Compliance

Compliance

Compliance

Boeing's Latest CMMC Memo

09/2025

5  

min read

Boeing has issued a new memo outlining expectations for the Department of War’s Cybersecurity Maturity Model Certification (CMMC) rollout. Beginning November 10, 2025, all new contracts — apart from commercial off-the-shelf (COTS) items — will require CMMC.

Because NIST SP 800-171 requirements flow down through the supply chain, this shift directly impacts a large number of companies with active Boeing contracts.

For most suppliers, this will mean meeting CMMC Level 2. The Department of War projects that nearly 94% of Level 2 companies will require a third-party CMMC audit. Boeing stresses that suppliers at this level must be prepared for assessment — a process that requires full compliance with CMMC practices and can be both complex and time-intensive.

CMMC Level 2 Certification Requirements

Suppliers required to obtain CMMC Level 2 certification must undergo an assessment performed by a certified Third-Party Assessment Organization (C3PAO). Boeing strongly encourages suppliers to begin preparations immediately, as certification efforts can take months and demand for C3PAOs is expected to rise significantly.

By prioritizing early action, suppliers will:

01

Demonstrate reliability to both Boeing and the Department of War.

02

Strengthen trust and credibility within the defense supply chain.

03

Safeguard eligibility for future contracts.

04

Reduce the risk of costly delays or lost opportunities during the roll out.

If you're concerned about your company's cybersecurity posture, contact Atomus to see how we can streamline compliance today.

Logo image

Become Compliant with NIST 800-171, DFARS 7012, and CMMC Requirements

Talk to an Expert