---
title: CMMC 2.13 is Here - Explore the 2025 Timeline
description: CMMC 2.1 is here! Here's a look at the history of the CMMC timeline, what's to come, and how organizations can prepare for what is next.
image: https://www.daymarksi.com/hubfs/New%20CMMC%20Timeline%20Image.png
---

- [MICROSOFT SERVICE OFFERINGS](https://www.daymarksi.com/microsoft-service-offerings)
- [CONTACT](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [SUPPORT](https://www.daymarksi.com/support)

[![DM_LogoTag_white-20yr](https://www.daymarksi.com/hubfs/brand-assets/DM_LogoTag_white-20yr.png "DM_LogoTag_white-20yr")](https://www.daymarksi.com)

- [About](https://www.daymarksi.com/about-daymark) 
    - [Why Daymark](https://www.daymarksi.com/why-daymark)
    - [Leadership](https://www.daymarksi.com/leadership)
    - [Industry Awards](https://www.daymarksi.com/industry-awards)
    - [Daymark Solutions Charitable Trust](https://www.daymarksi.com/charitable-trust)
    - [Customers](https://www.daymarksi.com/customers)
    - [Testimonials](https://www.daymarksi.com/testimonials)
    - [Technical Certifications](https://www.daymarksi.com/technical-certifications)
    - [Careers](https://www.daymarksi.com/careers)
    - [Locations](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [Solutions](https://www.daymarksi.com/solutions) 
    - [Cloud Solutions](https://www.daymarksi.com/cloud)
    - [CMMC Compliance](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Data Center Infrastructure](https://www.daymarksi.com/solutions/data-center-infrastructure-for-storage-networking-compute-security)
    - [Data Protection](https://www.daymarksi.com/solutions/data-protection-backups-recovery-restore)
    - [Networking](https://www.daymarksi.com/solutions/networking-and-security)
    - [Security](https://www.daymarksi.com/solutions/networking-and-security)
    - [Virtualization](https://www.daymarksi.com/solutions/virtualization)
    - [All Technology Partners](https://www.daymarksi.com/partners)
- Cloud 
    - [Microsoft Azure](https://www.daymarksi.com/microsoftazure)
    - [Microsoft Azure Government](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Microsoft 365](https://www.daymarksi.com/microsoft-365)
    - [Copilot for Microsoft 365](https://www.daymarksi.com/copilot-for-microsoft-365)
    - [Microsoft 365 GCC High](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Mimecast](https://www.daymarksi.com/cloud)
    - [Okta](https://www.daymarksi.com/cloud)
    - [All Cloud Partners](https://www.daymarksi.com/cloud-partners)
- [Services](https://www.daymarksi.com/services) 
    - [Microsoft Service Offerings](https://www.daymarksi.com/microsoft-service-offerings)
    - [Assessment & Health Checks](https://www.daymarksi.com/services/assessment-and-health-checks)
    - [Cloud Architecture](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
    - [CMMC Compliance Readiness](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Contract & Maintenance Management](https://www.daymarksi.com/services/contract-maintenance-management)
    - [Documentation & Knowledge Transfer](https://www.daymarksi.com/services/documentation)
    - [Government Community Cloud](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Identity Mangement](https://www.daymarksi.com/microsoft-entra-id-workshop)
    - [Implementations](https://www.daymarksi.com/services/it-project-implementation-on-budget-on-time-on-scope)
    - [Proof of Concepts](https://www.daymarksi.com/services/proof-of-concept-for-information-technology-initiatives)
    - [Solution Architecture](https://www.daymarksi.com/services/it-solution-architecture-for-complex-storage-network-and-computer-solutions)
    - [Staging & Integration](https://www.daymarksi.com/services/staging-and-integration)
- [MyDaymark](https://www.daymarksi.com/mydaymark/) 
    - [Advanced Support](https://www.daymarksi.com/mydaymark/advanced-support)
    - [Premier Support](https://www.daymarksi.com/mydaymark/premier-support)
    - [Managed Services](https://www.daymarksi.com/mydaymark/managed-services)
    - [Management Platform](https://www.daymarksi.com/mydaymark/management-platform)
    - [Security & Compliance](https://www.daymarksi.com/mydaymark/security-compliance)
- Industries 
    - [Energy & Utilities](https://www.daymarksi.com/new-england-it-project-management-and-implementation-for-energy-and-utilities-industry)
    - [Financial Services](https://www.daymarksi.com/new-england-it-project-implementation-for-financial-services-companies)
    - [Defense Industrial Base](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Healthcare](https://www.daymarksi.com/healthcare-information-technology-development-and-implementation)
    - [Life Sciences](https://www.daymarksi.com/new-england-it-initiative-implementation-for-life-sciences-companies)
- [Resources](https://www.daymarksi.com/information-technolocy-resources) 
    - [Case Studies](https://www.daymarksi.com/information-technolocy-resources?types=casestudy)
    - [Data Sheets](https://www.daymarksi.com/information-technolocy-resources?types=datasheet)
    - [Partner Resources](https://www.daymarksi.com/information-technolocy-resources?types=partnerresources)
    - [Workshops](https://www.daymarksi.com/information-technolocy-resources?types=workshop)
- [News & Events](https://www.daymarksi.com/news-events)
- Blog 
    - [Daymark IT Insights](https://www.daymarksi.com/blog)
    - [Cole Tramp's Microsoft Insights](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)

