CMMC Timeline: Key Dates And What To Expect

Written by: 
Team Knox
Published on: 
August 5, 2026

The Cybersecurity Maturity Model Certification (CMMC) program has moved from proposal to contract implementation. Both governing rules are final and in force: 32 CFR Part 170 took effect December 16, 2024, and the Defense Federal Acquisition Regulation Supplement (DFARS) acquisition rule took effect November 10, 2025. That second date started the clock on a CMMC phased rollout schedule that was set to put certification requirements into Department of Defense (DoD) contracts on a fixed calendar through 2028, though the later phases of that calendar are currently paused (see update below).

For SaaS CTOs, VPs of Compliance, and program managers at prime contractors, the harder question is when CMMC applies to a given company and how much runway exists before a solicitation makes certification a condition of award.

Planning often falls short in the gap between the regulatory calendar and a contractor's real deadline. Phase dates matter, but assessment turnaround and preparation decisions determine whether you clear certification in time to bid.

Update, August 2026: On July 13, 2026, the Department of Defense suspended the CMMC Phase 2, 3, and 4 implementation milestones, including the November 10, 2026 mandatory third-party certification date discussed below. Phase 1 self-assessment requirements remain in force and unaffected. The suspension was issued via a DoD CIO memo signed on July 13, 2026, launching a 60-day CMMC Reform Task Force review, with public comments due on August 14, 2026. This is an administrative pause, not a rule change: 32 CFR Part 170 and the DFARS acquisition rule remain unamended, and the Phase 2 to 4 dates below reflect the schedule as originally adopted and are now on hold pending the outcome of the review.

Key Takeaways

  • Phasing controls timing. Requirements were scheduled to enter contracts on a calendar spanning November 2025 through November 2028, with each phase starting one year after the last. As of July 2026, only Phase 1 is active; Phases 2 through 4 are suspended pending a 60-day DoD review.  
  • Phase 2 is currently suspended. The mandatory Level 2 third-party certification milestone, set to begin on November 10, 2026, for most contracts handling controlled unclassified information (CUI), has been administratively paused while DoD conducts a program-wide review.  
  • Assessor availability matters. Once Phase 2 requirements resume in some form, early assessor booking is likely to become important again given finite C3PAO capacity.  
  • Boundaries shorten preparation. Contractors inheriting infrastructure-layer controls from an environment authorized under the Federal Risk and Authorization Management Program (FedRAMP) reduce the amount of control implementation and evidence collection they must build from scratch.

What Is CMMC And What Drives Its Timeline

CMMC is the Department of Defense's framework for verifying that companies in the defense supply chain adequately protect the sensitive federal information they handle. It sets tiered cybersecurity requirements, from basic safeguarding at Level 1 to more rigorous controls at Levels 2 and 3, that a contractor must meet, and in most cases prove through assessment, before it can win or keep contracts that involve that information.

Two forces drive when CMMC affects a given company. The first is the phased schedule that governs when certification requirements can be included in contracts. The second is the assessment process that determines how long it takes to prove compliance once they do. As of July 2026, only the first phase of that schedule is active: Phase 1 remains in force, but the DoD has suspended the transition into Phases 2, 3, and 4 pending a 60-day program review.

The phased schedule sets the regulatory boundary. The assessment process, covered further below, sets the practical one.

CMMC Rollout Follows A Phased Implementation Schedule

The DoD structured the rollout so that requirements ramp up over three years. Phase 1 begins on the DFARS effective date, and each subsequent phase starts one calendar year after the preceding one, according to Electronic Code of Federal Regulations (eCFR) § 170.3. As of July 2026, this schedule is only partly active: Phase 1 remains in force, but the DoD has suspended the transition into Phases 2, 3, and 4 pending a 60-day program review.

The rollout was structured to include four phases:

  • November 10, 2025, to November 9, 2026: Contracts require Level 1 or Level 2 self-assessment as a condition of award, with affirmations submitted in the Supplier Performance Risk System (SPRS). The DoD may substitute a Level 2 third-party assessment at its discretion. This phase remains active.  
  • November 10, 2026, to November 9, 2027: Level 2 third-party certification becomes a condition of award for applicable CUI-handling contracts. Level 2 C3PAO assessment may also become a condition to exercise option periods on existing contracts. This transition is currently suspended; the November 10, 2026 start date will not take effect as scheduled while the DoD review is underway.  
  • November 10, 2027, to November 9, 2028: Level 2 certification requirements expand into more solicitations and option periods, and Level 3 requirements begin appearing as designated by the DoD. This phase is also suspended, and its timing depends on the outcome of the review.  
  • November 10, 2028 onward: Full implementation. CMMC requirements appear in all applicable DoD solicitations, contracts, and option periods. This milestone is likewise on hold pending the review.

