Leveling Up: Will CMMC Contract Obligations Impact Your Organization?

Sheppard Mullin Richter & Hampton LLP
Contact

Sheppard Mullin Richter & Hampton LLP

Will a final rule issued by the Department of Defense on September 10, 2025 (available here) cause companies to rethink their compliance approach? The rule –relating to the Cybersecurity Maturity Model Certification program or CMMC – will impact how defense contractors engage with the Department of Defense. (We wrote previously (here) about the separate, but related, CMMC rule that addressed substantive CMMC program requirements.)

This final rule will require defense contractors to affirm CMMC compliance on a phased approach, with full implementation by November 2028. The requirement will place a significant hurdle on defense contractors, who will need to affirm their CMMC compliance in order to contract with the Department of Defense. The first implementation phase begins November 10, 2025 and addresses self-assessment and affirmation for entities that handle “FCI” (or basic Federal Contract Information) and “CUI” (or Controlled Unclassified Information). More detail about the requirements are in our sister blog post here.

Performing assessments and obtaining certification will likely require organizational change on many levels. It will include C-suite attestations and flow down obligations to subcontractors. While obligations were already in effect before this rule, we expect CMMC to result in increased exposure under the False Claims Act if attestations are inaccurate.

Putting It Into Practice: Failing to get through the CMMC assessment and certification process can result in defense contractors losing their DoD business. Rushing through the assessment process, failing to involve key stakeholders, or otherwise mis-stepping, however, can expose entities to legal exposure. In the face of this, companies should consider organizational change principles: engage key stakeholders, conduct reviews under privilege, and treat CMMC as a key governance risk, not an IT problem.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Sheppard Mullin Richter & Hampton LLP

Written by:

Sheppard Mullin Richter & Hampton LLP
Contact
more
less

What do you want from legal thought leadership?

Please take our short survey – your perspective helps to shape how firms create relevant, useful content that addresses your needs:

Sheppard Mullin Richter & Hampton LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide