Pentagon Suppliers Face a Hard Deadline: Prove Your Cybersecurity or Lose the Contract
A phased federal rule is forcing every company in the US defence supply chain to show, not just promise, that it keeps sensitive government data safe. Here's what's changing and why it matters.

Key points
- The US Department of Defense's updated Cybersecurity Maturity Model Certification (CMMC) rule begins its first enforcement phase on 10 November 2025.
- From 10 November 2026, defence contracts will require suppliers to hold a formal Level 2 certification, not just a self-assessment.
- The rule covers every company that handles Federal Contract Information or Controlled Unclassified Information, from large prime contractors down to small machine shops.
- Foreign adversaries increasingly target smaller, less-protected suppliers to reach sensitive defence data indirectly.
- A single security failure at any supplier can put the prime contractor's own certification, and its contracts, at risk.
The US Department of Defense is tightening who can bid for defence work, and the changes will be felt far beyond large weapons manufacturers. CMMC, the Cybersecurity Maturity Model Certification, sets mandatory cybersecurity standards for the entire defence industrial base: every company, at every tier, that touches sensitive government information. We first covered the certification programme's troubled rollout on 14 July, when the Pentagon suspended its second phase for a 60-day review after complaints about too few auditors.
What exactly is CMMC and who does it affect?
CMMC is a federal certification programme that tells defence suppliers what cybersecurity practices they must have in place before they can win or keep government contracts. It applies to any company handling two categories of sensitive data: Federal Contract Information (FCI, meaning information the government shares with a contractor to get work done) and Controlled Unclassified Information (CUI, meaning data that's sensitive but not classified, such as engineering drawings or technical specifications).
Those standards draw on NIST Special Publication 800-171, a National Institute of Standards and Technology document covering practices from password management to incident response.
What is the timeline?
Rollout happens in two steps.
| Phase | Date | What changes |
|---|---|---|
| Phase 1 begins | 10 November 2025 | Companies self-assess against Level 1 and Level 2 requirements |
| Phase 2 begins | 10 November 2026 | Contract solicitations require formal Level 2 third-party certification |
After November 2026, winning a new defence contract without the right certification becomes very difficult. Losing a contract mid-term because of non-compliance is also a real possibility.
Why should a small supplier care?
Small and medium-sized suppliers are exactly who this rule is aimed at protecting, because they're exactly who foreign intelligence services go after first.
Rather than attacking heavily defended prime contractors head-on, adversaries break into smaller firms in the same supply chain. A small machine shop holding detailed engineering schematics, or a regional IT firm with remote access into dozens of defence-related networks, can open a path into the whole ecosystem. A breach at any tier can expose data that affects military operations, not just company finances.
What does the rule actually require organisations to do?
CMMC demands more than a one-time audit. Updated 2025 guidance stresses continuous readiness: day-to-day evidence that security controls are actually working, not just documentation filed once a year.
Traditional compliance relied on a point-in-time snapshot. A company cleared an audit, filed the certificate, and moved on. The problem is that a new vulnerability, an unexpected configuration drift, or unauthorised software can make that certificate meaningless within weeks. The rule pushes suppliers toward ongoing testing of their own defences, so gaps are found internally before an adversary finds them first. As Edna Conway argued in our August interview on compliance versus real security, ticking regulatory boxes isn't the same as being secure.
What should employees and customers watch for?
If you work for, or buy from, a company in the defence supply chain, check whether your employer is actively pursuing CMMC certification before the November 2025 start date. Suppliers that miss the Phase 2 deadline in 2026 face disqualification from new contracts, which can affect jobs and business continuity.
For prime contractors the risk is more immediate: if a supplier suffers a security incident, your own certification status can come under scrutiny.
Common questions
Does this rule apply to companies outside the United States?
Yes, if a non-US company holds or bids on Department of Defense contracts involving FCI or CUI, CMMC requirements apply to the relevant part of that company's operations.
What happens if a company fails its assessment?
A failed or missing certification can disqualify a company from new contract solicitations. Existing contracts may also be reviewed depending on the terms agreed at award.
Is self-assessment enough after November 2026?
For Level 1 (basic hygiene) contracts, self-assessment remains acceptable. For Level 2 contracts, which cover most work involving CUI, an independent third-party assessment organisation must conduct and certify the review from November 2026 onward.



