HomeBlogCMMC
CMMC2026-07-12SecReadyNow

What is CMMC Level 2? A Plain-English Guide for Defense Contractors

CMMC Level 2 applies to any defense contractor handling Controlled Unclassified Information. It requires third-party verification of all 110 NIST SP 800-171 practices - and it is already appearing in DoD contracts. Here is what it means and what you need to do.

If your company does business with the Department of Defense, you have probably seen CMMC in a solicitation by now. Maybe a prime contractor asked you to complete a questionnaire. Maybe a contracting officer mentioned it in a pre-award conversation. Either way, you need to understand what it is, what it requires, and whether it applies to you before you lose a contract over it.

This guide answers the fundamentals without the bureaucratic jargon.

What CMMC Actually Is

CMMC stands for Cybersecurity Maturity Model Certification. It is a DoD program that requires defense contractors and their subcontractors to meet verified cybersecurity standards before they can win or renew DoD contracts that involve sensitive federal information.

The key word is verified. Before CMMC, contractors self-attested their security posture. Many checked boxes on paper without implementing the underlying controls. CMMC changes that by requiring third-party assessments for most Level 2 contractors - an independent auditor (called a C3PAO) comes in and confirms that your controls are actually working.

The Two Levels That Matter

CMMC Level 1 covers basic cyber hygiene - 17 practices from NIST SP 800-171. It applies to contractors handling Federal Contract Information (FCI) and allows annual self-assessment. Most small contractors at this level are already compliant if they use reasonable IT practices.

CMMC Level 2 is where the serious work happens. It covers all 110 practices from NIST SP 800-171 Rev 2 across 14 security domains. It applies to contractors that handle Controlled Unclassified Information (CUI) - technical data, engineering drawings, proprietary manufacturing processes, and similar information that the DoD considers sensitive but not classified.

Level 3 exists for the most sensitive programs but applies to a very small subset of contractors.

Who Needs CMMC Level 2?

If your contracts include any of the following, assume you are in scope for Level 2:

The DFARS clause 252.204-7012 in your contract is the clearest indicator. If it is in your contract and you handle CUI, you are on the path to Level 2.

Subcontractors are not exempt. If a prime contractor flows CUI to you, you are subject to the same requirements. Many small manufacturers and engineering firms are discovering this when their prime asks for CMMC status.

The 14 Domains of CMMC Level 2

CMMC Level 2 maps directly to NIST SP 800-171 Rev 2, organized into 14 security domains. Each domain contains between 2 and 22 practices:

DomainAbbrevPractices
Access ControlAC22
Awareness and TrainingAT3
Audit and AccountabilityAU9
Configuration ManagementCM9
Identification and AuthenticationIA11
Incident ResponseIR3
MaintenanceMA6
Media ProtectionMP9
Personnel SecurityPS2
Physical ProtectionPE6
Risk AssessmentRA3
Security AssessmentCA4
System and Communications ProtectionSC16
System and Information IntegritySI7

What a CMMC Level 2 Assessment Looks Like

A C3PAO (Certified Third-Party Assessment Organization) conducts the assessment. They review your documentation, interview key personnel, and verify technical controls through observation and testing. The assessment typically takes 3 to 5 business days for a small organization, longer for more complex environments.

Each practice gets one of three results: MET, NOT MET, or NOT APPLICABLE. You need every practice to be MET (or properly scoped as NOT APPLICABLE) to achieve certification. Practices found NOT MET can be deferred to a Plan of Action and Milestones (POA&M) in some cases, but fundamental controls like MFA and audit logging are rarely accepted as deferrable.

The Documentation You Need Before the Assessment

Documentation is what assessors check first. Before they test anything, they read your System Security Plan (SSP) - the master document that describes how you implement every one of the 110 practices. If the SSP is thin or vague, the assessment starts on the wrong foot.

The core documentation set includes:

Ready to Start Your Documentation?

The CMMC Level 2 Complete Certification Kit includes the SSP, POA&M, and all 12 domain policies - everything in one download.

View the Certification Kit

Frequently Asked Questions

Level 1 covers 17 basic practices from FAR 52.204-21 and applies to contractors handling FCI (Federal Contract Information). It allows annual self-assessment. Level 2 covers all 110 NIST SP 800-171 Rev 2 practices and applies to contractors handling CUI (Controlled Unclassified Information). Most Level 2 contractors require a third-party assessment by a C3PAO.
Yes, if the prime contractor flows CUI to the subcontractor. CMMC requirements flow down the supply chain. If you receive CUI from a prime and handle it in your environment, you are subject to the same CMMC requirements as the prime for that information.
CMMC requirements are being phased into DoD contracts under 32 CFR Part 170. Level 2 requirements are appearing in new contracts and contract renewals now. The timeline depends on the specific contract program and phase. Check your solicitation for DFARS 252.204-7021 (CMMC) clause.
A Certified Third-Party Assessment Organization is an organization authorized by the CMMC Accreditation Body (Cyber AB) to conduct CMMC Level 2 assessments. C3PAOs employ certified assessors who have passed required training and are listed on the Cyber AB marketplace.
The Supplier Performance Risk System (SPRS) score is a self-assessment score that contractors submit to demonstrate their current NIST SP 800-171 implementation status. It ranges from -203 (zero practices implemented) to 110 (all practices fully implemented). Submitting an accurate SPRS score is required even before your C3PAO assessment, and false submissions carry legal risk.
For organizations starting from a reasonable security baseline, preparation typically takes 6 to 18 months before an assessment. The assessment itself takes 3 to 5 days for small organizations. After the assessment, the C3PAO submits results to the CMMC database and a certificate is issued, which takes additional weeks. Plan 12 to 24 months from decision to certification for most organizations.

Related Resources

Keep going - these are worth reading next.

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, no spam.