AuditXYZ

Lesson 2 of 6

CMMC Level 2 Requirements: The Complete Breakdown

14 min readIntermediate

CMMC Level 2 Requirements

CMMC Level 2 is where the defense industrial base does most of its compliance work. It applies to any contractor that stores, processes, or transmits Controlled Unclassified Information (CUI), and it requires implementing all 110 security controls from NIST SP 800-171 Rev 2 — then proving it, in most cases to a certified third-party assessment organization (C3PAO).

This lesson breaks down exactly what Level 2 requires: the control families, the two assessment tracks, the POA&M rules, the cloud and FedRAMP questions that trip up most contractors, and a realistic timeline.

The Foundation: NIST SP 800-171 Rev 2

CMMC Level 2 does not invent new security requirements. It verifies the requirements contractors have accepted since DFARS 252.204-7012 took effect: implement NIST SP 800-171. The CMMC program (finalized in the 32 CFR rule effective December 2024, with the 48 CFR acquisition rule following in 2025) is the enforcement mechanism, currently based on Rev 2 of the standard.

The 110 controls decompose into 320 assessment objectives — the granular statements an assessor actually evaluates. A control is only "met" when every one of its objectives is met. This is why organizations that skim the 110 control titles and declare themselves "mostly compliant" get unpleasant surprises: control 3.5.3 ("use multifactor authentication") sounds like one checkbox, but it is assessed for local access, network access, and privileged accounts separately.

The 14 Control Families

FamilyControlsWhat It CoversCommon Heavy Lifts
Access Control (AC)22Who can access what, least privilege, remote access, CUI flowSession controls, CUI flow enforcement, mobile devices
Awareness & Training (AT)3Security training, insider threat awarenessRole-based training records
Audit & Accountability (AU)9Logging, log review, audit protectionCentral log collection, retention, alerting
Configuration Management (CM)9Baselines, change control, least functionalityHardened baselines, software allowlisting
Identification & Authentication (IA)11Unique IDs, MFA, password rulesMFA everywhere, FIPS-validated crypto for passwords
Incident Response (IR)3IR plan, testing, reportingTested plan, 72-hour DoD reporting readiness
Maintenance (MA)6System maintenance, remote maintenance controlsSanitizing equipment leaving the facility
Media Protection (MP)9Marking, storing, sanitizing, transporting mediaEncrypting CUI on removable media
Personnel Security (PS)2Screening, offboardingTermination checklists tied to access removal
Physical Protection (PE)6Facility access, visitor logsEscort procedures, badge audits
Risk Assessment (RA)3Risk assessments, vulnerability scanningRecurring authenticated scans, remediation SLAs
Security Assessment (CA)4Control assessment, SSP, POA&M, monitoringKeeping the SSP current
System & Communications Protection (SC)16Boundary defense, encryption in transit/at restFIPS 140-validated encryption, DNS filtering, VoIP controls
System & Information Integrity (SI)7Flaw remediation, malware protection, monitoringPatch SLAs, EDR/monitoring coverage

Two families consistently cause the most findings: SC, because "encryption" must use FIPS 140-validated cryptographic modules (not just "we use TLS"), and AU, because collecting, retaining, reviewing, and protecting logs across every in-scope asset requires real tooling. For control-by-control detail, the standard behind all of this is NIST SP 800-171 — see our framework reference on NIST 800-171.

Scoping: What the 110 Controls Apply To

Before implementing anything, define your CMMC Assessment Scope. The scoping guidance categorizes assets as:

  • CUI Assets — process, store, or transmit CUI. Fully assessed.
  • Security Protection Assets — provide security functions for the scope (your SIEM, MFA provider, EDR). Assessed for the functions they provide.
  • Contractor Risk Managed Assets — can access CUI but are not intended to; documented and managed, spot-checked.
  • Specialized Assets — IoT, OT, test equipment, government property; documented in the SSP and managed via risk-based policies.
  • Out-of-Scope Assets — physically or logically separated from CUI. Not assessed, but you must be able to justify the separation.

Scoping is the highest-leverage decision in the entire program. A tightly bounded enclave with 15 users in scope is a radically cheaper project than a flat network where all 200 employees can theoretically reach CUI. We cover enclave strategy in the small business lesson.

