← Back to all briefings
Governance 5 min read Published Updated Credibility 91/100

Governance Briefing — DoD issues DFARS interim rule to roll out CMMC assessments

The Department of Defense published an interim DFARS rule establishing the Cybersecurity Maturity Model Certification (CMMC) assessment requirement and a NIST SP 800-171 DoD Assessment methodology for defense contractors starting in late 2020.

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)

Executive briefing: The interim rule (DFARS Case 2019-D041) adds clauses 252.204-7019 through -7021 requiring contractors to complete NIST SP 800-171 Basic/Medium/High assessments in SPRS and to obtain CMMC certification at the level specified in solicitations, with phased implementation through 2025.85 FR 61505; DFARS 252.204-7021

Programme steps

  • Submit assessments. Perform and upload the required NIST SP 800-171 DoD Assessment scores to SPRS before responding to covered solicitations as mandated by DFARS 252.204-7019.
  • Plan for certification. Identify target CMMC levels per contract types, engage a C3PAO for assessments, and update SSPs/POAMs to close control gaps.
  • Flow down requirements. Ensure subcontract agreements incorporate the new DFARS clauses and verification that subs meet required assessment or certification levels.

Sources

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)
Horizontal bar chart of credibility scores per cited source.
Credibility scores for every source cited in this briefing. Source data (JSON)

Continue in the Governance pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • CMMC
  • DFARS
  • Defense industrial base
  • Third-party assessments
Back to curated briefings