Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

What security controls does CMMC Level 2 require?

CMMC Level 2 security controls consist of 110 specific requirements from NIST SP 800-171 Revision 2 organized across 14 control families (also called domains). These controls establish comprehensive cybersecurity protections for defense contractors handling Controlled Unclassified Information (CUI).

CMMC Level 2 security controls define exactly what cybersecurity measures contractors must implement to protect sensitive government information.

According to compliance guidance, “there are a total of 320 assessment objectives (AOs) that you need to meet before you can be CMMC certified” across the 110 controls Agile IT. The controls span “14 control families with a total of 110 controls” where “each control family focuses on a set of standard security requirements” Sprinto.

This guide provides the complete breakdown of all 110 CMMC Level 2 security controls, organized by the 14 control families, with practical implementation guidance for each domain.

Understanding CMMC Level 2 Security Controls

How Controls Are Organized

NIST SP 800-171 “came from a combination of the minimum security requirements in Federal Information Processing Standard (FIPS) 200 and the Moderate protection level in NIST SP 800-53” and “contains administrative and technical requirements within 110 controls organized by 14 control families” Getpeerless.

Control families (also called domains) are logical groupings of related security requirements that address specific aspects of cybersecurity, making them easier to reference, implement, and manage.

Important: “Not all of the requirements can be implemented with technology. Many of the controls require documentation of policy, process, and procedures. Some controls address physical security, personnel security, security awareness, and security training” Getpeerless.

The 14 CMMC Level 2 Control Families

The 110 requirements are distributed across 14 control families covering every aspect of cybersecurity:

  1. Access Control (AC) – 22 requirements
  2. Awareness and Training (AT) – 3 requirements
  3. Audit and Accountability (AU) – 9 requirements
  4. Configuration Management (CM) – 9 requirements
  5. Identification and Authentication (IA) – 11 requirements
  6. Incident Response (IR) – 2 requirements
  7. Maintenance (MA) – 3 requirements
  8. Media Protection (MP) – 8 requirements
  9. Personnel Security (PS) – 2 requirements
  10. Physical Protection (PE) – 6 requirements
  11. Risk Assessment (RA) – 3 requirements
  12. Security Assessment (CA) – 3 requirements
  13. System and Communications Protection (SC) – 16 requirements
  14. System and Information Integrity (SI) – 7 requirements

Control Family 1: Access Control (AC) – 22 Requirements

Access Control is “the largest of the 14 control families” and “governs how users and systems gain access to sensitive information” establishing “the framework for managing who can access what, when, and under what conditions” Isidefense.

Access control manages user permissions based on the principle of least privilege—granting users only the minimum access needed to perform their job functions.

Key Access Control Requirements:

3.1.1 – Limit System Access to Authorized Users Ensure only authorized users, processes, and devices can access information systems.

3.1.2 – Limit System Access to Transaction Types Restrict users to only the types of transactions and functions they’re authorized to execute.

3.1.3 – Control CUI Flow Control the flow of CUI in accordance with approved authorizations to prevent unauthorized disclosure.

3.1.4 – Separation of Duties Enforce assigned authorizations for controlling information flow and separate duties of individuals to reduce insider threat risk.

3.1.5 – Least Privilege Employ the principle of least privilege, including specific security functions and privileged accounts, granting only minimum necessary access.

3.1.6 – Non-Privileged Account Usage Use non-privileged accounts or roles when accessing nonsecurity functions to limit exposure.

3.1.7 – Privileged User Functions Prevent non-privileged users from executing privileged functions—including disabling, circumventing, or altering security safeguards/countermeasures.

3.1.8 – Limit Unsuccessful Logon Attempts Limit unsuccessful logon attempts (typically 3-5 attempts) and enforce lockout periods to prevent brute force attacks.

3.1.9 – Privacy and Security Notices Provide privacy and security notices consistent with applicable CUI rules when displaying system use information.

3.1.10 – Session Lock Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity (typically 15 minutes).

3.1.11 – Session Termination Terminate (automatically) a user session after a defined condition (time-based or security event-based).

3.1.12 – Monitor and Control Remote Access Monitor and control remote access sessions, providing visibility into all remote connections.

