoD had not systematically assessed and documented the external factors, the ones largely outside its direct control, that could derail the rollout. Several of those factors matter directly to contractors:


Assessor capacity. The program depends on a private-sector ecosystem, overseen by the nonprofit Cyber AB, to supply enough C3PAOs and certified assessors. As of December 2025, only about 92 C3PAOs had been authorized to serve a defense industrial base of roughly 200,000 companies, tens of thousands of which are expected to need Level 2 certification. A capacity mismatch of that scale points to scheduling backlogs, which is why assessment lead times have already been lengthening.


Contractor attrition. The GAO warned that the cost and complexity of certification could push some companies, particularly small businesses, out of the defense market. That concern is echoed in the broader policy conversation, including proposals in subsequent NDAA cycles to help small contractors offset compliance costs.


Reliance on waivers. DoD officials suggested that assessment requirements could be waived when capacity is constrained. The GAO cautioned that leaning on waivers could undermine the very purpose of the program, which is to verify that contractors actually meet federal cybersecurity requirements, and is not a substitute for planning.


Evolving standards. CMMC is currently anchored to the 2021 edition of NIST SP 800-171 (Revision 2), even though a newer revision was published in 2024. The GAO noted that eventually updating the standard will ripple into assessor training and exam materials, adding another moving part to manage.


DoD concurred with the GAO's recommendation and agreed to assess and document these external factors. For contractors, the report's implication is straightforward: the ecosystem is still maturing, capacity is tight, and the smart response to a constrained assessment pipeline is to get in line early and arrive prepared rather than to assume timelines will slip in your favor.


What This Means for Contractors: Prepare, Don't Panic


Nothing in the current record suggests contractors should panic. It suggests they should prepare deliberately, and the preparation that pays off most is the work that has to happen before an assessor ever arrives.


The foundation of a defensible Level 2 posture is knowing exactly where CUI lives. Accurate identification of CUI drives everything downstream: the boundary you draw around your assessment scope, the controls you have to implement, the evidence you can produce, and the accuracy of the SPRS score you affirm. Over-scoping inflates cost and licensing; under-scoping leaves gaps that surface at exactly the wrong moment. Given the enforcement pattern around SPRS scores, the ability to show that your affirmed score reflects your actual environment, and to keep it current as data moves, is not a nicety but a risk-management essential.


Concretely, the priorities that align with both the DoD's requirements and the GAO's warnings are: map where CUI actually resides across your environment rather than relying on assumptions; define and minimize your CUI boundary so the assessment scope is tight and defensible; maintain repeatable, current documentation and evidence that will hold up under C3PAO scrutiny; keep your SPRS affirmations aligned with reality on an ongoing basis; and, because certification capacity is limited, begin engaging a C3PAO well ahead of the contract that will require one.


A note on tooling: Achieving and sustaining an accurate CUI footprint is one of the harder parts of this work, particularly in environments where sensitive data accumulates across Microsoft 365, file shares, endpoints, scanned documents, images, and engineering or CAD files. Purpose-built discovery tools such as Teramis are designed to identify and continuously monitor CUI across these repositories, which can support accurate self-assessments, tighter boundaries, and defensible evidence. Tooling is only one input. Process discipline, documentation, and expert guidance still matter, but reliable CUI discovery makes the rest of the compliance effort measurably easier.


Bottom Line


CMMC has moved from anticipated to operational. The rollout is phased, the enforcement mechanisms (SPRS affirmations, contract clauses, and False Claims Act liability) are already producing consequences, and an independent GAO assessment has flagged real capacity and readiness pressures in the ecosystem. None of that calls for alarm. It calls for the unglamorous, front-loaded work of knowing where your CUI is, scoping accurately, documenting thoroughly, and getting in the assessment queue before a contract forces the issue. In a program where the requirement arrives one contract at a time, the contractors who prepare ahead of the requirement are the ones who keep their competitive position intact.


Sources



Comments


bottom of page