The Two Assessment Tracks

Track 1: C3PAO Assessment (Most Contracts)

The majority of Level 2 contracts require a triennial assessment by a C3PAO — a private assessment firm accredited by the CMMC Accreditation Body. The assessment team examines evidence, interviews staff, and tests controls against all 320 objectives, then records results in the DoD's eMASS instance for CMMC. Between triennial assessments, a senior official submits an annual affirmation of continued compliance in SPRS.

C3PAO capacity is limited relative to the number of contractors that need assessments, so booking lead times of three to six months are common. Schedule early — ideally as soon as your gap assessment gives you a credible readiness date.

Track 2: Self-Assessment (Limited Contracts)

A small subset of Level 2 acquisitions — those involving CUI the DoD deems less critical — permit a triennial self-assessment with annual affirmation, entered in SPRS. The rigor expected is the same 320 objectives; only the assessor changes. You do not choose your track; the solicitation specifies it. Building to C3PAO standard is the safe planning assumption, since one future contract can flip your requirement.

SPRS Scores

Independent of CMMC status, DFARS 252.204-7019/7020 requires a current NIST SP 800-171 self-assessment score in SPRS (Supplier Performance Risk System). Scoring starts at 110 and subtracts 1, 3, or 5 points per unimplemented control, down to a floor of -203. Primes check SPRS when selecting subcontractors, and an implausibly perfect score that later proves false is a legal liability — score honestly.

POA&M Rules: Conditional Certification

CMMC 2.0 allows a limited Plan of Action and Milestones at Level 2, but the rules are strict:

  • You must score at least 88 out of 110 at assessment (80 percent).
  • Only certain lower-weighted (1-point) requirements may be open on the POA&M. The highest-weighted controls — such as MFA, FIPS-validated encryption, and other 3- and 5-point items — must be fully implemented, with narrow specified exceptions.
  • All POA&M items must be closed within 180 days of the assessment, verified through a POA&M closeout assessment.
  • Meet the deadline and your conditional status becomes final. Miss it and your conditional certification expires — with contract eligibility consequences.

Practical advice: treat the POA&M as an emergency landing option, not a strategy. Organizations that plan to "POA&M their way in" usually discover their open items are 3- or 5-pointers that are not POA&M-eligible at all.

Cloud, FedRAMP, and GCC High

Cloud services are where Level 2 scoping most often goes wrong.

The rule: Under DFARS 252.204-7012, if a cloud service provider stores, processes, or transmits CUI on your behalf, it must meet security requirements equivalent to FedRAMP Moderate (or hold a FedRAMP Moderate or higher authorization), and it must support the DFARS incident reporting and forensics obligations. DoD guidance on "equivalency" is demanding — in practice, a genuinely authorized offering is the defensible choice.

What that means for common stacks:

  • Microsoft 365: Commercial M365 does not satisfy the export-control side of many CUI environments. GCC can support some CUI scenarios, but GCC High is the standard answer where CUI includes ITAR/export-controlled data, because it is operated by screened US persons in US data centers. GCC High costs meaningfully more per seat and requires a migration project — budget for both.
  • Google Workspace, Slack, Dropbox (commercial tiers): If CUI can land there, they are in scope and generally cannot demonstrate equivalency. Either keep CUI out (technically enforced, not policy-only) or replace them within the CUI boundary.
  • AWS GovCloud / Azure Government: Appropriate infrastructure choices for CUI workloads.
  • Your MSP and other external service providers: If an MSP administers in-scope systems, it is part of your assessment scope. Assessors will examine what access the MSP has and what evidence it can produce. Choose providers who already support CMMC clients and will sign a customer responsibility matrix.

Encryption caveat: Wherever a control requires cryptography to protect CUI, the modules must be FIPS 140-validated — not merely "FIPS-capable." Verify actual validation certificates for your VPN, disk encryption, and wireless.

The System Security Plan and Evidence

Two things decide assessments: whether the controls work, and whether you can prove it.

The System Security Plan (SSP) is the master document describing your scope, architecture, and how each of the 110 controls is implemented. It is itself a requirement (3.12.4), and it is the first document a C3PAO reads. An SSP that says "we comply with 3.1.1" is worthless; assessors expect specifics — which systems, which settings, which responsible roles.

