The CMMC Level 2 checklist comes down to three jobs: implement all 110 security controls from NIST SP 800-171 Revision 2 across every system that touches Controlled Unclassified Information, document that implementation in a System Security Plan backed by real evidence, and prove it through either a self-assessment or a Certified Third-Party Assessment Organization (C3PAO) audit depending on what your DoD contract requires. The controls span 14 domains. The proof requirements are the same regardless of assessment path. What changes is who checks your work.
Scope Your Boundary Before Anything Else
Nothing else on the checklist matters if your scope is wrong. Assess too broadly and you burn budget hardening systems that never see CUI; assess too narrowly and an assessor will find the gap in an afternoon.
Start with your contracts. Look for DFARS 252.204-7012, which imposes the NIST SP 800-171 safeguarding requirements that Level 2 is built on.1Department of Defense Chief Information Officer. About CMMC Then trace CUI end to end: where it enters, where it lives, who touches it, and how it leaves. Every person, system, and physical location in that chain is in scope.
The DoD’s scoping guidance sorts in-scope assets into three buckets, each assessed differently:2U.S. Department of Defense. CMMC Scoping Guide – Level 2
- CUI Assets process, store, or transmit CUI directly. They are assessed against all 110 Level 2 controls and must appear in your asset inventory, SSP, and network diagram.
- Security Protection Assets provide security functions for the CUI environment (firewalls, intrusion detection, authentication servers). They are assessed against the Level 2 controls relevant to what they actually do.
- Specialized Assets include IoT, operational technology, government-furnished equipment, and test systems that may handle CUI but can’t be fully secured. They must be documented and managed under your risk-based policies but aren’t held against the full control set.
Anything that neither touches CUI nor secures something that does can be excluded. A tight boundary is the single biggest lever you have on cost and audit duration.
Cloud Providers and the FedRAMP Trap
If a cloud service stores or processes your CUI, that provider’s environment is in scope. DFARS 252.204-7012 requires security equivalent to FedRAMP Moderate. A provider marketing “FedRAMP Moderate equivalency” is not the same as one holding actual FedRAMP Moderate Authorization from the FedRAMP PMO. If you rely on equivalency claims without formal authorization, you may be non-compliant no matter what the sales deck says.
For any external cloud or managed service, get a shared responsibility matrix in writing. Many NIST 800-171 requirements, especially around access management, data classification, and endpoint protection, stay with you regardless of service model.
The 110 Controls Across 14 Domains
Level 2 maps one-to-one with NIST SP 800-171 Rev 2, which organizes 110 requirements into 14 families.3National Institute of Standards and Technology. NIST SP 800-171 Rev 2 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations Every control must be implemented or placed on a Plan of Action and Milestones with a fix date. You don’t pick and choose.
Access Control
The largest family and the most common failure point. Limit access to authorized users, restrict what they can do by role, and control CUI flow between systems. Multi-factor authentication is required for local and network access to privileged accounts and for network access to non-privileged accounts. Admins need MFA everywhere; standard users need it for network logins. Unencrypted portable storage, including USB drives, must be blocked on in-scope systems.
System and Communications Protection
Encryption is required in transit and at rest, and the cryptographic modules must be validated under FIPS 140.4National Institute of Standards and Technology. Cryptographic Module Validation Program FIPS 140-2 validations remain acceptable, and NIST now also accepts FIPS 140-3 validated modules.5Computer Security Resource Center. FIPS 140-2 – Security Requirements for Cryptographic Modules Firewalls or gateways must deny traffic by default. Publicly accessible components sit on a subnet logically or physically separated from the internal CUI network so a compromised web server can’t pivot straight into controlled data.
Identification, Authentication, and Audit
Every user and device must be uniquely identified so every action on a CUI system traces to a specific person. Passwords need complexity and periodic rotation, though MFA is the real defense. Audit logs must capture login attempts, privilege changes, file access, and security-relevant events, and they must be protected from tampering. An attacker who can edit logs can erase their own tracks.
Risk Assessment and Incident Response
Vulnerability scanning across in-scope systems is required on a regular cadence, with a documented process for prioritizing and remediating findings based on CUI risk. Your incident response plan must cover detection, reporting, and containment, and it needs to be tested through tabletop exercises. A plan that has never been exercised is a document, not a capability.
Physical Protection and Maintenance
Control who enters spaces where CUI systems live. Maintain visitor logs, escort procedures, and physical access restrictions to servers and network equipment. Maintenance must be performed by authorized personnel, and any equipment leaving your facility for repair must have CUI sanitized first.
The Remaining Families
Awareness and Training, Configuration Management, Media Protection, Personnel Security, and System and Information Integrity round out the 110. Configuration Management alone requires baseline configurations for all in-scope systems plus a formal change control process. Media Protection governs labeling, handling, and destruction of physical and digital media carrying CUI. Assessors check every control in every family; a strong showing in one domain doesn’t offset gaps in another.
