The Significance of November 10, 2025, for Cybersecurity Maturity Model Certification (CMMC)

After what may have felt like a long wait, CMMC is finally becoming a reality. The Cybersecurity Maturity Model Certification program, which aims to improve cybersecurity and minimize risks in the Defense Industrial Base (DIB), began its evolution back in 2010. During this time, there have been several changes in the structure of the program. Consequently, many organizations that are set to be impacted have adopted a cautious wait-and-see approach. However, on Monday, November 10, it will finally start to become a requirement in certain Department of War (formerly named Department of Defense) contracts. This is when 48 CFR, the CMMC Final Rule, takes effect.
Organizations have taken a number of different approaches in their preparation for CMMC. A small number got ahead of the game and have achieved certification. Some started early and are still working hard to be ready for this date - and some organizations have chosen to wait and see. Achieving CMMC certification is a significant endeavor, and insufficient preparation could result in delays in obtaining certification and potentially lost business opportunities.
It is important for organizations to be aware of the three levels of the CMMC model and which applies to them:
CMMC Level 1
Focuses on basic cybersecurity hygiene practices and is required when Federal Contract Information (FCI) is being handled.
CMMC Level 2
Designed for organizations that handle Controlled Unclassified Information (CUI).
CMMC Level 3
Designed for organizations that also handle CUI and are involved with critical Department of War programs.
Each Level requires more time, likely more cost, and a deeper understanding of the organization’s cybersecurity posture.
No matter where organizations are in their preparation for CMMC, NSF can help. Here’s what organizations need to consider:
- 1Don’t underestimate the effort required for CMMC compliance. Ensure you have the necessary resources and that leadership is engaged and prepared to provide ongoing support.
- 2Conduct a mock CMMC assessment beforehand to proactively identify gaps and areas requiring attention. Although this may seem like an additional step, completing this can lead to significant time and cost savings down the line. NSF can provide this service.
- 3Contact an authorized third-party assessment organization (C3PAO). NSF became the first C3PAO to be authorized in Michigan for CMMC and is listed on the Cyber AB Marketplace, the official accreditation body for the CMMC program.
Our team is ready to work with organizations to address any of the points above. Achieving CMMC compliance can be a challenge, especially for small to medium-sized businesses with limited resources, but you don’t have to navigate it alone.
Get started with CMMC
What’s New with NSF

CELSIUS® Products Earn NSF Certified for Sport® Certification
August 20, 2026CELSIUS® has earned NSF Certified for Sport® certification for select products, including the CELSIUS VIBES line, reinforcing the brand’s commitment to quality, transparency and consumer trust.
Thomas Vyles Honored With 2026 Walter F. Snyder Environmental Health Award
August 19, 2026The award honors Walter F. Snyder, co-founder and first executive director of NSF, and pioneers whose work advances environmental and public health.
NSF Hosts First External Review Panel for ‘NSF/KWTC 555’ with Key Asian Water Authorities
August 3, 2026Joint standard development gains momentum to enhance confidence in Asia’s water industry and advance drinking water safety.
NSF Achieves European Accreditation for Drinking Water Product Certification Ahead of 2027 EU Deadline
July 22, 2026The ISO/IEC 17065 accreditation from BELAC complements NSF’s testing capacity, enabling end-to-end support for EU Drinking Water Directive (DWD) readiness ahead of the January 2027 deadline.