Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
What is CMMC Level 2?
CMMC Level 2 is the intermediate cybersecurity level requiring defense contractors to implement 110 security controls from NIST SP 800-171 Revision 2 to protect Controlled Unclassified Information (CUI). Unlike Level 1, Level 2 offers contractors two assessment paths: self-assessment or third-party certification by a C3PAO, depending on contract requirements.
CMMC Level 2 establishes comprehensive cybersecurity protections for defense contractors handling sensitive government information beyond basic Federal Contract Information.
According to 32 CFR Part 170, “the 110 Level 2 requirements from NIST SP 800-171 R2” form the basis of CMMC Level 2 security requirements eCFR. The program implements a “minimum passing score of 80% (88/110)” for conditional certification and allows a “maximum 180-day POA&M close-out date” U.S. Department of Defense.
This guide explains what CMMC Level 2 is, who needs it, the 110 required security controls, assessment options, conditional vs final certification, POA&M requirements, and the three-year certification cycle.
Understanding CMMC Level 2 Basics
What Information Does Level 2 Protect?
CMMC Level 2 focuses exclusively on protecting Controlled Unclassified Information (CUI)—significantly more sensitive than the Federal Contract Information covered by Level 1.
Controlled Unclassified Information is defined in 32 CFR 2002.4(h) as “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.”
Controlled Unclassified Information (CUI) is sensitive government information that requires protection but is not classified as national security information.
Examples of CUI include:
- Technical data and specifications
- Export-controlled information (EAR/ITAR)
- Manufacturing processes and designs
- Source code and software documentation
- Research and development data
- Operational and tactical information
- Critical infrastructure details
- Personally Identifiable Information (PII) related to government missions
Critical Distinction: If your contract involves CUI, you need Level 2 or Level 3—not Level 1. Level 2 is expected to apply to roughly 80,000 contractors within the defense supply chain Isidefense.
Who Needs CMMC Level 2?
NIST SP 800-171 “is the federal safeguarding standard for controlled unclassified information (CUI) required by 32 CFR Part 2002, which the Department implemented contractually through inclusion of DFARS clause 252.204-7012 in applicable contracts” U.S. Department of Defense.
Level 2 applies to:
- Prime contractors processing, storing, or transmitting CUI
- Subcontractors at all tiers handling CUI in contract performance
- Research institutions conducting DoD-funded research with CUI
- Manufacturers producing defense systems with technical data
- Software developers accessing source code or specifications
DoD estimates Level 2 will apply to approximately 37% of the Defense Industrial Base, representing roughly 80,000 companies that handle CUI Isidefense.
The 110 CMMC Level 2 Security Requirements
CMMC Level 2 “does not introduce any new controls” beyond existing DFARS requirements, and contractors must implement controls “that are not already part of the existing DFARS requirements” McDermott Will & Emery. The CMMC Level 2 controls are “identical to the NIST SP 800-171 Rev 2 controls, merely adding a prefix of ‘DD.L2’ to the number of the control” McDermott Will & Emery.
NIST SP 800-171 (Special Publication 800-171) is the National Institute of Standards and Technology’s guideline titled “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”
The 110 requirements are organized into 14 security domains (also called control families):
Domain 1: Access Control (22 requirements)
Controls who can access systems and CUI, ensuring only authorized users have appropriate permissions.
Access control manages user authentication, authorization levels, session management, and restricts access based on need-to-know principles.
Key requirements include:
- Account management and periodic review
- Least privilege access enforcement
- Session locks after period of inactivity
- Remote access control and monitoring
- Unsuccessful logon attempt limitations
- Privileged account management
Domain 2: Awareness and Training (3 requirements)
Ensures personnel understand security responsibilities and can identify threats.
Requirements include:
- Security awareness training for all users
- Role-based security training for privileged functions
- Insider threat awareness training
Domain 3: Audit and Accountability (9 requirements)
Tracks system activity to detect unauthorized access and support incident investigations.
Audit and accountability involves logging system events, protecting log data, and reviewing logs to identify suspicious activities.
Key requirements include:
- Audit event logging for security-relevant events
- Audit log content requirements (who, what, when, where, outcomes)
- Protection of audit information from unauthorized access
- Audit log retention and review
- Alerts for audit process failures
- Correlation of audit records across systems
Domain 4: Configuration Management (9 requirements)
Maintains secure baseline configurations and controls system changes.
Requirements include:
- Baseline configuration establishment and maintenance
- Configuration change control procedures
- Security impact analysis before changes
- Least functionality principle implementation
- User-installed software restrictions
- Software usage restrictions
Domain 5: Identification and Authentication (11 requirements)
Verifies user and device identities before granting access.
Identification and authentication ensures that entities are who they claim to be through credentials, multi-factor authentication, and cryptographic verification.
Key requirements include:
- Unique identification for users and devices
- Multi-factor authentication for network and remote access
- Replay-resistant authentication mechanisms
- Password complexity and management
- Identifier management and reuse prevention
- Cryptographically-protected password storage
Domain 6: Incident Response (2 requirements)
Establishes capability to detect, report, and respond to security incidents.
Requirements include:
- Incident handling capability establishment
- Incident response tracking and documentation
- Incident response testing
Domain 7: Maintenance (3 requirements)
Manages system maintenance while maintaining security.
Requirements include:
- Controlled maintenance tool usage
- Media sanitization for maintenance equipment
- Nonlocal maintenance authorization and monitoring
Domain 8: Media Protection (8 requirements)
Protects CUI on physical and digital media throughout its lifecycle.
Media protection involves securing data on storage devices, during transmission, and ensuring proper sanitization before disposal or reuse.
Key requirements include:
- Media access restrictions
- Media marking with CUI designations
- Physical media sanitization before disposal
- Media transport restrictions
- Cryptographic protection for CUI at rest
- Media accountability tracking
Domain 9: Personnel Security (2 requirements)
Screens personnel before granting access to CUI.
Requirements include:
- Personnel screening before CUI access
- Formal sanctions for security policy violations
Domain 10: Physical Protection (6 requirements)
Secures physical access to facilities, systems, and equipment.
Requirements include:
- Physical access authorization and control
- Visitor access and escort procedures
- Physical access device management
- Maintenance records for physical access systems
- Asset removal authorization
- Alternate work site protections
Domain 11: Risk Assessment (3 requirements)
Identifies and manages security risks to organizational operations.
Risk assessment involves identifying threats, vulnerabilities, and potential impacts to determine appropriate security controls.
Requirements include:
- Periodic risk assessments
- Vulnerability scanning
- Remediation of identified vulnerabilities
Domain 12: Security Assessment (3 requirements)
Monitors security control effectiveness.
Requirements include:
- Periodic assessment of security controls
- Security assessment result documentation
- Remediation planning for control deficiencies
Domain 13: System and Communications Protection (16 requirements)
Secures system boundaries and communications.
Key requirements include:
- Boundary protection with monitoring
- Cryptographic protection for data in transit
- Network segmentation for CUI
- Denial-of-service protection
- Session authenticity verification
- Mobile code restrictions
- Voice over IP protection
- Communications at system boundaries
- Cryptographic key establishment
Domain 14: System and Information Integrity (7 requirements)
Identifies and corrects security flaws.
Requirements include:
- Flaw identification and remediation
- Malicious code protection at entry/exit points
- Security alert monitoring and response
- Software and firmware integrity verification
- Spam protection
- Information input validation
- Error handling
Assessment Objectives: Each of the 110 Level 2 requirements has multiple assessment objectives, totaling 320+ assessment objectives that must be evaluated Isidefense.
Assessment objectives are specific, measurable criteria used to determine if a security requirement has been properly implemented and is operating effectively.
CMMC Level 2 Assessment Options
Contractors must “either (i) conduct a self-assessment that demonstrates compliance with the 110 controls derived from NIST SP 800-171 Revision 2 (a Level 2 self-assessment) or (ii) engage a CMMC Third-Party Assessment Organization (C3PAO) to conduct the NIST SP 800-171 R2 assessment (a Level 2 certification assessment)” WilmerHale.
Option 1: Level 2 Self-Assessment
The OSA must “conduct a Level 2 self-assessment in accordance with NIST SP 800-171A Jun2018 and the CMMC Level 2 scoping requirements” eCFR and submit results to SPRS.
OSA (Organization Seeking Assessment) is the term used when a contractor performs a self-assessment to achieve Level 2 (Self) status.
Self-Assessment Requirements:
- Evaluate all 110 requirements against NIST SP 800-171A objectives
- Score each requirement as MET, NOT MET, or NOT APPLICABLE
- Calculate overall score (ranging from -203 to 110)
- Document findings and evidence
- Submit results to SPRS
- Submit executive affirmation of compliance
“To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS” eCFR.
