CMMC Level 2 Requirements: All 110 Practices, Organized by Domain
CMMC Level 2 maps directly to all 110 NIST SP 800-171 Rev 2 practices across 14 domains. This guide breaks each domain down - what it requires, how many practices it contains, and where organizations most commonly fail their C3PAO assessments.
CMMC Level 2 is built entirely on NIST SP 800-171 Rev 2 - a NIST publication that defines 110 security practices organized into 14 domains. Every practice has a number (e.g., 3.1.1), a description, and a set of assessment objectives that C3PAO assessors use to verify implementation.
This guide breaks down each domain, what it requires, and which domains are most commonly cited in assessment failures.
How the Practices Are Structured
Each practice follows the format 3.X.Y where X is the domain number and Y is the practice number within that domain. Practice 3.1.1 is Access Control practice 1. Practice 3.3.1 is Audit and Accountability practice 1. The numbering maps directly from NIST SP 800-171 Rev 2.
Assessors evaluate each practice against specific assessment objectives documented in NIST SP 800-171A. A single practice may have multiple objectives - you need to satisfy all of them to receive a MET rating.
Domain-by-Domain Breakdown
Access Control (AC) - 22 Practices
The largest domain. Covers who can access what, under what conditions. Key requirements: least privilege (3.1.3), separation of duties (3.1.4), non-privileged accounts for non-security functions (3.1.6), remote access restrictions (3.1.12-3.1.14), wireless access controls (3.1.16-3.1.17), and mobile device management (3.1.18-3.1.20). MFA for remote access (3.1.20) is one of the most frequently cited failures.
Awareness and Training (AT) - 3 Practices
Requires security awareness training for all personnel (3.2.1), role-based training for those with elevated responsibilities (3.2.2), and insider threat awareness training (3.2.3). Documentation of training completion is the primary evidence.
Audit and Accountability (AU) - 9 Practices
Requires audit logs for all CUI-system activity (3.3.1), unique user traceability (3.3.2 - no shared accounts), log content requirements, protection from modification, review and analysis, and audit failure response. Log retention and alerting on anomalies (3.3.5) are common gaps.
Configuration Management (CM) - 9 Practices
Requires baseline configurations for all CUI systems (3.4.1), configuration change control (3.4.2), security impact analysis before changes (3.4.3), user-installed software restrictions (3.4.8), and least-functionality principle - disabling unused services and features (3.4.6-3.4.7).
Identification and Authentication (IA) - 11 Practices
Covers MFA for privileged accounts (3.5.3), MFA for remote access (3.5.3), password complexity and management (3.5.7-3.5.11), authenticator management, and replay-resistant authentication. MFA is assessed here and in AC - it is the most common single failure point in CMMC assessments.
Incident Response (IR) - 3 Practices
Requires an incident response capability (3.6.1), an incident handling process covering preparation, detection, analysis, containment, recovery, and user activity (3.6.2), and testing of incident response capabilities (3.6.3). Many organizations have informal IR processes that are not documented or tested.
Maintenance (MA) - 6 Practices
Covers controlled system maintenance (3.7.1-3.7.2), maintenance tool controls (3.7.3), nonlocal (remote) maintenance requirements (3.7.4-3.7.5), and equipment removal authorization (3.7.6). Often overlooked until the assessment.
Media Protection (MP) - 9 Practices
Covers access controls on CUI media (3.8.1), removable media restrictions (3.8.7-3.8.8), marking and labeling of CUI media (3.8.2), secure storage (3.8.3), media sanitization per NIST SP 800-88 before disposal or reuse (3.8.3), and media transport controls (3.8.5-3.8.6).
Personnel Security (PS) - 2 Practices
Requires screening individuals before they are granted access to CUI systems (3.9.1) and protecting CUI during and after personnel actions (terminations and transfers) (3.9.2). The termination practice requires documented access revocation procedures with a defined timeline.
Physical Protection (PE) - 6 Practices
Covers physical access authorization (3.10.1-3.10.2), visitor escort and access logs (3.10.3), physical access device management (3.10.4), physical monitoring (3.10.5), and alternate work site protections (3.10.6). Remote work organizations often overlook the alternate work site practice.
Risk Assessment (RA) - 3 Practices
Requires a documented risk assessment process (3.11.1) aligned to NIST SP 800-30, periodic vulnerability scanning of CUI systems (3.11.2), and remediation of identified vulnerabilities (3.11.3). Quarterly scanning and a 15-day critical remediation SLA are the defensible standards.
Security Assessment (CA) - 4 Practices
Requires periodic assessment of security controls (3.12.1), a plan of action to correct deficiencies (3.12.2), monitoring of security controls on an ongoing basis (3.12.3), and development and management of a system security plan (3.12.4). The SSP requirement is housed in this domain.
System and Communications Protection (SC) - 16 Practices
Covers network segmentation and boundary protection (3.13.1-3.13.3), encryption of CUI in transit (3.13.8) and at rest (3.13.16), architectural controls, DNS filtering, and prohibition of split tunneling for remote access (3.13.7). Encryption and boundary controls are the main assessment focus.
System and Information Integrity (SI) - 7 Practices
Requires malicious code protection (antivirus/EDR) with automatic updates (3.14.2), security alerts from authoritative sources (3.14.3), software patching (3.14.4-3.14.5), security scanning for information systems (3.14.6-3.14.7), and network monitoring. Endpoint protection and patch management are assessed here.
The 5 Domains Where Most Organizations Fail
Based on assessment patterns, these five domains produce the most NOT MET findings:
- Identification and Authentication (IA) - MFA not deployed for all required access types
- Audit and Accountability (AU) - Logging not enabled, insufficient retention, no alerting
- Configuration Management (CM) - No documented baselines, uncontrolled changes
- System and Communications Protection (SC) - Unencrypted CUI, poor network segmentation
- Access Control (AC) - Excessive privileges, unreviewed accounts, split tunneling
Get All the Policies in One Download
The Complete Certification Kit includes the SSP, POA&M, and all 12 domain policies - written for each of the 14 domains above.
View the Certification Kit - $299Frequently Asked Questions
Related Resources
Keep going - these are worth reading next.