---
title: What Is the 48 CFR Rule and Why It Matters for CMMC 2.0 Compliance
description: Learn How 48 CFR connects to CMMC 2.0 and how it will require contractors and subs to be CMMC-certified to be eligible for DoD contracts.
image: https://www.daymarksi.com/hubfs/How%2048CFR%20Connects.png
---

- [MICROSOFT SERVICE OFFERINGS](https://www.daymarksi.com/microsoft-service-offerings)
- [CONTACT](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [SUPPORT](https://www.daymarksi.com/support)

[![DM_LogoTag_white-20yr](https://www.daymarksi.com/hubfs/brand-assets/DM_LogoTag_white-20yr.png "DM_LogoTag_white-20yr")](https://www.daymarksi.com)

- [About](https://www.daymarksi.com/about-daymark) 
    - [Why Daymark](https://www.daymarksi.com/why-daymark)
    - [Leadership](https://www.daymarksi.com/leadership)
    - [Industry Awards](https://www.daymarksi.com/industry-awards)
    - [Daymark Solutions Charitable Trust](https://www.daymarksi.com/charitable-trust)
    - [Customers](https://www.daymarksi.com/customers)
    - [Testimonials](https://www.daymarksi.com/testimonials)
    - [Technical Certifications](https://www.daymarksi.com/technical-certifications)
    - [Careers](https://www.daymarksi.com/careers)
    - [Locations](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [Solutions](https://www.daymarksi.com/solutions) 
    - [Cloud Solutions](https://www.daymarksi.com/cloud)
    - [CMMC Compliance](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Data Center Infrastructure](https://www.daymarksi.com/solutions/data-center-infrastructure-for-storage-networking-compute-security)
    - [Data Protection](https://www.daymarksi.com/solutions/data-protection-backups-recovery-restore)
    - [Networking](https://www.daymarksi.com/solutions/networking-and-security)
    - [Security](https://www.daymarksi.com/solutions/networking-and-security)
    - [Virtualization](https://www.daymarksi.com/solutions/virtualization)
    - [All Technology Partners](https://www.daymarksi.com/partners)
- Cloud 
    - [Microsoft Azure](https://www.daymarksi.com/microsoftazure)
    - [Microsoft Azure Government](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Microsoft 365](https://www.daymarksi.com/microsoft-365)
    - [Copilot for Microsoft 365](https://www.daymarksi.com/copilot-for-microsoft-365)
    - [Microsoft 365 GCC High](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Mimecast](https://www.daymarksi.com/cloud)
    - [Okta](https://www.daymarksi.com/cloud)
    - [All Cloud Partners](https://www.daymarksi.com/cloud-partners)
- [Services](https://www.daymarksi.com/services) 
    - [Microsoft Service Offerings](https://www.daymarksi.com/microsoft-service-offerings)
    - [Assessment & Health Checks](https://www.daymarksi.com/services/assessment-and-health-checks)
    - [Cloud Architecture](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
    - [CMMC Compliance Readiness](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Contract & Maintenance Management](https://www.daymarksi.com/services/contract-maintenance-management)
    - [Documentation & Knowledge Transfer](https://www.daymarksi.com/services/documentation)
    - [Government Community Cloud](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Identity Mangement](https://www.daymarksi.com/microsoft-entra-id-workshop)
    - [Implementations](https://www.daymarksi.com/services/it-project-implementation-on-budget-on-time-on-scope)
    - [Proof of Concepts](https://www.daymarksi.com/services/proof-of-concept-for-information-technology-initiatives)
    - [Solution Architecture](https://www.daymarksi.com/services/it-solution-architecture-for-complex-storage-network-and-computer-solutions)
    - [Staging & Integration](https://www.daymarksi.com/services/staging-and-integration)
- [MyDaymark](https://www.daymarksi.com/mydaymark/) 
    - [Advanced Support](https://www.daymarksi.com/mydaymark/advanced-support)
    - [Premier Support](https://www.daymarksi.com/mydaymark/premier-support)
    - [Managed Services](https://www.daymarksi.com/mydaymark/managed-services)
    - [Management Platform](https://www.daymarksi.com/mydaymark/management-platform)
    - [Security & Compliance](https://www.daymarksi.com/mydaymark/security-compliance)
- Industries 
    - [Energy & Utilities](https://www.daymarksi.com/new-england-it-project-management-and-implementation-for-energy-and-utilities-industry)
    - [Financial Services](https://www.daymarksi.com/new-england-it-project-implementation-for-financial-services-companies)
    - [Defense Industrial Base](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Healthcare](https://www.daymarksi.com/healthcare-information-technology-development-and-implementation)
    - [Life Sciences](https://www.daymarksi.com/new-england-it-initiative-implementation-for-life-sciences-companies)
- [Resources](https://www.daymarksi.com/information-technolocy-resources) 
    - [Case Studies](https://www.daymarksi.com/information-technolocy-resources?types=casestudy)
    - [Data Sheets](https://www.daymarksi.com/information-technolocy-resources?types=datasheet)
    - [Partner Resources](https://www.daymarksi.com/information-technolocy-resources?types=partnerresources)
    - [Workshops](https://www.daymarksi.com/information-technolocy-resources?types=workshop)
- [News & Events](https://www.daymarksi.com/news-events)
- Blog 
    - [Daymark IT Insights](https://www.daymarksi.com/blog)
    - [Cole Tramp's Microsoft Insights](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)

