Pentagon Announces Final Rule Implementing CMMC, Effective November 10, 2025
On September 9, 2025, the Department of Defense (DoD) released its long-anticipated final rule implementing the Cybersecurity Maturity Model Certification (CMMC) program. After several years of proposals, public comments, and interim measures, the DoD has now solidified the framework for its revamped CMMC program. The goal: ensure contractors in the Defense Industrial Base (DIB) properly protect sensitive information, particularly Controlled Unclassified Information (CUI) and Federal Contract Information (FCI), while clarifying legal obligations, streamlining processes, and providing a phased implementation. The final rule introduces a phased, three-year implementation period that begins on November 10, 2025. At a basic level, the CMMC program changes the […]