HomeBlogCMMC
CMMC2026-07-12SecReadyNow

CMMC Level 2 Requirements: All 110 Practices, Organized by Domain

CMMC Level 2 maps directly to all 110 NIST SP 800-171 Rev 2 practices across 14 domains. This guide breaks each domain down - what it requires, how many practices it contains, and where organizations most commonly fail their C3PAO assessments.

CMMC Level 2 is built entirely on NIST SP 800-171 Rev 2 - a NIST publication that defines 110 security practices organized into 14 domains. Every practice has a number (e.g., 3.1.1), a description, and a set of assessment objectives that C3PAO assessors use to verify implementation.

This guide breaks down each domain, what it requires, and which domains are most commonly cited in assessment failures.

How the Practices Are Structured

Each practice follows the format 3.X.Y where X is the domain number and Y is the practice number within that domain. Practice 3.1.1 is Access Control practice 1. Practice 3.3.1 is Audit and Accountability practice 1. The numbering maps directly from NIST SP 800-171 Rev 2.

Assessors evaluate each practice against specific assessment objectives documented in NIST SP 800-171A. A single practice may have multiple objectives - you need to satisfy all of them to receive a MET rating.

Domain-by-Domain Breakdown

Access Control (AC) - 22 Practices

The largest domain. Covers who can access what, under what conditions. Key requirements: least privilege (3.1.3), separation of duties (3.1.4), non-privileged accounts for non-security functions (3.1.6), remote access restrictions (3.1.12-3.1.14), wireless access controls (3.1.16-3.1.17), and mobile device management (3.1.18-3.1.20). MFA for remote access (3.1.20) is one of the most frequently cited failures.

Awareness and Training (AT) - 3 Practices

Requires security awareness training for all personnel (3.2.1), role-based training for those with elevated responsibilities (3.2.2), and insider threat awareness training (3.2.3). Documentation of training completion is the primary evidence.

Audit and Accountability (AU) - 9 Practices

Requires audit logs for all CUI-system activity (3.3.1), unique user traceability (3.3.2 - no shared accounts), log content requirements, protection from modification, review and analysis, and audit failure response. Log retention and alerting on anomalies (3.3.5) are common gaps.

Configuration Management (CM) - 9 Practices

Requires baseline configurations for all CUI systems (3.4.1), configuration change control (3.4.2), security impact analysis before changes (3.4.3), user-installed software restrictions (3.4.8), and least-functionality principle - disabling unused services and features (3.4.6-3.4.7).

Identification and Authentication (IA) - 11 Practices

Covers MFA for privileged accounts (3.5.3), MFA for remote access (3.5.3), password complexity and management (3.5.7-3.5.11), authenticator management, and replay-resistant authentication. MFA is assessed here and in AC - it is the most common single failure point in CMMC assessments.

Incident Response (IR) - 3 Practices

Requires an incident response capability (3.6.1), an incident handling process covering preparation, detection, analysis, containment, recovery, and user activity (3.6.2), and testing of incident response capabilities (3.6.3). Many organizations have informal IR processes that are not documented or tested.

Maintenance (MA) - 6 Practices

Covers controlled system maintenance (3.7.1-3.7.2), maintenance tool controls (3.7.3), nonlocal (remote) maintenance requirements (3.7.4-3.7.5), and equipment removal authorization (3.7.6). Often overlooked until the assessment.

Media Protection (MP) - 9 Practices

Covers access controls on CUI media (3.8.1), removable media restrictions (3.8.7-3.8.8), marking and labeling of CUI media (3.8.2), secure storage (3.8.3), media sanitization per NIST SP 800-88 before disposal or reuse (3.8.3), and media transport controls (3.8.5-3.8.6).

Personnel Security (PS) - 2 Practices

Requires screening individuals before they are granted access to CUI systems (3.9.1) and protecting CUI during and after personnel actions (terminations and transfers) (3.9.2). The termination practice requires documented access revocation procedures with a defined timeline.

Physical Protection (PE) - 6 Practices

Covers physical access authorization (3.10.1-3.10.2), visitor escort and access logs (3.10.3), physical access device management (3.10.4), physical monitoring (3.10.5), and alternate work site protections (3.10.6). Remote work organizations often overlook the alternate work site practice.

Risk Assessment (RA) - 3 Practices

Requires a documented risk assessment process (3.11.1) aligned to NIST SP 800-30, periodic vulnerability scanning of CUI systems (3.11.2), and remediation of identified vulnerabilities (3.11.3). Quarterly scanning and a 15-day critical remediation SLA are the defensible standards.

Security Assessment (CA) - 4 Practices

Requires periodic assessment of security controls (3.12.1), a plan of action to correct deficiencies (3.12.2), monitoring of security controls on an ongoing basis (3.12.3), and development and management of a system security plan (3.12.4). The SSP requirement is housed in this domain.

System and Communications Protection (SC) - 16 Practices

Covers network segmentation and boundary protection (3.13.1-3.13.3), encryption of CUI in transit (3.13.8) and at rest (3.13.16), architectural controls, DNS filtering, and prohibition of split tunneling for remote access (3.13.7). Encryption and boundary controls are the main assessment focus.

System and Information Integrity (SI) - 7 Practices

Requires malicious code protection (antivirus/EDR) with automatic updates (3.14.2), security alerts from authoritative sources (3.14.3), software patching (3.14.4-3.14.5), security scanning for information systems (3.14.6-3.14.7), and network monitoring. Endpoint protection and patch management are assessed here.

The 5 Domains Where Most Organizations Fail

Based on assessment patterns, these five domains produce the most NOT MET findings:

  1. Identification and Authentication (IA) - MFA not deployed for all required access types
  2. Audit and Accountability (AU) - Logging not enabled, insufficient retention, no alerting
  3. Configuration Management (CM) - No documented baselines, uncontrolled changes
  4. System and Communications Protection (SC) - Unencrypted CUI, poor network segmentation
  5. Access Control (AC) - Excessive privileges, unreviewed accounts, split tunneling

Get All the Policies in One Download

The Complete Certification Kit includes the SSP, POA&M, and all 12 domain policies - written for each of the 14 domains above.

View the Certification Kit - $299

Frequently Asked Questions

If a practice genuinely does not apply to your environment - for example, wireless access controls when you have no wireless infrastructure - you can document it as NOT APPLICABLE with a written justification. Assessors review NOT APPLICABLE claims carefully. You need documented evidence that the practice does not apply, not just an assertion.
NIST SP 800-171A is the assessment guide that describes the specific assessment objectives for each of the 110 practices. C3PAOs use 800-171A to determine exactly what evidence and conditions must be present for each practice to receive a MET rating. Reading 800-171A alongside 800-171 gives you a precise picture of what assessors look for.
They are nearly identical - CMMC Level 2 maps directly to NIST SP 800-171 Rev 2. The difference is the verification mechanism: NIST 800-171 compliance was self-attested; CMMC Level 2 requires third-party C3PAO verification for most contractors. The practices are the same.
Yes. CUI in cloud environments is in scope. Cloud systems that process, store, or transmit CUI must be included in your CMMC boundary. FedRAMP-authorized cloud services that meet FedRAMP Moderate baseline inherit some controls, but you still need to address the CMMC practices that are not covered by the cloud provider's authorization.
CMMC Level 2 certificates issued by a C3PAO are valid for 3 years. Annual affirmation by a senior official is also required during the 3-year period. If you make significant changes to your environment (major system changes, new facilities, major personnel changes), you should assess whether those changes require reassessment.

Related Resources

Keep going - these are worth reading next.

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, no spam.