CMMC Level 2

CMMC Level 2 Compliance & Certification

CMMC Level 2 is the Advanced tier of the Cybersecurity Maturity Model Certification, required for defense contractors and subcontractors that store, process or transmit Controlled Unclassified Information. It maps to the 110 security requirements of NIST SP 800-171 Revision 2, organized into 14 domains, and for most programs it is verified by a C3PAO assessment every three years with an annual senior official affirmation. Petronella Technology Group, Inc., Cyber AB Registered Provider Organization #1449, prepares contractors for that assessment: gap analysis, SPRS scoring, System Security Plan and POA&M development, remediation and C3PAO handoff.

Cyber AB RPO #1449 | CMMC-RP Certified Team | BBB A+ Since 2003

What It Is

What Is CMMC Level 2?

The goal is plain: prove that the CUI flowing through your environment is protected to the standard the Department of Defense requires before a contract is awarded.

CMMC Level 2 is the Advanced tier of CMMC 2.0, which simplified the original five-level model into three levels. This level aligns directly with NIST SP 800-171 Revision 2, comprising all 110 practices organized into 14 domains.

The contract, not the contractor, sets the verification path: some Level 2 contracts allow an annual self-assessment with a signed senior official affirmation; most programs require a C3PAO assessment, with reassessment every three years and the annual affirmation either way.

C3PAO Assessment and Certification

Only a C3PAO can issue a Level 2 certificate. The C3PAO submits the assessment results to eMASS, and the certificate is stored in SPRS.

The CMMC Program rule, 32 CFR Part 170, was published on 2024-10-15 and took effect on 2024-12-16. The 48 CFR acquisition rule (DFARS 252.204-7021) took effect on 2025-11-10, requiring contractors to hold a valid CMMC status at the specified level before award when this clause appears in a contract.

On 2026-07-13, the DoD CIO suspended the 2026-11-10 Phase II deadline. As a result, Phase I self-assessments remain in force. Later milestones are paused until further notice; this page does not name a new deadline.

A DoD class deviation currently keeps DFARS 252.204-7012 aligned with NIST SP 800-171 Revision 2. For information on upcoming changes, refer to our NIST 800-171 Rev 3 guide. For an overview of the CMMC program, visit our CMMC compliance guide.


Key Takeaways

CMMC Level 2 at a Glance

Key Takeaways

  • CMMC Level 2 requires all 110 controls of NIST SP 800-171 Rev 2 across 14 families and applies to any DoD contractor or subcontractor that handles CUI.
  • Most programs require a C3PAO assessment every three years plus an annual senior official affirmation; some contracts allow an annual self-assessment. Only a C3PAO can issue the certificate, which is stored in SPRS.
  • Your SPRS score runs from minus 203 to 110 (controls weigh 1, 3 or 5 points) and is visible to contracting officers before award. Estimate yours with the free SPRS score calculator.
  • POA&Ms are allowed only for not-met requirements within the limits of 32 CFR 170.21, with a 180-day closeout; the SSP is a living document reviewed as the environment changes.
  • Petronella Technology Group, Inc. is Cyber AB RPO #1449, has secured regulated businesses since 2002, and does not assess the clients it prepares.

Who It Applies To

Who Needs CMMC Level 2 Certification?

If your organization is anywhere in the Defense Industrial Base and CUI touches your systems, Level 2 almost certainly applies.

Controlled Unclassified Information (CUI) is defined by Executive Order 13556, signed on 2010-11-04. The National Archives and Records Administration serves as the Executive Agent, with 32 CFR Part 2002 acting as the government-wide rule. DoD Instruction 5200.48, issued on 2020-03-06, implements CUI within the Department of Defense. CUI is categorized into two types: CUI Basic and CUI Specified. For more information on CUI, visit our Controlled Unclassified Information guide.

Every DoD contractor handling Federal Contract Information (FCI) must meet the FAR 52.204-21 baseline, which consists of 15 requirements and is equivalent to CMMC Level 1. However, only contractors that receive or generate CUI are required to meet the full NIST SP 800-171 obligation, which corresponds to CMMC Level 2. Contractors can refer to our CMMC Level 1 self-assessment guide for more information on meeting the FAR 52.204-21 baseline.

Our readiness reviews have shown that a variety of organizations are swept into the CMMC Level 2 scope, including machine shops fabricating parts from controlled drawings, engineering firms developing prototypes, managed service providers supporting a contractor's network, logistics firms moving controlled hardware, and law firms holding export-controlled documents. The prime contractors at the top of the supply chain are in scope too.

