Nice To E-Meet You!



    What marketing services do you need for your project?

    CMMC Level 2 Requirements: A Complete Guide

    Short answer: CMMC Level 2 requires a defense contractor that handles controlled unclassified information (CUI) to implement all 110 security requirements in NIST SP 800-171 Rev. 2, organized into 14 families such as access control, incident response and system integrity. Compliance is shown through a scored assessment (a self-assessment or a third-party C3PAO assessment), a System Security Plan, a score posted in the Supplier Performance Risk System (SPRS), and an annual affirmation by a senior company official.

    2026 status check (as of 27 September 2026): The Department of War suspended CMMC Phase 2 on 13 July 2026, and a 3 September 2026 class deviation removes third-party assessment requirements from contracts. The Level 2 security requirements themselves, Level 2 self-assessments, SPRS scores and annual affirmations still apply. The CMMC Reform Task Force has delivered its recommendations to the Department of War CIO, but they have not been made public, so further changes are possible.

    In This Guide

    Who Needs CMMC Level 2

    You need Level 2 if your company stores, processes or transmits CUI on a Department of Defense contract, or receives it as a subcontractor. CUI is government information that is not classified but must be protected: technical drawings, specifications, export-controlled data, test results and similar material. Contracts that include DFARS 252.204-7012 have required the same NIST SP 800-171 controls since 2017; CMMC adds a way to verify them.

    If you only handle federal contract information (FCI), basic non-public information about the contract itself, you need Level 1 instead. The CMMC level is set in the solicitation, so check the contract rather than guessing.

    The 110 CMMC Level 2 Requirements By Family

    The CMMC Level 2 requirements map directly to the 110 requirements in NIST SP 800-171 Rev. 2. Although NIST published Rev. 3 in 2024, CMMC continues to assess against Rev. 2. Each requirement is broken into assessment objectives (320 in total, from NIST SP 800-171A) that an assessor checks individually. The table shows the 14 NIST 800-171 control families and how many Level 2 controls sit in each.

    FamilyRequirementsWhat it covers
    Access Control (AC)22Who can use which systems and data, least privilege, remote access, wireless and mobile devices
    Awareness and Training (AT)3Security awareness and role-based training, including insider threat awareness
    Audit and Accountability (AU)9Creating, protecting and reviewing audit logs so actions can be traced to users
    Configuration Management (CM)9Baseline configurations, change control, least functionality and software restrictions
    Identification and Authentication (IA)11Unique user IDs, multifactor authentication and password rules
    Incident Response (IR)3Incident handling capability, reporting and testing
    Maintenance (MA)6Controlling system maintenance, tools and remote maintenance sessions
    Media Protection (MP)9Protecting, marking, transporting and sanitizing media that holds CUI
    Personnel Security (PS)2Screening staff and protecting CUI when people leave or change roles
    Physical Protection (PE)6Limiting physical access, escorting visitors and keeping access logs
    Risk Assessment (RA)3Periodic risk assessments and vulnerability scanning and remediation
    Security Assessment (CA)4Assessing controls, plans of action and the System Security Plan
    System and Communications Protection (SC)16Boundary protection, network segmentation, encryption (including FIPS-validated cryptography) and session controls
    System and Information Integrity (SI)7Flaw remediation, malware protection, security alerts and system monitoring
    Total110

    Access Control, System and Communications Protection and Identification and Authentication together account for 49 of the 110 requirements, and they are where most technical work lands. For a working, tick-box version of each family, use our CMMC compliance checklist.

