CMMC

CMMC Level 2 requirements, explained

If you handle Controlled Unclassified Information for the US Department of Defense, Level 2 is the bar. Here is what it contains, who assesses you, and how the rollout works.
Certifyi compliance team · Updated September 2026
Short answer. CMMC Level 2 requires implementation of the 110 security requirements in NIST SP 800-171 Revision 2, covering 14 control families from access control to system and information integrity. Most Level 2 contracts require a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO) with an annual affirmation; a smaller set allow self-assessment. The CMMC programme rule took effect on 16 December 2024 and the contract clause began phasing into new DoD solicitations from 10 November 2025.

The three levels

LevelApplies toRequirementsAssessment
Level 1Federal Contract Information (FCI)15 requirements from FAR 52.204-21Annual self-assessment and affirmation
Level 2Controlled Unclassified Information (CUI)110 requirements, NIST SP 800-171 r2Triennial C3PAO assessment for most; self-assessment where the solicitation allows
Level 3CUI in highest-priority programmesLevel 2 plus 24 from NIST SP 800-172Government-led (DIBCAC) assessment

The 14 control families

Scoring, SPRS and POA&Ms

Each requirement carries a weight of 1, 3 or 5 points. A perfect score is 110; unimplemented requirements are subtracted, so scores can be negative. Your score is entered in the Supplier Performance Risk System (SPRS) and must be affirmed annually by a senior official. Under CMMC you may pass with a Plan of Action and Milestones (POA&M) only if your score is at least 88, no 5-point requirement is open (with limited exceptions), and every open item is closed within 180 days, verified by a closeout assessment.

Scoping, and why it decides the cost

The assessment covers every asset that processes, stores or transmits CUI, plus security-protective assets and contractor risk-managed assets. Most of the cost of Level 2 is scope: a company that isolates CUI in a dedicated enclave assesses a fraction of the environment, while one that lets CUI flow through email and shared drives assesses everything. Define the CUI boundary first, then decide on an enclave, a FedRAMP Moderate cloud, or both.

The rollout timeline

Phase 1 from 10 November 2025 allows Level 1 and Level 2 self-assessments in solicitations. Phase 2, one year later, adds Level 2 C3PAO certification requirements. Phase 3 adds Level 3, and Phase 4 makes the clause standard across applicable contracts. Primes are already flowing Level 2 down to subcontractors, so the practical deadline is set by your customer, not the phase.

Running Level 2 in Certifyi

The NIST SP 800-171 control set is one of the frameworks on the shared control library, so evidence collected for SOC 2 or ISO 27001 maps across. The System Security Plan, POA&M and SPRS score live in the platform, and the C3PAO works in the Auditor Workspace on the same hashed evidence.

CMMC Level 2, answered

The requirements are identical: the 110 practices in Revision 2. CMMC adds the assessment and affirmation regime that verifies you actually implemented them.

Only if the solicitation designates Level 2 self-assessment. Assume a C3PAO assessment unless your contracting officer or prime confirms otherwise.

If CUI is processed or stored in a cloud service, that service must be FedRAMP Moderate authorised or meet equivalent requirements. Commercial regions of the major clouds can qualify; check the provider’s current status.

Typically six to twelve months, most of it remediation and enclave design. Companies with an existing ISO 27001 or SOC 2 programme are faster because the shared controls are already in place.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top