CMMC Level 2

Handle CUI? We'll get you a score you can defend.

If your contracts involve Controlled Unclassified Information, you're looking at all 110 controls of NIST SP 800-171 — self-assessed, scored in SPRS, and personally affirmed by a senior official every year. Third-party audits are suspended as of July 13, 2026; the obligation and the liability are not. Greypike scopes it, builds it, runs it, and keeps it evidenced — so the affirmation is the easy part.

110 NIST 800-171 controls Defensible SPRS score RPA-led
The basics

What CMMC Level 2 actually is.

Level 2 applies to contractors who store, process, or transmit Controlled Unclassified Information (CUI). It means implementing the full NIST SP 800-171 control set — and proving it. During the current suspension of third-party audits, that proof is your self-assessment: a score in SPRS, evidence behind every control, and an annual affirmation signed by a senior official. Select government-led assessments continue, and a reformed assessment model may follow the 60-day CMMC review — but the standard being measured never changes.

14
Control families
Access, audit, IR, media…
110
Security controls
Scored to 110 in SPRS
320
Assessment objectives
What a C3PAO checks
Those 110 controls break down into ~320 individual assessment objectives in NIST SP 800-171A — the specific, checkable statements a control is measured against. A control only counts as implemented when every objective behind it is met, and that's the standard your SPRS score claims and your Affirming Official signs for. That granularity is exactly why scope discipline and real evidence matter so much — with or without an auditor in the room.

Self-assessed

For now C3PAO audits are suspended pending the CMMC reform review; contracts may only require Level 2 (Self). Your self-assessment must stay current within three years, with annual affirmations — and select government-led assessments continue.

CUI, not just FCI

Level 2 is triggered by Controlled Unclassified Information — a higher bar than the FCI-only Level 1.

Scope is everything

A smaller CUI boundary means fewer systems against those 320 objectives — faster, cheaper, more reliable.

We prepare you; we don’t grade you. Independent by design. Greypike is not a C3PAO, and that separation matters more now, not less: with audits suspended, the value of your assessment rests entirely on its honesty. We assess you against all ~320 objectives the way an independent assessor would — no incentive to inflate, no conflict of interest in the number you sign. If third-party audits return, that same separation means we prepare you and an independent C3PAO grades you.
The problem — and the fix

110 controls. A signed affirmation. And your contracts on the line.

Level 2 used to be where good intentions met a graded exam. The exam is suspended — what's left is a take-home test you grade yourself, then a senior official signs the result and submits it to the federal government. The cost and risk aren't in wanting to comply — they're in scope creep, thin evidence, and a posture that drifts the moment the project ends, right underneath a score someone keeps affirming.

What gets in the way

  • CUI scattered across email, laptops, and shared drives — pulling your whole company into scope.
  • All 110 controls to implement — and an SSP, POA&M, and SPRS score that a government assessor, a prime's supplier review, or a DOJ inquiry will actually scrutinize.
  • Compliance that's "done" once and decayed by month three — right before someone signs the annual affirmation saying it isn't.

How Greypike addresses it

  • We shrink the boundary — consolidating CUI into a contained enclave so most of your business falls out of scope.
  • We implement and document all 110 controls, owning the SSP, POA&M, evidence, and SPRS submission.
  • We keep it ready year-round — so every affirmation, and any assessment that comes, is backed by current evidence.
How we get you there

Four ways we deliver Level 2 — as one connected path.

Most clients move through these in order: scope it, contain it, keep it ready — with expert time on tap whenever you need it. Take the whole journey or just the piece you’re missing.

1
Start here

CMMC Readiness Roadmap

A fixed-fee scoping engagement that maps your CUI, defines your boundary, and gives you a corrected SPRS score plus a prioritized path to full compliance — before you commit to a full implementation. It de-risks everything that follows, including the next affirmation.

CUI mappingBoundary definitionPrioritized roadmap
2
The anchor

Managed Compliant Enclave

We stand up and operate a hardened, evidence-ready environment — built in your own Microsoft GCC High or Google Assured Workloads account — so your CUI is contained and your compliance scope stays tight. Compliance is included in the per-user price.

GCC High or Assured WorkloadsYou own the accountScope containment
3
Stays ready

Managed Compliance

Ongoing oversight of your compliance program — SSP, POA&M, evidence, and SPRS kept current month over month. Greypike owns the program, cadence, and remediation direction; your IT executes the hands-on work. You stay affirmation-ready every year, not just ready once.

SSP & POA&M upkeepEvidence & SPRSAnnual affirmation support
4
Expertise on tap

Consulting Blocks

Expert, RPA-led time for the parts that don’t fit a fixed package — complex scoping, prime and customer security questionnaires, remediation guidance, or working alongside your existing IT or MSP. Buy the help you need, when you need it.

Complex scopingQuestionnaire supportWorks with your MSP

Make your Level 2 affirmation the easy part.

Start with a scoping session, or see transparent, fixed-fee pricing for each stage of the journey.