Cybersecurity and compliance professionals reviewing a 110-control CMMC framework

If your organization handles Controlled Unclassified Information (CUI) for the Department of Defense, you need a clear plan for meeting CMMC Level 2 requirements. Level 2 is the primary cybersecurity standard for many DoD contractors and subcontractors. It requires mature, documented, and operational security practices across your CUI environment.

The path can appear complex. The framework includes 110 security requirements, detailed assessment objectives, evidence reviews, technical testing, and formal documentation. This guide breaks the process into practical steps.

Important 2026 update: The Department of Defense has suspended CMMC Phase II, which was scheduled to expand mandatory third-party assessments. The suspension does not eliminate the underlying cybersecurity obligations. Contractors must continue protecting CUI, maintaining accurate self-assessments, and preparing for future requirements. Review the official Phase II implementation suspension memo for current policy direction.

Understand What Level 2 Requires

CMMC Level 2 incorporates the 110 security requirements from NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. These requirements are distributed across 14 control families:

  • Access Control (AC): 22 requirements
  • Awareness and Training (AT): 3 requirements
  • Audit and Accountability (AU): 9 requirements
  • Configuration Management (CM): 9 requirements
  • Identification and Authentication (IA): 11 requirements
  • Incident Response (IR): 3 requirements
  • Maintenance (MA): 6 requirements
  • Media Protection (MP): 9 requirements
  • Personnel Security (PS): 2 requirements
  • Physical Protection (PE): 6 requirements
  • Risk Assessment (RA): 3 requirements
  • Security Assessment (CA): 4 requirements
  • System and Communications Protection (SC): 16 requirements
  • System and Information Integrity (SI): 7 requirements

Together, these requirements address how you identify users, protect systems, manage vulnerabilities, respond to incidents, control CUI flows, secure facilities, and maintain evidence that your safeguards work.

Level 2 assessments use the assessment objectives in NIST SP 800-171A. A requirement is generally considered satisfied only when all applicable objectives have been met. Assessors examine documentation, interview personnel, and test technical or operational safeguards.

Review the DoD CMMC Assessment Guide for Level 2 for the authoritative assessment methodology.

Distinguish Level 1 from Level 2

Use the type of information your organization handles to determine the likely CMMC level.

Choose Level 1 for FCI

Level 1 focuses on Federal Contract Information (FCI). FCI is information provided by or generated for the government under a contract that is not intended for public release.

Level 1 includes 17 basic safeguarding practices based primarily on FAR 52.204-21. Typical requirements include:

  • Limiting system access to authorized users
  • Verifying users and devices
  • Controlling external system connections
  • Identifying and reporting incidents
  • Protecting system communications
  • Updating malicious code protection

Prepare for Level 2 when you handle CUI

Level 2 applies when your organization stores, processes, or transmits CUI. CUI is government information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy.

Level 2 is significantly broader than Level 1. It requires a documented and functioning security program covering all 110 NIST SP 800-171 requirements.

Do not rely only on the contract office or a data label to determine your obligations. Review:

  • Contract clauses and flow-down requirements
  • Statements of work and technical data requirements
  • CUI categories and handling instructions
  • Data received from prime contractors
  • Systems used by employees, subcontractors, and external service providers

If you support a DoD program involving technical drawings, engineering data, controlled specifications, or other regulated information, confirm whether that data qualifies as CUI.

Define Who Needs Level 2

Prioritize Level 2 if you are:

  • A prime DoD contractor handling CUI
  • A subcontractor receiving CUI from a prime contractor
  • A manufacturer, engineering firm, software company, or service provider supporting DoD programs
  • A company seeking solicitations that require protection of CUI
  • An organization using external providers to store, process, transmit, or protect CUI

Your contract determines the specific CMMC status required. Some requirements may call for a Level 2 self-assessment. Others may call for a Level 2 certification assessment performed by an accredited Certified Third-Party Assessment Organization, or C3PAO.

The formal C3PAO-led certification pathway remains the benchmark for contractors that will eventually need third-party certification. However, under the current Phase II suspension, DoD procurement documents are limited to Level 1 Self and Level 2 Self requirements during the review period. Continue monitoring the official DoD CMMC site because assessment requirements and implementation milestones may change.

Scope Your CUI Environment Correctly

Treat scoping as a strategic design decision. A well-defined scope can reduce unnecessary assessment costs and clarify accountability. A weak scope can exclude systems that an assessor later determines are relevant.

The Level 2 assessment scope includes the assets that must be evaluated against CMMC requirements. The DoD Level 2 Scoping Guide identifies five asset categories:

  • CUI assets: Systems that process, store, or transmit CUI.
  • Security protection assets: Systems, services, people, or facilities that provide security capabilities or handle Security Protection Data, such as security logs and configuration data.
  • Contractor Risk Managed Assets: Assets that could handle CUI but are prevented from doing so through documented policies, procedures, and practices.
  • Specialized assets: Assets such as Internet of Things devices, operational technology, Government Furnished Equipment, restricted information systems, and test equipment.
  • Out-of-scope assets: Assets that cannot process, store, or transmit CUI and do not provide security protections for CUI assets.