![banner-why-daymark.jpg](https://www.daymarksi.com/hs-fs/hub/30865/file-2671640025-jpg/2015_Images/Banner_Images/banner-why-daymark.jpg?width=1400&name=banner-why-daymark.jpg "banner-why-daymark.jpg")

##### **Daymark IT Insights**

Enterprise IT, cloud, security, and AI guidance from Daymark’s technology experts.

# [What Is the 48 CFR Rule and Why It Matters for CMMC 2.0 Compliance](https://www.daymarksi.com/blog/what-is-the-48-cfr-rule-and-why-it-matters-for-cmmc-2.0-compliance)

Posted by [Blake Bernard](https://www.daymarksi.com/blog/author/blake-bernard)

 Mon, Jun 30, 2025

- [Tweet](https://twitter.com/share)

![How 48CFR Connects](https://www.daymarksi.com/hs-fs/hubfs/How%2048CFR%20Connects.png?width=1920&height=1275&name=How%2048CFR%20Connects.png)

The **Cybersecurity Maturity Model Certification (CMMC)** is on track to become a core requirement for defense contractors. However, before CMMC can be included in Department of Defense (DoD) contracts, a key regulation must take effect: [**Title 48 of the Code of Federal Regulations (48 CFR)**.](https://www.federalregister.gov/documents/2024/08/15/2024-18110/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of)

If your organization does business with the DoD—or hopes to—you need to understand this rule and how it will impact your eligibility to win and maintain government contracts.

**What Is 48 CFR?**

48 CFR is part of the Federal Acquisition Regulation (FAR) System, which governs how the federal government procures goods and services. Within this system, the Defense Federal Acquisition Regulation Supplement (DFARS) adds DoD-specific rules. The 48 CFR rule specifically integrates CMMC 2.0 into the DFARS. In short, this rule establishes cybersecurity requirements as a contractual obligation—not just policy guidance.

How 48 CFR Connects to CMMC 2.0

Two key regulations support CMMC:

- 32 CFR Part 170 – Establishes the CMMC program structure, including certification levels, assessment procedures, and governance (via the Cyber AB).
- 48 CFR / DFARS 252.204-7021 – Puts teeth behind the program by requiring CMMC certification in order to win or perform on DoD contracts.

Once finalized, 48 CFR will require contractors and subcontractors to be CMMC-certified in order to be eligible for DoD contracts, making CMMC enforcement real in procurement.

**What Will the 48 CFR Rule Do?**

The 48 CFR rule will:

- Mandate CMMC certification in DoD solicitations and contracts.
- Define the required certification level (1, 2, or 3) based on the sensitivity of the information being handled.
- Enforce timelines for achieving and maintaining certification.
- Clarify the use of self-assessments vs. third-party assessments.
- Require [**CMMC flowdown to subcontractors**](https://www.daymarksi.com/information-technology-navigator-blog/how-government-subcontractors-should-know-about-dfars-flowdowns) that handle FCI or CUI.
- Include penalties and contract enforcement for non-compliance.

**When Will It Take Effect?**

When the 48 CFR CMMC Acquisition Rule will be released is the big question right now. It has completed the public comment period and is undergoing final review by the Office of Information and Regulatory Affairs (OIRA). The DoD has been anticipating the rule to be finalized soon. Although there is no official date, many expect it in the summer of 2025.  

Once finalized, CMMC certification will be phased into contracts—starting with Level 1 requirements and eventually expanding to include Level 2 for contractors handling Controlled Unclassified Information (CUI).

**Why This Rule Matters to Your Business**

This is not a drill—CMMC is becoming a contractual gatekeeper.

