What Changes Were in The Final CMMC Rule That Differed From The Proposed Rule?

The long-awaited final Cybersecurity Maturity Model Certification (CMMC) rule released in October 2024 introduced several key changes from the proposed version earlier in the year. Here are the main updates that you need to know.

Extended Implementation Phases

The final rule retains the four-phase rollout but extends Phase 1 from six months to one year. This phase will require contractors to begin self-assessments for Level 1 and some Level 2 contracts, while later phases gradually implement third-party certification and DoD-led assessments for higher security levels. By October 2026, all DoD contracts will require CMMC compliance, with final full implementation covering all relevant contracts

The implementation phases are as follows:

  • Phase 1 (Effective Date – December 16, 2024): Focuses on Level 1 self-assessments for contractors handling Federal Contract Information (FCI). Level 2 contracts involving Controlled Unclassified Information (CUI) may also require self-assessments during this phase.
  • Phase 2 (One year after Phase 1): Begins requiring Level 2 third-party assessments (conducted by C3PAOs) for contractors handling CUI on specific contracts.
  • Phase 3 (Two years after Phase 1): Introduces Level 3 certifications, requiring a DoD-led assessment process for contractors managing highly sensitive CUI associated with critical programs.
  • Phase 4 (Three years after Phase 1): Full implementation across all applicable DoD contracts, including requirements for option periods and subcontractor flowdowns.

By October 2026, all relevant DoD contracts will enforce these CMMC compliance requirements, enhancing cybersecurity maturity across the defense supply chain

Revised Certification Levels

The three-level structure remains unchanged:

  • Level 1 requires basic safeguarding for Federal Contract Information (FCI) and is self-assessed.
  • Level 2 aligns with NIST SP 800-171 and involves 110 security controls for protecting Controlled Unclassified Information (CUI); it now requires third-party certification for critical programs, with annual self-assessments for some contractors.
  • Level 3 adds controls from NIST SP 800-172, designed to protect against Advanced Persistent Threats (APTs), and mandates DoD-led assessments

Changes in Asset Scoping and Definitions

The rule clarifies asset categories, focusing on CUI Assets, Security Protection Assets (SPAs), and Security Protection Data (SPD). Each category has specific safeguarding requirements, primarily ensuring that SPAs (firewalls, encryption tools) are correctly configured to protect CUI Assets without directly processing CUI. This distinction helps contractors scope their assessments more precisely, aligning controls with each asset type

Introduction of Conditional Certifications

Contractors can receive a conditional certification at Level 2 if they achieve at least 80% of the controls but have a Plan of Action and Milestones (POA&M) to address any gaps. These gaps must be resolved within 180 days to maintain eligibility for sensitive contracts. This flexibility allows contractors to continue contract work while closing compliance gaps

Managed and External Service Providers (MSPs and ESPs)

The final rule clarifies that MSPs and ESPs not directly handling CUI are not required to obtain certification unless they store, process, or transmit CUI on behalf of their clients. This provision, which eliminates certification needs for certain providers, reduces compliance burdens for contractors using MSPs and ESPs for non-CUI services

Enhanced Compliance Enforcement

Non-compliance may result in contract loss, and contractors must annually affirm their compliance. Additionally, misrepresentation of cybersecurity status now has legal implications, including potential penalties. The Department of Justice has taken a stronger stance on enforcing compliance under this rule, ensuring that contractors are transparent and diligent in their cybersecurity practices

These final changes in CMMC 2.0 emphasize flexibility, clear asset definitions, and phased implementation, balancing the need for robust cybersecurity with the operational needs of defense contractors. If you are struggling with what you need to do or how to get started, you should engage a CMMC Registered Practicing Organization (RPO) such as Kyber and we can help.

CMMC Compliance Support for Fairfield County Contractors

Kyber Security is a CyberAB-certified Registered Practitioner Organization based in Trumbull, CT, helping defense contractors and subcontractors throughout Bridgeport, Stamford, Norwalk, and the rest of Fairfield County prepare for CMMC assessment. See our CMMC Compliance Services for the full breakdown.

Categories