CMMC Level 2 Reference

    CMMC Level 2 requirements

    What the Cybersecurity Maturity Model Certification Level 2 actually requires: 110 NIST SP 800-171 Rev. 2 controls, 320 NIST SP 800-171A assessment objectives, 32 CFR Part 170 codification, SPRS scoring, and what a C3PAO third-party assessment covers.

    The regulatory anchor: 32 CFR Part 170

    The CMMC Program rule was finalized by the Department of Defense in October 2024 and codified in 32 CFR Part 170. The rule defines three certification levels, sets the assessment requirements for each, and gives DoD contracting officers the authority to require certification as a condition of award. CMMC requirements are now appearing in DoD solicitations alongside DFARS 252.204-7012 (the existing CUI safeguarding clause) and the forthcoming DFARS 252.204-7021 clause that will operationalize CMMC in contracts.

    The 110 controls and 320 assessment objectives

    CMMC Level 2 aligns to NIST SP 800-171 Rev. 2, which defines 110 security requirements across 14 control families. The assessment is performed against NIST SP 800-171A, which breaks each control into one or more assessment objectives — 320 in total. A C3PAO evaluates every objective; a control is "met" only if every underlying objective is met.

    AC — Access Control
    22

    AT — Awareness and Training
    3

    AU — Audit and Accountability
    9

    CM — Configuration Management
    9

    IA — Identification and Authentication
    11

    IR — Incident Response
    3

    MA — Maintenance
    6

    MP — Media Protection
    9

    PS — Personnel Security
    2

    PE — Physical Protection
    6

    RA — Risk Assessment
    3

    CA — Security Assessment
    4

    SC — System and Communications Protection
    16

    SI — System and Information Integrity
    7

    Level 1 vs. Level 2 vs. Level 3

    Level 1 covers basic safeguarding of Federal Contract Information (FCI) — 17 controls from FAR 52.204-21, annual self-assessment. Level 2 covers protection of Controlled Unclassified Information (CUI) — all 110 NIST SP 800-171 controls, third-party assessment by a C3PAO every three years for the vast majority of contractors handling CUI. Level 3 adds a subset of NIST SP 800-172 enhanced security requirements and is assessed by DIBCAC for the most sensitive CUI categories.

    SPRS scoring

    The Supplier Performance Risk System (SPRS) is the DoD's repository for contractor self-assessment scores against NIST SP 800-171. The score starts at 110 and deducts weighted points (1, 3, or 5) per unimplemented control. A perfect score is 110; a fully unimplemented environment scores -203. DoD contracting officers see the score when evaluating contractors for CUI-handling work, so the SPRS submission is materially tied to bid eligibility.

    What a C3PAO assessment covers

    The C3PAO follows the NIST SP 800-171A methodology: examine documents, interview personnel, and test technical controls. Every objective must be supported by evidence the assessor can verify on-site. The deliverables on assessment day include the System Security Plan (SSP), Plan of Action & Milestones (POA&M), Security Assessment Report (SAR), and supporting evidence — typically bundled into an eMASS-ready package. After certification, continuous monitoring obligations apply under 32 CFR Part 170; the Affirming Official must attest to ongoing compliance annually.

    Conditional vs. Final Level 2 certification

    A C3PAO can issue Conditional Level 2 certification when a limited subset of controls is deferred via POA&M. The deferral window is 180 days, high-weight controls cannot be deferred, and the POA&M must include closure plans with milestones, owners, and evidence. Final certification requires every control closed and verified. Conditional certification still allows contract award in most cases, but the clock starts immediately.

    What this means for DoD contractors

    If you handle CUI under a DoD contract — or you're a sub to a prime that does — Level 2 is on your roadmap. The work splits into evidence collection against the 320 objectives, control implementation where gaps exist, document assembly (SSP, POA&M, SAR), SPRS score submission, and a third-party assessment by a C3PAO. Each phase has its own artifacts, deadlines, and audit-trail requirements. Run the free Quick Score to baseline against the 320 objectives, then walk through the workflow automation page to see what defensible end-to-end execution looks like.

    Frequently asked questions

    What is CMMC Level 2?

    CMMC Level 2 is the Cybersecurity Maturity Model Certification tier that DoD contractors handling Controlled Unclassified Information (CUI) must achieve. It aligns to all 110 controls in NIST SP 800-171 Rev. 2 and is assessed against the 320 objectives in NIST SP 800-171A by a Certified Third-Party Assessment Organization (C3PAO).

    How many NIST SP 800-171 controls are required?

    All 110 controls across 14 control families (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, SI). CMMC Level 2 requires implementation of every control. Each control breaks down into one or more assessment objectives — 320 in total — that the C3PAO will evaluate.

    What is 32 CFR Part 170?

    32 CFR Part 170 is the CMMC Program rule finalized by the DoD in October 2024. It codifies the CMMC framework into federal regulation, defines the three certification levels, sets assessment requirements, and is now appearing in DoD solicitations alongside DFARS 252.204-7012 and the forthcoming DFARS 252.204-7021 clause.

    How is the SPRS score calculated?

    The Supplier Performance Risk System score starts at 110 and deducts weighted points (1, 3, or 5) for each unimplemented NIST SP 800-171 control. A perfect score is 110; a fully unimplemented environment scores -203. DoD contracting officers see the score when evaluating contractors for CUI-handling work.

    Can a POA&M close the gap to certification?

    A POA&M can defer a limited subset of controls under Conditional Level 2 certification, but the deferral window is 180 days and excludes high-weight controls. The POA&M must be backed by a closure plan with milestones, owners, and evidence — not a placeholder commitment.

    Ready to act on the requirements?

    Run a free Quick Score, then see what the full Assessment Pack looks like.