Marquee Background
Marquee Background

Offit Kurman Blogs

Business

Non-Compliance with CMMC Could Put Your DoD Contracts at Risk

August 27, 2025

By Edward Tolchin

Non-Compliance with CMMC Could Put Your DoD Contracts at Risk

This past month, the Department of Defense sent the final rule for the new Cybersecurity Maturity Model Certification (CMMC) program under the Federal Acquisition Regulation to the Office of Information and Regulatory Affairs for review. This action precedes the inclusion of the new rule in Department of Defense contracts beginning this autumn. So, it is time to get into compliance for all who have been delaying the inevitable.

Below is a quick review of these requirements.

Background

CMMC is designed to bolster the cybersecurity posture of the DoD’s supply chain by validating that DoD contractors and subcontractors possess the necessary cybersecurity practices and processes to safeguard Federal Contract Information (FCI) and various kinds of Controlled Unclassified Information (CUI). CMMC introduces a tiered, certification-based approach, ranging from Level 1 (basic cybersecurity practices for FCI) to Level 2 (advanced practices for most CUI), and Level 3 (expert practices for sensitive CUI).

Why is This Important?

Contractors and subcontractors must attain the appropriate CMMC level aligned with the security requirements of their contracts to bid and work on DoD projects. In addition to the cybersecurity and reputational risks of non-compliance, if contractors and subcontractors fib or cut corners, they could face False Claims Act (FCA) liability, including draconian damage and penalty assessments. One disgruntled employee who decides to bring an FCA complaint can cost a company significant pain.

Contracts Covered by CMMC

The CMMC requirement applies to DoD acquisitions that involve the handling of FCI and CUI.

  • Major Contract Programs: Contracts for the procurement of defense systems, weapons, military equipment, and related services that require access to CUI or FCI will be directly impacted. This includes a broad spectrum of procurement categories across the DoD, from large-scale hardware contracts to software development and services.
  • Subcontractors and Supply Chain: Importantly, the rule also extends to subcontractors at all tiers. This flow-down creates a ripple effect throughout the defense supply chain.

Contracts Not Subject to CMMC

While the rule is broad, it does not universally apply to all federal contracts.

  • FAR Part 12 Commercial Item Contracts: Some commercial item contracts purchased under FAR Part 12 may be excluded unless the scope involves sensitive information or national security concerns.
  • Contracts with No Access to CUI or FCI: Contracts that do not involve access to or handling of CUI/FCI will not be subject to CMMC requirements.
  • Other Exceptions: The FAR Council has provisions for exemptions for technical or administrative reasons, but these are limited and require justification.

What is FCI

If you are a contractor or subcontractor that handles controlled information such as CUI, you likely have some sophistication regarding cybersecurity. But those with FCI may not be aware that they have protectible information, and most medium and larger-sized DoD contracts will have FCI.

  • FCI refers to information that is not intended for public release but is provided by the federal government to a contractor or subcontractor for the purpose of fulfilling a federal contract. It includes data that is critical to the performance of government contracts.
  • Examples include technical data (e.g., details about a supplier’s hardware specifications), contract schedules and milestones (e.g., timelines for delivering military equipment), and financial or administrative information shared with contractors.
  • Typical Contracts:
    • Smaller contracts
    • Basic supply chain activities

FCI Requires Level 1: Basic Cyber Hygiene

Key Requirements:

  • Implementation of basic controls, including access only by authorized users, maintaining identification and authentication, and physical protection of information systems.
  • Practices include routine login credentials, portable device protections, and basic awareness training.
  • Annual self-assessment and annual affirmation of compliance with CMMC requirements.

What is CUI

  • It’s not classified information, but it is information that requires safeguarding pursuant to various laws, regulations, and government policy.
  • Examples include information about physical security, system vulnerability, or operational issues.