During the first three years, CMMC requirements appear only in contracts designated by the CMMC Program Office. After that window closes, DoD component program offices must include CMMC in every applicable solicitation under the DFARS acquisition rule. That structure is what the current review is evaluating; it has not been repealed, only paused.

The phase dates explain when requirements can enter contracts. Readiness work and assessment scheduling determine how long it takes to prove compliance after that point.

CMMC Rollout Follows A Phased Implementation Schedule

The DoD structured the rollout so that requirements ramp up over three years. Phase 1 begins on the DFARS effective date, and each subsequent phase starts one calendar year after the preceding one, according to Electronic Code of Federal Regulations (eCFR) § 170.3.

The rollout includes four phases:

  1. November 10, 2025, to November 9, 2026: Contracts require Level 1 or Level 2 self-assessment as a condition of award, with affirmations submitted in the Supplier Performance Risk System (SPRS). The DoD may substitute a Level 2 third-party assessment at its discretion.  
  2. November 10, 2026, to November 9, 2027: Level 2 third-party certification becomes a condition of award for applicable CUI-handling contracts. Level 2 C3PAO assessment may also become a condition to exercise option periods on existing contracts.  
  3. November 10, 2027, to November 9, 2028: Level 2 certification requirements expand into more solicitations and option periods, and Level 3 requirements begin appearing as designated by the DoD.  
  4. November 10, 2028 onward: Full implementation. CMMC requirements appear in all applicable DoD solicitations, contracts, and option periods.

During the first three years, CMMC requirements appear only in contracts designated by the CMMC Program Office. After that window closes, DoD component program offices must include CMMC in every applicable solicitation under the DFARS acquisition rule.

The phase dates explain when requirements can enter contracts. Readiness work and assessment scheduling determine how long it takes to prove compliance after that point.

Assessment Timelines Vary By Level And Organizational Readiness

Turnaround varies sharply by certification level, and scheduling availability further complicates the picture. DoD describes CMMC levels and assessment types through these assessment paths.

  • Level 1 self-assessment: A contractor completes this annual assessment internally against 15 Level 1 safeguards, submits the score to SPRS, and files a senior officer affirmation. Certification lapses if the annual affirmation is not filed.  
  • Level 2 C3PAO scheduling: Scheduling has historically created the larger constraint. Assessor booking dynamics for Phase 2 are currently on hold, along with the phase itself. However, contractors that already require Level 2 certification under an existing contract should continue with their scheduled assessments; this suspension affects the upcoming mandatory milestone, not assessments already underway.  
  • Level 3 government assessment: Government-led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) on a recurring cycle. The contractor must already hold Final Level 2 (C3PAO) status for the same scope before a Level 3 assessment can begin.

Assessment capacity pressure tied to the original Phase 2 date is currently paused. Contractors should watch for the CMMC Reform Task Force's findings, expected within 60 days of the July 13, 2026 suspension, for a clearer signal of when and how demand for third-party certification will resume.

Contractors Need Readiness Before CMMC Appears In Contract Language

By the time CMMC language appears in a solicitation, preparation needs to be substantially complete. A contractor must have the required self-assessment or certification recorded before it can satisfy a CMMC condition of award under the DFARS rule. With readiness work and scheduling delays both adding time, waiting for the requirement to appear may leave too little time to respond. That makes readiness work part of proposal planning.

The readiness work is not limited to implementing controls. Contractors also need a defensible scope, current evidence, mapped responsibilities, and a realistic assessment sequence. If the environment changes during preparation, the evidence set may need to be refreshed before the assessment begins. That is why CMMC planning belongs in pipeline review, not only in your compliance checklist.

Early Preparation Compresses The Effective Timeline

The organizations that clear certification on time start preparation before a contract forces the issue.

  • Start with a gap assessment: scope your CUI environment and evaluate your current posture against the CMMC Level 2 requirements. A gap analysis shows what remediation is needed and how long it will take.  
  • Run remediation and documentation alongside active business development to keep a real deadline achievable.  
  • Book a C3PAO assessment slot while completing final preparations, and plan recertification before the current certification expires.

A workable plan usually moves in a fixed order: forecast the contract opportunity, define the CMMC scope, complete the gap assessment, remediate control gaps, collect evidence, schedule the assessment, and maintain the certification record. The sequence matters because late scoping changes can reset evidence work. Early decisions about where CUI is stored, processed, and transmitted make the later assessment less volatile.

After readiness planning, the assessment boundary determines how much infrastructure work remains to be done.

Compliant Infrastructure Shortens The CMMC Timeline

Timeline planning often misses the infrastructure boundary. The requirements for CMMC Level 2 are drawn one-to-one from the National Institute of Standards and Technology (NIST) SP 800-171 Rev2, and FedRAMP is built on the NIST 800-53 Rev5 catalog. The two frameworks overlap significantly at the infrastructure layer, meaning the platform a contractor runs on directly affects how much CMMC work remains.

