Morningstar CMMC 2.0 Implementation Begins for Defense Contractors
Article Content
- •CMMC 2.0 requirements are now being rolled out for defense contractors.
- •All contracts with Federal Contract Information and Controlled Unclassified Information require cybersecurity assessments.
- •Full implementation of CMMC 2.0 is expected by fiscal year 2028.
The Department of War has initiated the phased rollout of Cybersecurity Maturity Model Certification (CMMC) 2.0 requirements, starting with select contracts on November 10, 2025. This rollout follows the finalization of federal regulations, including the 32 CFR CMMC Final Rule and the 48 CFR rule, which integrate CMMC into the Defense Federal Acquisition Regulation Supplement. All contracts involving Federal Contract Information and Controlled Unclassified Information will now require cybersecurity assessments. Contractors must achieve certification before contract awards, shifting the compliance landscape significantly. Prime contractors are responsible for ensuring their subcontractors meet CMMC levels, creating cascading compliance requirements. The full implementation of CMMC 2.0 is expected by fiscal year 2028, emphasizing ongoing maintenance of cybersecurity practices through continuous monitoring. Organizations are advised to conduct gap analyses and develop compliance strategies to meet the new requirements.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (178)
Following this threat?
Track Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…