The Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 was published establishing requirements for Controlled Unclassified Information (CUI), and paragraph (b)(2)(ii) required contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.” This led to the Cybersecurity Maturity Model (CMMC) Ecosystem. By the Spring of 2025, any DoD contractor doing business with the federal government must have a CMMC Assessment to achieve a Supplier Performance Risk System (SPRS) score of 80 or better to get a contract. This presentation will discuss: 1. What is required for a CMMC Assessment 2. What is the timeline for a third-party assessment after the self-assessment is completed 3. What happens if the minimum SPRS Score of 80 is not achieved?