FAR and DFARS › DFARS Part 252: Solicitation Provisions and Contract Clauses › Subpart 252.2
DFARS 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This provision tells offerors what Cybersecurity Maturity Model Certification (CMMC) level the solicitation requires and that this level, or higher, must be met before award for each contractor information system that will handle Federal contract information (FCI) or controlled unclassified information (CUI). It also requires the offeror to have a current CMMC status and a current affirmation of continuous compliance in the Supplier Performance Risk System (SPRS), and to provide CMMC unique identifiers in the proposal. If the offeror's CMMC status is Conditional, it must close out a valid plan of action and milestones to reach Final status.
Applies to: Offerors responding to a solicitation that includes this provision
What it requires
- Have the current CMMC status entered in SPRS at the required CMMC level for each contractor information system that will process, store, or transmit FCI or CUI
- Have a current affirmation of continuous compliance with the security requirements at 32 CFR part 170 in SPRS
- If CMMC status is Conditional, successfully close out a valid plan of action and milestones to achieve a CMMC status of Final
- Provide in the proposal the CMMC unique identifier(s) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI, and update the list when new CMMC UIDs are generated in SPRS
Key terms: controlled unclassified information (CUI) · current · Cybersecurity Maturity Model Certification (CMMC) status · Cybersecurity Maturity Model Certification unique identifier (CMMC UID) · Federal contract information (FCI)
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
As prescribed in 204.7504(b), use the following provision:
Notice of Cybersecurity Maturity Model Certification Level Requirements (NOV 2025)
(a) Definitions. As used in this provision, controlled unclassified information (CUI), current, Cybersecurity Maturity Model Certification (CMMC) status, Cybersecurity Maturity Model Certification unique identifier (CMMC UID), Federal contract information (FCI), and Plan of action and milestones have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements, clause of this solicitation.
(b)(1) Cybersecurity Maturity Model Certification (CMMC) level. The CMMC level required by this solicitation is: ___[Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]. This CMMC level, or higher (see 32 CFR part 170), is required prior to award for each contractor information system that will process, store, or transmit Federal contract information (FCI) or controlled unclassified information (CUI) during performance of the contract.
(2) The Offeror will not be eligible for award of a contract, task order, or delivery order resulting from this solicitation if the Offeror does not have, for each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of a contract resulting from this solicitation—
(i) The current CMMC status entered in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) at the CMMC level required by paragraph (b)(1) of this provision; and
(ii) A current affirmation of continuous compliance with the security requirements identified at 32 CFR part 170 in SPRS.
(c) Plan of action and milestones. If the Offeror has a CMMC Status of Conditional, the Offeror shall successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.
(d) CMMC unique identifiers. The Offeror shall provide, in the proposal, the CMMC unique identifier(s) (CMMC UIDs) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI during performance of a contract, task order, or delivery order resulting from this solicitation. The Offeror also shall update the list when new CMMC UIDs are generated in SPRS. The CMMC UIDs are provided in SPRS after the Offeror enters the results of self-assessment(s) for each such information system.
(End of provision)
Sections it refers to
- 204.7504 Solicitation provision and contract clause.
- 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
← 252.204-7024 Notice on the Use of the Supplier Performance Risk System. · 252.205-7000 Provision of Information to Cooperative Agreement Holders. →
Rule changes for DFARS Part 252
- Defense Federal Acquisition Regulation Supplement: Modifications to Printed Circuit Board Acquisition Restrictions (DFARS Case 2022-D011) ↗ · proposed 2026-07-02 · comments due 2026-08-31
- Defense Federal Acquisition Regulation Supplement: Certification Requirement for Military Recruitment Advertising (DFARS Case 2024-D022) ↗ · proposed 2026-06-25 · comments due 2026-08-24
- Defense Federal Acquisition Regulation Supplement: Small Purchase Exception for the Acquisition of U.S. Flags (DFARS Case 2024-D013) ↗ · proposed 2026-06-25 · comments due 2026-08-24
- Defense Federal Acquisition Regulation Supplement: Mitigating Risks Related to Foreign Ownership, Control, or Influence (DFARS Case 2021-D011) ↗ · proposed 2026-05-07 · comments due 2026-07-06
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Limitation on Certain Institutes of Higher Education (DFARS Case 2024-D023); Correction ↗ · final rule 2025-08-28 · effective 2025-08-28
- Defense Federal Acquisition Regulation Supplement: Disclosure of DoD Funding in Technical Publications (DFARS Case 2024-D003) ↗ · proposed 2025-08-25 · comments due 2025-10-24
- Defense Federal Acquisition Regulation Supplement: Limitation on Certain Institutes of Higher Education (DFARS Case 2024-D023) ↗ · final rule 2025-08-25 · effective 2025-08-25
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.