HomeBlogCompliance

CMMC Level 2 Requirements: The 110 Controls Explained

Pixel-art illustration of a robot on a pirate ship's deck holding up a glowing blue shield against red bug-shaped threats above stormy waves

CMMC Level 2 requires a defense contractor that handles controlled unclassified information (CUI) to meet all 110 security requirements in NIST SP 800-171 Revision 2. Since the Department of War suspended Phase II on July 13, 2026, Level 2 is met by a self-assessment every three years, scored in SPRS and affirmed every year by a senior official.

We checked the Department of War CIO's CMMC pages on October 7, 2026: Phase II remains suspended. Our CMMC compliance services scope where CUI lives, build the controls and write the System Security Plan; we are not a C3PAO and certify no one. This is general information, not legal advice.

Who needs CMMC Level 2?

Any company that will process, store or transmit CUI on its own systems while performing a defense contract or subcontract. The CMMC program rule, 32 CFR Part 170, applies to primes and subcontractors at every tier: a subcontractor that handles only federal contract information (FCI) needs Level 1, and one that handles CUI needs at least Level 2 (Self). Our CMMC glossary entry explains the program as a whole.

CUI is government information that a law, regulation or government-wide policy requires or permits to be handled with safeguarding or dissemination controls, such as drawings or specifications marked CUI. If a prime sends you files like that, ask in writing which CMMC level the subcontract carries. If you only handle non-public contract information, read our CMMC Level 1 checklist instead.

What are the 110 CMMC Level 2 requirements?

Level 2 uses the 110 requirements of NIST SP 800-171 Revision 2, grouped into 14 families that CMMC calls domains. NIST withdrew Revision 2 on May 14, 2024, when it published Revision 3, but the Department still applies Revision 2 for both CMMC and DFARS 252.204-7012. Our NIST SP 800-171 glossary entry explains the standard itself.

FamilyRequirementsWhat it covers
Access Control (AC)22Authorized users and devices, least privilege, separate admin accounts, remote and wireless access, encrypting CUI on mobile devices
Awareness and Training (AT)3Security awareness, role-based training, insider threat awareness
Audit and Accountability (AU)9Audit logs that trace actions to users, log review, alerts when logging fails, protected logs
Configuration Management (CM)9Baseline configurations, approved changes, least functionality, application allow or deny lists, control of user-installed software
Identification and Authentication (IA)11Unique identifiers, multifactor authentication, replay-resistant authentication, password rules, no reuse of identifiers
Incident Response (IR)3An incident handling capability, tracking and reporting incidents, testing the response
Maintenance (MA)6Controlled maintenance and tools, sanitizing equipment removed for repair, MFA for remote maintenance, supervising maintenance staff
Media Protection (MP)9Protecting, marking and sanitizing media with CUI, encrypting portable storage, controlling removable media, protecting backups
Personnel Security (PS)2Screening people before access, protecting CUI when staff leave or transfer
Physical Protection (PE)6Limiting and monitoring physical access, escorting visitors, access logs, safeguards at alternate work sites
Risk Assessment (RA)3Periodic risk assessments, vulnerability scans, remediation
Security Assessment (CA)4Assessing controls, plans of action, ongoing monitoring, the System Security Plan
System and Communications Protection (SC)16Boundary protection, deny by default, no split tunneling, separate subnetworks for public systems, FIPS-validated encryption for CUI in transit and at rest
System and Information Integrity (SI)7Flaw remediation, malware protection and scans, security alerts, monitoring for attacks and unauthorized use

A self-assessment checks every assessment objective in NIST SP 800-171A; miss one, and the whole requirement is scored as not met.

How is CMMC Level 2 assessed during the Phase II suspension?

On July 13, 2026 the Department of War suspended Phase II, which was due to start on November 10, 2026. The Department of War CIO's CMMC page says that all Phase I self-assessment requirements remain in place. The implementing memo says that during the suspension, program offices may only require CMMC Level 1 (Self) or Level 2 (Self), may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, and will grant no waivers. Contracts that already carry a C3PAO or DIBCAC requirement are to have it removed at the next option period or administrative modification, so check yours.

The memo also says the Department will enforce NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments, and that DFARS 252.204-7012 remains in effect, including its 72-hour cyber incident reporting. Third-party assessment by a C3PAO still exists in the rule, every three years, but no new contract can require it during the suspension. Further guidance is due at the end of the CIO's 60-day review; on October 7, 2026 none had been posted. Our post on the CMMC Phase II suspension tracks what changes next.

How is a Level 2 self-assessment scored in SPRS?

