Phased Implementation of CMMC Requirements at DLA
DLA will implement Cybersecurity Maturity Model Certification (CMMC) 2.0 pursuant to DFARS 204.75 using a phased approach beginning on the effective date of November 10, 2025. As part of this rollout, DLA may gradually introduce requirements, in the form of DLA Procurement Notes and Standard Text Objects (STOs), aligned with the appropriate CMMC levels.
To support early visibility for industry partners, DLA has identified which NIINs will correspond to Level 2 (self-assessment or C3PAO certification) and, in rare cases, Level 3 (DIBCAC certification). While final DLA procurement policy is still in development, more guidance will be provided near the DFARS effective date.
CMMC requirements may appear in any contract after November 10, 2025, if included by the requiring activity. However, for most DLA contracts, DLA will follow the phased approach outlined below:
Collapse All Expand All

Phase 1
- Begins at 48 CFR Rule Effective Date
- Where applicable, solicitations will require Level 1 or 2 Self-Assessment (after the effective date)

Phase 2
- Begins 12 months after Phase 1 start
- Where applicable, solicitations will require Level 2 Certification (11 Nov 26-10 Nov 27)

Phase 3
- Begins 24 months after Phase 1 start
- Where applicable solicitations will require Level 3 Certification (11 Nov 27-10 Nov 28)

Phase 4 - Full Implementation
- Begins 36 months after Phase 1 start
- All solicitations and contracts will include applicable CMMC Level requirements as a condition of contract award