Inside Cybersecurity

December 5, 2025

Daily News

CMMC final rule clarifies addressing assessment gaps, removes notification requirement for information security lapses

By Sara Friedman / September 15, 2025

The Defense Department is making targeted changes in its acquisition final rule to implement the Cybersecurity Maturity Model Certification program, including clarifications on addressing assessment gaps and information security lapses.

The final rule amends the Defense Federal Acquisition Regulation Supplement and will go into effect on Nov. 10. The first rulemaking to implement CMMC 2.0 established the program in Title 32 of the Code of Federal Regulations and went into effect on Dec. 16, 2024.

“Technical and programmatic...


Log in to access this content.


Not a subscriber? Sign up for 30 days free access to exclusive news and analysis on cybersecurity regulations and more.