The CMMC scoring method in 32 CFR 170.24 starts at the maximum, 110, and subtracts the value of each requirement that is not met: 5, 3 or 1 points, depending on how much risk the gap creates. The score can go negative, and partial credit exists only in limited cases, such as multifactor authentication. A requirement that does not apply counts as met, and evidence must be in final form: drafts and unapproved policies do not count.

Enter the results in the Supplier Performance Risk System (SPRS): the level, date, scope, CAGE codes and overall score, such as 105 out of 110. A senior person, the Affirming Official, then affirms compliance in SPRS, again after any POA&M closeout and every year after that. Keep the evidence for six years from the status date.

What are the POA&M limits for Level 2?

A plan of action and milestones (POA&M) lets you hold a Conditional Level 2 (Self) status while you close a few gaps, but only within limits set by 32 CFR 170.21:

  • Your score must be at least 80% of the maximum, which is 88 of 110.
  • No requirement on the POA&M may be worth more than 1 point, except CUI encryption (SC.L2-3.13.11) when you encrypt with cryptography that is not FIPS-validated.
  • Six requirements can never go on a POA&M: external connections (AC.L2-3.1.20), control of public information (AC.L2-3.1.22), the System Security Plan (CA.L2-3.12.4), and escorting visitors, physical access logs and managing physical access (PE.L2-3.10.3 to 3.10.5).
  • You must close every item and complete a closeout self-assessment of those items within 180 days, or the conditional status expires.

What goes in the System Security Plan?

Requirement CA.L2-3.12.4 asks for a System Security Plan (SSP) that describes the system boundary, the environments it runs in, how each requirement is implemented and its connections to other systems. NIST prescribes no format and offers a template. Write it from the configuration you deployed: for each requirement, name the setting, the procedure and the evidence, and keep the asset inventory and network diagram the scoping rule expects beside it. The SSP can never sit on a POA&M, and an enduring exception it documents, with its mitigations, is assessed as met.

How does an enclave shrink the scope?

Every asset that processes, stores or transmits CUI is assessed against all 110 requirements, so the cheapest Level 2 is usually the smallest one. 32 CFR 170.19 sorts assets into five categories:

Asset categoryWhat it isHow it is assessed
CUI assetsSystems that process, store or transmit CUIAgainst all Level 2 requirements
Security protection assetsTools that protect the scope, such as the firewall, identity provider or monitoringAgainst the requirements relevant to what they do
Contractor risk managed assetsSystems that could handle CUI but are kept from it by policy and practiceDocumented in the SSP; an assessor may run a limited check
Specialized assetsIoT, operational technology, test equipment and government-furnished equipmentDocumented and managed under your risk-based policies
Out-of-scope assetsSystems that cannot handle CUI and are physically or logically separatedNot assessed; be ready to justify why they cannot handle CUI

An enclave puts CUI, and the people who need it, into a separate environment, such as a dedicated cloud tenant or a segmented network, so most of the company falls out of scope. A cloud service that holds CUI must be FedRAMP Moderate authorized or meet equivalent requirements, and which Microsoft 365 environment fits (commercial, GCC or GCC High) depends on the data you hold.

What is a realistic sequence for reaching Level 2?

  1. Confirm the data. Read each contract and flow-down, and ask the prime in writing whether you will receive CUI.
  2. Map where CUI goes and draw the boundary.
  3. Assess the gaps against the NIST SP 800-171A objectives.
  4. Fix the 5-point requirements first. They move the score most and can never go on a POA&M.
  5. Write the SSP from the deployed configuration.
  6. Self-assess with the 32 CFR 170.24 method, using a POA&M only where the rule allows.
  7. Enter and affirm in SPRS.
  8. Operate it: monitor and patch all year, affirm annually and reassess within three years.

Our pages for government contractors and manufacturers cover the rest of their IT.

Frequently asked questions

Is CMMC Level 2 certification required right now?

Not by any new contract. During the Phase II suspension, contracts may require only Level 1 (Self) or Level 2 (Self), and C3PAO requirements are to come out of existing contracts. The 110 requirements still apply. We checked this on October 7, 2026.

How often is a CMMC Level 2 self-assessment required?

Every three years, with an affirmation by your Affirming Official at each assessment and every year in between. The Department of War CIO's CMMC page says an assessment lapses if the annual affirmation is missed.

What SPRS score do you need for CMMC Level 2?

A final Level 2 (Self) status needs every requirement met, a score of 110, with requirements that do not apply counted as met. A score of at least 88 can earn a conditional status if the open items meet the POA&M rules, but they must be closed and reassessed within 180 days.

Sources and further reading

CMMC 2.0 Compliance Services

Discuss cmmc 2.0 compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore CMMC 2.0 Compliance Services 845-203-3914