The CMMC Rollout Timeline: Phases, Dates, and What They Mean for Small DIBs
CMMC is phasing into DoD contracts — self-assessments now, third-party assessments for many CUI contracts from around November 2026. Here's the timeline in plain language.
Where things stand
After years of buildup, CMMC requirements are now actually appearing in DoD contracts. The program rolls out in four phases, each phase widening which contracts carry a requirement and raising the bar from self-assessment toward third-party assessment.
This article is generic and educational. It does not interpret your contracts or tell you what applies to you — the exact applicability is set by the rule and your contracting officer. Read the authoritative sources linked below and verify dates against them, since the rollout has shifted before and the precise effective dates are reported inconsistently.
The four phases, in plain language
- Phase 1 — happening now. Applicable solicitations and contracts can require a self-assessment at Level 1 or Level 2 as a condition of award. You assess your own program; for Level 2 / NIST SP 800-171, that includes a score posted in SPRS.
- Phase 2 — around November 2026. Level 2 third-party certification (a C3PAO assessment) becomes required for most contracts involving CUI. For these contracts, a self-assessment is no longer enough.
- Phase 3 — around November 2027. The requirement extends to more contracts and option periods, and Level 3 (assessed by the government’s DIBCAC) is introduced for select high-priority programs.
- Phase 4 — around November 2028. Full rollout: CMMC requirements apply across applicable DoD contracts.
The trend is clear: the window where a self-assessment suffices for many contracts is open now and narrows as Phase 2 approaches.
”But I’m just a subcontractor”
CMMC requirements flow down. Primes are responsible for ensuring their subcontractors meet the level required for the work they do. In practice, many small shops first hear about CMMC when a prime asks them to demonstrate Level 1 or Level 2 — often well before a contract formally requires it. Waiting for a clause to appear is usually waiting too long.
What it means for organizing your evidence
Whether you self-assess today or face a third-party assessment later, the same thing makes it manageable: evidence you can actually find. The teams that struggle are not usually the ones missing controls — they’re the ones whose proof is scattered across email, tickets, spreadsheets, and shop-floor paper. The phased timeline is a good reason to get that organized now, while there’s time, rather than during a scramble.
A consistent evidence folder structure, an owner for each artifact, and dated files turn “we probably have that somewhere” into “here it is.”
Read it at the source
- 32 CFR Part 170 — CMMC Program Rule: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- DFARS 252.204-7021 — CMMC contract clause: https://www.ecfr.gov/current/title-48/chapter-2/subchapter-H/part-252/subpart-252.2/section-252.204-7021
See our regulatory sources guide for the full map.
Getting organized
You can build your evidence structure from scratch, or start from a standardized one. The DIBStack Evidence Binder gives you a ready-to-use folder structure plus the checklists, workbooks, logs, and templates that fill it — a self-service kit you run on your side. It helps you organize evidence; it does not determine whether your organization is compliant or which phase or level applies to you.
Related product
DIBStack Evidence Binder
Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.
View DIBStack Evidence Binder