CMMC Brings New Era of Cybersecurity Compliance for Defense Contractors – November 2025

Dec 8, 2025

Alston and Bird’s Privacy, Cyber & Data Strategy Team breaks down the Department of Defense’s finalized Cybersecurity Maturity Model Certification (CMMC) rule, which establishes a tiered compliance framework that will soon be mandatory for all defense contractors and subcontractors.

  • Contractors must achieve and maintain the required CMMC level, based on the sensitivity of information handled, to be eligible for DoD contracts
  • Discretionary adoption begins November 2025, with mandatory compliance for applicable contracts by November 2028
  • Prime and subcontractors should immediately assess their information security posture, certification needs, and subcontractor compliance to prepare for stricter oversight

Read More

Ten Checkpoints - On the Way to Your GSA Schedule

Download our new step-by-step guide to learn the process for getting your own GSA Schedule!