    Self-Assessment Vs C3PAO Assessment

    The CMMC rule created two ways to meet Level 2, with the contract deciding which applies:

    Level 2 (Self)Level 2 (C3PAO)
    Who assessesThe contractorAn accredited CMMC Third-Party Assessment Organization
    RequirementsAll 110All 110
    FrequencyEvery 3 years, affirmed annuallyEvery 3 years, affirmed annually
    Result recorded inSPRSCMMC eMASS, reflected in SPRS
    Status in 2026Required where the contract calls for itRemoved from contracts by the September 2026 class deviation; available voluntarily

    The security requirements are identical. The difference is who checks your work. Both routes follow the DoD’s CMMC Level 2 Assessment Guide, which sets out each assessment objective and the evidence an assessor expects. Many primes still prefer suppliers with a C3PAO certificate because it is independent evidence, and a self-assessment that later proves inflated can create False Claims Act exposure.

    How Level 2 Scoring Works (SPRS)

    Level 2 uses the DoD Assessment Methodology. You start at 110 points and subtract points for each requirement not fully met. Requirements are weighted at 1, 3 or 5 points depending on how much risk a gap creates, which is why scores can go negative: the lowest possible score is minus 203.

    • 110: every requirement met.
    • 88 or above (80 percent): the minimum to achieve conditional status, with open items on a POA&M.
    • Below 88: not eligible for conditional status.

    The score, the date of assessment and the scope are posted in SPRS, where contracting officers and primes can see them.

    POA&Ms And Conditional Status

    A Plan of Action and Milestones (POA&M) lists requirements that are not yet met and how you will fix them. Under CMMC, POA&Ms are allowed at Level 2 but tightly limited:

    • Your score must be at least 88 to use one.
    • Only certain lower-weighted requirements can go on a POA&M. Higher-weighted requirements, and a small list of specific ones including having a System Security Plan, must be met at assessment. One partial exception covers encryption that is in place but not FIPS-validated.
    • Every POA&M item must be closed within 180 days, confirmed by a closeout assessment. If not, the conditional status expires.

    In short, a POA&M is for finishing a few small items, not for deferring a security program.

    Required Documentation

    Assessors check that your documents exist and that they match what is actually running. At minimum you need:

    • System Security Plan (SSP): describes your CUI environment, its boundary and how each of the 110 requirements is implemented. It is mandatory and cannot be on a POA&M.
    • Policies and procedures: for each family, showing how requirements are carried out.
    • Asset inventory and network diagram: defining what is in scope.
    • POA&M: if you have open items.
    • Evidence: logs, configuration screenshots, training records, visitor logs and incident response test results.
    • Customer responsibility matrix: if you rely on a cloud or managed service provider, showing which requirements they cover and which remain yours.

    The Hardest Level 2 Requirements To Meet

    Across small and mid-sized contractors, the same few requirements cause most delays and cost:

    1. Multifactor authentication (IA 3.5.3): required for privileged accounts and for network access to non-privileged accounts, including older systems that do not support it easily.
    2. FIPS-validated cryptography (SC 3.13.11): encryption protecting CUI must use FIPS-validated modules, which rules out some consumer tools and default settings.
    3. Cloud services: cloud providers storing CUI must meet FedRAMP Moderate or an equivalent baseline, which often means moving to a government cloud tenant.
    4. Audit logging and review (AU family): collecting, protecting and actually reviewing logs usually requires a SIEM or managed detection service.
    5. Boundary protection and segmentation (SC 3.13.1 and 3.13.5): CUI systems must be separated from the rest of the network, which is where CUI enclaves come in.
    6. Incident reporting: DFARS 252.204-7012 requires reporting cyber incidents to DoD within 72 hours, and your incident response plan has to support that.

    How To Get CMMC Level 2 Certification

    CMMC Level 2 compliance follows the same sequence whichever assessment route your contract names:

    1. Confirm Level 2 applies. Check the solicitation and ask your prime whether CUI will flow to you.
    2. Scope the CUI environment. Map where CUI lives and decide whether an enclave can shrink the boundary.
    3. Run a gap assessment. Test every requirement against the 320 assessment objectives in NIST SP 800-171A.
    4. Remediate and document. Close gaps, write the SSP and collect evidence for each family.
    5. Score and post to SPRS. Calculate the score with the DoD Assessment Methodology, or book a C3PAO for a certified assessment.
    6. Affirm and maintain. A senior official affirms compliance in SPRS every year, and the assessment is repeated every three years.

