DoD Finalizes Cybersecurity Maturity Model Certification Rule: What Defense Contractors Need to Know
On September 10, 2025, the U.S. Department of Defense (DoD) published a final rule that will shake up cybersecurity compliance for DoD contractors. The new rule formally incorporates the Cybersecurity Maturity Model Certification (CMMC) program into nearly all DoD contracts through the Defense Federal Acquisition Regulation Supplement (DFARS). This move has far-reaching implications for employers across the defense industrial base.