3.1.13 – Cryptographic Mechanisms for Remote Access Employ cryptographic mechanisms (e.g., VPN, encrypted protocols) to protect the confidentiality of remote access sessions.

3.1.14 – Route Remote Access via Managed Points Route all remote access via managed network access control points to enable monitoring and control.

3.1.15 – Authorize Remote Access Authorize remote access prior to allowing such connections, maintaining documentation of authorized users.

3.1.16 – Wireless Access Authorization Authorize wireless access prior to allowing connections and monitor for unauthorized wireless connections.

3.1.17 – Protect Wireless Access Using Authentication and Encryption Protect wireless access using authentication (WPA2/WPA3 Enterprise) and encryption (AES).

3.1.18 – Control Connection of Mobile Devices Control connection of mobile devices to organizational systems through policies, procedures, and technical controls.

3.1.19 – Encrypt CUI on Mobile Devices Encrypt CUI on mobile devices and mobile computing platforms (laptops, tablets, smartphones).

3.1.20 – External System Connections Verify and control/limit connections to and use of external information systems not under organizational control.

3.1.21 – Limit Use of Portable Storage Limit use of organizational portable storage devices on external systems to prevent data leakage.

3.1.22 – Publicly Accessible Content Control Control information posted or processed on publicly accessible information systems (public websites, social media).


Control Family 2: Awareness and Training (AT) – 3 Requirements

Security awareness and training ensure personnel understand their cybersecurity responsibilities and can identify threats.

Key Awareness and Training Requirements:

3.2.1 – Security Awareness Training Ensure managers and users are trained to carry out their assigned information security-related duties and responsibilities.

3.2.2 – Role-Based Security Training Provide role-based security training to personnel with assigned security roles and responsibilities before authorizing access and when required by system changes.

3.2.3 – Insider Threat Awareness Provide security awareness training on recognizing and reporting potential indicators of insider threat.

Implementation Notes:

  • Annual training minimum for all users
  • Role-specific training for privileged users
  • Phishing simulations and exercises
  • Documentation of training completion
  • Updates when threats or systems change

Control Family 3: Audit and Accountability (AU) – 9 Requirements

“Audit logs are critical for forensic analysis and investigation” and require contractors to “log and review system activities for unauthorized and malicious attempts to create accountability and trace events back to individuals” Sprinto.

Audit and accountability involves creating comprehensive logs of system activities, protecting those logs from tampering, and regularly reviewing them to detect security incidents.

Key Audit and Accountability Requirements:

3.3.1 – Create and Retain Audit Records Create, protect, and retain information system audit records to the extent needed to enable monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate system activity.

3.3.2 – Audit Events Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable—including logging successful and failed access attempts, privileged activities, and security-relevant events.

3.3.3 – Review and Update Logged Events Review and update logged events based on current threat information and ongoing assessment of risk.

3.3.4 – Alert on Audit Failure Alert in the event of an audit logging process failure and take appropriate action.

3.3.5 – Audit Record Content Provide audit record generation capability with content that includes: what type of event occurred, when, where, source, outcome, and identity of individuals.

3.3.6 – Protect Audit Information Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

3.3.7 – Audit Reduction and Report Generation Provide an audit reduction and report generation capability that supports on-demand audit review, analysis, and reporting requirements.

3.3.8 – Time Stamps Provide time stamps for use in audit record generation using system clocks synchronized to an authoritative time source.

3.3.9 – Limit Audit Information Access Authorize access to management of audit logging functionality to only a subset of privileged users.

Implementation Notes:

  • Centralized log management (SIEM)
  • Log retention typically 90 days minimum
  • Protection against unauthorized deletion
  • Regular log review procedures
  • Automated alerting for critical events

Control Family 4: Configuration Management (CM) – 9 Requirements

“Poor configurations can lead to security gaps and increase the attack surface area” making configuration management “essential to ensure that all system configurations are secure and up to date and that no unauthorized changes are made” Sprinto.

Key Configuration Management Requirements:

3.4.1 – Baseline Configurations Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware) throughout system development lifecycles.

3.4.2 – Security Configuration Settings Establish and enforce security configuration settings for information technology products employed in organizational systems.