Subcontractors are not exempt from meeting CMMC Level 2 requirements. According to DFARS 252.204-7012, subcontractors must be flowed down the clause, including for commercial products and services, when performance involves covered defense information. Subcontractors are also required to report their own incidents to DoD and provide the report number to the next higher tier. More information on DFARS 252.204-7012 requirements can be found on our DFARS 252.204-7012 page.

Signs You Are in Scope

Signals that an organization is in scope for CMMC Level 2 certification include CUI markings on a document, a DFARS flow-down clause, or a request for their Supplier Performance Risk System (SPRS) score. Scope the assessment to where CUI actually lives rather than certifying systems that never touch it; confirming that boundary is the first thing our team does.


The 110 Practices

The 110 Practices in 14 NIST SP 800-171 Families

CMMC Level 2 inherits the structure of NIST SP 800-171 Revision 2. Every one of the 110 requirements falls into one of these 14 families, and an assessment looks at all of them. Each family below links to its practice-by-practice guide.

Access Control (3.1)

Limit system access to authorized users, processes and devices, and enforce least privilege and separation of duties across CUI systems.

Awareness and Training (3.2)

Make sure managers and users understand the security risks tied to their roles and are trained on policies and procedures.

Audit and Accountability (3.3)

Create, protect and retain audit logs so activity on CUI systems can be monitored, analyzed and traced to individual users.

Configuration Management (3.4)

Establish and maintain baseline configurations and enforce security settings, change control and approved software inventories.

Identification and Authentication (3.5)

Identify users and devices and authenticate them, including multifactor authentication for access to CUI and privileged accounts.

Incident Response (3.6)

Build and test the capability to detect, report and respond to security incidents and meet the 72-hour DoD reporting requirement.

Maintenance (3.7)

Perform system maintenance and control the tools, techniques, personnel and remote sessions used to carry it out.

Media Protection (3.8)

Protect, sanitize and control CUI on digital and physical media, including marking, transport and secure disposal.

Personnel Security (3.9)

Screen individuals before granting access to CUI and protect that information during personnel actions such as transfers and terminations.

Physical Protection (3.10)

Limit physical access to systems, equipment and operating environments, and escort and monitor visitors.

Risk Assessment (3.11)

Periodically assess risk, scan for vulnerabilities and remediate findings on systems that store or process CUI.

Security Assessment (3.12)

Assess controls, develop and maintain the System Security Plan and the Plan of Action, and monitor controls on an ongoing basis.

System and Communications Protection (3.13)

Monitor and protect communications at system boundaries and use FIPS-validated cryptography and architecture controls for CUI in transit and at rest.

System and Information Integrity (3.14)

Identify and correct flaws quickly, protect against malicious code, and monitor systems and alerts for emerging threats.

Implementing these families correctly is the heart of NIST 800-171 compliance, and it is where most contractors stall: the controls are written in government language, several require specific technical architecture, and partially done still scores as not done.


Self-Assessment vs C3PAO

The Two Paths to CMMC Level 2

Not every Level 2 contract requires a third-party assessment. Knowing which path your contract triggers protects you from over- or under-investing.

Petronella Technology Group, Inc. guides Defense Industrial Base contractors through CMMC Level 2 compliance. There are two paths to achieving this level of certification. The first path involves self-assessment, where the company assesses itself against all 110 controls and records the results in the Supplier Performance Risk System (SPRS). The second path requires a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO). The specific DFARS clauses in a contract determine which path applies, and enforcement is real either way.

Self-Assessment Path

The self-assessment path is an annual, internally conducted evaluation where the company assesses itself against all 110 CMMC Level 2 controls, records the results in SPRS, and a senior official signs an annual affirmation of continued compliance. This path is lower in cost but carries real accountability under the civil False Claims Act. The self-assessment must be thorough, with the same 110 requirements implemented, and the System Security Plan (SSP) and evidence must be current and accurate.

C3PAO Assessment Path

The C3PAO assessment path involves a triennial evaluation by an authorized Certified Third-Party Assessment Organization. The Cyber AB marketplace maintains a list of authorized C3PAOs. A C3PAO reviews the environment, interviews staff, and validates evidence against each control, submitting results to eMASS, with the certificate stored in SPRS. To maintain independence, a C3PAO cannot be the firm that implemented the controls, which is where a CMMC Registered Provider Organization (RPO) comes in. The consequences of non-compliance are severe, as seen in DOJ Civil Cyber-Fraud Initiative settlements, such as Verizon's $4.09M settlement in 2023, Penn State's $1.25M settlement in 2024, Raytheon's $8.4M settlement in May 2025, and Georgia Tech's $875K settlement on 2025-09-30, each of them a compliance claim that became a False Claims Act matter.

Not Sure Whether CMMC Level 2 Applies to You?

A short scoping conversation with a CMMC Registered Practitioner tells you whether CUI is in your environment and which assessment path your contract triggers. The first 30 minutes are free.


SPRS Scoring

Understanding Your SPRS Score

Before any certification the DoD wants a number: your Supplier Performance Risk System score.

DFARS 252.204-7019 requires a current NIST SP 800-171 assessment summary score in SPRS when an offer is submitted, while 252.204-7020 governs how the assessment is conducted under the DoD Assessment Methodology and gives DoD access to verify it.

The methodology starts at a perfect 110 and subtracts a weighted value for every control not fully implemented, resulting in a scale that runs down to minus 203. A negative score is common for companies that have not started, and it is visible to the contracting officers deciding who is eligible for award.

Improving Your SPRS Score

Raising the score is not about manipulating the math; it is about closing gaps in the right order so the score reflects real protection. We help clients calculate an honest baseline, prioritize the highest-weighted remediations first, and track the score up over time.

To estimate your current SPRS score, you can use our free SPRS score calculator. It walks all 110 controls with their 1, 3 or 5 point weights.

For a deeper understanding of the SPRS methodology, we recommend checking out our SPRS score guide. It covers how the score is calculated, posted and read by a contracting officer.


POA&M Rules

POA&M Rules Under 32 CFR 170

A Plan of Action and Milestones is not a parking lot for controls you would rather not implement. The program rule limits what it can hold and for how long.

A Plan of Action and Milestones (POA&M) under CMMC Level 2 compliance is a dated, owned register of open gaps. Each gap has a milestone and a closeout that the assessor expects to see honored. This means that contractors must maintain a living document that outlines their plan to address unmet requirements.

Two key practices anchor this process: developing and implementing plans of action and developing, documenting, and periodically updating system security plans. The System Security Plan (SSP) describes the environment as it actually exists, while the POA&M records what is still open.

The POA&M is allowed only for not-met requirements within the limits of 32 CFR 170.21, with a 180-day closeout. This means that contractors must regularly review and update their POA&M to ensure that they are making progress towards addressing unmet requirements.

Continuous Compliance

CMMC Level 2 compliance is continuous, not one-time. The SSP is a living document, the POA&M is reviewed at least quarterly, and the senior official affirms annually. Re-assessment occurs every three years. This ongoing process helps ensure that contractors remain compliant over time.

Despite this, projects can still stall due to various reasons. For example, scope may never be pinned down, allowing Controlled Unclassified Information (CUI) to spread into email and file shares. Multi-Factor Authentication (MFA) may be switched on for some systems but not the privileged accounts that matter most. An SSP may be written once and never updated, and POA&M items may be opened with good intentions but drift past their milestones with no one accountable.

To avoid these common pitfalls, Petronella Technology Group's ComplianceArmor® compliance documentation platform automates SSP authoring, POA&M tracking, and evidence repository organization. This helps ensure that documents do not go stale and that contractors remain on track to meet their compliance requirements.


Assessment Flow

The C3PAO Assessment Flow, Step by Step

The sequence from scoping to certificate, and what an RPO does at each step so nothing on assessment day is a surprise.

Six steps take a contractor from an undefined boundary to a certificate in SPRS. Petronella Technology Group, Inc., Cyber AB RPO #1449, does steps 1 through 4 with you and prepares you for 5 and 6; every practitioner on the compliance team holds the CMMC-RP credential. The full readiness engagement typically runs 12 to 14 weeks for a mid-size contractor, described on the CMMC compliance consultant services page.

1

Step 1: Scoping and CUI data flow: Define the assessment boundary and map CUI movement through the environment. Accurate scoping prevents project expansion.

2

Step 2: Gap analysis and SPRS baseline: Assess controls against all 110 requirements with an honest baseline score, using tools like our free SPRS calculator.

3

Step 3: SSP, POA&M and remediation: Build the System Security Plan and Plan of Action and Milestones, then remediate in priority order, focusing on high-scoring controls first.

4

Step 4: Evidence and mock assessment: Assemble the evidence package indexed by control and rehearse with a walkthrough using the Cyber AB CMMC Assessment Process.

