Complies
CMMC GUIDES

CMMC Level 2 Requirements: All 110 NIST 800-171 Controls

JULY 2026 · 11 MIN READ · BY THE COMPLIES TEAM

CMMC Level 2 requires you to implement all 110 security requirements in NIST SP 800-171 Revision 2, across 14 control families, and to prove it. You need a System Security Plan documenting how each requirement is met, a score submitted to the Supplier Performance Risk System (SPRS) on a 110-point scale, and an annual affirmation signed by a senior official. Level 2 applies to defense contractors and subcontractors that store, process, or transmit Controlled Unclassified Information (CUI). Verification is either a self-assessment or a certification assessment by an accredited third party, and that part changed on July 13, 2026, when the Department of War suspended the Phase 2 third-party requirement. The 110 controls did not go anywhere.

The 14 NIST SP 800-171 control families

CMMC Level 2 maps one-to-one to NIST SP 800-171 Revision 2. DoD issued a class deviation in May 2024 keeping DFARS 252.204-7012 pinned to Revision 2, and CMMC assessments still use it, so set Revision 3 aside until DoD rewrites the rules pointing at it.

Control family Abbr. What it demands Controls
Access Control AC Limit access to authorized users, enforce least privilege, control remote and external connections 22
Awareness and Training AT Train personnel on security risks and their duties, including insider threat awareness 3
Audit and Accountability AU Create, protect, retain, and review logs so actions trace to individual users 9
Configuration Management CM Baselines, change control, least functionality, and an inventory of what you run 9
Identification and Authentication IA Identify users and devices, enforce multifactor authentication and password rules 11
Incident Response IR Detect, report, and respond to incidents, and test the process 3
Maintenance MA Control who performs maintenance, how, and with what tools 6
Media Protection MP Protect, mark, transport, and sanitize media holding CUI 9
Personnel Security PS Screen people before granting CUI access, protect systems during transfers 2
Physical Protection PE Limit physical access, escort visitors, keep access logs, manage badges 6
Risk Assessment RA Assess risk, scan for vulnerabilities, and remediate what you find 3
Security Assessment CA Maintain the SSP, run POA&Ms, periodically assess your controls 4
System and Communications Protection SC Boundary protection, FIPS-validated cryptography, encryption of CUI in transit and at rest 16
System and Information Integrity SI Flaw remediation, malicious code protection, monitoring and alerting 7

Access Control, System and Communications Protection, and Identification and Authentication are 49 of the 110 on their own. The small families are deceptive: Awareness and Training is three requirements, but you must train every employee who touches CUI and keep a record of who completed what and when, plus role-specific training for security duties.

What is CMMC Level 2?

CMMC Level 2 is the tier of the Cybersecurity Maturity Model Certification program covering Controlled Unclassified Information. It requires all 110 NIST SP 800-171 Rev 2 requirements, verified by self-assessment or third-party certification assessment, plus an annual affirmation. It is defined in 32 CFR Part 170 and reaches contracts through DFARS 252.204-7021.

CMMC 2.0 collapsed five levels into three. Level 1 is the 15 basic safeguarding requirements at FAR 52.204-21, covers Federal Contract Information only, and is self-assessed annually. Level 3 adds NIST SP 800-172 requirements and is assessed by the government's DIBCAC. Our guide to the three CMMC levels lays out the boundaries.

How many controls are in CMMC Level 2?

There are 110 controls in CMMC Level 2, taken directly from NIST SP 800-171 Revision 2 and organized into 14 families. No CMMC-specific practices are layered on top. Those 110 requirements decompose into 320 assessment objectives in NIST SP 800-171A, and assessors score objectives, not controls. Miss one objective and the whole requirement scores as not met. There is no partial credit, with one exception covered below.

Who needs CMMC Level 2?

You need CMMC Level 2 if you store, process, or transmit Controlled Unclassified Information under a DoD contract. That includes subcontractors: if CUI flows down to you, the requirement flows down with it. DoD has estimated roughly 80,000 companies in the Defense Industrial Base fall under Level 2.

