---
title: "CMMC Now Effective: Phase 1 Begins"
description: CMMC Phase 1 is now in effect. New DoD contracts may include CMMC requirements under DFARS 252.204-7021. Peerless helps you stay compliant and audit-ready.
---

[Peerless Post | Peerless Tech Solutions ](https://www.getpeerless.com/blog)

# [CMMC Now Effective: Phase 1 Begins](https://www.getpeerless.com/blog/cmmc-phase-1-has-started)

 Written by [Ismail McCowin (Director of Cybersecurity & Compliance)](https://www.getpeerless.com/blog/author/ismail-mccowin) | November 10, 2025

**CMMC Acquisition Rule Now Effective – Today 10 November 2025 CMMC Phase 1 Begins!**** **

As of today, the [48 CFR Parts, 204, 212, 217, and 252](https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Fwww.federalregister.gov%2Fdocuments%2F2025%2F09%2F10%2F2025-17359%2Fdefense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of&data=05%7C02%7Csean.meyers%40getpeerless.com%7C160fa06c5e9b4c0e1f8a08de20686522%7C21959262211a47169df7b076dbb104e8%7C0%7C0%7C638983829903513851%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=wfTeNQn1DbUu7Ewt4Kc3SdnFaNcBAWj1gSziqkIh43w%3D&reserved=0): Cybersecurity Maturity Model Certification (CMMC) Acquisition Rule is officially effective, granting Government Program Managers (PMs) the authority to enforce the [32 CFR Part 170 CMMC Program](https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Fwww.federalregister.gov%2Fdocuments%2F2024%2F10%2F15%2F2024-22905%2Fcybersecurity-maturity-model-certification-cmmc-program&data=05%7C02%7Csean.meyers%40getpeerless.com%7C160fa06c5e9b4c0e1f8a08de20686522%7C21959262211a47169df7b076dbb104e8%7C0%7C0%7C638983829903529019%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Q%2BIn5VWas1EOfMoUQFZLpjobkQ29eFmApiyJyR%2F1T7k%3D&reserved=0) within DoD contracts. This means that new or modified contracts **may** now include **DFARS 252.204-7021**, which specifies the required CMMC Level — whether Level 1, Level 2 *Self-Assessment*, Level 2 *Certification Assessment*, or Level 3.

Today also marks the start of **CMMC Phase 1** (*Nov 10, 2025 – Nov 9, 2026*), focused on **Level 2 Self-Assessments**. The goal of **Phase 1** is to ensure all contractors have completed or begun their **self-assessment** and are actively working toward Phase 2, which begins in November 2026 and introduces mandatory CMMC Level 2 Certification Assessments conducted by accredited Certified 3rd Party Assessing Organizations (C3PAOs).

DoD has clarified that Phase 2 Certification Assessments are required when CUI categories fall under the National Archives CUI Registry ([archives.gov/cui/registry/category-list](https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Fwww.archives.gov%2Fcui%2Fregistry%2Fcategory-list&data=05%7C02%7Csean.meyers%40getpeerless.com%7C160fa06c5e9b4c0e1f8a08de20686522%7C21959262211a47169df7b076dbb104e8%7C0%7C0%7C638983829903539316%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=lrOGR%2FIF38JwgL5F0BHTaITtCO53Ap8EsBDU8QK%2FBJE%3D&reserved=0)). However, PMs may choose to require a C3PAO assessment during Phase 1 if CUI categories in the contract warrant it. **Contractors should first** **contact their Program Manager (PM) or Contracting Officer Representative (COR) to confirm which CMMC level applies** to their contract and the expected compliance timeline. Subcontractors must coordinate with their Prime contractor to determine their flow-down obligations. While Phase 1 takes effect today, **implementation remains at the PM’s discretion**, and some contracts may continue requiring only DFARS 252.204-7012 and 252.204-7019 at this stage.

Once your requirement is confirmed:

1. Complete your self-assessment if not already completed.
2. Remediate deficiencies identified during your self-assessment (e.g. gap assessment) to reach 110.
3. If applicable, begin planning and scheduling with a C3PAO to conduct a CMMC Level 2 certification audit in preparation for **Phase 2**.

Contact Peerless today for help with your self-assessment, remediation planning and engineering projects, or to connect with trusted C3PAOs listed in the Cyber AB Marketplace once you are CMMC ready. Let us support you in getting audit-ready and certified.

Don't get left behind. Get Peerless.

[View full post](https://www.getpeerless.com/blog/cmmc-phase-1-has-started)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Ismail McCowin (Director of Cybersecurity & Compliance)"
  },
  "dateModified" : "2025-11-10T16:09:32.514Z",
  "datePublished" : "2025-11-10T16:09:32Z",
  "headline" : "CMMC Now Effective: Phase 1 Begins",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1024,
    "url" : "https://6040502.fs1.hubspotusercontent-na1.net/hubfs/6040502/AI-Generated%20Media/Images/photographic%20An%20F35%20Lightning%20II%20fighter%20jet%20taking%20off%20from%20an%20aircraft%20carrier%20at%20sunrise%20captured%20in%20a%20cinematic%20wide%20shot%20The%20scene%20should%20convey-1.png",
    "width" : 1536
  },
  "mainEntityOfPage" : "https://www.getpeerless.com/blog/cmmc-phase-1-has-started",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://www.getpeerless.com/hubfs/New%20Peerless%20Logo_Color_No%20Tech-1.png",
      "width" : 103.646835
    },
    "name" : "Peerless Post"
  }
}
```