Compliance Guide
CMMC Level 2 Requirements, Explained.
CMMC Level 2 is the standard for defense contractors handling Controlled Unclassified Information (CUI). It requires full implementation of the 110 security controls in NIST SP 800-171, documented in a System Security Plan, and verified by a third-party C3PAO assessment. This guide breaks down what that actually means in practice.
The Foundation
110 Controls. 14 Families.
CMMC Level 2 maps one-to-one to NIST SP 800-171. Each of the 110 controls is assessed against 320 objectives. There is no partial credit culture here: assessors test implementation, not intent.
Access Control
Who can access CUI systems, least privilege, session controls, and remote access rules.
Awareness & Training
Role-based security training for everyone who touches CUI systems.
Audit & Accountability
Logging, log retention, and the ability to trace actions back to individual users.
Configuration Management
Baseline configurations, change control, and tracking system settings over time.
Identification & Authentication
MFA, password policy, and cryptographic authentication for users and devices.
Incident Response
A tested plan for detecting, reporting, and recovering from security incidents.
Maintenance
Controls on system maintenance, including media sanitization and nonlocal maintenance.
Media Protection
Protecting, marking, sanitizing, and controlling physical and digital media containing CUI.
Personnel Security
Screening personnel and protecting CUI during offboarding.
Physical Protection
Limiting physical access to systems and facilities where CUI lives.
Risk Assessment
Scanning for vulnerabilities and remediating them on a defined cadence.
Security Assessment
Assessing controls, developing the SSP, and managing the POA&M.
System & Communications Protection
Encryption in transit and at rest, boundary protection, and FIPS-validated cryptography.
System & Information Integrity
Malware protection, security alerts, and monitoring for unauthorized activity.
The Path
From Gap to Certification.
01
Scope the CUI environment
Map exactly where Controlled Unclassified Information is stored, processed, and transmitted. Everything in scope must meet all 110 controls. Tight scoping is the single biggest cost lever in a Level 2 program.
02
Run a gap assessment against NIST 800-171
Score your current environment against all 110 controls and 320 assessment objectives using the NIST 800-171A methodology. This produces your SPRS score and the honest picture of the work ahead.
03
Build the SSP and POA&M
The System Security Plan documents how each control is implemented. The Plan of Action & Milestones tracks what is not yet met, with owners and dates. Assessors read these documents before they look at a single system.
04
Remediate in the right environment
Most contractors handling CUI need a government cloud enclave such as Microsoft GCC High to satisfy requirements like FedRAMP Moderate-equivalent hosting and ITAR data residency. Remediation outside the right boundary is wasted work.
05
Collect evidence as you go
Every control needs proof: screenshots, policies, configurations, logs, and tickets. Build the evidence package during remediation, not in the weeks before the assessment.
06
Pass the C3PAO assessment
Level 2 certification requires a third-party assessment by a C3PAO every three years. With a complete SSP, closed POA&M items (or a qualifying limited POA&M), and organized evidence, the assessment is a formality, not a gamble.
Where Contractors Stumble
The Failure Points We See Most.
- Scoping the entire company network instead of building a CUI enclave, multiplying cost and assessment surface.
- Treating the SSP as paperwork. Assessors test the environment against what the SSP claims, line by line.
- Running CUI in commercial Microsoft 365 when the contract requires GCC High for FedRAMP Moderate equivalency or ITAR.
- Starting evidence collection after remediation instead of during it, then scrambling in the final weeks.
- Waiting for a contract deadline. C3PAO capacity is limited and readiness takes months, not weeks.
How Davis Tech Pro Runs Level 2 Programs
We take defense contractors from gap assessment through C3PAO assessment prep, including GCC High tenant builds, technical remediation, and audit-ready evidence packages. Our clients have achieved perfect 110/110 first-attempt scores, and we have not failed a CMMC assessment to date. See our CMMC readiness services for the full scope.
Facing a Level 2 Deadline?
Book a consultation and we'll map your fastest defensible path from current state to assessment-ready.