3.4.3 – Configuration Change Control Track, review, approve/disapprove, and audit changes to organizational systems using a documented change management process.

3.4.4 – Security Impact Analysis Analyze the security impact of changes prior to implementation to identify potential vulnerabilities introduced by changes.

3.4.5 – Access Restrictions for Change Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

3.4.6 – Least Functionality Employ the principle of least functionality by configuring systems to provide only essential capabilities (disabling unnecessary services, protocols, ports).

3.4.7 – Restrict Software Restrict, disable, and prevent the use of nonessential programs, functions, ports, protocols, and services.

3.4.8 – User-Installed Software Apply deny-by-exception (blacklist) policy to prohibit use of unauthorized software or allow-by-exception (whitelist) policy to permit execution of authorized software.

3.4.9 – Software Usage Restrictions Control and monitor user-installed software to prevent malicious software installation and configuration drift.


Control Family 5: Identification and Authentication (IA) – 11 Requirements

Identification and authentication verify that users, processes, and devices are who or what they claim to be before granting access to systems.

Key Identification and Authentication Requirements:

3.5.1 – Identify System Users Identify information system users, processes acting on behalf of users, and devices.

3.5.2 – Authenticate System Users Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational systems.

3.5.3 – Multi-Factor Authentication (MFA) Use multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Multi-factor authentication (MFA) requires two or more different types of credentials: something you know (password), something you have (token/phone), or something you are (biometric).

3.5.4 – Replay-Resistant Authentication Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

3.5.5 – Prevent Identifier Reuse Prevent reuse of identifiers for a defined period (typically 2 years minimum).

3.5.6 – Disable Inactive Identifiers Disable identifiers after a defined period of inactivity (typically 90 days).

3.5.7 – Password Complexity Enforce a minimum password complexity and change of characters when new passwords are created (typically 14+ characters, mix of character types).

3.5.8 – Prohibit Password Reuse Prohibit password reuse for a specified number of generations (typically 24 generations minimum).

3.5.9 – Temporary Passwords Allow temporary password use for system logons with an immediate change to a permanent password.

3.5.10 – Cryptographically-Protected Passwords Store and transmit only cryptographically-protected passwords using strong hashing algorithms (e.g., bcrypt, PBKDF2).

3.5.11 – Obscure Feedback Obscure feedback of authentication information during the authentication process to prevent unauthorized disclosure (e.g., display asterisks instead of password characters).


Control Family 6: Incident Response (IR) – 2 Requirements

Incident response establishes the capability to detect, report, and respond to security incidents.

Key Incident Response Requirements:

3.6.1 – Incident Handling Capability Establish an operational incident handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

3.6.2 – Incident Tracking and Reporting Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

Implementation Notes:

  • Documented incident response plan
  • Incident response team identified
  • Contact information maintained
  • Incident tracking system
  • Reporting procedures for various incident types
  • Post-incident reviews

Control Family 7: Maintenance (MA) – 3 Requirements

Maintenance controls ensure systems remain secure during maintenance activities.

Key Maintenance Requirements:

3.7.1 – Maintenance with Oversight Perform maintenance on organizational systems with oversight and documentation.

3.7.2 – Effective Maintenance Controls Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

3.7.3 – Sanitization of Maintenance Equipment Ensure equipment removed for off-site maintenance is sanitized of any CUI and media is sanitized or destroyed before disposal or release for reuse.

Implementation Notes:

  • Maintenance scheduling and approval
  • Escorting external maintenance personnel
  • Inspection of maintenance tools
  • Documentation of all maintenance activities

Control Family 8: Media Protection (MP) – 8 Requirements

Media protection secures CUI on physical and digital storage throughout its lifecycle.

Key Media Protection Requirements:

3.8.1 – Protect System Media Protect (physically control and securely store) system media containing CUI, both paper and digital.

3.8.2 – Limit Media Access Limit access to CUI on system media to authorized users.

3.8.3 – Sanitize or Destroy Media Sanitize or destroy system media containing CUI before disposal or release for reuse using approved sanitization techniques.

Sanitization means using approved methods to make data unrecoverable—overwriting for hard drives, degaussing for magnetic media, or physical destruction.