- No certification, no contract – You won’t be able to bid or perform on affected DoD contracts without the proper CMMC level.
- Third-party assessments – Many contractors will need a Certified Third-Party Assessment Organization (C3PAO) to certify compliance.
- Supply chain responsibility – Prime contractors must ensure their subcontractors are also compliant, creating a ripple effect across the defense industrial base.

**Government Compliance Workshops and Services to Get You Ready**

The 48 CFR rule is the mechanism that will make CMMC real for DoD contractors. If you're in the defense supply chain, the time to act is now. Everyone agrees that the rules are complicated. Once the 48 CFR rule is released, experts at every level of the compliance chain will be in short supply. Together with our partners, Daymark has the certifications and qualifications to guide you through the entire CMMC 2.0 compliance process.

You can start with our Government Scoping Workshop. It’s a first step to scope your environment in the compliance program. This workshop helps determine which requirements your organization needs to follow and identifies sensitive information you may be creating, processing, storing, or transmitting. If you’re further along, we offer a Government Implementation Workshop, which guides you through a detailed plan for achieving compliance within your organization.

[Migration services](https://www.daymarksi.com/microsoft-365-gcc-high-rapid-deploymentmicrosoft-365-tenant-security-assessment) are obviously critical. Daymark has the proven expertise to migrate data from your current environment to Microsoft’s Government Cloud, leveraging Microsoft-authorized GCC, GCC High, and Azure Government licenses. This can include:

- Deployment of Entra ID, Intune, Defender, and Microsoft Purview Information Protection to solve various security and compliance controls
- CMMC Compliance Services
- CMMC Gap Analysis
- Comprehensive Documentation, including SSP and POA&M
- CMMC Readiness Assessment
- Tabletop Exercises

These are just some of the many ways we can help you quickly prepare for CMMC deadlines. [Contact us today to get started.](https://www.daymarksi.com/cmmc-compliance-starts-here)

 

### Subscribe to Daymark Insights

### Latest Posts

### Browse by Tag

- [Microsoft (88)](https://www.daymarksi.com/blog/topic/microsoft)
- [Cloud (70)](https://www.daymarksi.com/blog/topic/cloud)
- [Cole Tramp's Microsoft Insights (58)](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)
- [Azure (55)](https://www.daymarksi.com/blog/topic/azure)
- [Security (49)](https://www.daymarksi.com/blog/topic/security)
- [Data Protection (43)](https://www.daymarksi.com/blog/topic/data-protection)
- [Microsoft Fabric (41)](https://www.daymarksi.com/blog/topic/microsoft-fabric)
- [Data Governance (38)](https://www.daymarksi.com/blog/topic/data-governance)
- [AI (35)](https://www.daymarksi.com/blog/topic/ai)
- [Partners (33)](https://www.daymarksi.com/blog/topic/partners)
- [Compliance (31)](https://www.daymarksi.com/blog/topic/compliance)
- [Data Center (30)](https://www.daymarksi.com/blog/topic/data-center)
- [CMMC (27)](https://www.daymarksi.com/blog/topic/cmmc)
- [Backup (26)](https://www.daymarksi.com/blog/topic/backup)
- [Daymark News (23)](https://www.daymarksi.com/blog/topic/daymark-news)
- [Storage (22)](https://www.daymarksi.com/blog/topic/storage)
- [GCC High (19)](https://www.daymarksi.com/blog/topic/gcc-high)
- [Veritas (18)](https://www.daymarksi.com/blog/topic/veritas)
- [Virtualization (18)](https://www.daymarksi.com/blog/topic/virtualization)
- [Cybersecurity (17)](https://www.daymarksi.com/blog/topic/cybersecurity)
- [Azure AI Foundry (16)](https://www.daymarksi.com/blog/topic/azure-ai-foundry)
- [Featured Gov (16)](https://www.daymarksi.com/blog/topic/featured-gov)
- [Government Cloud (16)](https://www.daymarksi.com/blog/topic/government-cloud)
- [Disaster Recovery (15)](https://www.daymarksi.com/blog/topic/disaster-recovery)
- [Cloud Backup (14)](https://www.daymarksi.com/blog/topic/cloud-backup)
- [Managed Services (13)](https://www.daymarksi.com/blog/topic/managed-services)
- [Copilot (11)](https://www.daymarksi.com/blog/topic/copilot)
- [Industry Expertise (9)](https://www.daymarksi.com/blog/topic/industry-expertise)
- [NIST SP 800-171 (7)](https://www.daymarksi.com/blog/topic/nist-sp-800-171)
- [Hybrid Cloud (6)](https://www.daymarksi.com/blog/topic/hybrid-cloud)
- [Networking (6)](https://www.daymarksi.com/blog/topic/networking)
- [Power BI (6)](https://www.daymarksi.com/blog/topic/power-bi)
- [Pure Storage (4)](https://www.daymarksi.com/blog/topic/pure-storage)
- [Reporting (3)](https://www.daymarksi.com/blog/topic/reporting)
- [Services (3)](https://www.daymarksi.com/blog/topic/services)
- [AI for Defense (2)](https://www.daymarksi.com/blog/topic/ai-for-defense)
- [Cloud Security (2)](https://www.daymarksi.com/blog/topic/cloud-security)
- [Everpure (2)](https://www.daymarksi.com/blog/topic/everpure)
- [GDPR (2)](https://www.daymarksi.com/blog/topic/gdpr)
- [Microsoft Purview (2)](https://www.daymarksi.com/blog/topic/microsoft-purview)
- [Apple (1)](https://www.daymarksi.com/blog/topic/apple)
- [CMMC 2.0 Requirements (1)](https://www.daymarksi.com/blog/topic/cmmc-2-0-requirements)
- [FedRamp AI (1)](https://www.daymarksi.com/blog/topic/fedramp-ai)
- [Mobile (1)](https://www.daymarksi.com/blog/topic/mobile)
- [Power Automate (1)](https://www.daymarksi.com/blog/topic/power-automate)

