Home / Glossary / 32 CFR Part 170
32 CFR Part 170
Also known as: CMMC 2.0 Final Rule · Part 170
The federal regulation that established the CMMC 2.0 program. Took effect December 16, 2024.
32 CFR Part 170 is the codified federal regulation that established the Cybersecurity Maturity Model Certification (CMMC) 2.0 program. It was published as a final rule in October 2024 and took effect December 16, 2024.
Part 170 governs the program-side mechanics of CMMC: the three-level structure, the role of the Cyber AB and C3PAOs, the assessment process, the affirmation requirements, and the conditions under which a contractor can hold conditional or final certification status.
The acquisition-side complement — the contract clause that actually requires CMMC certification on a given contract — is DFARS 252.204-7021, which is being phased in beginning in 2025.
Stop Googling. Start working.
CMMCDocs has all 110 NIST SP 800-171 Rev 2 requirements built in — with the language, the templates, and the evidence vault you need. Spin up a free demo workspace and click around the way an assessor would.
Get my demo account
CMMCDocs.com