3.8.4 – Mark Media Mark media with necessary CUI markings and distribution limitations according to CUI marking standards.

3.8.5 – Control Media Access Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.

3.8.6 – Cryptographic Protection Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless protected by alternative physical safeguards.

3.8.7 – Control Media Use Control the use of removable media on system components (USB drives, external hard drives, CDs/DVDs).

3.8.8 – Prohibit Media Use Prohibit the use of portable storage devices when such devices have no identifiable owner or when prohibited by organizational policy.

3.8.9 – Protect Backups Protect the confidentiality of backup CUI at storage locations using encryption or physical security.


Control Family 9: Personnel Security (PS) – 2 Requirements

Personnel security ensures individuals are appropriately screened before being granted access to CUI.

Key Personnel Security Requirements:

3.9.1 – Personnel Screening Screen individuals prior to authorizing access to organizational systems containing CUI.

3.9.2 – Formal Sanctions Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers, and enforce formal sanctions for failing to comply with security policies.

Implementation Notes:

  • Background checks before CUI access
  • Access removal upon termination
  • Formal sanctions process
  • Annual attestations

Control Family 10: Physical Protection (PE) – 6 Requirements

Physical protection controls physical access to facilities, systems, and equipment containing CUI.

Key Physical Protection Requirements:

3.10.1 – Limit Physical Access Limit physical access to organizational information systems, equipment, and operating environments to authorized individuals.

3.10.2 – Escort and Monitor Visitors Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

3.10.3 – Physical Access Control Protect and monitor the physical facility and support infrastructure for organizational systems.

3.10.4 – Control Physical Access Devices Control physical access devices (keys, access cards, locks) through inventories, periodic inspections, and changing combinations when compromised.

3.10.5 – Control Asset Removal Control information system output devices (printers, scanners, copiers) to prevent unauthorized individuals from accessing CUI and authorize removal of assets from controlled areas.

3.10.6 – Alternate Work Sites Enforce safeguarding measures for CUI at alternate work sites (home offices, remote locations).


Control Family 11: Risk Assessment (RA) – 3 Requirements

Risk assessment identifies and manages security risks to organizational operations and assets.

Key Risk Assessment Requirements:

3.11.1 – Periodic Risk Assessments Periodically assess the risk to organizational operations, assets, and individuals from the operation of organizational systems and the associated processing, storage, or transmission of CUI.

3.11.2 – Vulnerability Scanning Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting the system are identified.

Vulnerability scanning uses automated tools to identify known security weaknesses in systems, applications, and configurations that could be exploited.

3.11.3 – Remediation of Vulnerabilities Remediate vulnerabilities in accordance with risk assessments, prioritizing critical and high-severity vulnerabilities.

Implementation Notes:

  • Risk assessments annually minimum
  • Vulnerability scans monthly minimum
  • Authenticated scans for internal systems
  • Remediation tracking with timelines
  • Critical vulnerabilities: 30 days
  • High vulnerabilities: 90 days

Control Family 12: Security Assessment (CA) – 3 Requirements

Security assessment monitors the effectiveness of security controls.

Key Security Assessment Requirements:

3.12.1 – Periodic Assessments Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

3.12.2 – Security Assessment Plans Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

3.12.3 – Monitor Security Controls Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

3.12.4 – System Security Plan (SSP) Develop, document, and periodically update system security plans that describe system boundaries, operating environment, security requirements implementation, and relationships with other systems.

System Security Plan (SSP) is the comprehensive document describing all security controls implemented or planned for an information system.


Control Family 13: System and Communications Protection (SC) – 16 Requirements

System and communications protection secures system boundaries and protects data during transmission.

Key System and Communications Protection Requirements:

3.13.1 – Boundary Protection Monitor, control, and protect organizational communications at external boundaries and key internal boundaries of information systems.

3.13.2 – Security Function Isolation Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

3.13.3 – Denial of Service Protection Employ architectural designs, software development techniques, and systems engineering principles to limit damage from denial of service attacks.

3.13.4 – Information in Shared Resources Prevent unauthorized and unintended information transfer via shared system resources.

3.13.5 – Network Segmentation Implement network segmentation to separate systems processing CUI from other organizational systems.