![banner-why-daymark.jpg](https://www.daymarksi.com/hs-fs/hub/30865/file-2671640025-jpg/2015_Images/Banner_Images/banner-why-daymark.jpg?width=1400&name=banner-why-daymark.jpg "banner-why-daymark.jpg")

##### **Daymark IT Insights**

Enterprise IT, cloud, security, and AI guidance from Daymark’s technology experts.

# [CMMC 2.13 is Here - Explore the 2025 Timeline](https://www.daymarksi.com/blog/2025-timeline-for-cmmc-2.0-compliance)

Posted by [Ken Bergeron](https://www.daymarksi.com/blog/author/ken-bergeron)

 Tue, Nov 05, 2024

- [Tweet](https://twitter.com/share)

![New CMMC Timeline Image](https://www.daymarksi.com/hs-fs/hubfs/New%20CMMC%20Timeline%20Image.png?width=1920&height=1280&name=New%20CMMC%20Timeline%20Image.png)

On October 15, 2024, the final rule for the Cybersecurity Maturity Model Certification (CMMC) program was officially published. [This rule, codified as 32 CFR, becomes effective on December 16, 2024](https://www.defense.gov/News/Releases/Release/Article/3932947/cybersecurity-maturity-model-certification-program-final-rule-published/). The CMMC journey began in 2019 with DFARS Case 2019-D041, and after four years of development, the rule is now finalized. Let’s take a look at the history of the CMMC timeline, what's to come, and how organizations can prepare for what is next.

**CMMC Rulemaking Timeline**

The rulemaking process illustrated in the graphic below shows a high-level workflow from the Government Accountability Office (GAO).

![CMMC Timeline](https://www.daymarksi.com/hs-fs/hubfs/CMMC%20Timeline.png?width=685&height=325&name=CMMC%20Timeline.png)

Figure 1: GAO Federal Rulemaking

In Figure 2, Estimated Rulemaking and CMMC 2.13 timeframe shows the [32 CFR](https://www.ecfr.gov/current/title-32) and [48 CFR](https://www.ecfr.gov/current/title-48) rulemaking timelines. 48 CFR started in March 2024, as communicated to the community by the [DoD](https://www.defense.gov/News/News-Stories/Article/Article/3678476/defense-department-releases-companion-video-for-cmmc-public-comment-period/). The rulemaking process in the diagrams below moves left to right with assumed timeframes calculated based on the rulemaking process and educated guesses. The estimates are in the blue description blocks. Once the rulemaking process has been completed and the effective day arrives, we follow the text in the [rule](https://www.govinfo.gov/content/pkg/FR-2024-10-15/pdf/2024-22905.pdf) to determine the effective dates. The 48 CFR [stated](https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program#h-77) that the DoD anticipates all contract solicitations from October 1, 2026, will have the CMMC requirement in it.