When Self-Assessment is Allowed:
- Contract specifies Level 2 (Self) requirement
- Early Phase 1 implementation period
- Lower-sensitivity CUI contracts
- DoD discretion during phased rollout
Option 2: C3PAO Certification Assessment
“An authorized or accredited C3PAO must perform a Level 2 certification assessment in accordance with NIST SP 800-171A Jun2018 and the CMMC Level 2 scoping requirements” eCFR.
C3PAO (CMMC Third-Party Assessment Organization) is an independent organization authorized by the Cyber Accreditation Body to conduct official CMMC Level 2 certification assessments.
C3PAO Assessment Process:
- Independent third-party evaluation
- On-site and remote assessment activities
- Evidence collection and validation
- Interviews with personnel
- Technical testing of controls
- Assessment Findings Report delivery
- Results submitted to eMASS (then transmitted to SPRS)
- Certificate of CMMC Status issued
“To maintain compliance with the requirements for a CMMC Status of Level 2 (C3PAO), the Level 2 certification assessment must be completed within three years of the CMMC Status Date” eCFR.
When C3PAO Assessment is Required:
- Contract specifies Level 2 (C3PAO) requirement
- Phase 2+ implementation period (after November 2026)
- Higher-value or sensitive CUI contracts
- Prime contractors in critical programs
- When prime contract requires Level 3
Conditional vs Final CMMC Level 2 Status
CMMC Level 2 uniquely allows Conditional Status—contractors can achieve certification while still having open security gaps, provided they meet specific criteria.
Conditional Level 2 Status
“The OSA has achieved the CMMC Status of Conditional Level 2 (Self) if the Level 2 self-assessment results in a POA&M and the POA&M meets all the CMMC Level 2 POA&M requirements listed in § 170.21(a)(2)” Legal Information Institute.
Requirements for Conditional Status:
- Minimum Score: Achieve at least 88 out of 110 (80% compliance)
- POA&M Restrictions: Only specific requirements can be NOT MET
- 180-Day Deadline: Close all POA&M items within 180 days of Conditional Status Date
- Contract Eligibility: Can be awarded contracts while in Conditional Status
POA&M (Plan of Action and Milestones) is a documented schedule for correcting security deficiencies, including specific tasks, responsible parties, resources required, and completion dates.
The minimum passing score is “80% (88/110)” with a “maximum 180-day POA&M close-out date” U.S. Department of Defense.
POA&M Restrictions:
To earn a conditional certification, contractors must ensure that “all requirements, except those specifically called out under 32 CFR 170.21, are met” and their “total score, as calculated using the scoring methodology defined in 32 CFR 170.24, is at least an 88” CUI Institute.
Critical requirements that CANNOT be placed on a POA&M include:
- Access control for CUI (AC.L2-3.1.1, AC.L2-3.1.2, AC.L2-3.1.20, AC.L2-3.1.22)
- Multi-factor authentication (IA.L2-3.5.3)
- Incident response capability (IR.L2-3.6.1)
- Media protection and sanitization (MP.L2-3.8.3, MP.L2-3.8.9)
- Boundary protection (SC.L2-3.13.1, SC.L2-3.13.5)
- Malicious code protection (SI.L2-3.14.1, SI.L2-3.14.2, SI.L2-3.14.4)
Encryption-related requirements can be on POA&M only if encryption is implemented but not yet FIPS-validated.
POA&M Closeout Timeline:
“The POA&M closeout self-assessment must be performed within 180-days of the Conditional CMMC Status Date” eCFR.
“If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional Level 2 (Self) CMMC Status for the information system will expire” eCFR, making the contractor ineligible for new awards until a new CMMC Status is achieved.
Final Level 2 Status
“The OSA has achieved the CMMC Status of Final Level 2 (Self) if the Level 2 self-assessment results in a passing score as defined in § 170.24” eCFR—meaning all 110 requirements scored MET or NOT APPLICABLE (score of 110).
