Nexeris

What Is CMMC Level 2? Requirements, Controls and Assessments

CMMC Level 2 is one of the most important cybersecurity requirements for organizations working in the Defense Industrial Base. It primarily applies to contractors and subcontractors that process, store, or transmit Controlled Unclassified Information (CUI) while performing work for the U.S. Department of Defense.

Unlike CMMC Level 1, which focuses on basic safeguarding of Federal Contract Information, Level 2 requires a more comprehensive cybersecurity program based on NIST SP 800-171. Organizations must implement technical and administrative safeguards, define their CUI environment, maintain accurate documentation, collect assessment evidence, and complete the assessment process required by their contract.

The CMMC implementation timeline also changed in 2026. Phase II, which was expected to expand third-party certification requirements, was suspended in July 2026. However, Level 2 self-assessment requirements and the underlying NIST SP 800-171 and DFARS obligations remain important for defense contractors handling CUI.

What Is CMMC Level 2?

CMMC Level 2 is the advanced level of the Cybersecurity Maturity Model Certification framework designed to protect CUI within contractor information systems.
Under the current CMMC framework, Level 2 aligns with the 110 security requirements in NIST SP 800-171 Revision 2. These requirements address how organizations control access, secure systems, identify threats, respond to incidents, protect communications, manage configurations, and maintain the confidentiality of sensitive government information.
Level 2 is significantly more demanding than Level 1 because CUI can include information that could negatively affect government missions, defense programs, technologies, or operations if exposed.

What Does CMMC Level 2 Protect?

CMMC Level 2 protects CUI that is processed, stored, or transmitted through contractor-owned or contractor-managed systems.
Depending on the contract, CUI may include:

  • Technical drawings
  • Engineering specifications
  • Research data
  • Controlled technical information
  • Program documentation
  • Maintenance information
  • Sensitive acquisition information
  • Other government information requiring safeguarding

The organization must understand exactly where this information is located and which users, devices, applications, servers, cloud platforms, and external providers interact with it.

CMMC Level 1 vs. Level 2

The biggest difference between CMMC Level 1 and Level 2 is the sensitivity of the information being protected.
CMMC Level 1 focuses on Federal Contract Information and uses foundational safeguarding requirements derived from FAR 52.204-21.
CMMC Level 2 applies when an organization handles CUI and requires implementation of the 110 NIST SP 800-171 Revision 2 security requirements.
Level 2 therefore involves a much more detailed cybersecurity environment, including formal scoping, a System Security Plan, security policies, assessment evidence, scoring, ongoing affirmations, and potentially more rigorous assessments depending on the contract and CMMC implementation phase.

Why Controlled Unclassified Information (CUI) Triggers Level 2

Handling Controlled Unclassified Information is one of the main reasons a defense contractor moves from CMMC Level 1 to Level 2.
CUI is not classified information, but it still requires protection because unauthorized access or disclosure could affect government programs, national security interests, technology, procurement activity, or military operations.
Organizations therefore need to determine whether they receive, create, process, transmit, or store CUI before deciding which CMMC level applies.

Who Needs CMMC Level 2 Compliance?

CMMC Level 2 generally applies to organizations participating in DoD contracts or subcontracts that involve CUI.
The size of the organization does not determine whether Level 2 applies. A small machine shop, a software company, and a major defense contractor can all face Level 2 requirements when their systems handle CUI.

DoD Prime Contractors Handling CUI

Prime contractors working directly with the Department of Defense may need CMMC Level 2 when their contract requires them to handle CUI.
These organizations need to identify which systems will process, store, or transmit CUI and establish a defined assessment boundary around those assets.
Prime contractors also need to consider which subcontractors receive CUI because applicable cybersecurity requirements can flow down through the defense supply chain.

Defense Subcontractors Handling CUI

A subcontractor does not need a direct contract with DoD to fall under CMMC Level 2.
If a prime contractor or higher-tier subcontractor provides CUI to another company, that organization may need to meet Level 2 requirements before processing the information.
This can affect component manufacturers, engineering firms, specialized suppliers, IT providers, research organizations, and many other companies supporting defense programs.

