For organizations looking to participate in Department of Defense (DoD) contracts, CMMC compliance is no longer optional or coming at a later date. On November 10, 2025, the DoD officially launched Phase 1 of the CMMC 2.0 rollout. This milestone marks a major inflection point for contractors across the Defense Industrial Base (DIB) as verified cybersecurity compliance is now a requirement.
The Official CMMC 2.0 Rollout Began on November 10
With the final version of the CMMC Rule under 48 CFR published, CMMC Level 1 and Level 2 certification requirements will now be added to all DoD contracts, RFPs, or RFIs as of November 10, 2025, via the DFARS 7021 enforcement clause. Phase 1 of the rollout has begun and will run from November 10, 2025, through November 9, 2026. During this initial period, DoD’s primary focus will be on Level 1 and Level 2 self-assessment requirements but select contracts will also require some participants to successfully pass third-party C3PAO audits.
New DFARS Clause Mandates CMMC

With the new DFARS 7021 Clause in place, the DoD can enforce CMMC compliance directly through contract eligibility. Contractors must possess a current CMMC certificate at the required level specified in the contract. The same CMMC requirements flow down to any subcontractors on the contract. CMMC certificates are generally valid for three years.
Any contractors that fail to meet the mandated CMMC level or don’t provide verification of their self-assessment results in the Supplier Performance Risk System (SPRS) will find themselves ineligible to bid on contracts or receive awards. Although Phase 1 will primarily focus on Level 1 and 2 self-assessments, DoD may still require third-party assessments for Level 2 in select solicitations.
Four Phases of the CMMC 2.0 Roll-out
CMMC will roll out in four phases over the next three years:
- Phase 1 (Nov 2025 – Nov 2026): Level 1 and Level 2 self-assessments introduced into select contracts. A limited number of contracts will require companies to pass third-party C3PAO audits.
- Phase 2 (Nov 2026 – Nov 2027): Broader inclusion of Level 2 third-party C3PAO assessments in solicitations.
- Phase 3 (Nov 2027 – Nov 2028): Level 2 third-party and Level 3 assessments become more common.
- Phase 4 (From Nov 2028 onward): Full CMMC 2.0 implementation expected across all applicable contracts.
Impact on DIB Contractors
For small and mid-sized DIB contractors, the implications of the start of CMMC 2.0 Phase 1 are important:
- CMMC is now an enforced condition of doing business with the DoD.
- Self-assessment accuracy is critical; false or unsupported SPRS entries can result in loss of contracts and costly penalties.
- Prime contractors must ensure compliance across their supply chains, as subcontractors are also in scope for CMMC.
- Proof of cyber hygiene will increasingly influence the competitive ability of contractors.
Work with a CMMC Expert and Take the Following Steps
To stay compliant and competitive, Network Depot recommends all organizations in the DIB immediately work with a CMMC expert to take the following steps.
- Determine your CMMC Level (Level 1 for Federal Contract Information (FCI); Level 2 for Controlled Unclassified Information CUI).
- Decide if you want to follow the CMMC Enclave or Enterprise approach.
- Complete your CMMC self-assessment and submit accurate results to SPRS.
- Update contract to include required DFARS information.
- Train all company team members involved in DoD solicitations on CMMC implications.
- Prepare for third-party C3PA0 assessments starting in some Phase 1 situations and in Phase 2.
By following these steps, your company will be able to participate fully in the challenging world of securing a position on DoD contracts. You will also have an advantage against competitors who are lagging in their CMMC compliance efforts. Your company will also benefit from improved cyber hygiene, which will make your organization’s operations more secure and efficient.
Contact A CMMC Expert Today

The challenging quest for CMMC compliance should not be attempted without the valuable assistance of an experienced CMMC expert like Network Depot.
Your experienced CMMC partner will work with you every step of the way to help you obtain a CMMC certificate that fits your needs. They will quickly identify and remediate any cybersecurity issues and assist you in achieving successful CMMC self-assessments or third-party C3PA0 audits on the first attempt. Your trusted IT compliance partner will also implement the processes and install the tools that will make your organization CMMC compliant and ensure you stay that way.
Contact Network Depot today and learn how they can guide your company to optimal cyber hygiene and CMMC compliance.