![CMMC Timeline 2nd image](https://www.daymarksi.com/hs-fs/hubfs/CMMC%20Timeline%202nd%20image.png?width=977&height=129&name=CMMC%20Timeline%202nd%20image.png)

Figure 2: Estimated Rulemaking and CMMC 2.13 timeframe

During the [February 2024 CyberAB Town Hall](https://vimeo.com/918105584), the [CyberAB](https://cyberab.org/) presented their timeline for the rulemaking process, as seen in Figure 3, estimating that October 2024 is when the [32 CFR](https://www.ecfr.gov/current/title-32) would be issued. They also highlighted that federal elections and the adjournment of the 118th Congress may influence the rulemaking process.

![CMMC Timeline 3rd image](https://www.daymarksi.com/hs-fs/hubfs/CMMC%20Timeline%203rd%20image.png?width=591&height=420&name=CMMC%20Timeline%203rd%20image.png)

Figure 3: Estimates from the CyberAB February 2024 Town Hall

 

When the final rule has been published and the 30–60-day effective date is up, then it will be a requirement, right? Well, this is where it gets complicated, or should I say more complicated. The rule gives the framework for what is required, but now the assessors need education, training, and certification to conduct assessments. The CyberAB has a sub-organization called the Cybersecurity Assessor and Instructor Certification Organization (CAICO) that will need to update the blueprints for the Certified CMMC Professional (CCP) and the Certified CMMC Assessor (CCA) training. After the blueprints have been updated, the exam needs updating, and delta training needs to be offered to existing CCP and CCA personnel so that they understand the differences in the CMMC models (CMMC 2.0 vs 2.13). Then, delta training needs to be offered to existing CCP and CCA personnel so that they understand the differences in the CMMC models (CMMC 2.0 vs. 2.13). The C3PAOs may also need to update their assessment procedures under [ISO 17020](https://www.iso.org/standard/52994.html#:~:text=This%20standard%20was,their%20inspection%20activities.) and provide their assessment teams training on the changes.

**Now we are ready, correct?**

Not quite. Every Licensed Publishing Partner (LPP) in the ecosystem will need to update their CCP and CCA training, send it to [ProCert](https://procert.com/) for verification, and then, once approved, use that new content for education and training for new CCP and CCA candidates. While the assessments can happen, it is unlikely that there will be enough educated and trained personnel to conduct the assessments.

**Okay, let’s get the assessments going!**

There is one final thing that comes into play here. The DFARS 252.204-7021 rule must be inserted into a contract (new awards, recompete awards, and potentially option year contracts) by the contracting officer. During the phase-in period, the contracting officer will decide if they should insert the clause into the contract or not. Based on the rulemaking, other clauses will be added as well, and it is assumed that the additional clauses will provide the specifications as to which CMMC level the contractor must obtain.

**Call to Action**

Many companies have been holding off on their implementation of a cybersecurity compliance program to meet the 7012 clause because they are linking it directly to the CMMC rulemaking; others have a program in place and are wondering when they may need to get the DFARS 252.204-7021 (CMMC requirement) clause inserted into their contracts. Most, if not all, contracts have the 7012 clause as a requirement today, so there should be no hesitation in implementing a compliance program for your organization.

The program implementation estimates are 6-9 months from the DoD and 12-18 months from industry. If we look at the rulemaking process, your organization may be required to get a CMMC certification as soon as April 2025. If we roll that back 12 months, that means April 2024 was the timeframe for starting to work on putting together a program.

If you need to rely on a third party to set up a program, the longer you wait, the less likely they will be available to help, or the more it will cost to rush the order. The contractor will still be required to implement a [NIST SP800-171](https://doi.org/10.6028/NIST.SP.800-171r2) program under the 7012 clause, conduct a self-assessment using [NIST SP800-171A](https://doi.org/10.6028/NIST.SP.800-171A) and the [DoD Assessment Methodology](https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf). and then upload their score to the Procurement Integrated Enterprise Environment (PIEE) Supplier Performance Risk System (SPRS) under the [DFARS 252.204-7019](https://www.acquisition.gov/dfars/252.204-7019-notice-nistsp-800-171-dod-assessment-requirements.) clause to be considered for award. The contractor may need to allow the Defense Contract Management Agency (DCMA)/ Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) to perform their own moderate or high assessment following the 7020 clause. The contracting officers will follow the [DFARS 252.204-7024](https://www.acquisition.gov/dfars/252.204-7024-notice-use-supplier-performance-risk-system.) clause to look at the scores in the SPRS system as part of the award determination.

