CMMC May Be New to Your Contract. The Cybersecurity Requirements Are Not.

For defense contractors and subcontractors, CMMC may appear to introduce a new cybersecurity obligation.

It does not.

The Cybersecurity Maturity Model Certification program builds on contractual cybersecurity requirements that have developed over more than a decade. What has changed is the framework for assessing and demonstrating compliance with those requirements.

That distinction is particularly important during the current CMMC rollout. Changes in implementation do not erase the cybersecurity obligations that came before CMMC.

CMMC Didn’t Start the Cybersecurity Requirement

The road to CMMC began years before the program itself.

Requirements for safeguarding sensitive information developed into a broader framework for assessing, verifying and ultimately certifying contractor compliance.

From Safeguarding to Verification to Certification

Required: 2013–2017

DFARS 252.204-7012 began appearing on contracts and established incident reporting and safeguarding requirements, including compliance with NIST SP 800-171 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Applicable defense contractors were expected to implement NIST SP 800-171 by December 31, 2017.

Self-Verify: 2019–2020

DFARS 252.204-7019 and 252.204-7020 increased the emphasis on demonstrating implementation through Supplier Performance Risk System, or SPRS, scores and DoW assessments.  These clauses required self-reporting compliance and allowed the DoW  to perform assessments to validate that reported compliance.

Define the Assessment Process: 2024

Because many DoW assessments found most self-assessment scores were higher than DoW scores, it was determined that a broader independent process for evaluating compliance was needed.  32 CFR Part 170 established CMMC and set its levels and assessment rules.

Certification: 2025

The CMMC acquisition rule brought CMMC into Do-W contracts and revised DFARS 252.204-7021.

The progression can be summarized simply:

DFARS 7012 established the obligation. DFARS 7019 and 7020 increased verification through SPRS and assessments. CMMC established a formal assessment and certification framework.  It also provided contractors with better guidance for how to perform a self-assessment.

CMMC does not replace the cybersecurity requirements that preceded it. It builds on them.

CMMC Formalizes How Contractors Demonstrate Compliance

The FY2020 National Defense Authorization Act directed the Department of Defense to develop a consistent cybersecurity framework for the Defense Industrial Base.

That framework was to include unified cybersecurity standards across DoD contractors and subcontractors and a process for assessing compliance. Congress specifically called for clear metrics for assessing compliance and a process for third-party independent assessment certification.

CMMC became the DoD program developed to address those requirements.

It builds on existing contractual cybersecurity requirements, including DFARS 252.204-7012, 252.204-7019 and 252.204-7020. Its purpose is to better validate and increase the cybersecurity posture of the Defense Industrial Base and better protect sensitive unclassified information.

CMMC establishes how contractors demonstrate compliance with applicable security requirements. Depending on the contract requirements, that may involve self-assessment, third-party assessment or, at Level 3, both a third-party assessment and a DoD assessment.

A Pause in the Rollout Does Not Reset the Requirements

The distinction between CMMC and the cybersecurity requirements underlying it becomes especially important during changes to the program’s rollout.

The CMMC program remains operational. DFARS 7012 remains in force. Certified third Party Assessment Organizations (C3PAOs) continue conducting Level 2 certification assessments, and CMMC eMASS and SPRS continue processing Level 2 certifications.

Contractors therefore should not interpret pauses in CMMC implementation as a pause of the requirements.

Those requirements are part of the foundation on which CMMC was built.

Look Beyond the CMMC Timeline

For defense contractors and subcontractors, the question is not simply when CMMC will reach their next contract.

The more immediate questions are whether they are already meeting the cybersecurity requirements on which CMMC is built and whether they can demonstrate that compliance when required.

CMMC may be new to a contract.

The obligation to protect sensitive federal information is not.