The regulatory anchor: 32 CFR Part 170
The CMMC Program rule was finalized by the Department of Defense in October 2024 and codified in 32 CFR Part 170. The rule defines three certification levels, sets the assessment requirements for each, and gives DoD contracting officers the authority to require certification as a condition of award. CMMC requirements are now appearing in DoD solicitations alongside DFARS 252.204-7012 (the existing CUI safeguarding clause) and the forthcoming DFARS 252.204-7021 clause that will operationalize CMMC in contracts.
The 110 controls and 320 assessment objectives
CMMC Level 2 aligns to NIST SP 800-171 Rev. 2, which defines 110 security requirements across 14 control families. The assessment is performed against NIST SP 800-171A, which breaks each control into one or more assessment objectives — 320 in total. A C3PAO evaluates every objective; a control is "met" only if every underlying objective is met.
AC — Access Control22
AT — Awareness and Training3
AU — Audit and Accountability9
CM — Configuration Management9
IA — Identification and Authentication11
IR — Incident Response3
MA — Maintenance6
MP — Media Protection9
PS — Personnel Security2
PE — Physical Protection6
RA — Risk Assessment3
CA — Security Assessment4
SC — System and Communications Protection16
SI — System and Information Integrity7
Level 1 vs. Level 2 vs. Level 3
Level 1 covers basic safeguarding of Federal Contract Information (FCI) — 17 controls from FAR 52.204-21, annual self-assessment. Level 2 covers protection of Controlled Unclassified Information (CUI) — all 110 NIST SP 800-171 controls, third-party assessment by a C3PAO every three years for the vast majority of contractors handling CUI. Level 3 adds a subset of NIST SP 800-172 enhanced security requirements and is assessed by DIBCAC for the most sensitive CUI categories.
SPRS scoring
The Supplier Performance Risk System (SPRS) is the DoD's repository for contractor self-assessment scores against NIST SP 800-171. The score starts at 110 and deducts weighted points (1, 3, or 5) per unimplemented control. A perfect score is 110; a fully unimplemented environment scores -203. DoD contracting officers see the score when evaluating contractors for CUI-handling work, so the SPRS submission is materially tied to bid eligibility.
What a C3PAO assessment covers
The C3PAO follows the NIST SP 800-171A methodology: examine documents, interview personnel, and test technical controls. Every objective must be supported by evidence the assessor can verify on-site. The deliverables on assessment day include the System Security Plan (SSP), Plan of Action & Milestones (POA&M), Security Assessment Report (SAR), and supporting evidence — typically bundled into an eMASS-ready package. After certification, continuous monitoring obligations apply under 32 CFR Part 170; the Affirming Official must attest to ongoing compliance annually.
Conditional vs. Final Level 2 certification
A C3PAO can issue Conditional Level 2 certification when a limited subset of controls is deferred via POA&M. The deferral window is 180 days, high-weight controls cannot be deferred, and the POA&M must include closure plans with milestones, owners, and evidence. Final certification requires every control closed and verified. Conditional certification still allows contract award in most cases, but the clock starts immediately.
What this means for DoD contractors
If you handle CUI under a DoD contract — or you're a sub to a prime that does — Level 2 is on your roadmap. The work splits into evidence collection against the 320 objectives, control implementation where gaps exist, document assembly (SSP, POA&M, SAR), SPRS score submission, and a third-party assessment by a C3PAO. Each phase has its own artifacts, deadlines, and audit-trail requirements. Run the free Quick Score to baseline against the 320 objectives, then walk through the workflow automation page to see what defensible end-to-end execution looks like.