Dictionary

CMMC Level 2: Requirements, Controls & Certification Guide

September 03, 2024

 CyberAB RPO Badge 2022 - Transparent BG

If your organization handles Controlled Unclassified Information (CUI) for the Department of War, achieving CMMC Level 2 is no longer optional—it’s essential for winning and retaining contracts.

This guide explains CMMC Level 2 requirements, what’s involved in CMMC Level 2 certification, and how to prepare for CMMC 2.0 certification under the updated rulemaking.

What Is CMMC Level 2?

Under the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework established by the U.S. Department of War (DoW), Level 2 is designed for contractors that store, process, or transmit CUI.

Level 2 aligns directly with the 110 security controls outlined in NIST Special Publication 800-171, making it a significant step up from Level 1’s foundational safeguards.

If your contracts include DFARS 252.204-7012 clauses or involve sensitive defense data, CMMC Level 2 compliance is likely required.

Understanding CMMC Level 2 Requirements

The updated CMMC 2.0 requirements focus on implementing and documenting 110 security practices across 14 control families, including:

  • Access Control (AC)
  • Incident Response (IR)
  • Risk Management (RM)
    System & Communications Protection (SC)
  • Audit & Accountability (AU)

These CMMC Level 2 controls are not just technical safeguards—they require policies, procedures, documentation, and demonstrable operational maturity.

You can review the official control requirements directly from the National Institute of Standards and Technology (NIST), but translating them into an audit-ready environment is where many contractors struggle.

CMMC Level 2 Certification: Self-Assessment or C3PAO?

Not all organizations follow the same path to CMMC Level 2 certification.

Under CMMC 2.0:

  • Critical national security programs require a third-party assessment by an authorized C3PAO every three years.
  • Non-prioritized contracts may allow for annual self-assessments with executive affirmation.

Understanding which category your contract falls under is essential before budgeting time and resources. For official guidance, visit the U.S. Department of Defense CMMC program page.

A Practical CMMC Level 2 Checklist

Preparing for certification starts with visibility and scoping. A strong CMMC Level 2 checklist includes:

  1. Identifying where CUI resides in your environment
  2. Defining and documenting your CUI boundary
  3. Mapping CUI data flows
  4. Performing a gap assessment against all 110 controls
  5. Creating Plans of Action & Milestones (POA&Ms)
  6. Remediating deficiencies before assessment

Many organizations underestimate the effort required for documentation and evidence collection. 

Even technically mature companies often fail audits due to incomplete policies or insufficient proof of control implementation.

Common Pain Points in CMMC Level 2 Compliance

Organizations pursuing CMMC Level 2 compliance frequently encounter:

  • Undefined CUI boundaries
  • Overly complex network environments
  • Legacy systems that don’t meet modern security standards
  • Third-party vendors lacking compliant controls
  • Insufficient executive buy-in

Strategically reducing scope can significantly reduce both cost and complexity.

Why CMMC 2.0 Certification Is Different

Compared to earlier iterations, CMMC 2.0 certification simplifies the model to three levels—but it increases accountability.

In some cases, executive leadership must now formally attest to compliance, and false claims carry potential legal and financial consequences.

This shift makes preparation, documentation, and independent validation more critical than ever.

Looking Ahead: CMMC Level 3 (Expert)

While CMMC Level 2 focuses on protecting CUI through the 110 controls in NIST Special Publication 800-171, Level 3 is designed for organizations supporting the most critical national security programs.

CMMC Level 3 builds on CMMC 2.0 requirements by incorporating additional controls from NIST Special Publication 800-172, emphasizing advanced threat detection, proactive risk management, and resilience against sophisticated adversaries.

Most contractors will only need CMMC Level 2 certification, but companies involved in high-priority DoD programs should evaluate whether Level 3 readiness may be required in future contract awards.

Moving Forward With Confidence

Achieving CMMC Level 2 is not just about passing an audit—it’s about building a defensible cybersecurity posture that protects your contracts, reputation, and future growth.

Whether you need:

  • A CUI boundary analysis
  • A formal gap assessment
  • Mock assessments before your C3PAO review
  • End-to-end support toward CMMC Level 2 certification

The right guidance can reduce risk, shorten timelines, and control costs.

Frequently Asked Questions About CMMC Level 2

The scope of a CMMC Level 2 assessment is defined by your CUI boundary—the systems, users, processes, and external service providers that store or handle CUI.

Properly scoping your environment is a critical first step in achieving CMMC Level 2 compliance and can significantly impact cost and complexity.

Assessment findings may include:

  • Fully implemented controls
  • Partially implemented controls
  • Not implemented controls

Organizations must remediate gaps identified in CMMC Level 2 controls and document corrective actions through Plans of Action and Milestones (POA&Ms) before achieving certification.

Assessors evaluate CMMC Level 2 requirements using three primary methods: examination (documentation review), interviews (personnel validation), and testing (technical verification).

Evidence may include security policies, system configurations, access logs, incident response records, and risk assessments.

Yes. Small and mid-sized businesses can achieve CMMC Level 2 certification, especially with proper scoping, environment segmentation, and structured remediation planning.

Reducing the CUI footprint is often the most effective way to simplify CMMC Level 2 compliance for smaller organizations.

Organizations can strengthen CMMC Level 2 compliance by:

  • Conducting a formal gap assessment
  • Defining and documenting the CUI boundary
  • Implementing missing technical controls
  • Developing complete policies and procedures
  • Performing mock assessments before certification

Using a structured CMMC Level 2 checklist helps ensure all 110 controls are addressed before formal evaluation.

Get Ready for CMMC Level 2

Talk to an Expert

Related Resources