Pentagon Suppliers Face a Hard Deadline: Prove Your Cybersecurity or Lose the Contract

A phased federal rule is forcing every company in the US defence supply chain to show, not just promise, that it keeps sensitive government data safe. Here is what is changing and why it matters.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial image of a darkened developer workstation with a large monitor showing abstract cascading package dependency graphs in green and
Share

Key points

  • The US Department of Defense's updated Cybersecurity Maturity Model Certification (CMMC) rule begins its first enforcement phase on 10 November 2025.
  • From 10 November 2026, defence contracts will require suppliers to hold a formal Level 2 certification, not just a self-assessment.
  • The rule covers every company that handles Federal Contract Information or Controlled Unclassified Information, from large prime contractors down to small machine shops.
  • Foreign adversaries are increasingly targeting smaller, less-protected suppliers to reach sensitive defence data indirectly.
  • A single security failure at any supplier can put the prime contractor's own certification, and its contracts, at risk.

The US Department of Defense is tightening the rules on who can bid for defence work, and the changes will be felt far beyond large weapons manufacturers. The updated Cybersecurity Maturity Model Certification, known as CMMC, sets mandatory cybersecurity standards for the entire defence industrial base: every company, at every tier, that touches sensitive government information.

The rule was first reported by CSO Online as part of broader coverage of supply chain security trends.

What exactly is CMMC and who does it affect?

CMMC is a federal certification programme that tells defence suppliers what cybersecurity practices they must have in place before they can win or keep government contracts. It applies to any company that handles two categories of sensitive data: Federal Contract Information (FCI, meaning information the government shares with a contractor to get work done) and Controlled Unclassified Information (CUI, meaning data that is sensitive but not classified as a state secret, such as engineering drawings or technical specifications).

The standards are built around guidelines published by the National Institute of Standards and Technology, specifically a document called NIST Special Publication 800-171, which sets out 110 security practices covering everything from password management to incident response.

What is the timeline?

The rule rolls out in two steps.

Phase Date What changes
Phase 1 begins 10 November 2025 Companies self-assess against Level 1 and Level 2 requirements
Phase 2 begins 10 November 2026 Contract solicitations require formal Level 2 third-party certification

After November 2026, winning a new defence contract without the right certification becomes very difficult. Losing a contract mid-term because of non-compliance is also a real possibility.

Why should a small supplier care?

Small and medium-sized suppliers are exactly who this rule is aimed at protecting, because they are exactly who foreign spies go after first.

Rather than attacking heavily defended prime contractors head-on, foreign intelligence services increasingly break into smaller firms in the same supply chain. A small machine shop that makes a specialised component may hold detailed engineering schematics. A regional IT services company may have remote access into dozens of defence-related networks. One break-in at that smaller firm can open a path into the whole ecosystem.

A breach at any tier can expose data that affects military operations, not just company finances.

What does the rule actually require organisations to do?

CMMC demands more than a one-time audit. The updated 2025 guidance stresses continuous readiness: day-to-day evidence that security controls are actually working, not just documentation filed once a year.

Traditional compliance relied on a point-in-time snapshot. A company passed an audit, got a certificate, and moved on. The problem is that a new software flaw, a configuration change, or a new piece of unauthorised software can make that certificate meaningless within weeks.

The rule pushes suppliers toward ongoing testing of their own defences, so that gaps are found internally before an adversary finds them first.

What should employees and customers watch for?

If you work for, or buy from, a company in the defence supply chain, the practical ask is straightforward. Check whether your employer is actively pursuing CMMC certification before the November 2025 start date. Suppliers that miss the Phase 2 deadline in 2026 face disqualification from new contracts, which can affect jobs and business continuity.

For prime contractors, the risk is more immediate: if a supplier you rely on suffers a security incident, your own certification status can come under scrutiny.

Common questions

Does this rule apply to companies outside the United States?

Yes, if a non-US company holds or bids on Department of Defense contracts that involve FCI or CUI, CMMC requirements apply to the relevant part of that company's operations.

What happens if a company fails its assessment?

A failed or missing certification can disqualify a company from new contract solicitations under Section 170.4 of the CMMC final rule framework. Existing contracts may also be reviewed depending on the terms agreed at award.

Is self-assessment enough after November 2026?

For Level 1 (basic hygiene) contracts, self-assessment remains acceptable. For Level 2 contracts, which cover most work involving CUI, an independent third-party assessment organisation must conduct and certify the review from November 2026 onward.

© 2026 Threat Vectr