Compliance Guide

CMMC Level 2 Requirements, Explained.

CMMC Level 2 is the standard for defense contractors handling Controlled Unclassified Information (CUI). It requires full implementation of the 110 security controls in NIST SP 800-171, documented in a System Security Plan, and verified by a third-party C3PAO assessment. This guide breaks down what that actually means in practice.

The Foundation

110 Controls. 14 Families.

CMMC Level 2 maps one-to-one to NIST SP 800-171. Each of the 110 controls is assessed against 320 objectives. There is no partial credit culture here: assessors test implementation, not intent.

AC22 controls

Access Control

Who can access CUI systems, least privilege, session controls, and remote access rules.

AT3 controls

Awareness & Training

Role-based security training for everyone who touches CUI systems.

AU9 controls

Audit & Accountability

Logging, log retention, and the ability to trace actions back to individual users.

CM9 controls

Configuration Management

Baseline configurations, change control, and tracking system settings over time.

IA11 controls

Identification & Authentication

MFA, password policy, and cryptographic authentication for users and devices.

IR3 controls

Incident Response

A tested plan for detecting, reporting, and recovering from security incidents.

MA6 controls

Maintenance

Controls on system maintenance, including media sanitization and nonlocal maintenance.

MP9 controls

Media Protection

Protecting, marking, sanitizing, and controlling physical and digital media containing CUI.

PS2 controls

Personnel Security

Screening personnel and protecting CUI during offboarding.

PE6 controls

Physical Protection

Limiting physical access to systems and facilities where CUI lives.

RA3 controls

Risk Assessment

Scanning for vulnerabilities and remediating them on a defined cadence.

CA4 controls

Security Assessment

Assessing controls, developing the SSP, and managing the POA&M.

SC16 controls

System & Communications Protection

Encryption in transit and at rest, boundary protection, and FIPS-validated cryptography.

SI7 controls

System & Information Integrity

Malware protection, security alerts, and monitoring for unauthorized activity.

The Path

From Gap to Certification.

01

Scope the CUI environment

Map exactly where Controlled Unclassified Information is stored, processed, and transmitted. Everything in scope must meet all 110 controls. Tight scoping is the single biggest cost lever in a Level 2 program.

02

Run a gap assessment against NIST 800-171

Score your current environment against all 110 controls and 320 assessment objectives using the NIST 800-171A methodology. This produces your SPRS score and the honest picture of the work ahead.

03

Build the SSP and POA&M

The System Security Plan documents how each control is implemented. The Plan of Action & Milestones tracks what is not yet met, with owners and dates. Assessors read these documents before they look at a single system.

04

Remediate in the right environment

Most contractors handling CUI need a government cloud enclave such as Microsoft GCC High to satisfy requirements like FedRAMP Moderate-equivalent hosting and ITAR data residency. Remediation outside the right boundary is wasted work.

05

Collect evidence as you go

Every control needs proof: screenshots, policies, configurations, logs, and tickets. Build the evidence package during remediation, not in the weeks before the assessment.

06

Pass the C3PAO assessment

Level 2 certification requires a third-party assessment by a C3PAO every three years. With a complete SSP, closed POA&M items (or a qualifying limited POA&M), and organized evidence, the assessment is a formality, not a gamble.

Where Contractors Stumble

The Failure Points We See Most.

  • Scoping the entire company network instead of building a CUI enclave, multiplying cost and assessment surface.
  • Treating the SSP as paperwork. Assessors test the environment against what the SSP claims, line by line.
  • Running CUI in commercial Microsoft 365 when the contract requires GCC High for FedRAMP Moderate equivalency or ITAR.
  • Starting evidence collection after remediation instead of during it, then scrambling in the final weeks.
  • Waiting for a contract deadline. C3PAO capacity is limited and readiness takes months, not weeks.

How Davis Tech Pro Runs Level 2 Programs

We take defense contractors from gap assessment through C3PAO assessment prep, including GCC High tenant builds, technical remediation, and audit-ready evidence packages. Our clients have achieved perfect 110/110 first-attempt scores, and we have not failed a CMMC assessment to date. See our CMMC readiness services for the full scope.

Facing a Level 2 Deadline?

Book a consultation and we'll map your fastest defensible path from current state to assessment-ready.