Short answer: CMMC Level 2 requires a defense contractor that handles controlled unclassified information (CUI) to implement all 110 security requirements in NIST SP 800-171 Rev. 2, organized into 14 families such as access control, incident response and system integrity. Compliance is shown through a scored assessment (a self-assessment or a third-party C3PAO assessment), a System Security Plan, a score posted in the Supplier Performance Risk System (SPRS), and an annual affirmation by a senior company official.
2026 status check (as of 27 September 2026): The Department of War suspended CMMC Phase 2 on 13 July 2026, and a 3 September 2026 class deviation removes third-party assessment requirements from contracts. The Level 2 security requirements themselves, Level 2 self-assessments, SPRS scores and annual affirmations still apply. The CMMC Reform Task Force has delivered its recommendations to the Department of War CIO, but they have not been made public, so further changes are possible.
You need Level 2 if your company stores, processes or transmits CUI on a Department of Defense contract, or receives it as a subcontractor. CUI is government information that is not classified but must be protected: technical drawings, specifications, export-controlled data, test results and similar material. Contracts that include DFARS 252.204-7012 have required the same NIST SP 800-171 controls since 2017; CMMC adds a way to verify them.
If you only handle federal contract information (FCI), basic non-public information about the contract itself, you need Level 1 instead. The CMMC level is set in the solicitation, so check the contract rather than guessing.
The CMMC Level 2 requirements map directly to the 110 requirements in NIST SP 800-171 Rev. 2. Although NIST published Rev. 3 in 2024, CMMC continues to assess against Rev. 2. Each requirement is broken into assessment objectives (320 in total, from NIST SP 800-171A) that an assessor checks individually. The table shows the 14 NIST 800-171 control families and how many Level 2 controls sit in each.
| Family | Requirements | What it covers |
| Access Control (AC) | 22 | Who can use which systems and data, least privilege, remote access, wireless and mobile devices |
| Awareness and Training (AT) | 3 | Security awareness and role-based training, including insider threat awareness |
| Audit and Accountability (AU) | 9 | Creating, protecting and reviewing audit logs so actions can be traced to users |
| Configuration Management (CM) | 9 | Baseline configurations, change control, least functionality and software restrictions |
| Identification and Authentication (IA) | 11 | Unique user IDs, multifactor authentication and password rules |
| Incident Response (IR) | 3 | Incident handling capability, reporting and testing |
| Maintenance (MA) | 6 | Controlling system maintenance, tools and remote maintenance sessions |
| Media Protection (MP) | 9 | Protecting, marking, transporting and sanitizing media that holds CUI |
| Personnel Security (PS) | 2 | Screening staff and protecting CUI when people leave or change roles |
| Physical Protection (PE) | 6 | Limiting physical access, escorting visitors and keeping access logs |
| Risk Assessment (RA) | 3 | Periodic risk assessments and vulnerability scanning and remediation |
| Security Assessment (CA) | 4 | Assessing controls, plans of action and the System Security Plan |
| System and Communications Protection (SC) | 16 | Boundary protection, network segmentation, encryption (including FIPS-validated cryptography) and session controls |
| System and Information Integrity (SI) | 7 | Flaw remediation, malware protection, security alerts and system monitoring |
| Total | 110 |
Access Control, System and Communications Protection and Identification and Authentication together account for 49 of the 110 requirements, and they are where most technical work lands. For a working, tick-box version of each family, use our CMMC compliance checklist.
The CMMC rule created two ways to meet Level 2, with the contract deciding which applies:
| Level 2 (Self) | Level 2 (C3PAO) | |
| Who assesses | The contractor | An accredited CMMC Third-Party Assessment Organization |
| Requirements | All 110 | All 110 |
| Frequency | Every 3 years, affirmed annually | Every 3 years, affirmed annually |
| Result recorded in | SPRS | CMMC eMASS, reflected in SPRS |
| Status in 2026 | Required where the contract calls for it | Removed from contracts by the September 2026 class deviation; available voluntarily |
The security requirements are identical. The difference is who checks your work. Both routes follow the DoD’s CMMC Level 2 Assessment Guide, which sets out each assessment objective and the evidence an assessor expects. Many primes still prefer suppliers with a C3PAO certificate because it is independent evidence, and a self-assessment that later proves inflated can create False Claims Act exposure.
Level 2 uses the DoD Assessment Methodology. You start at 110 points and subtract points for each requirement not fully met. Requirements are weighted at 1, 3 or 5 points depending on how much risk a gap creates, which is why scores can go negative: the lowest possible score is minus 203.
The score, the date of assessment and the scope are posted in SPRS, where contracting officers and primes can see them.
A Plan of Action and Milestones (POA&M) lists requirements that are not yet met and how you will fix them. Under CMMC, POA&Ms are allowed at Level 2 but tightly limited:
In short, a POA&M is for finishing a few small items, not for deferring a security program.
Assessors check that your documents exist and that they match what is actually running. At minimum you need:
Across small and mid-sized contractors, the same few requirements cause most delays and cost:
CMMC Level 2 compliance follows the same sequence whichever assessment route your contract names:
| Level 1 | Level 2 | Level 3 | |
| Protects | FCI | CUI | High-priority CUI |
| Requirements | 15 (FAR 52.204-21) | 110 (NIST SP 800-171 Rev. 2) | 110 plus 24 from NIST SP 800-172 |
| Assessment | Annual self-assessment | Self or C3PAO every 3 years | DoD DIBCAC every 3 years, after Level 2 C3PAO certification |
| POA&Ms | Not allowed | Limited, 180 days to close | Limited, 180 days to close |
| Annual affirmation | Yes | Yes | Yes |
Phase 1 of CMMC began on 10 November 2025, adding Level 1 and Level 2 self-assessment requirements to new solicitations. Phase 2, scheduled for 10 November 2026, would have required C3PAO certification in applicable contracts. On 13 July 2026 the Department of War suspended Phase 2 and later milestones pending a task force review, and on 3 September 2026 a class deviation made the pause binding.
For Level 2, that means:
If you need outside help, REVERB’s lists of the top cybersecurity companies and top penetration testing companies include firms that assess and harden environments like these. For budgeting the testing side, see what penetration testing costs. For the full CMMC budget, see our guide to how much CMMC certification costs.
The 110 security requirements in NIST SP 800-171 Rev. 2, across 14 families, plus a System Security Plan, a scored assessment posted in SPRS and an annual affirmation by a senior official.
110 requirements, broken into 320 assessment objectives.
A score of 110 means full compliance. A score of at least 88 is required for conditional status, with remaining items on a POA&M that must be closed within 180 days.
It can be. The contract specifies either a Level 2 self-assessment or a Level 2 C3PAO assessment. Since September 2026, third-party assessment requirements have been removed from contracts, so self-assessments are the current mandatory route.
A DoD document that walks through every Level 2 requirement and its assessment objectives, with examples of the evidence assessors look for. It is the reference both self-assessors and C3PAOs work from.
Rev. 2. NIST released Rev. 3 in 2024, but CMMC assessments continue to use Rev. 2.
Three years, with an annual affirmation required to keep it active.
Yes, for a limited set of lower-weighted requirements, if your score is at least 88. All items must be closed within 180 days.
Level 1 protects FCI with 15 basic requirements and an annual self-assessment. Level 2 protects CUI with 110 requirements and a scored assessment every three years.