CMMC compliance starts with knowing your actual posture.
Not your intended posture.
32 CFR Part 170. Effective November 14, 2024.
Cybersecurity Maturity Model Certification is codified at 32 CFR Part 170, effective November 14, 2024. Phase 2 enforcement began November 10, 2025. New DoD contracts requiring Level 2 certification now mandate demonstrated compliance as a condition of award — not a condition of continued performance.
The requirement is not new. DFARS 252.204-7012, which has been in place since 2016, already required contractors handling CUI to implement NIST SP 800-171. What changed in 32 CFR Part 170 is verification: the attestation is now formal, the CMMC UID is tracked in SPRS, and the False Claims Act exposure from a false attestation is documented explicitly in the rulemaking.
Most contractors implementing NIST SP 800-171 for the first time discover that implementation and documentation are two separate problems. A control that is implemented but not documented fails the assessment. A control that is documented but not implemented fails the assessment and creates FCA exposure.
The assessment methodology assigns point values to practices. The resulting score, entered into SPRS, is visible to every prime contractor who accesses the system. A score below a prime’s minimum threshold means the contractor is eliminated before the technical proposal is read.
The certification is a legal claim.
When a senior official submits a CMMC self-attestation, they are making a formal claim to the federal government about the organization's cybersecurity posture. The False Claims Act, 31 U.S.C. §§ 3729-3733, creates civil liability for knowing misrepresentations in connection with government contracts.
The DoJ Civil Cyber-Fraud Initiative, launched in 2021, has pursued FCA enforcement actions against contractors who misrepresented cybersecurity compliance. The evidentiary question in an FCA action is not whether the contractor believed they were compliant. It is whether they had a documented basis for the claim. Assessment records, signed evidence artifacts, and a POA&M tracking known deficiencies are the documented basis.
Source: DOJ Civil Cyber-Fraud Initiative · 31 U.S.C. §§ 3729-3733
Know where you stand — free.
Start with the free CMMC Scoping Wizard. No account. No credit card. 20 minutes.
Authorization is not a destination.
It is a system property.
REAEGIS is the infrastructure that maintains it — converting every commit, scan, and approval into evidence your Authorizing Official can act on.