Technology, Manufacturing and Professional Service Providers

CMMC Level 2 can apply across a wide range of industries.
A manufacturer may receive controlled technical drawings. A software developer may work with defense system specifications. An engineering company may handle sensitive program documentation. A consulting business may access CUI while supporting a government project.
The organization’s industry does not determine applicability. The important question is whether its systems handle CUI while performing covered DoD work.

Cloud Providers, MSPs and External Service Providers

Cloud platforms, Managed Service Providers, Managed Security Service Providers, and other External Service Providers can also affect Level 2 compliance.
If an outside provider processes, stores, or transmits CUI, or provides security functions for the CUI environment, parts of that provider’s service may become relevant to the contractor’s CMMC scope.
Organizations therefore need to understand:

  • What information the provider handles
  • Which security controls the provider manages
  • Which responsibilities remain with the contractor
  • Whether the cloud environment meets applicable federal requirements
  • How the provider is documented within the SSP

Using a third party does not eliminate the contractor’s responsibility for protecting CUI.

What Are the CMMC Level 2 Requirements?

CMMC Level 2 requires organizations to combine technical safeguards, written documentation, defined responsibilities, evidence collection, assessment activities, and continuous compliance.

Implement the 110 NIST SP 800-171 Security Requirements

The foundation of Level 2 is implementation of the 110 NIST SP 800-171 requirements.
These requirements address how organizations protect CUI across 14 cybersecurity families, including access management, authentication, logging, configuration management, incident response, physical security, risk assessment, communications protection, and system integrity.
Implementing the requirements means more than purchasing security products. Organizations must show that safeguards are properly configured, used consistently, documented, and supported by objective evidence.

Define and Protect the CUI Environment

An organization cannot protect CUI effectively if it does not understand where the information exists.
The first step is to identify how CUI enters the organization and then follow it through the systems, users, applications, devices, networks, and providers that interact with it.
CMMC Level 2 scoping can include several categories of assets:

  • CUI Assets
  • Security Protection Assets
  • Contractor Risk Managed Assets
  • Specialized Assets
  • Out-of-Scope Assets

Correct scoping is important because it determines which systems need to be assessed.
An overly broad environment can create unnecessary cost and complexity, while an overly narrow scope can leave important systems outside the assessment boundary.

Maintain Required Security Policies and Procedures

Organizations also need written policies and procedures that accurately describe how cybersecurity controls operate.
Documentation may cover areas such as access management, password requirements, incident response, configuration management, employee training, vulnerability management, physical access, media handling, and risk assessment.
Policies should reflect actual operations.
For example, if a policy says user access is reviewed every quarter, the organization should be able to show evidence that those quarterly reviews actually happen.

Collect Evidence That Controls Are Operating Effectively

CMMC assessments are evidence-based.
An organization cannot simply tell an assessor that a requirement has been implemented. It needs documentation or technical evidence demonstrating that the safeguard exists and works.
Evidence may include:

  • Screenshots
  • Security logs
  • Configuration exports
  • Access reviews
  • Training records
  • Vulnerability reports
  • Change-management tickets
  • Incident-response records
  • Network diagrams
  • Asset inventories
  • Policies and procedures

Evidence should be current, organized, and mapped to the specific security requirements it supports.

Complete Annual Affirmations of Compliance

CMMC Level 2 also includes ongoing affirmation requirements.
An authorized organizational official must affirm that the organization continues to meet the applicable CMMC requirements.
This makes Level 2 an ongoing cybersecurity responsibility rather than a one-time project that ends after an assessment.

What Are the 14 CMMC Level 2 Control Families?

The 110 Level 2 requirements are organized into 14 families under NIST SP 800-171 Revision 2.
Together, they establish a broad cybersecurity program for protecting CUI.

Access Control

Access Control limits who and what can access systems containing CUI.
Organizations need to manage user permissions, privileged accounts, remote access, wireless access, external connections, information flows, session controls, and other methods of restricting sensitive information.

Awareness and Training

Employees must understand cybersecurity risks and their individual security responsibilities.
Organizations should provide general security awareness training as well as role-based training for employees who perform specific cybersecurity duties.

Audit and Accountability

Audit and Accountability requirements focus on logging and monitoring important system activity.
Organizations need to generate useful audit records, protect logs, review activity, maintain accurate timestamps, and support investigations when suspicious behavior occurs.

Configuration Management

Configuration Management helps organizations keep systems in a secure and controlled state.
It covers security baselines, configuration settings, change management, software restrictions, unnecessary services, and processes for approving changes that could affect security.

Identification and Authentication

Organizations must ensure that users and devices are properly identified before receiving access.
Requirements include passwords, multifactor authentication, device identification, authentication safeguards, credential protection, and controls that reduce the risk of unauthorized access.

Incident Response

Organizations need a documented process for identifying, analyzing, containing, reporting, and recovering from security incidents.
Incident response should include assigned roles, escalation procedures, reporting requirements, exercises, and evidence showing that the process is maintained.

Maintenance

Maintenance requirements address how systems are serviced and repaired securely. Organizations need controls around system maintenance activities, maintenance tools, remote maintenance, and personnel who perform maintenance on systems within the CUI environment.

Media Protection

Media Protection focuses on safeguarding digital and physical media containing CUI. This includes controlling access to media, protecting it during storage and transportation, and securely sanitizing or destroying media when it is no longer needed.

Personnel Security

Personnel security addresses risks associated with employees and other individuals who have access to sensitive systems and information. Organizations need processes for screening personnel where appropriate and protecting systems when employees are transferred or terminated.

Physical Protection

Physical protection focuses on restricting physical access to systems, equipment, facilities, and operating environments that contain or provide access to CUI. Organizations also need to manage visitors and monitor physical access where required.

Risk Assessment

Risk assessment helps organizations identify threats and vulnerabilities that could affect systems within the CUI environment. Regular assessments help teams understand cybersecurity risks and prioritize actions that reduce potential exposure.

Security Assessment

Security assessment requires organizations to periodically evaluate whether safeguards are operating effectively, develop corrective actions for identified weaknesses, monitor security controls, and maintain documentation describing how security requirements are implemented.

System and Communications Protection

These requirements focus on protecting data and communications as information moves through the environment.
They can involve network segmentation, system boundaries, encryption, secure communications, external connections, and architectural safeguards.

System and Information Integrity

System and Information Integrity requirements help organizations identify and respond to security weaknesses.
They address areas such as vulnerability management, flaw remediation, malicious code protection, security monitoring, alerts, and suspicious system activity.

What Documentation Is Required for CMMC Level 2?

Strong documentation is essential because Level 2 assessments evaluate both cybersecurity implementation and the evidence supporting that implementation.

System Security Plan (SSP)

The System Security Plan is one of the most important documents for CMMC Level 2.
The SSP should describe the organization’s security environment, including:

  • The system boundary
  • Relevant assets
  • Network architecture
  • CUI systems
  • Security responsibilities
  • External connections
  • Third-party services
  • How the NIST SP 800-171 requirements are implemented

The SSP should always describe the real environment.
Documenting a planned security control as though it is already operating can create problems during an assessment.

Policies and Standard Operating Procedures

Policies establish the organization’s cybersecurity expectations, while procedures explain how those expectations are carried out.
Typical Level 2 documentation may include procedures for identity management, incident response, security training, vulnerability management, system changes, physical security, access reviews, and media protection.
Documentation should be practical enough for employees to follow and detailed enough to support assessment evidence.

Plan of Action and Milestones (POA&M)

A Plan of Action and Milestones identifies eligible security requirements that have not yet been fully implemented and explains how they will be corrected.
However, CMMC does not allow every missing requirement to be placed on a POA&M.
Certain important security requirements must already be satisfied before an organization can receive conditional Level 2 status.
POA&Ms should therefore be treated as limited remediation tools rather than a replacement for implementing required controls.

Network Diagrams and CUI Data Flows

Network diagrams help show how the CUI environment is structured.
Organizations should clearly identify relevant systems, network segments, security tools, cloud platforms, endpoints, and external connections.
Mapping CUI data flows can also help show where information enters the organization, where it is stored, how it moves between systems, who accesses it, and where it is transmitted externally.
These diagrams make both scoping and assessment preparation much easier.

Security Control Evidence and Assessment Artifacts

Each security requirement should be supported by appropriate evidence.
Examples include logs, screenshots, access records, vulnerability scans, configuration files, policy documents, training records, ticket histories, risk assessments, and system reports.
Evidence should be organized before an assessment rather than collected at the last minute.

How Do CMMC Level 2 Assessments Work?

Under the full CMMC framework, Level 2 can involve either a self-assessment or a third-party C3PAO assessment depending on the procurement.
The 2026 Phase II suspension changes which assessment types can currently be required in DoD procurements, but the broader assessment framework remains part of CMMC.

Level 2 Self-Assessments

Level 2 self-assessments require the organization to evaluate its own implementation against the applicable NIST SP 800-171 security requirements and CMMC assessment procedures.
The resulting score and required information are submitted through the Supplier Performance Risk System.
A self-assessment should still be treated as a formal evaluation.
Organizations should review the complete scope, test safeguards, interview responsible personnel, examine evidence, and document deficiencies accurately.

Level 2 C3PAO Certification Assessments

Under the full CMMC framework, certain Level 2 contracts can require an assessment conducted by an authorized CMMC Third-Party Assessment Organization.
A C3PAO independently reviews whether the organization satisfies the applicable Level 2 requirements.
However, as of 2026, the Phase II suspension means DoD requiring activities cannot currently designate new Level 2 C3PAO requirements in procurements during the suspension period.
That does not eliminate the C3PAO assessment model itself. It affects the current rollout and procurement requirements.

Examine, Interview and Test Assessment Methods

Level 2 assessments use three primary methods to determine whether safeguards are implemented.
Examine involves reviewing documentation, configurations, policies, plans, records, and other evidence.
Interview involves speaking with personnel responsible for performing or managing security processes.
Test involves checking whether systems or safeguards operate as expected under defined conditions.
For example, an assessor may examine the multifactor authentication policy, interview the administrator responsible for identity systems, and test whether MFA is actually required for relevant users.

Assessment Scoring and Conditional Status

A Level 2 assessment has a maximum score of 110. Security requirements have different point values, so unmet requirements can reduce the overall score by different amounts depending on their significance.
An organization must score at least 88 out of 110, or 80% of the maximum score, to qualify for Conditional Level 2 status. It must also meet the applicable POA&M eligibility requirements, since certain critical security requirements cannot remain incomplete.
Conditional status gives the organization a limited period to remediate eligible outstanding requirements. Final Level 2 status is achieved after all applicable requirements are met, including successful closeout of any approved POA&M items.

POA&M Closeout Requirements

Conditional CMMC status is temporary.
Eligible requirements placed on a POA&M generally need to be remediated and verified within 180 days.
Organizations that fail to close the remaining gaps within the allowed period can lose their conditional status.
This makes it important to enter the assessment with as few unresolved requirements as possible.

What Is the Current CMMC Level 2 Assessment Status in 2026?

CMMC implementation changed significantly in July 2026.
Contractors should understand the current status rather than relying on older articles that describe the original Phase II timeline.

Phase I Level 2 Self-Assessment Requirements

CMMC currently remains in Phase I.
During this period, DoD requiring activities can include Level 1 self-assessment and Level 2 self-assessment requirements in applicable procurements.
Organizations handling CUI should therefore continue preparing for and maintaining Level 2 self-assessment readiness.
The current implementation position does not remove the obligation to comply with the underlying cybersecurity requirements.

CMMC Phase II and C3PAO Assessment Suspension

On July 13, 2026, the Department suspended implementation of CMMC Phase II, which had been scheduled to begin later in 2026.
The CMMC Phase 2 suspension means requiring activities may not currently designate Level 2 C3PAO or Level 3 DIBCAC assessment requirements during the suspension.
Level 1 and Level 2 self-assessments remain available under Phase I.
The suspension changes the timeline for broader third-party certification. It does not eliminate CMMC or the underlying cybersecurity requirements.

What Level 2 Contractors Still Need to Do

Organizations handling CUI should continue working toward strong NIST SP 800-171 compliance.
Important activities include:

  • Maintaining Level 2 security requirements
  • Keeping the SSP accurate
  • Updating policies and procedures
  • Maintaining assessment evidence
  • Tracking CUI assets
  • Monitoring third-party dependencies
  • Keeping assessment information current
  • Continuing DFARS compliance
  • Addressing security weaknesses

Organizations should use the Phase II suspension as additional preparation time rather than assuming CMMC requirements have disappeared.

How CMMC Level 2 Relates to NIST 800-171 and DFARS

CMMC Level 2, NIST SP 800-171, and DFARS work together but serve different purposes.

CMMC Level 2 vs. NIST SP 800-171

NIST SP 800-171 defines the cybersecurity safeguards used to protect CUI in applicable nonfederal systems.
CMMC Level 2 uses the 110 NIST SP 800-171 Revision 2 security requirements as its foundation and adds formal processes for assessment, scoping, scoring, evidence, status, POA&Ms, and ongoing affirmations.
In simple terms, NIST SP 800-171 describes what security requirements need to be implemented, while CMMC provides the framework for demonstrating that those requirements are actually implemented.

CMMC Level 2 and DFARS 252.204-7012

DFARS 252.204-7012 establishes important cybersecurity responsibilities for contractors handling covered defense information.
These requirements can include safeguarding covered contractor information systems, implementing NIST SP 800-171 requirements, reporting certain cyber incidents, preserving relevant system information, and meeting other contractual cybersecurity obligations.
CMMC Level 2 does not replace DFARS.
Organizations can be responsible for meeting DFARS cybersecurity requirements while also maintaining the applicable CMMC status.

SPRS and Level 2 Compliance

The Supplier Performance Risk System, or SPRS, plays an important role in DoD cybersecurity assessments.
Organizations subject to applicable NIST SP 800-171 requirements may need a current assessment score in SPRS.
CMMC Level 2 self-assessment information is also submitted through SPRS.
Contractors should make sure that any score submitted to the government accurately reflects the real cybersecurity environment and can be supported by evidence.

How to Prepare for CMMC Level 2

CMMC Level 2 preparation becomes easier when organizations follow a structured sequence rather than trying to resolve every requirement at once.

Identify and Scope Your CUI Environment

Begin by identifying what CUI the organization handles.
Determine where the information enters the company, which employees access it, which systems process it, where it is stored, how it is transmitted, and which providers support those systems.
Then define the assessment boundary around the relevant assets.

Conduct a NIST 800-171 Gap Assessment

Compare the current cybersecurity environment against all 110 applicable requirements.
For each requirement, determine:

  • Whether it is implemented
  • Where it is implemented
  • Who owns it
  • Whether documentation exists
  • Whether evidence is available
  • Whether actual operations match the documented process

A gap assessment should identify weaknesses accurately rather than focus on producing the highest possible score.

Remediate Technical and Documentation Gaps

Once gaps are identified, prioritize them according to complexity and security impact.
Technical remediation may involve:

  • Multifactor authentication
  • Identity and access management
  • Endpoint protection
  • Logging
  • Encryption
  • Network segmentation
  • Vulnerability management
  • Secure cloud architecture
  • Incident response

Documentation should be updated as technical changes are implemented.

Build and Maintain Your SSP

The SSP should be developed alongside the technical environment rather than written immediately before the assessment.
It needs to stay accurate as systems, networks, vendors, controls, and responsibilities change.
A well-maintained SSP can also reveal implementation gaps because teams are required to explain exactly how each security requirement operates.

Organize Assessment Evidence

Create a structured evidence repository mapped to the Level 2 requirements.
Assign an owner to each requirement and identify which evidence proves implementation.
Evidence should also be updated regularly so assessors are not presented with outdated screenshots, expired records, or policies that no longer match current operations.

Conduct a Pre-Assessment Readiness Review

Before completing the required assessment, perform a realistic readiness review.
A strong CMMC audit preparation process should evaluate the assessment scope, SSP, policies, network diagrams, security controls, evidence, external providers, employee understanding, and remaining remediation items.
This helps identify problems before they affect the official assessment.

Common CMMC Level 2 Compliance Challenges

Many Level 2 problems are caused by weak scoping, documentation, and evidence rather than a complete absence of cybersecurity tools.

Incorrect CUI Scoping

Incorrect scope can make a CMMC project unnecessarily difficult or leave important assets unprotected.
Organizations should understand exactly where CUI exists before defining their Level 2 environment.
Segmentation and carefully controlled data flows can often help reduce the number of systems that need to be included.

Incomplete SSP Documentation

The SSP should clearly describe the real cybersecurity environment.
Generic descriptions, missing assets, outdated network diagrams, incorrect vendor information, or incomplete control explanations can create assessment issues.
The document should be updated whenever meaningful changes occur.