For SaaS vendors selling into the DoD, this is not a one-sided calculation. If your application handles CUI on behalf of a federal customer, the cloud service itself typically needs FedRAMP authorization at the appropriate impact level, in addition to your CMMC obligations as a contractor. Treating FedRAMP and CMMC as separate, sequential projects tends to duplicate effort, extend timelines, and create conflicting evidence sets. Planning both together lets a single control implementation satisfy overlapping requirements and reduces the total assessment scope.

The practical effect is not automatic compliance. It is a narrower implementation problem when the scope is correct. Contractors still need to prove their own application controls, workforce processes, endpoint practices, and supplier responsibilities. But they do not have to treat every infrastructure control as a new build if the boundary already carries evidence that can be inherited.

Planning FedRAMP And CMMC Together Around A Pre-Authorized Boundary

What if the infrastructure controls in your CMMC scope were already evidenced before the solicitation arrived?

Building a FedRAMP boundary from scratch typically costs upwards of $3.5 million and takes 12 to 36 months, and that timeline does not include any CMMC-specific application work. For most SaaS vendors, that path is difficult to reconcile with a CMMC Level 2 deadline, whenever that deadline lands under the current or a revised phase schedule. A pre-authorized boundary changes the math by giving the contractor an inheritable set of infrastructure controls on day one, so preparation focuses on the application layer rather than the platform.

The benefits of building on a pre-authorized boundary are concrete:

  • Faster path to authorization. Inheriting infrastructure controls collapses months of engineering, documentation, and third-party review into weeks.  
  • Lower cost of entry. The upfront investment in physical security, hypervisor management, core networking, logging, and personnel controls is amortized across tenants rather than rebuilt per vendor.  
  • Shared evidence across frameworks. Because FedRAMP and CMMC Level 2 draw from adjacent NIST catalogs, the same inherited evidence supports both authorizations.  
  • Predictable scope. With the infrastructure boundary settled, remediation and assessment planning target a known set of application-layer controls.

Knox Systems is a FedRAMP-as-a-Service government cloud platform designed around exactly this model. SaaS vendors deploy onto a pre-authorized Knox FedRAMP boundary and inherit 60% to 80% of the required security controls, reducing the remaining work to application-specific configuration, documentation, and evidence collection. In practice, that means teams building on Knox can reach FedRAMP authorization in approximately 90 days at 90% less cost than a standalone build, and the same inherited controls carry directly into the CMMC Level 2 scope.

Phase Dates Set A Baseline; The Current Suspension Doesn't Remove The Underlying Work

Waiting for Phase 2 language to return before acting is still the most expensive way to plan a CMMC timeline. The contractors who stay ready regardless of the exact resumption date treat phase dates as constraints rather than deadlines, resolve boundary decisions early, and maintain assessment readiness so they aren't starting from zero once the DoD's 60-day review concludes and a schedule, whether the original one or a revised one, takes effect.

Knox Systems reduces the largest variable in that plan by handing SaaS vendors a pre-authorized FedRAMP boundary that carries directly into the CMMC scope. Fewer infrastructure components to build means less evidence to produce and a shorter path to a defensible assessment package, whenever third-party certification requirements resume.

The platform currently supports FedRAMP Moderate, FedRAMP High, and Defense Information Systems Agency Impact Level 4 (DISA IL-4), with IL-5 authorization in process and an estimated completion date of December 2026.

Book a meeting to map how a pre-authorized boundary fits your CMMC and FedRAMP obligations.

FAQs about the CMMC timeline

When does CMMC Level 2 certification become mandatory?

As of August 2026, it doesn't, at least not yet: DoD suspended the Phase 2 milestone that would have made Level 2 C3PAO certification a mandatory condition of award starting November 10, 2026. The suspension, announced July 13, 2026, is administrative and pending a 60-day program review, not a repeal of the underlying rule. During the current Phase 1 period, the DoD may still require third-party assessment at its discretion for a given contract.

How far in advance should I schedule a C3PAO assessment?

Schedule as early as your readiness plan allows. Even with Phase 2's mandatory start date suspended, contracts that already call for Level 2 certification, or that resume requiring it once the DoD review concludes, mean assessment scheduling should run alongside remediation rather than after it.

Does FedRAMP authorization make me CMMC compliant?

No. FedRAMP-authorized infrastructure can support inherited infrastructure controls, but your CMMC scope still includes your application layer, endpoints, workforce training, and supply chain controls.

What happens if I wait until a solicitation requires CMMC?

You may have too little time to compete. A CMMC condition of award requires the necessary self-assessment or certification to be in place before award eligibility can be satisfied.

What is the difference between the CMMC phase dates and my real deadline?

The phase dates, including the ones currently suspended, set the regulatory boundary. Your real deadline depends on the contracts you pursue, prime contractor expectations, readiness work, and assessment scheduling.