Abstract network boundary showing CUI systems, security tools, cloud services, and protected data flows

Start scoping by mapping:

  1. Where CUI enters your organization
  2. Where CUI is stored, processed, and transmitted
  3. Which users, devices, applications, and networks access CUI
  4. Which security tools protect the environment
  5. Which external service providers support the environment
  6. Where CUI leaves the environment

Document the result in an asset inventory, network diagram, and System Security Plan (SSP). Use physical or logical separation, such as dedicated enclaves, VLANs, firewalls, or approved virtual desktop infrastructure, when appropriate.

Read the DoD CMMC Scoping Guide for Level 2 before finalizing your boundary.

Follow the Level 2 Readiness Roadmap

1. Confirm contract and data requirements

Identify the CMMC level in each active contract, solicitation, and subcontract. Confirm whether your organization handles FCI, CUI, or both.

Assign executive ownership. CMMC affects IT, security, human resources, facilities, legal, procurement, operations, and program management.

2. Conduct a readiness assessment

Evaluate your current environment against all 110 requirements. Use the same principles that apply to a formal assessment.

Review:

  • Policies and procedures
  • Network and data flow diagrams
  • Asset inventories
  • User and administrator accounts
  • Endpoint and firewall configurations
  • Vulnerability scan results
  • Incident response records
  • Training records
  • Physical access records
  • Backup and media handling processes
  • Vendor and external service provider relationships

Do not treat a checklist as proof of compliance. A policy must be approved, implemented, followed, and supported by evidence.

3. Complete a documented gap analysis

Map every requirement to one of three conditions:

  • Implemented: The requirement is operating and evidence is available.
  • Partially implemented: Some objectives or components remain incomplete.
  • Not implemented: The requirement is absent or unsupported.

Prioritize gaps according to business impact and security risk. Focus first on issues that affect access to CUI, privileged accounts, multifactor authentication, encryption, logging, vulnerability remediation, incident response, and system boundaries.

4. Build and maintain your SSP

An SSP explains how your organization protects CUI. It should describe:

  • The CMMC assessment scope
  • The environment of operation
  • Systems, networks, and locations in scope
  • CUI data flows
  • Connections to other systems
  • Security roles and responsibilities
  • How each requirement is implemented
  • Approved exclusions or non-applicable requirements
  • The frequency for reviewing and updating the plan

Use the SSP as an operational document. Update it when your architecture, vendors, applications, users, or data flows change.

Compliance team collaborating on a System Security Plan and remediation roadmap

5. Create a controlled POA&M

A Plan of Action and Milestones, or POA&M, tracks deficiencies and remediation activities. Each item should include:

  • The affected requirement
  • The specific deficiency
  • Business and security impact
  • Assigned owner
  • Remediation steps
  • Milestones
  • Target completion date
  • Validation method
  • Current status

Do not use a POA&M as a substitute for implementing the controls. Treat it as a managed risk and remediation mechanism. Your target should be full implementation of all applicable requirements.

Also distinguish a CMMC assessment POA&M from an operational plan of action used for ongoing security management. They serve related but different purposes.

6. Calculate and submit your self-assessment

For a Level 2 self-assessment, evaluate the environment using the NIST SP 800-171A objectives. Calculate your score, document findings, and submit required results through the Supplier Performance Risk System (SPRS), where applicable.

Maintain evidence that supports your score. Inaccurate or unsupported self-assessments can create contractual, legal, and business risk.

7. Prepare for the C3PAO assessment

When your contract requires a third-party certification assessment, engage an accredited C3PAO and prepare for an independent review.

Expect the assessment team to use three methods:

  • Examine: Review policies, procedures, diagrams, records, configurations, and reports.
  • Interview: Speak with managers, system administrators, security personnel, and users.
  • Test: Demonstrate that technical mechanisms and operational processes work as described.

A C3PAO will validate the assessment scope and review whether your controls are implemented correctly, operating as intended, and producing the desired outcome.

Independent assessor and defense contractor security lead reviewing CMMC assessment evidence

For a final Level 2 status, plan to achieve a MET or NOT APPLICABLE finding for every applicable security requirement. If a permitted conditional status applies, understand the POA&M limitations and closeout requirements before relying on that path.

Turn Compliance Into Contract Readiness

CMMC Level 2 is more than a certification event. It is an operating discipline that protects CUI, reduces cyber risk, and strengthens your position in the Defense Industrial Base.

Start with scope. Validate your data flows. Assess all 110 requirements. Build the SSP. Assign POA&M owners. Test your controls. Keep your evidence current.

Quad-B Systems helps DoD contractors with CMMC gap analysis, SSP development, control implementation, staff training, and ongoing monitoring. We have helped more than 20 DoD contractors move toward compliance with tailored, end-to-end support.

Request a free CMMC consultation, or contact us at info@quadbsystems.com or 949.693.0664.