whitepaper

The History of CMMC 2.0: How We Got Here

Aerospace & Defense
Compliance & Risk Management

2013 — The Foundation: DFARS 7012

The story of CMMC begins over a decade before most people realize. In 2013, the Department of Defense created DFARS clause 252.204-7012, pulling 59 security controls from NIST SP 800-53. The clause had a critical flaw: no verification mechanism existed. Contractors simply accepted the clause and were trusted to comply, with no audits or proof required.

2015 — The OPM Breach

The Office of Personnel Management experienced one of the largest compromises of federal information systems in history, exposing a major gap: the 2013 requirements didn't adequately cover cloud systems and sensitive unclassified information.

2015–2016 — Rule Revisions

The DoD issued an interim final rule — a rare regulatory action that bypassed normal public comment periods due to national security urgency — adding cloud security requirements and replacing the original 59 controls with the newly published NIST SP 800-171 (110 requirements). Industry pushback led to an extension, and an October 2016 update established the December 31, 2017 deadline that became infamous in the contractor community. Remarkably, even after two major national security incidents, there was still no third-party verification mechanism.

2017–2018 — The Sea Dragon Compromise

Chinese cyber operations compromised unclassified contractor systems, stealing data from major programs including the F-35, F-22, and the Sea Dragon submarine-launched hypersonic anti-ship missile program.

2018 — The Government's Resistance to Verification

Even at this point, DoD and NARA officials publicly stated they did not want third-party assessments unless "absolutely necessary" — reflecting continued resistance to a verification requirement despite two major breaches.

2019 — The Government's Response

Major General Murphy, appointed to lead the Protecting Critical Technology Task Force, delivered a blunt message: contractors who won't protect critical technology should not have DoD contracts — setting the stage for the Congressional mandate and CMMC 2.0 that followed.