**Government Compliance Workshops and Services to Get You Ready**

Everyone agrees that the rules are complicated. The bottom line is that prime contractors can begin to include CMMC 2.0 in contracts as early as January 2025. Once that happens, experts at every level of the compliance chain will be in short supply. Together with our partner, [Critical Prism Defense](https://criticalprismdefense.com/), we have the certifications and qualifications to guide you through the entire CMMC 2.0 compliance process.

You can start with our Government Scoping Workshop. It’s a first step to scope your environment in the compliance program. This Workshop assists with determining which requirements your organization needs to follow and uncovers sensitive information you may be creating, processing, storing, or transmitting. If you’re further along, we offer a Government Implementation Workshop, which walks you through a detailed plan of how your organization can achieve compliance.

Migration services are obviously critical. Daymark has the proven expertise to migrate data from your current environment to Microsoft’s Government Cloud, leveraging Microsoft-authorized GCC, GCC High, and Azure Government licenses. This can include:

- Deployment of Entra ID, Intune, Defender, and Microsoft Purview Information Protection to solve various security and compliance controls.
- CMMC Compliance Services:
- CMMC Gap Analysis
- Comprehensive Documentation, including SSP and POA&M
- CMMC Readiness Assessment
- Tabletop Exercises

These are just some of the many ways we can help you quickly prepare for CMMC deadlines. [Contact us today to get started.](https://www.daymarksi.com/cmmc-compliance-starts-here)

### Subscribe to Daymark Insights

### Latest Posts

### Browse by Tag

- [Microsoft (88)](https://www.daymarksi.com/blog/topic/microsoft)
- [Cloud (70)](https://www.daymarksi.com/blog/topic/cloud)
- [Cole Tramp's Microsoft Insights (58)](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)
- [Azure (55)](https://www.daymarksi.com/blog/topic/azure)
- [Security (49)](https://www.daymarksi.com/blog/topic/security)
- [Data Protection (43)](https://www.daymarksi.com/blog/topic/data-protection)
- [Microsoft Fabric (41)](https://www.daymarksi.com/blog/topic/microsoft-fabric)
- [Data Governance (38)](https://www.daymarksi.com/blog/topic/data-governance)
- [AI (35)](https://www.daymarksi.com/blog/topic/ai)
- [Partners (33)](https://www.daymarksi.com/blog/topic/partners)
- [Compliance (31)](https://www.daymarksi.com/blog/topic/compliance)
- [Data Center (30)](https://www.daymarksi.com/blog/topic/data-center)
- [CMMC (27)](https://www.daymarksi.com/blog/topic/cmmc)
- [Backup (26)](https://www.daymarksi.com/blog/topic/backup)
- [Daymark News (23)](https://www.daymarksi.com/blog/topic/daymark-news)
- [Storage (22)](https://www.daymarksi.com/blog/topic/storage)
- [GCC High (19)](https://www.daymarksi.com/blog/topic/gcc-high)
- [Veritas (18)](https://www.daymarksi.com/blog/topic/veritas)
- [Virtualization (18)](https://www.daymarksi.com/blog/topic/virtualization)
- [Cybersecurity (17)](https://www.daymarksi.com/blog/topic/cybersecurity)
- [Azure AI Foundry (16)](https://www.daymarksi.com/blog/topic/azure-ai-foundry)
- [Featured Gov (16)](https://www.daymarksi.com/blog/topic/featured-gov)
- [Government Cloud (16)](https://www.daymarksi.com/blog/topic/government-cloud)
- [Disaster Recovery (15)](https://www.daymarksi.com/blog/topic/disaster-recovery)
- [Cloud Backup (14)](https://www.daymarksi.com/blog/topic/cloud-backup)
- [Managed Services (13)](https://www.daymarksi.com/blog/topic/managed-services)
- [Copilot (11)](https://www.daymarksi.com/blog/topic/copilot)
- [Industry Expertise (9)](https://www.daymarksi.com/blog/topic/industry-expertise)
- [NIST SP 800-171 (7)](https://www.daymarksi.com/blog/topic/nist-sp-800-171)
- [Hybrid Cloud (6)](https://www.daymarksi.com/blog/topic/hybrid-cloud)
- [Networking (6)](https://www.daymarksi.com/blog/topic/networking)
- [Power BI (6)](https://www.daymarksi.com/blog/topic/power-bi)
- [Pure Storage (4)](https://www.daymarksi.com/blog/topic/pure-storage)
- [Reporting (3)](https://www.daymarksi.com/blog/topic/reporting)
- [Services (3)](https://www.daymarksi.com/blog/topic/services)
- [AI for Defense (2)](https://www.daymarksi.com/blog/topic/ai-for-defense)
- [Cloud Security (2)](https://www.daymarksi.com/blog/topic/cloud-security)
- [Everpure (2)](https://www.daymarksi.com/blog/topic/everpure)
- [GDPR (2)](https://www.daymarksi.com/blog/topic/gdpr)
- [Microsoft Purview (2)](https://www.daymarksi.com/blog/topic/microsoft-purview)
- [Apple (1)](https://www.daymarksi.com/blog/topic/apple)
- [CMMC 2.0 Requirements (1)](https://www.daymarksi.com/blog/topic/cmmc-2-0-requirements)
- [FedRamp AI (1)](https://www.daymarksi.com/blog/topic/fedramp-ai)
- [Mobile (1)](https://www.daymarksi.com/blog/topic/mobile)
- [Power Automate (1)](https://www.daymarksi.com/blog/topic/power-automate)