[see all](https://www.daymarksi.com/blog/what-is-the-48-cfr-rule-and-why-it-matters-for-cmmc-2.0-compliance#)

### How Can We Help?  [![Speak With An Expert](https://no-cache.hubspot.com/cta/default/30865/5de282fd-640c-49b2-bf45-603dbee66842.png)](https://cta-redirect.hubspot.com/cta/redirect/30865/5de282fd-640c-49b2-bf45-603dbee66842)

#### About

Daymark Solutions is an experienced technology integration and solutions provider that helps organizations effectively architect, implement, and deploy customized solutions to help their customers grow and scale their IT infrastructure. Specializing in AI, cloud and modern data center solutions, Daymark’s unique combination of in-depth technical knowledge, extensive experience, and proven methodologies enable its customers to successfully address even the most difficult technology challenges.

#### Connect

<https://twitter.com/daymarksi>     <https://twitter.com/daymarksi><https://www.linkedin.com/company/daymark-solutions-inc./>

#### Links

- [About](https://www.daymarksi.com/about-daymark)
- [Industry Expertise](https://www.daymarksi.com/industry-experience-in-finance-healthcare-energy-utilities-and-life-sciences)
- [Solutions](https://www.daymarksi.com/solutions)
- [Services](https://www.daymarksi.com/services)
- [Cloud](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
- [Resources](https://www.daymarksi.com/whitepapers-videos-analyst-reports-and-case-studies-on-information-technologies)
- [News & Events](https://www.daymarksi.com/news-events)
- [Blog](https://www.daymarksi.com/blog)

#### Contact

**Corporate Headquarters**  
Daymark Solutions  
131 Middlesex Turnpike  
Burlington, MA 01803

**Corporate:** [+1 781-359-3000](tel:17813593000)

**Email:** [info@daymarksi.com](mailto:info@daymarksi.com)

![DM_LogoTag_white.png](https://www.daymarksi.com/hs-fs/hubfs/Daymarksi-2017/Image/DM_LogoTag_white.png?width=176&name=DM_LogoTag_white.png "DM_LogoTag_white.png")

© 2026 Daymark Solutions, Inc. All rights reserved.  |  [Daymark Privacy Policy](https://www.daymarksi.com/hubfs/Daymark%20-%20Privacy%20Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Blake Bernard",
    "url" : "https://www.daymarksi.com/blog/author/blake-bernard"
  },
  "dateModified" : "2025-06-30T15:22:29.371Z",
  "datePublished" : "2025-06-30T15:22:10.000Z",
  "headline" : "What Is the 48 CFR Rule and Why It Matters for CMMC 2.0 Compliance",
  "image" : [ "https://www.daymarksi.com/hubfs/How%2048CFR%20Connects.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.daymarksi.com/blog/what-is-the-48-cfr-rule-and-why-it-matters-for-cmmc-2.0-compliance",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.daymarksi.com/hubfs/v2/images/daymark-logo.png"
    },
    "name" : "Daymark Solutions, Inc."
  }
}
```