CMMC Level 2 Requirements
CMMC Level 2 covers 110 practices across 14 families, all aligned to NIST 800-171. Here is what your environment needs to satisfy and what assessors actually verify.
What CMMC Level 2 Covers
CMMC Level 2 applies to any organization that processes, stores, or transmits Controlled Unclassified Information (CUI) for the Department of Defense. It maps directly to the 110 practices in NIST SP 800-171 Rev 2, organized into 14 families covering access control, audit, configuration management, incident response, and more.
Level 2 is the threshold most defense contractors land at. Anything below it (Level 1) only handles Federal Contract Information, which is a much smaller scope. Anything above (Level 3) requires 800-172 enhanced practices and only applies to a handful of programs handling the most sensitive CUI.
The practical implication: if your DD254 or contract clause references CUI, you need Level 2. Start by reading the framework reference at our CMMC overview to confirm which contract types put you in scope.
The 14 Practice Families
The 110 practices break down across 14 families. Each family covers a security domain you need to operationalize, document, and prove during assessment:
- Access Control (AC): 22 practices covering authentication, session management, remote access
- Awareness and Training (AT): 3 practices on security training and insider threat awareness
- Audit and Accountability (AU): 9 practices on log generation, review, and retention
- Configuration Management (CM): 9 practices on baselines, change control, software inventory
- Identification and Authentication (IA): 11 practices on MFA, password policy, identity proofing
- Incident Response (IR): 3 practices on detection, reporting, response capability
- Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity: the remaining families round out the 110
Map every practice to a system, owner, and evidence file before you book your assessment.
Assessment Requirements
Level 2 has two assessment paths depending on the sensitivity of the CUI you handle. For the majority of contracts, you need a third-party assessment performed by a CMMC Third Party Assessment Organization (C3PAO). The assessment runs over multiple days, includes interviews, document review, and technical testing, and ends with a formal scoring decision.
A smaller subset of contracts allow self-assessment with annual senior-official affirmation. Even self-assessed companies still calculate and submit their SPRS score in the Supplier Performance Risk System. Self-assessment does not mean lower rigor. The DoD audits self-attestations and false claims carry significant liability under the False Claims Act.
Confirm your path by reading the contract clauses (DFARS 252.204-7012, 7019, 7020, 7021) before you scope your assessment.
Common Gaps Found During Assessments
The same handful of gaps show up across most failed assessments. Knowing them in advance lets you fix them before an assessor finds them:
- FIPS-validated cryptography: Practice SC.L2-3.13.11 requires FIPS 140-2 or 140-3 validated modules. Many cloud services advertise encryption but use non-validated modules. Check the certificate explicitly.
- MFA on all privileged accounts: IA.L2-3.5.3 requires multi-factor authentication for local and network access to privileged accounts. SMS does not count.
- SPRS score submitted but stale: Score must reflect current state and be updated when material changes occur.
- Mobile device controls: Most teams have laptops covered but ignore phones that receive corporate email.
- POA&M with vague milestones: Items like "will fix by Q4" fail. Each milestone needs date, owner, and verification step.
Run a self-assessment against these five before you schedule the C3PAO.
How to Prepare for Level 2 Certification
Treat the certification as a 12-month project, not a 12-week sprint. Here is the sequence that works:
- Scope your CUI boundary. Identify every system, network segment, and data flow that touches CUI. Document this in a network diagram.
- Build your System Security Plan (SSP). The SSP describes how each of the 110 practices is implemented in your environment. This is the primary document the assessor reads.
- Calculate your SPRS score. Use the SPRS calculator to see where you stand today.
- Build a POA&M for any practices not fully implemented. The plan must show realistic remediation dates.
- Mock assess. Hire an RPO (Registered Practitioner Organization) for a pre-assessment, or run an internal one against the CMMC Assessment Guide.
- Book the C3PAO. Assessors are scarce. Book 4-6 months in advance.
The companies that pass on the first try start this project before they need certification, not after.
Frequently Asked Questions
Related Articles
How to Calculate Your SPRS Score
The SPRS score starts at 110 and deducts weighted points for every practice you have not implemented. Here is how to calculate it correctly and what counts as fully implemented.
CMMC Plan of Action and Milestones
A CMMC POA&M is the document that lets you certify with open gaps, but only if those gaps are POA&M-eligible and the milestones are credible. Here is how to build one that holds up.
CUI Boundary Scoping for CMMC
Your CUI boundary defines what gets assessed. Get it wrong and you either over-spend on out-of-scope systems or fail because in-scope assets were missed. Here is how to scope correctly.