CUI Requires Level 2 (Intermediate) or Level 3 (Expert) Processes

  • Level 2: Intermediate Cyber Hygiene
    • Practices: 110 practices, aligned with NIST SP 800-171 security requirements.
    • Focus: Establishing more disciplined cybersecurity processes and practices suitable for organizations handling CUI.
    • Third-party assessments are required for certification at this level.
  • Level 3: Expert Cyber Hygiene
    • Practices: Over 130 security controls, closely aligned with NIST SP 800-171, plus some additional practices.
    • Focus: A mature, enterprise-wide cybersecurity program.
    • This will apply only to a limited number of contractors with larger, more sensitive defense contracts that require higher levels of CUI protection.
    • Third-party assessment is required.
Categories: Business

Related People

  • Posts
  • About
  • Subscribe

Firm Highlights

  • Events
    AIA Tri-State Conference
    Princeton will serve as the backdrop for three days of connection, learning, and design leadership. From keynotes to tours to the Tri-State Design Awards, this year’s conference is designed to go far beyond education sessions. Kick off the week with pre-conference intensives and individual state component Design Award celebrations, followed by three days of education, inspiration, networking, and design excellence at the 2026 AIA Tri-State Conference—featuring pre-conference intensives, three keynote speakers, 25 education sessions, curated tours, an expo, spec academies, and the AIA Tri-State Design Awards—bringing together architects and design professionals from New Jersey, New York, and Pennsylvania to connect, learn, and celebrate the best of the profession. G2. Designing Secure Practices: Cybersecurity, Data Privacy, Contractual Provisions, and Insurance Risks for Architects (4:00 PM - 5:30 PM) Architects and design professionals increasingly rely on cloud platforms, BIM software, and digital tools to manage sensitive data, creating cybersecurity and privacy risks. A single incident can trigger liability claims, regulatory obligations, reputational harm, and insurance challenges. Yet many firms underestimate how contracts, insurance, and internal practices intersect during a breach. This program offers legal and insurance perspectives on cyber risk in architecture, examining liability exposure, risky contract provisions, and mitigation strategies. A cyber insurance expert will explain policy responses, coverage gaps, coordination with professional liability, and best practices for aligning insurance with contractual risk and protecting firms from evolving cyber threats. Learning Objectives: Identify key cybersecurity and data privacy risks faced by architecture firms and explain how these risks can impact professional liability and project outcomes. Analyze common contractual provisions to determine which clauses may increase exposure to cyber incidents and propose strategies to mitigate these risks. Evaluate the scope and limitations of cyber insurance policies, including coordination with professional liability coverage, to determine how a policy would respond in a breach scenario. Develop actionable risk management strategies by integrating legal, contractual, and insurance considerations to protect sensitive client and project data.
  • Blog Posts
    Law, Love, and Life's Battles: Facing Breast Cancer
    What happens to a marriage and a family when a breast cancer diagnosis changes everything? In this episode of Love Ends, Law Begins, hosts Fara Rodriguez and Stephanie Lehman have a deeply personal conversation about breast cancer, marriage, family, and the challenges that can come with a serious illness. This episode is especially meaningful for Fara, who shares her own recent breast cancer diagnosis and journey. She opens up about discovering a lump, receiving her diagnosis, undergoing a double mastectomy and subsequent treatments, and navigating the emotional impact of cancer while continuing to work and care for her family. Fara and Stephanie discuss how a cancer diagnosis can affect a marriage in unexpected ways—from changing family roles and creating new caregiving responsibilities to putting pressure on finances, health insurance, and household responsibilities. They explore how illness can either bring couples closer together or create additional challenges, particularly when one spouse becomes the primary caregiver or when the family is dealing with fear and uncertainty. The conversation also addresses the unique challenges of parenting during an illness, including how to talk to children about a cancer diagnosis and how divorced parents may need to adjust parenting schedules and responsibilities when one parent becomes sick. From navigating medical expenses and insurance coverage to balancing work, parenting, caregiving, and intimacy, Fara and Stephanie offer a candid look at the ways illness can reshape relationships and family dynamics. In recognition of Breast Cancer Awareness Month, this episode provides an honest and personal conversation about facing cancer while navigating marriage, family, and the many practical challenges that come with a serious diagnosis. In this episode, you'll hear about: • Fara's personal breast cancer diagnosis and journey • How a cancer diagnosis can affect a marriage • The challenges of becoming a caregiver to your spouse • How illness can bring couples closer together—or create new challenges • Talking to children about a parent's cancer diagnosis • How divorced parents can navigate parenting responsibilities when one parent becomes ill • The financial impact of illness and the loss of household income • Health insurance and medical coverage considerations • How medical expenses can create additional financial strain • The importance of support from family, friends, and caregivers • Balancing work, parenting, treatment, and recovery • How illness can affect intimacy and marital dynamics • The importance of supporting children through a parent's illness • Why communication and cooperation matter during a health crisis • Breast Cancer Awareness Month and the importance of mammograms