What CMMC Level 2 is
CMMC Level 2 is the tier for contractors that handle Controlled Unclassified Information. Where Level 1 asks for fifteen basic safeguarding requirements, Level 2 is the full set of 110 security requirements in NIST Special Publication 800-171, assessed across 320 objectives.
The 110 requirements are not new either. DFARS 252.204-7012 has obliged defense contractors handling covered defense information to implement NIST SP 800-171 since 2017. What CMMC added was a verification regime on top of a requirement that had been largely self-declared: a scored assessment, a record in the Supplier Performance Risk System, an annual affirmation, and — for part of the industrial base — an independent assessor.
Revision 2 remains the assessment baseline. NIST published Revision 3 of SP 800-171, but the Department has issued a class deviation confirming that Rev. 2 is what Level 2 is assessed against until that changes.
Who it applies to
Level 2 reaches any organization that processes, stores, or transmits Controlled Unclassified Information on a DoD contract. CUI is government-created or government-owned information that requires safeguarding under law, regulation, or government-wide policy — in the defense context most often controlled technical information: drawings, specifications, process sheets, test data, source code, and engineering documentation.
The distinction from Level 1 is what the data is, not how large the company is. A ten-person machine shop that receives a controlled drawing is in Level 2 territory. A large services firm that only ever sees schedules and invoices may not be.
- –Manufacturers and engineering firms receiving controlled technical information or export-controlled data
- –Software and cloud providers whose systems hold CUI on a defense contract
- –Primes that generate CUI and flow it down, and every subcontractor that receives it
- –Research organizations and universities performing on defense contracts involving controlled data
- –Managed service providers and hosting partners inside a client CUI boundary
The 110 requirements, by family
NIST SP 800-171 organizes its 110 requirements into fourteen families. The count per family is worth knowing before scoping, because the weight is not evenly distributed: access control and system and communications protection alone carry more than a third of the total.
- –Access Control — 22 requirements
- –System and Communications Protection — 16
- –Identification and Authentication — 11
- –Audit and Accountability — 9
- –Configuration Management — 9
- –Media Protection — 9
- –System and Information Integrity — 7
- –Maintenance — 6
- –Physical Protection — 6
- –Security Assessment — 4
- –Awareness and Training — 3
- –Incident Response — 3
- –Risk Assessment — 3
- –Personnel Security — 2
Scoping is the decision that sets the cost
Before any control work begins, Level 2 asks a question that determines everything after it: where does CUI actually live? Every system, service, device, and person inside that boundary is in scope for all 110 requirements. Everything outside it is not.
An organization that never answers this deliberately ends up assessing its whole network, which means hardening laptops, servers, collaboration tools, and business applications that never touch controlled data. The alternative is a defined enclave — a bounded environment where CUI is received, worked on, and stored, with controlled paths in and out — which narrows the assessment to the systems that genuinely hold the data.
Scoping also decides what your external providers are. A cloud service that stores or processes CUI is inside the boundary and carries requirements of its own. Discovering that after the environment is built is expensive; discovering it during an assessment is worse.
- –Identify every inbound path CUI arrives by — email, supplier portals, file transfer, physical media, drawings shipped with a purchase order
- –Decide between an enclave and a whole-network scope, and document why
- –Categorize every asset: CUI, security protection, contractor risk managed, specialized, and out of scope
- –Determine which external service providers sit inside the boundary and what they are obliged to implement
- –Write the asset inventory and network diagram that the assessment will be run against
The System Security Plan, the score, and the POA&M
Level 2 produces a System Security Plan describing how each of the 110 requirements is implemented in the environment you scoped. This is the document an assessor reads first and tests against, and a plan that describes an intended state rather than the running configuration is the fastest way to fail.
Implementation is scored to a maximum of 110 in SPRS, with points deducted for unimplemented requirements — one, three, or five depending on weight — so an unstarted environment can score well below zero. A score of 88 or better, with the remaining gaps on a Plan of Action and Milestones, supports a Conditional status; the POA&M must be closed out and verified within 180 days to reach Final. Certain high-weight requirements cannot be carried on a POA&M at all, which is why a score alone does not tell you whether you are eligible.
- –A System Security Plan covering all 110 requirements as implemented, not as intended
- –Supporting policies and procedures that match what the systems actually do
- –Evidence for each of the 320 objectives, collected and dated
- –A Plan of Action and Milestones with owners, milestones, and closure dates for every open gap
- –An SPRS score submitted under the correct scope and CAGE code
- –An annual affirmation of continuing compliance by a named affirming official
Self-assessment, C3PAO assessment, and where the program stands
Level 2 has two assessment paths. Level 2 (Self) is a self-assessment on the same 110 requirements, submitted to SPRS and affirmed annually. Level 2 (C3PAO) is an assessment performed by an authorized CMMC Third-Party Assessment Organization, valid for three years with annual affirmations in between. Which path a contract requires is set by the program office that wrote it.
The acquisition rule took effect on 10 November 2025, opening Phase 1 and putting self-assessment requirements into DoD solicitations. On 13 July 2026 the Department of War suspended Phase 2 — the milestone at which C3PAO assessment was to become mandatory for CUI contracts, set for 10 November 2026 — and stood up a reform task force. Solicitations and contracts already carrying Level 2 (C3PAO) or Level 3 requirements were directed to have them removed. The task force delivered its recommendations to the department CIO on 13 September 2026, and the outcome had not been published as of the date on this page.
What the suspension paused is the third-party assessment milestone, not the requirement. Phase 1 self-assessments remain in force, DFARS 252.204-7012 safeguarding obligations were never suspended, SPRS scores and annual affirmations are still expected, and the Department has said it will continue to enforce NIST SP 800-171 through self-assessment and government-led assessment — the Defense Industrial Base Cybersecurity Assessment Center has always been able to audit a score it does not believe. No plausible outcome of the review removes the 110 requirements, which is the argument for treating the pause as schedule relief rather than as a reason to stop.
Why it does not stay finished
An assessment describes an environment on a date. Systems get rebuilt, staff change, a new collaboration tool arrives, a supplier starts sending drawings by a different route, and the boundary you documented stops matching the boundary you have.
Because the affirmation is annual and signed, that drift carries weight that the underlying engineering work does not. A statement that was accurate when it was made becomes inaccurate without anyone deciding to make it false. The record has to be maintained at the pace the environment changes, not at the pace of the assessment cycle.
How Verdict helps
Verdict runs the Level 2 work as an engagement. We scope the CUI boundary and defend that decision in writing, assess all 110 requirements and their 320 objectives against the running environment, build the System Security Plan and the policy set behind it, drive the remediation that moves the SPRS score, and assemble the evidence an assessor will ask for.
We prepare, we do not assess. A CMMC assessment belongs to an authorized C3PAO or to the government, and we do not compete with them for that role — we build and maintain what they examine, and we work alongside them rather than in place of them. The affirming official is yours, and our job is to make sure what gets affirmed is true.
After the assessment we keep the record current: the plan, the evidence, the POA&M, and the score, maintained as the environment changes and reviewed by you in a client portal. Nothing to install, and nothing for your team to operate.
CMMC Level 2 is part of federal authorization, the work that covers what an agency, or a company selling to one, has to satisfy before a system can operate or be bought. The same lane also covers FedRAMP, CMMC Level 1, NIST SP 800-53, and FISMA. For the mechanics of an engagement, see how we work.

