The section of the Code of Federal Regulations where the Department of Defense formally codified the Cybersecurity Maturity Model Certification (CMMC) 2.0 program into law. Published as a Final Rule on October 16, 2024, this regulation establishes the legal framework requiring defense contractors and subcontractors to meet specific cybersecurity standards in order to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

32 CFR Part 170 outlines key program elements such as which contractors must be certified, how CMMC requirements are applied to contracts, the roles of assessors and the Cyber AB, and the enforcement timelines. By moving CMMC into federal regulation, the DoD made compliance not just a best practice, but a contractual and legal obligation for companies across the Defense Industrial Base (DIB).

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.