3.13.6 – Deny by Default Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

3.13.7 – Split Tunneling Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection (split tunneling prevention).

3.13.8 – Cryptographic Protection for Transmission Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless protected by alternative physical safeguards.

Encryption during transmission protects data as it moves across networks using protocols like TLS/SSL, IPsec VPN, or SFTP.

3.13.9 – Network Disconnect Terminate network connections associated with communications sessions at the end of the session or after a defined period of inactivity.

3.13.10 – Cryptographic Key Management Establish and manage cryptographic keys for required cryptography employed within organizational systems.

3.13.11 – CUI Encryption Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

FIPS 140-2 validated cryptography means encryption that has been tested and certified by NIST to meet Federal Information Processing Standards.

3.13.12 – Collaborative Computing Devices Prohibit remote activation of collaborative computing devices (cameras, microphones) and provide indication of use to users present at the device.

3.13.13 – Mobile Code Control and monitor the use of mobile code (JavaScript, ActiveX, etc.).

3.13.14 – Voice over IP Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

3.13.15 – Cryptographic Protection for Data at Rest Protect the confidentiality of CUI at rest using encryption.

3.13.16 – Protection of Information at Rest Protect the confidentiality of CUI at rest through approved encryption or isolation on separate systems/media.


Control Family 14: System and Information Integrity (SI) – 7 Requirements

System and information integrity ensures systems can identify and correct security flaws.

Key System and Information Integrity Requirements:

3.14.1 – Flaw Identification and Remediation Identify, report, and correct information system flaws in a timely manner.

3.14.2 – Malicious Code Protection Provide protection from malicious code (viruses, worms, Trojans, ransomware) at appropriate locations within organizational information systems.

3.14.3 – Update Malicious Code Protection Update malicious code protection mechanisms when new releases are available.

3.14.4 – Scan for Malicious Code Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

3.14.5 – Monitoring and Alerts Monitor organizational systems including inbound and outbound communications traffic, for unusual or unauthorized activities or conditions.

3.14.6 – Security Alerts and Advisories Monitor system security alerts and advisories and take action in response.

3.14.7 – Software and Firmware Integrity Employ integrity verification tools to detect unauthorized changes to software, firmware, and information.


Implementation Best Practices

Starting Your CMMC Level 2 Implementation:

  1. Gap Assessment: Evaluate current compliance against all 110 requirements
  2. Prioritize Critical Controls: Focus first on encryption, MFA, boundary protection, malicious code protection
  3. Document Everything: Create SSP, policies, procedures for each control family
  4. Technical Implementation: Deploy required security tools (SIEM, EDR, encryption, MFA)
  5. Training: Conduct security awareness training for all personnel
  6. Evidence Collection: Gather documentation proving implementation of each control
  7. Assessment Objectives: Verify you meet all 320 assessment objectives across the 110 controls

Common Implementation Challenges:

  • Scope Definition: Determining which systems and assets are in scope
  • Documentation: Creating comprehensive policies and procedures
  • Technical Complexity: Implementing FIPS-validated encryption and advanced controls
  • Cost: Security tools, consulting, and assessment fees
  • Timeline: 9-18 months typical implementation period
  • Ongoing Maintenance: Continuous monitoring and annual reassessments

Key Takeaways: CMMC Level 2 Security Controls

CMMC Level 2 requires comprehensive implementation of 110 security controls:

14 control families covering all aspects of cybersecurity
110 specific requirements from NIST SP 800-171 Revision 2
320 assessment objectives that must all be met for certification
Access Control (22 requirements) is the largest family
Encryption required for CUI at rest and in transit (FIPS 140-2)
Multi-factor authentication mandatory for privileged and network access
System Security Plan required documenting all controls
Technical and administrative controls—not just technology
Continuous monitoring and ongoing compliance required
Third-party assessment validates implementation of all controls

Understanding and implementing all 110 CMMC Level 2 security controls is essential for defense contractors handling CUI—ensuring both compliance eligibility and robust protection of sensitive government information.


Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” NIST SP 800-171A “Assessing Security Requirements for Controlled Unclassified Information,” and 32 CFR 170.14 which specifies CMMC Level 2 security requirements.

Table of Contents