What is CMMC Level 2? A Plain-English Guide for Defense Contractors
CMMC Level 2 applies to any defense contractor handling Controlled Unclassified Information. It requires third-party verification of all 110 NIST SP 800-171 practices - and it is already appearing in DoD contracts. Here is what it means and what you need to do.
If your company does business with the Department of Defense, you have probably seen CMMC in a solicitation by now. Maybe a prime contractor asked you to complete a questionnaire. Maybe a contracting officer mentioned it in a pre-award conversation. Either way, you need to understand what it is, what it requires, and whether it applies to you before you lose a contract over it.
This guide answers the fundamentals without the bureaucratic jargon.
What CMMC Actually Is
CMMC stands for Cybersecurity Maturity Model Certification. It is a DoD program that requires defense contractors and their subcontractors to meet verified cybersecurity standards before they can win or renew DoD contracts that involve sensitive federal information.
The key word is verified. Before CMMC, contractors self-attested their security posture. Many checked boxes on paper without implementing the underlying controls. CMMC changes that by requiring third-party assessments for most Level 2 contractors - an independent auditor (called a C3PAO) comes in and confirms that your controls are actually working.
The Two Levels That Matter
CMMC Level 1 covers basic cyber hygiene - 17 practices from NIST SP 800-171. It applies to contractors handling Federal Contract Information (FCI) and allows annual self-assessment. Most small contractors at this level are already compliant if they use reasonable IT practices.
CMMC Level 2 is where the serious work happens. It covers all 110 practices from NIST SP 800-171 Rev 2 across 14 security domains. It applies to contractors that handle Controlled Unclassified Information (CUI) - technical data, engineering drawings, proprietary manufacturing processes, and similar information that the DoD considers sensitive but not classified.
Level 3 exists for the most sensitive programs but applies to a very small subset of contractors.
Who Needs CMMC Level 2?
If your contracts include any of the following, assume you are in scope for Level 2:
- Technical data or drawings related to a defense system
- Export-controlled information (ITAR, EAR)
- DoD-developed software or source code
- Contract performance information related to sensitive programs
- Information marked CUI or FOUO in contract documents
The DFARS clause 252.204-7012 in your contract is the clearest indicator. If it is in your contract and you handle CUI, you are on the path to Level 2.
Subcontractors are not exempt. If a prime contractor flows CUI to you, you are subject to the same requirements. Many small manufacturers and engineering firms are discovering this when their prime asks for CMMC status.
The 14 Domains of CMMC Level 2
CMMC Level 2 maps directly to NIST SP 800-171 Rev 2, organized into 14 security domains. Each domain contains between 2 and 22 practices:
| Domain | Abbrev | Practices |
|---|---|---|
| Access Control | AC | 22 |
| Awareness and Training | AT | 3 |
| Audit and Accountability | AU | 9 |
| Configuration Management | CM | 9 |
| Identification and Authentication | IA | 11 |
| Incident Response | IR | 3 |
| Maintenance | MA | 6 |
| Media Protection | MP | 9 |
| Personnel Security | PS | 2 |
| Physical Protection | PE | 6 |
| Risk Assessment | RA | 3 |
| Security Assessment | CA | 4 |
| System and Communications Protection | SC | 16 |
| System and Information Integrity | SI | 7 |
What a CMMC Level 2 Assessment Looks Like
A C3PAO (Certified Third-Party Assessment Organization) conducts the assessment. They review your documentation, interview key personnel, and verify technical controls through observation and testing. The assessment typically takes 3 to 5 business days for a small organization, longer for more complex environments.
Each practice gets one of three results: MET, NOT MET, or NOT APPLICABLE. You need every practice to be MET (or properly scoped as NOT APPLICABLE) to achieve certification. Practices found NOT MET can be deferred to a Plan of Action and Milestones (POA&M) in some cases, but fundamental controls like MFA and audit logging are rarely accepted as deferrable.
The Documentation You Need Before the Assessment
Documentation is what assessors check first. Before they test anything, they read your System Security Plan (SSP) - the master document that describes how you implement every one of the 110 practices. If the SSP is thin or vague, the assessment starts on the wrong foot.
The core documentation set includes:
- System Security Plan (SSP) - all 110 practices documented
- Plan of Action and Milestones (POA&M) - any gaps and remediation timelines
- Domain-specific policies (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, SI)
- Network diagrams showing the CUI boundary
- Evidence artifacts - screenshots, configurations, logs, and records
Ready to Start Your Documentation?
The CMMC Level 2 Complete Certification Kit includes the SSP, POA&M, and all 12 domain policies - everything in one download.
View the Certification KitFrequently Asked Questions
Related Resources
Keep going - these are worth reading next.