Documentation and Evidence
Every control needs proof. Assessors verify claims through documents, technical artifacts, and interviews.
System Security Plan
The SSP is the backbone of the assessment. It describes your architecture, data flows, and how each of the 110 controls is implemented in your actual environment: which firewalls, which access tools, which encryption methods, and how they fit together. Update it whenever the environment changes. A stale SSP that no longer matches your network is one of the fastest routes to a failed assessment.
Plan of Action and Milestones
A POA&M lists controls you haven’t fully implemented, with specific steps and deadlines. Level 2 allows certain non-critical deficiencies on a POA&M and still permits a conditional certification status, provided those items are remediated within 180 days of the assessment. High-priority controls, including multi-factor authentication and encryption of CUI, cannot be deferred. They must be fully operational at assessment time.
Evidence You’ll Need to Produce
- Technical artifacts: firewall rule sets, screenshots of security configurations, vulnerability scan reports, and log samples showing audit events are captured and retained.
- Policy documents: written policies and standard operating procedures for access management, incident response, media handling, and each other in-scope domain.
- Interview readiness: assessors interview staff to confirm employees understand their security responsibilities. A policy nobody follows is a finding.
- Physical evidence: visitor logs, images of secured server rooms, badge reader records, and equipment disposal documentation.
- Shared responsibility matrix: for cloud or managed services, a control-by-control mapping of who owns what, so the assessor sees you haven’t assumed a provider covers something that’s actually yours.
Self-Assessment or C3PAO Certification
Which path applies depends on your contract, not your preference.
Self-Assessment
For contracts involving CUI the DoD treats as lower risk, you assess yourself against all 110 controls and submit results to the Supplier Performance Risk System (SPRS).6Supplier Performance Risk System. SPRS – NIST SP 800-171 A senior official at your company must sign an affirmation certifying the results are accurate.7Supplier Performance Risk System. Supplier Performance Risk System That signature is not a formality. Misrepresenting your posture can trigger False Claims Act liability, with treble damages and per-claim penalties that adjust for inflation. Personal accountability rests on the signing official.
C3PAO Assessment
For higher-sensitivity CUI, the DoD requires an independent assessment by a Certified Third-Party Assessment Organization accredited by the Cyber AB. The C3PAO reviews your SSP, tests controls through hands-on validation, interviews staff, and submits results to the government’s database. Contracting officers check that record before award, so certification status directly affects your ability to win work.
Scoring
Your assessment produces a score out of 110, one point per implemented control, with deductions for gaps. The score and any open POA&M items sit in SPRS where contracting officers can see them. Higher scores signal lower risk. A low score with too many deferred controls can make you ineligible for award.
Flow-Down to Subcontractors
If you’re a prime sharing CUI with subs, those subs must meet the same Level 2 requirements you do. Your subcontract agreements need language mandating CMMC Level 2 compliance aligned with DFARS 252.204-7012, but a clause alone isn’t enough. Verify that subcontractors are actually implementing the 110 controls: request SPRS scores, internal assessment results, policy documentation, and remediation plans. Map every subcontractor that touches CUI, document how the data moves, and identify which entities fall under Level 2.
Weak flow-down creates findings in your own assessment, DFARS exposure, and award ineligibility. If a subcontractor’s poor security leads to a CUI breach, the prime typically bears the accountability.
Timeline Pressure
The rollout is phased, and where your contracts sit on that timeline determines urgency.1Department of Defense Chief Information Officer. About CMMC
- Phase 1 runs from November 10, 2025 to November 9, 2026. New DoD solicitations may include Level 1 and Level 2 self-assessment requirements. If you handle CUI on contracts where self-assessment suffices, you need to be compliant now, with results filed in SPRS.
- Phase 2 begins November 10, 2026. Solicitations will start requiring Level 2 certification through a C3PAO where applicable. On some contracts the DoD may delay the requirement to an option period.
Phase 2 sounds distant. It isn’t. C3PAO engagements take months to schedule and complete, and demand will spike as the deadline approaches. If your contracts will require third-party certification, start the engagement now.
Maintaining Certification After You Pass
Level 2 certification is valid for three years, after which you undergo a new assessment. During those three years you must file annual affirmations, signed by a designated official and submitted through SPRS, confirming you continue to meet all 110 controls.
If controls degrade and an annual affirmation turns out to be inaccurate, False Claims Act exposure applies the same way it would for a fraudulent initial submission. Keep the SSP current, close POA&M items on schedule, run vulnerability scans on your defined cadence, and test the incident response plan at least once a year. Compliance is an operating requirement, not a project with an end date.
One boundary worth naming: the framework is not draft or aspirational. The regulations are final, SPRS is live, and contracting officers are already checking compliance data before award. Treating CMMC as something to worry about later is a decision to lose contracts.