CMMC Is Creating IT Jobs: What It Means for Your Career
Thousands of Florida defense suppliers have to prove their cybersecurity to keep winning contracts, and Phase 2 of that requirement starts on 10 November 2026. They need people who can do the work.
Most CMMC pages are written for the business owner who has to comply. This one is written for the person who wants the job that compliance creates.
Why this is a hiring driver
| Phase | When | What applicable solicitations require |
|---|---|---|
| Phase 1 | from 10 November 2025 | Level 1 or Level 2 self-assessment, where the requirement applies |
| Phase 2 | from 10 November 2026 | Level 2 certification assessment, where the requirement applies |
| Phase 3 | the following year | Level 3 certification requirements begin to appear |
| Phase 4 | from 10 November 2028 | all applicable solicitations and contracts carry a CMMC requirement |
The dfars acquisition rule (48 cfr, dfars case 2019-d041) took effect 10 November 2025, and the requirement reaches contractors and subcontractors that process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Every one of those companies needs somebody who can implement controls, run security operations, handle incidents and keep the evidence an assessor will ask for.
Which skills are actually in demand?
From what employers ask us for: security operations and monitoring, incident response, identity and access management, documentation and policy work, and basic system hardening. That maps onto CompTIA Security+ first, then CySA+ for the analyst side, with CISSP or CISM for anyone heading towards management.
See our cyber security courses.
Is this a Florida opportunity?
Yes. South Florida has a substantial defense supplier base, and the smaller firms in it are the ones least likely to have in-house security staff. That is where entry and mid-level roles come from.
Related pages
Government and military training
- DoD 8140 certifications explained
- NICE Framework cyber careers
- Military credentialing
- Government and military discount
Frequently asked questions
What is CMMC in simple terms?
A Department of Defense programme that requires contractors handling federal contract information or controlled unclassified information to prove they meet cybersecurity requirements.
When does the next CMMC deadline hit?
Phase 2 begins 10 November 2026, when applicable solicitations require a Level 2 certification assessment instead of a self-assessment.
Do I need a CMMC certification to get hired?
Usually not. Employers hire for the underlying skills – security operations, incident response, access management – which is what Security+ and CySA+ cover.
Do you teach the CCP or CCA?
No. Those assessor credentials come from CMMC Licensed Training Providers.
Where should I start if I am new to security?
CompTIA Security+, after A+ and Network+ if you have no IT background yet.
Talk to us about your requirement
Government agencies and military personnel get a 10% discount on our training. Private group delivery is available on your dates, on site, at our Miami campus or live online.
Official sources: CMMC Program rule ยท DFARS rule
Written by The Code Academy. Last updated October 2026. This page summarises public federal guidance and is not legal or contractual advice — confirm requirements against the official sources above or with your security manager.