The trigger is CUI, not company size or contract value. A ten-person shop that receives a drawing marked CUI is in scope. Do not assume you have no CUI because nothing arrived stamped, since markings are often missing or wrong, and do not forget your supply chain. If you pass CUI to a subcontractor or cloud provider, you must flow the requirement down and know whether they meet it, which is ordinary vendor risk management with sharp consequences.

What is a C3PAO?

A C3PAO is a CMMC Third-Party Assessment Organization: a company accredited by the Cyber AB to perform Level 2 certification assessments and issue certificates valid for three years. It is a real audit, scoring each of the 320 objectives as met or not met. A C3PAO cannot both consult on your remediation and certify the same scope, so plan on two vendors.

As of July 2026, though, you probably do not owe one yet. The Department of War has suspended C3PAO assessments as a contract requirement, and program managers may currently designate only Level 1 (Self) or Level 2 (Self). The last section covers what that changes.

What is an SPRS score?

An SPRS score is your NIST 800-171 self-assessment score submitted to DoD's Supplier Performance Risk System. It starts at 110 and deducts points for each requirement not fully implemented: 5 points where absence could let an attacker significantly exploit the network or exfiltrate CUI, 3 for a specific and confined effect, 1 for a limited or indirect effect. The scale runs from 110 down to a floor of -203, because the weighted deductions total 313 points.

Negative scores are common on a first honest pass, and a brand new 110 attracts attention rather than deflecting it. Scoring is all or nothing per requirement, with one meaningful exception: SC.L2-3.13.11, cryptography for CUI, where encryption that is not FIPS-validated takes a 3-point deduction instead of 5. Treat the score as a legal assertion. DoJ has settled cases over misrepresented 800-171 scores.

Can I use a POA&M for CMMC Level 2?

Yes, but narrowly. Under 32 CFR 170.21 you need a score of at least 88 out of 110 (80 percent) to earn Conditional CMMC Status, only 1-point requirements are generally eligible, and every item must close within 180 days of the Conditional status date to convert to Final. Miss the window and the status lapses.

Six requirements can never sit on a POA&M, regardless of point value:

  • AC.L2-3.1.20 Verify and control connections to external systems
  • AC.L2-3.1.22 Control CUI posted on publicly accessible systems
  • CA.L2-3.12.4 Develop, document, and update the System Security Plan
  • PE.L2-3.10.3 Escort visitors and monitor visitor activity
  • PE.L2-3.10.4 Maintain audit logs of physical access
  • PE.L2-3.10.5 Control and manage physical access devices

The SSP entry matters most: you cannot POA&M the plan itself, so arriving without a complete, current System Security Plan ends the assessment.

How much does a CMMC Level 2 assessment cost?

DoD published its own estimates in the CMMC rulemaking. For a small entity it projected roughly $105,000 across a three-year cycle: about $77,000 to conduct the assessment, roughly $21,000 to plan and prepare, about $2,900 to report results, and around $1,500 per annual affirmation. Those are government estimates, not a quote, and they exclude remediation.

Remediation is usually the larger number, and you control most of the drivers:

  • Enclave versus whole company. Keeping CUI in a defined enclave is the biggest cost lever available. Fewer systems in scope means fewer to secure, document, and assess.
  • Your baseline. Already running SOC 2 or ISO 27001 is a real head start. Ad hoc IT with shared logins is not.
  • Cloud posture. CUI generally needs FedRAMP Moderate equivalency, which for Microsoft shops usually means GCC High rather than commercial Microsoft 365. A migration, not a checkbox.
  • Documentation debt. Controls that work but were never written down still score as not met.

How long does CMMC Level 2 take?

For most small and mid-sized contractors starting from a partial baseline, expect 6 to 18 months from serious kickoff to a defensible Level 2 posture. The clock is dominated by remediation and evidence history, not the assessment itself. A cloud migration alone routinely takes three to six months, and assessors want controls operating over time, so log reviews, scans, access reviews, and training records need real history behind them.