[see all](https://www.daymarksi.com/blog/2025-timeline-for-cmmc-2.0-compliance#)

### How Can We Help?  [![Speak With An Expert](https://no-cache.hubspot.com/cta/default/30865/5de282fd-640c-49b2-bf45-603dbee66842.png)](https://cta-redirect.hubspot.com/cta/redirect/30865/5de282fd-640c-49b2-bf45-603dbee66842)

#### About

Daymark Solutions is an experienced technology integration and solutions provider that helps organizations effectively architect, implement, and deploy customized solutions to help their customers grow and scale their IT infrastructure. Specializing in AI, cloud and modern data center solutions, Daymark’s unique combination of in-depth technical knowledge, extensive experience, and proven methodologies enable its customers to successfully address even the most difficult technology challenges.

#### Connect

<https://twitter.com/daymarksi>     <https://twitter.com/daymarksi><https://www.linkedin.com/company/daymark-solutions-inc./>

#### Links

- [About](https://www.daymarksi.com/about-daymark)
- [Industry Expertise](https://www.daymarksi.com/industry-experience-in-finance-healthcare-energy-utilities-and-life-sciences)
- [Solutions](https://www.daymarksi.com/solutions)
- [Services](https://www.daymarksi.com/services)
- [Cloud](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
- [Resources](https://www.daymarksi.com/whitepapers-videos-analyst-reports-and-case-studies-on-information-technologies)
- [News & Events](https://www.daymarksi.com/news-events)
- [Blog](https://www.daymarksi.com/blog)

#### Contact

**Corporate Headquarters**  
Daymark Solutions  
131 Middlesex Turnpike  
Burlington, MA 01803

**Corporate:** [+1 781-359-3000](tel:17813593000)

**Email:** [info@daymarksi.com](mailto:info@daymarksi.com)

![DM_LogoTag_white.png](https://www.daymarksi.com/hs-fs/hubfs/Daymarksi-2017/Image/DM_LogoTag_white.png?width=176&name=DM_LogoTag_white.png "DM_LogoTag_white.png")

© 2026 Daymark Solutions, Inc. All rights reserved.  |  [Daymark Privacy Policy](https://www.daymarksi.com/hubfs/Daymark%20-%20Privacy%20Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Ken Bergeron",
    "url" : "https://www.daymarksi.com/blog/author/ken-bergeron"
  },
  "dateModified" : "2025-03-06T13:02:19.255Z",
  "datePublished" : "2024-11-05T15:52:53.000Z",
  "headline" : "CMMC 2.13 is Here - Explore the 2025 Timeline",
  "image" : [ "https://www.daymarksi.com/hubfs/New%20CMMC%20Timeline%20Image.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.daymarksi.com/blog/2025-timeline-for-cmmc-2.0-compliance",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.daymarksi.com/hubfs/v2/images/daymark-logo.png"
    },
    "name" : "Daymark Solutions, Inc."
  }
}
```