Beyond the SSP, expect to produce evidence for each assessment objective: policy documents, configuration screenshots and exports, log samples, training records, visitor logs, incident response test results, vulnerability scan reports, and change tickets. Assessors verify through the examine/interview/test triad, so your staff must also be able to describe the procedures they actually follow. The full documentation stack gets its own lesson: CMMC documentation requirements.

Realistic Timeline

For an organization starting with typical commercial IT maturity:

PhaseDurationKey Activities
Scoping & data flow mapping1–2 monthsIdentify CUI, define boundary, choose enclave vs enterprise scope
Gap assessment1–2 monthsScore all 320 objectives, produce remediation plan and SPRS score
Remediation4–9 monthsTechnical fixes (MFA, FIPS, logging, GCC High migration), process changes
Documentation2–4 months (overlaps)SSP, policies, procedures, responsibility matrices
Evidence collection & operation2–3 monthsRun controls, collect artifacts, train staff
Readiness/mock assessment1 monthInternal or third-party dry run, fix findings
C3PAO assessment1–2 weeks on site/virtualExamine, interview, test; results to eMASS

Total: 12–18 months is the honest planning number, though a small, disciplined enclave can move faster — see the quickest path to CMMC. Cost-conscious approaches are covered in the cheapest path to CMMC.

Level 2 Readiness Checklist

  • CUI identified, data flows mapped, assessment scope documented
  • Asset inventory categorized (CUI, security protection, CRMA, specialized, out-of-scope)
  • Gap assessment completed against all 320 objectives; SPRS score submitted
  • MFA enforced for network, privileged, and remote access
  • FIPS 140-validated encryption verified for CUI at rest and in transit
  • Centralized logging with retention, review, and alerting in place
  • Cloud services carrying CUI are FedRAMP Moderate (or equivalent); GCC High decision made if ITAR data is involved
  • External service providers documented with shared responsibility matrices
  • SSP complete and current; POA&M tracking remaining gaps
  • Policies and procedures issued for all 14 families; staff trained
  • Incident response plan tested; DFARS 72-hour reporting procedure ready
  • Mock assessment passed; C3PAO booked

Frequently Asked Questions

Is CMMC Level 2 based on NIST SP 800-171 Rev 2 or Rev 3?

The current CMMC program assesses against Rev 2 and its 110 controls. NIST has published Rev 3, and the DoD will transition the program through rulemaking with notice — but you certify today against Rev 2. Building an environment that is well-documented against Rev 2 puts you in good shape for the eventual transition.

What score do I need to pass a Level 2 assessment?

To achieve final certification you must meet all 110 controls. Conditional certification is possible at a score of 88 or higher, provided the open items are limited to POA&M-eligible lower-weighted requirements and are closed within 180 days.

Do I need GCC High for CMMC Level 2?

Not automatically. You need cloud services meeting FedRAMP Moderate or equivalent for anything touching CUI. GCC High becomes the practical requirement when your CUI includes export-controlled (ITAR) data or when contracts demand US-persons handling. Many contractors choose GCC High anyway because it removes the equivalency argument entirely.

Does my MSP need its own CMMC certification?

Current program rules focus on assessing the MSP's services as part of your scope rather than requiring every MSP to hold its own certificate, but the practical bar is the same: your MSP must implement and evidence the controls relevant to the services it provides. An MSP that cannot support an assessment will sink yours. Ask for their responsibility matrix and CMMC client references before signing.

How much does a C3PAO assessment cost?

Most small and mid-sized contractors report C3PAO assessment fees in the $30,000–$60,000 range per triennial cycle, driven by scope size and complexity. That excludes preparation, tooling, and remediation, which usually cost more than the assessment itself.

Can I keep working on DoD contracts while I pursue Level 2?

Existing contracts continue under their current terms. The pressure point is new awards, recompetes, and option decisions during the phased rollout — those increasingly require certification at proposal or award time. The earlier you certify, the fewer opportunities you forfeit.


Choosing GRC platforms, readiness partners, and a C3PAO involves comparing dozens of options. AuditXYZ helps you compare compliance automation tools and auditors — coverage, integrations, and pricing in one place — so your Level 2 project starts with the right stack.