| Location: | District of Columbia |
|---|---|
| Posted: | Sep 2, 2025 |
| Due: | |
| Agency: | DEPT OF DEFENSE |
| Type of Government: | Federal |
| Category: |
|
| Publication URL: | To access bid details, please log in. |
Related Notice: INFOSEC ALERT - NOTICE TO THE DEFENSE INDUSTRIAL BASE *UPDATED* (Published 31-JUL-2025)
Title: UPDATE - Cybersecurity Maturity Model Certification (CMMC) 2.0 Implementation
SPECIAL NOTICE: UPDATE - Cybersecurity Maturity Model Certification (CMMC) 2.0 Implementation
Federal Organization Issuing Notice: U.S. Army Corps of Engineers (USACE), Headquarters, Directorate of Contracting
Description: The Department of Defense (DoD) finalized the Cybersecurity Maturity Model Certification (CMMC) 2.0 program on 16 December 2024. Once fully implemented, CMMC 2.0 will mandate that all DoD contractors and government organizations handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) achieve specific cybersecurity maturity levels to protect sensitive data. USACE and their Defense Industrial Base (DIB) contractors must comply with CMMC requirements for federal contracts and internal systems upon publication of the final Defense Federal Acquisition Regulations Supplement (DFARS) rule.
The CMMC Program establishes requirements for contractors and subcontractors to conduct an assessment of compliance with the applicable cybersecurity standard for contractor information systems that: process, store, or transmit FCI or CUI; provide security protections for systems which process, store, or transmit CUI; or are not logically or physically isolated from systems which process, store, or transmit CUI.
CMMC provides a consistent methodology to assess a defense contractor's implementation of required cybersecurity requirements using the security standards set forth in the 48 CFR 52.204-21; National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Basic Safeguarding of Covered Contractor Information Systems.
KEY HIGHLIGHTS FOR INDUSTRY
Status: Report due date extended to 10/01/2025.
Status: Report due date extended to 10/01/2025.
Status: Draft final DFARS Rule; Report due date extended to 9/10/2025.
Status: 08/25/2025 Office of Information and Regulatory Affairs (OIRA) cleared final DFARS rule. Defense Acquisition Regulations System (DARS) Regulatory Control Officer preparing for publication, pending DoD Authority to Proceed (ATP).
“New Solicitations and Contracts issued on or after [8/25/2025] will, to the maximum extent practicable, comply with Class Deviation 2005-O0006, requiring contracting officers not to use the contract clause at Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirement, in new solicitations and contracts.”
CONTRACTOR ACTIONS NOW:
Important Disclaimers
Questions and Resources
NOTICE: THE CONTENTS OF THIS PUBLICATION DOES NOT HAVE THE FORCE OR EFFECT OF LAW AND IS NOT MEANT TO BIND THE PUBLIC OR GOVERNMENT IN ANY WAY. THIS NOTIFICATION IS SOLELY FOR INFORMATIONAL PURPOSES ONLY.

With GovernmentContracts, you can:
...70RSAT26Q00000010 Related Notice Department/Ind. Agency HOMELAND SECURITY, DEPARTMENT OF Sub-tier OFFICE OF...) Subpart ...
HOMELAND SECURITY, DEPARTMENT OF
Bid Due: 6/08/2026
...70RDA125R00000013 Related Notice Department/Ind. Agency HOMELAND SECURITY, DEPARTMENT OF Sub-tier... an assessment of ...
HOMELAND SECURITY, DEPARTMENT OF
Bid Due: 8/05/2026