Skip to main content
Category: CMMC & DIB Assessment

32 CFR Part 170

Also known as: CMMC Program Rule, CMMC Program Final Rule
Simply put

32 CFR Part 170 is the federal regulation that formally establishes the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) Program. It sets out how defense contractors are expected to process, transmit, and store Controlled Unclassified Information (CUI) as a condition of doing business with the DoD. Because it is codified in the Code of Federal Regulations, it gives the CMMC program enforceable legal standing rather than being merely policy guidance.

Formal definition

32 CFR Part 170 is the DoD final rule, published in the Federal Register on October 15, 2024, that describes and establishes the Cybersecurity Maturity Model Certification (CMMC) Program and its requirements for defense contractors handling Federal Contract Information and Controlled Unclassified Information (CUI). It provides the programmatic and regulatory framework for CMMC, including its structure and assessment mechanisms, and, per the evidence, was set to take effect on December 16, 2024. Practitioners should distinguish this program rule (32 CFR Part 170) from the separate acquisition/contractual mechanism that will implement CMMC requirements in DoD contracts (the DFARS clause under 48 CFR); the two are related but distinct instruments. Readers should verify the current effective date, phased implementation timeline, and specific provisions against the official eCFR and Federal Register text, as program details continue to evolve.

Why it matters

32 CFR Part 170 matters because it moves the Cybersecurity Maturity Model Certification (CMMC) Program from policy aspiration to codified federal regulation. By being placed in the Code of Federal Regulations, the program rule gives CMMC enforceable legal standing rather than the status of discretionary guidance. For defense contractors, this means the way they process, transmit, and store Controlled Unclassified Information (CUI) becomes a formal condition tied to the CMMC framework the DoD administers, not simply a best practice they may choose to adopt.

The rule also clarifies where CMMC's authority originates. As the program rule, 32 CFR Part 170 describes and establishes the CMMC Program and its requirements, but it is distinct from the acquisition and contractual mechanism, the DFARS clause codified under 48 CFR, that actually inserts CMMC obligations into individual DoD contracts. Practitioners who conflate the two risk misjudging when and how requirements attach to their work. Understanding that the program rule provides the structure and assessment framework, while the contractual instrument operationalizes it in acquisitions, is essential to preparing accurately.

Because CMMC and its supporting rules continue to evolve through phased implementation, contractors should treat effective dates and specific provisions as subject to change. The evidence indicates the rule was published in the Federal Register on October 15, 2024, and was set to take effect on December 16, 2024, but readers should verify the current effective date, phased timeline, and specific provisions against the official eCFR and Federal Register text rather than relying on secondary summaries.

Who it's relevant to

Defense contractors handling CUI and FCI
Companies that process, transmit, or store Controlled Unclassified Information or Federal Contract Information in support of DoD work are directly within the scope of the CMMC Program established by 32 CFR Part 170. They should understand how the program rule frames safeguarding expectations and confirm how CMMC obligations will attach to their specific contracts through the separate DFARS mechanism.
Compliance officers and ISSMs
Those responsible for interpreting and operationalizing security requirements need to recognize that 32 CFR Part 170 gives the CMMC Program enforceable regulatory standing, and to distinguish this program rule from the acquisition clause that implements it in contracts. They should track the effective date and phased timeline against official sources as the program continues to evolve.
Government contracting and acquisition professionals
Personnel involved in DoD acquisitions should understand that the program rule establishes CMMC in regulation, while the DFARS clause under 48 CFR is the instrument that will introduce CMMC requirements into individual contracts. Treating the two as the same instrument can lead to misjudging when requirements apply.
Auditors and assessors
Those evaluating contractor compliance benefit from anchoring assessments to the program framework and assessment mechanisms described in 32 CFR Part 170, while verifying current provisions, effective dates, and phased implementation details against the eCFR and Federal Register rather than secondary summaries.

Inside 32 CFR Part 170

CMMC Program Rule
32 CFR Part 170 is the codified rule establishing the Cybersecurity Maturity Model Certification (CMMC) Program as maintained by the DoD. It sets out the program's structure, requirements, and administration rather than being a contractual clause; the contractual mechanism for imposing CMMC on contractors is addressed separately through DFARS rulemaking under 48 CFR, which practitioners should track independently.
CMMC Levels
The rule generally describes the tiered assessment levels used to gauge a contractor's protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The specific security requirements at each level are anchored to established sources such as FAR requirements for FCI and NIST SP 800-171 for CUI; readers should verify the current level structure and mappings against the official rule text.
Assessment Types
The rule addresses how conformance is evaluated, which in most implementations includes self-assessment and third-party assessment by authorized assessors, depending on the level. Assessment establishes a point-in-time evaluation of conformance and is distinct from any authorization decision; the precise assessment requirements per level should be confirmed in the current rule.
Assessment Ecosystem and Accreditation
The rule outlines roles within the CMMC ecosystem, such as authorized assessment organizations and the accreditation body responsible for overseeing assessor qualification. This governance structure is administered under the DoD CMMC Program rather than by NIST, which authors the underlying control sources.
Scope of Applicability
As a DoD program rule, 32 CFR Part 170 applies to defense contractors and, where applicable, subcontractors handling FCI or CUI in the context of DoD acquisitions. It does not govern federal civilian agency systems under FISMA or FedRAMP authorizations, and applicability to specific contracts is driven by contractual implementation that must be confirmed.
Phased Implementation
The CMMC Program is described as rolling out in phases, and both the program rule and its requirements have evolved across revisions. Practitioners should treat effective dates, phase timing, and level requirements as subject to change and verify against the current authoritative text.