    Level 2 Vs Level 1 Vs Level 3

    Level 1Level 2Level 3
    ProtectsFCICUIHigh-priority CUI
    Requirements15 (FAR 52.204-21)110 (NIST SP 800-171 Rev. 2)110 plus 24 from NIST SP 800-172
    AssessmentAnnual self-assessmentSelf or C3PAO every 3 yearsDoD DIBCAC every 3 years, after Level 2 C3PAO certification
    POA&MsNot allowedLimited, 180 days to closeLimited, 180 days to close
    Annual affirmationYesYesYes

    What The 2026 Changes Mean For Level 2

    Phase 1 of CMMC began on 10 November 2025, adding Level 1 and Level 2 self-assessment requirements to new solicitations. Phase 2, scheduled for 10 November 2026, would have required C3PAO certification in applicable contracts. On 13 July 2026 the Department of War suspended Phase 2 and later milestones pending a task force review, and on 3 September 2026 a class deviation made the pause binding.

    For Level 2, that means:

    • All 110 NIST SP 800-171 requirements still apply through DFARS 252.204-7012.
    • Level 2 self-assessments, SPRS scores and annual affirmations still apply where contracts require them.
    • Mandatory third-party certification is off the table for now, but voluntary C3PAO assessments continue.
    • The program may change again once task force recommendations are acted on, so treat dates as provisional.

    If you need outside help, REVERB’s lists of the top cybersecurity companies and top penetration testing companies include firms that assess and harden environments like these. For budgeting the testing side, see what penetration testing costs. For the full CMMC budget, see our guide to how much CMMC certification costs.

    Frequently Asked Questions

    What are the CMMC Level 2 requirements?

    The 110 security requirements in NIST SP 800-171 Rev. 2, across 14 families, plus a System Security Plan, a scored assessment posted in SPRS and an annual affirmation by a senior official.

    How many controls are in CMMC Level 2?

    110 requirements, broken into 320 assessment objectives.

    What is the minimum SPRS score for CMMC Level 2?

    A score of 110 means full compliance. A score of at least 88 is required for conditional status, with remaining items on a POA&M that must be closed within 180 days.

    Is CMMC Level 2 a self-assessment?

    It can be. The contract specifies either a Level 2 self-assessment or a Level 2 C3PAO assessment. Since September 2026, third-party assessment requirements have been removed from contracts, so self-assessments are the current mandatory route.

    What is the CMMC Level 2 Assessment Guide?

    A DoD document that walks through every Level 2 requirement and its assessment objectives, with examples of the evidence assessors look for. It is the reference both self-assessors and C3PAOs work from.

    Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?

    Rev. 2. NIST released Rev. 3 in 2024, but CMMC assessments continue to use Rev. 2.

    How long is a CMMC Level 2 certification valid?

    Three years, with an annual affirmation required to keep it active.

    Can I use a POA&M for CMMC Level 2?

    Yes, for a limited set of lower-weighted requirements, if your score is at least 88. All items must be closed within 180 days.

    What is the difference between CMMC Level 1 and Level 2?

    Level 1 protects FCI with 15 basic requirements and an annual self-assessment. Level 2 protects CUI with 110 requirements and a scored assessment every three years.

    The Short Version

    • Level 2 applies if you handle CUI on a DoD contract.
    • It requires all 110 NIST SP 800-171 Rev. 2 requirements across 14 families.
    • Scores run from 110 down to minus 203; 88 is the floor for conditional status and POA&Ms must close within 180 days.
    • An SSP, SPRS score and annual affirmation are mandatory.
    • Since the 2026 Phase 2 suspension, self-assessment is the required route, but every security requirement still applies.

      Once a week you will get the latest articles delivered right to your inbox