Requirements for Final Status:
- All 110 requirements MET (or NOT APPLICABLE)
- Maximum score of 110 achieved
- No open POA&M items
- All evidence documented
- Results submitted to SPRS
- Executive affirmation submitted
Advantages of Final Status:
- Three-year validity starts immediately (not from Conditional Status Date)
- No POA&M closeout assessment needed
- Stronger competitive positioning
- Lower risk of contract issues
- No 180-day deadline pressure
CMMC Level 2 Scoring Methodology
Each required control uses “the control objectives in NIST SP 800-171A and results in a finding of MET, NOT MET, or NOT APPLICABLE. The maximum score is 110, representing a finding of MET for each of the 110 NIST SP 800-171 controls” McDermott Will & Emery.
How Scoring Works
“Each required control has a weighted number of points: five, three, or one” McDermott Will & Emery based on criticality:
- 5-point controls: Most critical requirements (e.g., access control, encryption, incident response)
- 3-point controls: Important security controls
- 1-point controls: Basic safeguarding requirements
“An entity’s score can be as low as -203 if none of the required controls are implemented. Controls with a finding of NOT MET reduce the score, even if there is an entry in a POA&M addressing the control” McDermott Will & Emery.
Scoring Examples:
- All 110 MET = 110 points (Final Status)
- 88 points with eligible POA&Ms = Conditional Status ✓
- 88 points with ineligible POA&Ms = No certification ✗
- 87 points = No certification (below 80% threshold) ✗
NOT APPLICABLE Findings: Have no effect on score—neither add nor subtract points.
Annual Affirmation Requirements
Both Level 2 (Self) and Level 2 (C3PAO) require annual affirmations between triennial assessments.
The program requires “annual affirmation of continued compliance in SPRS” U.S. Department of Defense for all contractors maintaining Level 2 status.
Annual Affirmation Process:
- Conducted every year between assessments
- Affirming Official certifies continuing compliance
- Submitted in SPRS
- Confirms no material changes affecting compliance
- Verifies security controls remain effective
Affirming Official is a senior-level executive with authority to attest to the organization’s continuing compliance with CMMC requirements, who assumes legal responsibility for the accuracy of the affirmation.
Consequences of Missing Annual Affirmation: CMMC Status becomes invalid, making the contractor ineligible for new contract awards until affirmation is submitted.
Three-Year Certification Cycle
Unlike Level 1’s annual cycle, Level 2 operates on a three-year recertification schedule.
Timeline:
- Year 1: Complete initial assessment (self or C3PAO), achieve Conditional or Final Status, submit affirmation
- Year 2: Submit annual affirmation (no full assessment)
- Year 3: Submit annual affirmation (no full assessment)
- Year 4 (within 3 years of CMMC Status Date): Complete full reassessment
Contractors must “conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self)” eCFR.
Important: The three-year period starts from the Conditional Status Date (if you achieved Conditional first) or the Final Status Date—NOT from when you close your POA&M.
Required Documentation for Level 2
CMMC Level 2 requires significantly more documentation than Level 1.
Required Documents:
- System Security Plan (SSP) – Comprehensive documentation of security implementation
- POA&M (if applicable) – Remediation plan for unmet requirements
- Asset Inventory – Complete list of hardware, software, and systems
- Network Diagrams – Visual representation of network architecture
- Data Flow Diagrams – How CUI moves through systems
- Policies and Procedures – Written security policies for each control family
- Evidence Artifacts – Screenshots, logs, configurations proving implementation
- Assessment Results – Self-assessment or C3PAO findings
- Customer Responsibility Matrix – For cloud service providers
System Security Plan (SSP) is a formal document describing the security controls implemented or planned for an information system, including policies, procedures, and technical configurations.
Common CMMC Level 2 Implementation Challenges
Achieving Level 2 compliance presents significantly greater challenges than Level 1.
Challenge 1: Scope Complexity
“For a CMMC Level 2 self-assessment, the assets that process, store, or transmit CUI and assets that provide security protections for these assets are considered in scope” Secureframe.
Level 2 scoping includes five asset categories:
- CUI Assets
- Security Protection Assets
- Contractor Risk Managed Assets
- Specialized Assets
- Out-of-Scope Assets
This complexity requires careful boundary definition and documentation.
Challenge 2: 110 Requirements vs 15 Requirements
Implementing 110 controls across 14 domains is exponentially more complex than Level 1’s 15 requirements. Organizations typically need 9-18 months for full implementation.
Challenge 3: Technical Control Implementation
Many Level 2 controls require technical implementations:
- FIPS 140-2 validated encryption
- Multi-factor authentication for all access
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Network segmentation and monitoring
- Privileged Access Management (PAM)
Challenge 4: POA&M Strategy
Contractors can “achieve Conditional status with a score of at least 80% of the maximum (88 out of 110), but only specified items may be included in a POA&M” RainTech.
