Is CMMC required now, or is it still being phased in?

CMMC is final and live: the 48 CFR DFARS final rule published 2025-09-10 and took effect 2025-11-10, so the requirement is real today and being phased into solicitations on a schedule. Phase 1 began with self-assessment levels; higher-assurance Level 2…

register 09 · Compliance pins· CMMC
01 ·

Answer.

Certification / ATO evidence regime · CMMC.

CMMC is final and live: the 48 CFR DFARS final rule published 2025-09-10 and took effect 2025-11-10, so the requirement is real today and being phased into solicitations on a schedule. Phase 1 began with self-assessment levels; higher-assurance Level 2 certification in contracts ramps through later phases (into 2026). Planisphere does not perform a CMMC assessment — that is a self-assessment or a C3PAO's role — but it can supply reproducible model-behaviour evidence for AI components touching the relevant 800-171 controls.

02 ·

The mark behind the answer.

CMMC is a certification, ATO, or clearance evidence regime: owners assemble machine-readable security evidence, route it…

Cybersecurity Maturity Model · L1 · L2 · L3.

→ Full reference for CMMC

Try CMMC with a free test key.

Start with the free sandbox. Planisphere measures model behaviour and emits a reproducible, sha-pinned record — it does not certify, file, or give legal advice.

API ·

When CMMC asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

See how a record is checked