Common questions

Answers to the questions practitioners most commonly ask about 32 CFR Part 170.

Does 32 CFR Part 170 replace or supersede the DFARS clause 252.204-7012 cybersecurity requirements?
No. 32 CFR Part 170 is the DoD rule that establishes the CMMC Program, while DFARS clause 252.204-7012 is a separate contractual requirement addressing safeguarding of covered defense information and cyber incident reporting. They are distinct authorities issued through different regulatory vehicles: 32 CFR Part 170 sits in Title 32 (National Defense) of the Code of Federal Regulations, whereas the DFARS clause is implemented through Title 48 (the Federal Acquisition Regulation System) and is applied to contracts through separate rulemaking. The CMMC Program generally works alongside, rather than in place of, existing safeguarding and reporting obligations. Readers should confirm how these requirements interact for a specific contract against the current authoritative text, because implementation and contractual specifics are outside the scope of this entry.
If my organization is FedRAMP authorized, does that automatically satisfy the CMMC requirements established under 32 CFR Part 170?
Not automatically. FedRAMP authorization and CMMC address different programs and objectives. FedRAMP, managed through the FedRAMP PMO, concerns the authorization of cloud service offerings for federal use, while CMMC under 32 CFR Part 170 concerns the assessment of a defense contractor's protection of certain information in connection with DoD contracts. A FedRAMP authorization may be relevant to how a contractor uses cloud services, but it does not by itself establish CMMC status. The two should not be treated as interchangeable. Confirm any relationship or acceptance of one program's results within the other against the current official sources, as this entry does not cover those implementation specifics.
Where does 32 CFR Part 170 sit in the Code of Federal Regulations, and who maintains it?
32 CFR Part 170 is codified in Title 32 of the Code of Federal Regulations, which covers National Defense, and it is the DoD rule that establishes the CMMC Program. It is distinct from acquisition regulation provisions found in Title 48. Because the rule is subject to revision and phased implementation, readers should verify the current version and effective provisions directly against the official regulatory text rather than relying on a summary.
How should I determine which CMMC requirements under 32 CFR Part 170 apply to a given contract?
The applicability of CMMC requirements to a specific contract is generally driven by the terms and clauses incorporated into that contract, not by the rule in isolation. 32 CFR Part 170 establishes the program framework, but the contract-specific requirement, level, and timing are matters a reader must confirm against the applicable solicitation, contract language, and current authoritative sources. This entry does not resolve contractual or acquisition specifics for any individual procurement.
Does an assessment conducted under the CMMC Program mean my organization is permanently in compliance?
No. An assessment result should not be treated as a permanent or one-time achievement. Compliance status is generally time-bound and depends on maintaining the required safeguards over the applicable period, and an assessment is distinct from a permanent qualification. Organizations should confirm the current requirements for the validity period, reassessment, and any ongoing obligations against the authoritative text, and should not equate having passed an assessment at one point with continuous compliance or with security itself.
Because CMMC is being implemented in phases, how should I track which provisions of 32 CFR Part 170 are currently in effect?
CMMC has been rolled out through phased implementation and revisions, so the provisions in effect at any given time may differ from earlier or planned states of the program. Rather than relying on prior summaries, organizations should track the current effective text of 32 CFR Part 170 and any associated guidance directly through official DoD sources. This entry describes the concept and does not assert specific effective dates or phase details that a reader must verify against the current authoritative publication.

Common misconceptions

32 CFR Part 170 is the clause that puts CMMC into contracts.
The 32 CFR Part 170 rule establishes the CMMC Program itself. The contractual obligation to meet CMMC is generally imposed through separate DFARS rulemaking under Title 48. Practitioners should not treat the program rule and the contractual clause as interchangeable and should verify current DFARS language.
A CMMC assessment is the same as an authorization or a permanent status.
Assessment under the CMMC Program is a point-in-time evaluation of conformance against required security requirements; it is not an authorization decision, and passing an assessment does not make compliance permanent. Continued conformance is expected, and requirements may change across revisions.
Meeting CMMC requirements is the same as being secure, and it satisfies civilian or other federal frameworks.
CMMC conformance demonstrates alignment to specified requirements for protecting FCI and CUI in DoD contracts but does not by itself guarantee security. It also does not automatically satisfy federal civilian obligations under FISMA or a FedRAMP authorization, which fall outside this rule's scope.

Best practices

Read 32 CFR Part 170 alongside the applicable DFARS rulemaking, since the program rule and the contractual mechanism serve different functions and both must be understood to determine what applies to a given contract.
Determine whether your environment handles FCI, CUI, or both, and map the corresponding CMMC level and its anchored requirements (such as NIST SP 800-171 for CUI) before scoping any assessment.
Confirm the current CMMC level structure, assessment types, and phase timing against the authoritative rule text rather than relying on prior revisions, because the program is being implemented in phases and has evolved.
Treat assessment results as point-in-time and plan for ongoing conformance, rather than assuming a completed assessment confers a permanent or authorization-equivalent status.
Verify assessor and accreditation-body requirements when a third-party assessment is required for your level, and confirm the assessment organization is properly authorized under the DoD-administered ecosystem.
Do not assume CMMC conformance satisfies FISMA, FedRAMP, or other non-DoD frameworks; verify separate obligations for any systems outside the scope of this rule with current official sources.