Deciding which 22 requirements to place on POA&M (if pursuing Conditional Status) requires strategic planning to ensure:
- No ineligible requirements are on POA&M
- Realistic 180-day remediation timeline
- Resource availability for closeout
- Risk acceptance during POA&M period
Challenge 5: C3PAO Assessment Preparation
Third-party assessments are rigorous:
- 1-2 week on-site engagement
- Detailed evidence requirements
- Technical testing and validation
- Personnel interviews
- Cost: $30,000-$150,000+ depending on scope
System Security Plan (SSP) Requirements
The SSP is the cornerstone of Level 2 compliance documentation.
SSP Must Include:
- Comprehensive description of information system
- System boundaries and architecture
- CUI identification and handling
- All 110 controls with implementation descriptions
- Inherited controls from service providers
- Assessment methodology and results
- Responsible parties for each control
- Integration with organizational policies
- External service provider documentation
SSP Maintenance: Must be updated whenever significant changes occur to the system or when reassessments are conducted.
When CMMC Level 2 is Required
The CMMC DFARS Clause effective date is November 10, 2025, implementing phased requirements U.S. Department of Defense.
Phase 1 (November 2025 – November 2026):
- Level 2 (Self) required for most CUI contracts
- DoD may require Level 2 (C3PAO) for select contracts
- Implementation at DoD discretion
Phase 2 (November 2026 – November 2027):
- Level 2 (C3PAO) becomes standard for most CUI contracts
- Self-assessments still allowed for lower-sensitivity contracts
- Increased C3PAO requirement percentage
Phase 3 (November 2027 – November 2028):
- Level 2 (C3PAO) required for option period exercises
- Near-universal C3PAO requirement for CUI contracts
Phase 4 (November 2028+):
- Full implementation across all applicable contracts
- Level 2 (C3PAO) standard for CUI
Cloud Service Provider Requirements
An OSA may use cloud environments for CUI if “the CSP product or service offering is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace” or meets equivalent security requirements eCFR.
FedRAMP (Federal Risk and Authorization Management Program) is the government program providing a standardized approach to security assessment and authorization for cloud services.
CSP Requirements:
- FedRAMP Moderate or High authorization required
- On-premises infrastructure connecting to CSP is in scope
- Customer Responsibility Matrix required
- Shared responsibility model clearly defined
Common FedRAMP Moderate CSPs: Microsoft Azure Government, AWS GovCloud, Google Cloud, Oracle Cloud Government.
Key Takeaways: What is CMMC Level 2?
CMMC Level 2 establishes comprehensive cybersecurity protections for contractors handling Controlled Unclassified Information:
✓ 110 security controls from NIST SP 800-171 Rev 2
✓ 14 control families covering all aspects of information security
✓ Two assessment options: Self-assessment or C3PAO certification
✓ Conditional Status available with 88/110 minimum score (80%)
✓ POA&M allowed but restricted to eligible requirements only
✓ 180-day POA&M closeout requirement from Conditional Status Date
✓ Three-year certification cycle with annual affirmations
✓ Applies to ~80,000 contractors handling CUI (~37% of DIB)
✓ Required starting November 10, 2025 for applicable contracts
✓ System Security Plan (SSP) and comprehensive documentation required
✓ FedRAMP Moderate CSPs required for cloud-based CUI processing
CMMC Level 2 represents a significant increase in cybersecurity rigor compared to Level 1, requiring 9-18 months of focused implementation effort and ongoing commitment to maintaining compliance through triennial assessments and annual affirmations.
Related Articles:
- 32 CFR 170.16 – CMMC Level 2 Self-Assessment Requirements
- 32 CFR 170.17 – CMMC Level 2 Certification Assessment Requirements
- NIST SP 800-171 Rev 2 – Protecting CUI
- CMMC Level 2 Assessment Guide (DoD)
Official Sources: This article is based on 32 CFR 170.16 “CMMC Level 2 self-assessment and affirmation requirements,” 32 CFR 170.17 “CMMC Level 2 certification assessment and affirmation requirements,” 32 CFR 170.21 “Plans of Action and Milestones,” NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” and the DoD CMMC Level 2 Assessment Guide.