CMMC
CMMC Level 2 requirements, explained
If you handle Controlled Unclassified Information for the US Department of Defense, Level 2 is the bar. Here is what it contains, who assesses you, and how the rollout works.
Certifyi compliance team · Updated September 2026
Short answer. CMMC Level 2 requires implementation of the 110 security requirements in NIST SP 800-171 Revision 2, covering 14 control families from access control to system and information integrity. Most Level 2 contracts require a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO) with an annual affirmation; a smaller set allow self-assessment. The CMMC programme rule took effect on 16 December 2024 and the contract clause began phasing into new DoD solicitations from 10 November 2025.
The three levels
| Level | Applies to | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 requirements from FAR 52.204-21 | Annual self-assessment and affirmation |
| Level 2 | Controlled Unclassified Information (CUI) | 110 requirements, NIST SP 800-171 r2 | Triennial C3PAO assessment for most; self-assessment where the solicitation allows |
| Level 3 | CUI in highest-priority programmes | Level 2 plus 24 from NIST SP 800-172 | Government-led (DIBCAC) assessment |
The 14 control families
- Access Control (22 practices): least privilege, session control, remote access, CUI flow.
- Awareness and Training (3), Audit and Accountability (9), Configuration Management (9).
- Identification and Authentication (11): MFA for network and privileged access, password rules.
- Incident Response (3), Maintenance (6), Media Protection (9).
- Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4).
- System and Communications Protection (16): boundary protection, encryption of CUI in transit and at rest with FIPS-validated cryptography.
- System and Information Integrity (7): flaw remediation, malware protection, monitoring.
Scoring, SPRS and POA&Ms
Each requirement carries a weight of 1, 3 or 5 points. A perfect score is 110; unimplemented requirements are subtracted, so scores can be negative. Your score is entered in the Supplier Performance Risk System (SPRS) and must be affirmed annually by a senior official. Under CMMC you may pass with a Plan of Action and Milestones (POA&M) only if your score is at least 88, no 5-point requirement is open (with limited exceptions), and every open item is closed within 180 days, verified by a closeout assessment.
Scoping, and why it decides the cost
The assessment covers every asset that processes, stores or transmits CUI, plus security-protective assets and contractor risk-managed assets. Most of the cost of Level 2 is scope: a company that isolates CUI in a dedicated enclave assesses a fraction of the environment, while one that lets CUI flow through email and shared drives assesses everything. Define the CUI boundary first, then decide on an enclave, a FedRAMP Moderate cloud, or both.
The rollout timeline
Phase 1 from 10 November 2025 allows Level 1 and Level 2 self-assessments in solicitations. Phase 2, one year later, adds Level 2 C3PAO certification requirements. Phase 3 adds Level 3, and Phase 4 makes the clause standard across applicable contracts. Primes are already flowing Level 2 down to subcontractors, so the practical deadline is set by your customer, not the phase.
Running Level 2 in Certifyi
The NIST SP 800-171 control set is one of the frameworks on the shared control library, so evidence collected for SOC 2 or ISO 27001 maps across. The System Security Plan, POA&M and SPRS score live in the platform, and the C3PAO works in the Auditor Workspace on the same hashed evidence.
CMMC Level 2, answered
Is CMMC Level 2 the same as NIST SP 800-171?
The requirements are identical: the 110 practices in Revision 2. CMMC adds the assessment and affirmation regime that verifies you actually implemented them.
Can a small subcontractor self-assess?
Only if the solicitation designates Level 2 self-assessment. Assume a C3PAO assessment unless your contracting officer or prime confirms otherwise.
Do we need a FedRAMP cloud?
If CUI is processed or stored in a cloud service, that service must be FedRAMP Moderate authorised or meet equivalent requirements. Commercial regions of the major clouds can qualify; check the provider’s current status.
How long does Level 2 take from a standing start?
Typically six to twelve months, most of it remediation and enclave design. Companies with an existing ISO 27001 or SOC 2 programme are faster because the shared controls are already in place.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.