The CMMC Level 2 assessment process, end to end

The sequence is the same whether you self-assess or bring in a C3PAO. Only the verification step changes.

  • Scope the CUI. Find every place CUI enters, lives, and leaves: email, file shares, laptops, ERP, the shop floor, the backup vendor. Draw the boundary, then shrink it. Everything inside is in scope, including people and physical space.
  • Write the System Security Plan. The SSP describes your boundary and how each of the 110 requirements is implemented. It cannot be POA&M'd, and the assessor reads it first. Policies sit underneath it, which is ordinary policy management work: approved, reviewed on a cadence, acknowledged by staff.
  • Self-assess against 800-171A, scoring all 320 objectives honestly, then build the POA&M for what fails.
  • Remediate. Close the 5-point and 3-point gaps first, since they cannot ride on a POA&M.
  • Verify. Submit the self-assessment or schedule the C3PAO assessment, depending on your contract.
  • Submit to SPRS: the score, assessment date, scope, and SSP details.
  • Affirm annually. A senior official attests to continuing compliance. The liability is personal, so that official should have seen the evidence.

A practical readiness sequence

Order matters. Doing these out of sequence is how companies spend six figures securing systems that never needed to be in scope.

  • Confirm you actually have CUI. Read the clauses, check what the prime sends, get it in writing. Some companies find they only handle FCI and owe Level 1.
  • Map the CUI flow before buying anything. Data flow first, tooling second. This step decides your budget.
  • Shrink the boundary. Every system you exclude is one you never have to document.
  • Score yourself honestly and post it. A low, accurate score with a credible POA&M is defensible. A flattering one is a liability.
  • Fix the structural items. MFA, FIPS-validated encryption, logging, access reviews, and the cloud environment carry the heavy deductions and longest lead times.
  • Write the SSP as you go, not at the end. Then run the controls long enough to leave a trail before you assess.

Many 800-171 requirements are the same underlying work as SOC 2 and ISO 27001 controls, wearing different labels. Complies does not ship a CMMC control library today and cannot certify anyone for CMMC, but if you already run SOC 2 or ISO 27001, control mapping software and compliance evidence collection mean the overlapping controls are evidenced once instead of rebuilt from scratch.

Where CMMC Level 2 stands after the July 2026 Phase 2 suspension

A memorandum dated July 10, 2026, signed by Department of War CIO Kirsten Davies and announced July 13, suspended CMMC Phase 2, which had been scheduled to make C3PAO certification the standard requirement for CUI contracts on November 10, 2026. It also halts the Phase 3 and Phase 4 milestones and directs a 60-day CMMC Reform Task Force review, citing prohibitive costs, a shortage of assessment capacity, and timelines pushing small businesses out of defense contracting.

Program managers may now designate only Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3 (DIBCAC), and solicitations carrying those requirements are to be amended. No waivers during the review. So there is no November 10 countdown to run at. Almost nothing else changed:

  • DFARS 252.204-7012 is untouched. You remain contractually obligated to implement NIST SP 800-171. That clause predates CMMC and survives it.
  • 32 CFR Part 170 and the acquisition rule are not rescinded. One verification mechanism is paused.
  • Phase 1 remains in force. Level 1 and Level 2 self-assessments and affirmations have applied since November 10, 2025 and still do.
  • Existing contract language still binds you until your contracting officer actually amends it.
  • Flow-downs survive. DoW paused its own verification, not what primes require of subs.
  • Existing certifications stay valid for their three years.

Removing the third-party check raises your exposure rather than lowering it. When an accredited assessor validated your posture, the score had a witness. Now it rests on your own attestation, submitted to a government system, in support of contract awards, with False Claims Act liability behind it. Paused is not canceled. Keep closing NIST 800-171 gaps while assessment queues are empty, make your SPRS score defensible against real evidence, and audit active contracts for C3PAO language nobody has amended out.

This reflects the situation as of July 2026. The task force report is expected around September 2026 and may reshape how Level 2 is verified, so confirm the state of play before making budget decisions. This article is educational and not legal advice; confirm your obligations against your contract clauses and with qualified counsel.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.