Missing Evidence for Implemented Controls

Organizations frequently have security controls in place but cannot provide evidence showing that those controls operate consistently.
Examples include performing access reviews without retaining records or maintaining vulnerability management processes without preserving reports.
Evidence collection should therefore become part of normal cybersecurity operations.

Cloud and Third-Party Compliance Gaps

Cloud platforms, MSPs, MSSPs, SaaS applications, and other service providers may affect the CUI environment.
Organizations need to understand which party is responsible for each security requirement and whether the provider’s environment meets the applicable requirements.
Third-party relationships should also be reflected correctly in the SSP and assessment scope.

Treating CMMC as a One-Time Assessment

Passing an assessment does not mean compliance work is finished.
Technology changes. Employees leave. Vendors change. New applications are introduced. Security vulnerabilities appear. CUI may begin flowing through new systems.
CMMC therefore requires continuous cybersecurity management.
Organizations should maintain controls, documentation, evidence, risk assessments, and security processes between formal assessment cycles.

How Nexeris Helps With CMMC Level 2 Readiness

Preparing for CMMC Level 2 requires coordination between cybersecurity, compliance, IT, contracts, leadership, and outside service providers.
Nexeris provides CMMC Level 2 consulting to help defense contractors understand their requirements and build a practical path toward readiness.
Support can include identifying CUI, defining the CMMC assessment scope, conducting NIST SP 800-171 gap assessments, prioritizing remediation, developing the SSP, reviewing security policies, evaluating cloud and MSP dependencies, organizing assessment evidence, and performing readiness reviews.
The 2026 Phase II suspension gives many contractors additional preparation time, but it does not eliminate existing cybersecurity obligations. Organizations that continue improving their security controls, documentation, and evidence will be better positioned for current Level 2 self-assessment requirements and future CMMC assessment changes.

FAQs

1. What is CMMC Level 2?

CMMC Level 2 is the advanced CMMC level primarily designed for organizations that process, store, or transmit Controlled Unclassified Information. It aligns with the 110 security requirements in NIST SP 800-171 Revision 2 and requires organizations to demonstrate that those safeguards are properly implemented.

2. Who needs CMMC Level 2 compliance?

DoD prime contractors and subcontractors that handle CUI may need CMMC Level 2 when required by their contract or solicitation. Manufacturers, software providers, engineering firms, professional service companies, and other defense suppliers can also fall under Level 2 when they handle CUI.

3. How many controls are required for CMMC Level 2?

CMMC Level 2 contains 110 NIST SP 800-171 Revision 2 security requirements across 14 cybersecurity families. These are commonly referred to as controls, although the CMMC regulation formally refers to them as security requirements.

4. Does CMMC Level 2 require a C3PAO assessment in 2026?

Not for new procurement requirements during the current Phase II suspension. As of 2026, DoD requiring activities can designate Level 2 self-assessments, while broader Level 2 C3PAO procurement requirements have been suspended. The C3PAO assessment framework still exists, but its Phase II rollout is currently paused.

5. What is the difference between CMMC Level 2 and NIST SP 800-171?

NIST SP 800-171 defines the security requirements used to protect CUI. CMMC Level 2 uses those NIST requirements and adds a structured framework for scoping, assessments, scoring, evidence, POA&Ms, affirmations, and maintaining compliance.

Zach Tracy, Nexeris founder and CEO

Zach Tracy, CISA, CISSP

Zach Tracy is the CEO and a cybersecurity executive with more than 10 years of experience in security program management and regulatory compliance. He has served as a fractional Chief Information Security Officer for over 40 organizations and has led more than 100 audits across frameworks including SOC 2, CMMC, NIST CSF, ISO 27001, HIPAA, and HITRUST.

Zach specializes in helping defense contractors and regulated organizations build practical, audit-ready security programs that protect contract eligibility and reduce operational risk. He holds CISA, CISSP, CMMC-RP, and ISO 27001 and 9001 Lead Implementer certifications, along with a B.S. in Cybersecurity from Thomas College.

A Marine Corps veteran and former law enforcement officer, Zach brings a mission-focused, disciplined approach to cybersecurity leadership.

Connect with Zach on LinkedIn

Scroll to Top