A community resource for the acquisition workforce not a .gov website
part52.dev Federal Acquisition Clause Monitor
This PGI section supplements: DFARS 204.7501 · FAR 4.7501
The corresponding FAR Part 4 and DFARS Part 204 have been overhauled under the RFO. PGI replacement text is provided in the RFO deviation attachment. View FAR Part 4

Current Content

(a) The contracting officer shall include in the solicitation the required CMMC level, if provided by the requiring activity. Contracting officers shall not award a contract, task order, or delivery order to an offeror that does not have a current (i.e., not more than 3 years old) CMMC certificate at the level required by the solicitation.

(b) Contractors are required to achieve, at time of award, a CMMC certificate at the level specified in the solicitation. Contractors are required to maintain a current (i.e., not more than 3 years old) CMMC certificate at the specified level, if required by the statement of work or requirement document, throughout the life of the contract, task order, or delivery order. Contracting officers shall not exercise an option period or extend the period of performance on a contract, task order, or delivery order, unless the contract has a current (i.e., not more than 3 years old) CMMC certificate at the level required by the contract, task order, or delivery order.

(c) The CMMC assessments shall not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a re-assessment may be necessary such as, but not limited to when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.

Change History

Detected Type Summary
2025-11-10 [PGI] PGI_MODIFIED PGI 204.7501 updated: 3 lines added, 16 lines removed
View diff
--- previous
+++ current
@@ -1,16 +1,3 @@
-As used in this subpart-- "Controlled unclassified information" means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)). "Current" means--
-(1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status--
-(i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with-- (A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and
-(ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with-- (A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and (B) A corresponding affirmation of continuous compliance by an affirming official;
-(2) With regard to Final CMMC Status--
-(i) Not older than 1 year for Final Level 1 (Self), with-- (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;
-(ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with-- (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and
-(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with-- (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and
-(3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170. "Cybersecurity Maturity Model Certification (CMMC) status" means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:
-(1) Final Level 1 (Self).
-(2) Conditional Level 2 (Self).
-(3) Final Level 2 (Self).
-(4) Conditional Level 2 (C3PAO).
-(5) Final Level 2 (C3PAO).
-(6) Conditional Level 3 (DIBCAC).
-(7) Final Level 3 (DIBCAC). "Cybersecurity Maturity Model Certification unique identifier (CMMC UID)" means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in theSupplier Performance Risk System (SPRS) for each contractor information system. "Federal contract information (FCI)" means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.+(a) The contracting officer shall include in the solicitation the required CMMC level, if provided by the requiring activity. Contracting officers shall not award a contract, task order, or delivery order to an offeror that does not have a current (i.e., not more than 3 years old) CMMC certificate at the level required by the solicitation.
+(b) Contractors are required to achieve, at time of award, a CMMC certificate at the level specified in the solicitation. Contractors are required to maintain a current (i.e., not more than 3 years old) CMMC certificate at the specified level, if required by the statement of work or requirement document, throughout the life of the contract, task order, or delivery order. Contracting officers shall not exercise an option period or extend the period of performance on a contract, task order, or delivery order, unless the contract has a current (i.e., not more than 3 years old) CMMC certificate at the level required by the contract, task order, or delivery order.
+(c) The CMMC assessments shall not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a re-assessment may be necessary such as, but not limited to when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.
Sources: Search on acquisition.gov · View on acq.osd.mil