32 CFR Part 170
32 CFR Part 170 is the federal regulation that formally establishes the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) Program. It sets out how defense contractors are expected to process, transmit, and store Controlled Unclassified Information (CUI) as a condition of doing business with the DoD. Because it is codified in the Code of Federal Regulations, it gives the CMMC program enforceable legal standing rather than being merely policy guidance.
32 CFR Part 170 is the DoD final rule, published in the Federal Register on October 15, 2024, that describes and establishes the Cybersecurity Maturity Model Certification (CMMC) Program and its requirements for defense contractors handling Federal Contract Information and Controlled Unclassified Information (CUI). It provides the programmatic and regulatory framework for CMMC, including its structure and assessment mechanisms, and, per the evidence, was set to take effect on December 16, 2024. Practitioners should distinguish this program rule (32 CFR Part 170) from the separate acquisition/contractual mechanism that will implement CMMC requirements in DoD contracts (the DFARS clause under 48 CFR); the two are related but distinct instruments. Readers should verify the current effective date, phased implementation timeline, and specific provisions against the official eCFR and Federal Register text, as program details continue to evolve.
Why it matters
32 CFR Part 170 matters because it moves the Cybersecurity Maturity Model Certification (CMMC) Program from policy aspiration to codified federal regulation. By being placed in the Code of Federal Regulations, the program rule gives CMMC enforceable legal standing rather than the status of discretionary guidance. For defense contractors, this means the way they process, transmit, and store Controlled Unclassified Information (CUI) becomes a formal condition tied to the CMMC framework the DoD administers, not simply a best practice they may choose to adopt.
The rule also clarifies where CMMC's authority originates. As the program rule, 32 CFR Part 170 describes and establishes the CMMC Program and its requirements, but it is distinct from the acquisition and contractual mechanism, the DFARS clause codified under 48 CFR, that actually inserts CMMC obligations into individual DoD contracts. Practitioners who conflate the two risk misjudging when and how requirements attach to their work. Understanding that the program rule provides the structure and assessment framework, while the contractual instrument operationalizes it in acquisitions, is essential to preparing accurately.
Because CMMC and its supporting rules continue to evolve through phased implementation, contractors should treat effective dates and specific provisions as subject to change. The evidence indicates the rule was published in the Federal Register on October 15, 2024, and was set to take effect on December 16, 2024, but readers should verify the current effective date, phased timeline, and specific provisions against the official eCFR and Federal Register text rather than relying on secondary summaries.
Who it's relevant to
Inside 32 CFR Part 170
Common questions
Answers to the questions practitioners most commonly ask about 32 CFR Part 170.