5

Step 5: C3PAO selection and assessment: Choose from the authorized list at cyberab.org/marketplace (103 C3PAOs as of the March 2026 Town Hall); the C3PAO interviews staff, validates evidence and submits results to eMASS, storing the certificate in SPRS.

6

Step 6: Maintain: Complete annual senior official affirmation, review the POA&M quarterly, and undergo re-assessment every three years, as part of the ongoing CMMC Level 2 maintenance process, which applies to DoD's estimated 220,966 entities, with Level 2 certifications growing from 773 to 1,391 between January and May 2026.


Enclave Option

The Enclave Option: Shrink the Boundary Before You Secure It

Most cost-efficient Level 2 programs rely on enclaving CUI so the 110 controls do not have to apply across the entire enterprise network.

Enclaving Controlled Unclassified Information (CUI) into a narrowly scoped boundary reduces audit surface, shortens timelines, and lowers ongoing cost. Typically that boundary is a GCC High tenant or a dedicated cloud landing zone, and the choice is one of the biggest drivers of quote variance, because it keeps the 110 controls from applying across the entire enterprise network. For more information on designing a CMMC enclave, visit our CMMC enclave design page. We also compare CMMC and GCC High requirements on our CMMC and GCC High page.

Cloud service providers handling covered defense information must meet the FedRAMP Moderate baseline or equivalency, as required by DFARS 252.204-7012. The DoD CIO FAQ clarifies that encrypted CUI is still considered CUI and requires FedRAMP Moderate or equivalency, even in a cloud environment.

Cryptography Requirements

NIST SP 800-171 mandates FIPS-validated cryptography to protect CUI confidentiality. Strong but unvalidated encryption does not meet this requirement. The FIPS-validated cryptography requirement (3.13.11) page covers what validated means in practice.

The discovery phase determines whether the existing environment is enclave-ready or if remediation efforts must include constructing an enclave. Both paths are viable, but costs and timelines differ significantly.

The DoD CIO FAQ adds one more scoping rule worth knowing before the design starts: VDI endpoints are out of scope only in a KVM-only configuration.


Why Petronella Technology Group, Inc.

Our CMMC Level 2 Process and the AI Behind It

A repeatable, evidence-driven path from where are we to assessment-ready, delivered by a team that also operates the controls it helps you implement.

At Petronella Technology Group, Inc., our CMMC Level 2 compliance engagement is a structured process that typically runs 12 to 14 weeks. It begins with Discovery in week 1, followed by Gap Analysis from weeks 2 to 4, Remediation Sprint from weeks 5 to 12, and finally, C3PAO Readiness Handoff from weeks 13 to 14.

Our deliverables include a System Security Plan (SSP) that covers all 110 controls with owners and evidence pointers, as well as 14 control-family policies, incident response, acceptable use, and media protection policies. We also provide a live Plan of Action and Milestones (POA&M), a mock Cyber AB CMMC Assessment Process (CAP) assessment, a baselined Supplier Performance Risk System (SPRS) score, and a C3PAO shortlist with warm introductions.

AI-Driven Compliance

Our approach combines AI and cybersecurity to ensure the security and integrity of Controlled Unclassified Information (CUI). We design, build, and operate private AI clusters for regulated businesses, ensuring that CUI never leaves the designated boundary. Visit our AI services hub to learn more about how we integrate AI into our compliance solutions.

Our own private AI cluster, along with a 24/7 AI-plus-human hybrid threat analysis stack, underpins our managed detection and response services for Defense Industrial Base clients who cannot send CUI to a public-cloud Security Operations Center (SOC). The hybrid SOC runs ten-plus production AI agents, which never close tickets on their own or touch production systems without human authorization. Every action is logged for CMMC audit purposes. For more information on our private AI solutions and managed detection and response capabilities, visit private AI solutions and managed detection and response pages.

As a Cyber AB Registered Provider Organization (RPO #1449), every engineer assigned to a defense client holds the CMMC Registered Practitioner (CMMC-RP) credential. Our founder, Craig Petronella, holds the CMMC-RP, the CCNA and the CWNE, is an NC Licensed Digital Forensic Examiner (#604180), and holds an MIT AI certificate. The company was founded in 2002 and has held a BBB A+ rating continuously since 2003. Learn more about our company on the about Petronella Technology Group, Inc. page.

The first step towards achieving CMMC Level 2 compliance is a free 30-minute scoping consultation run by a CMMC Registered Practitioner. Engagements are delivered remote-first across all 50 states.



FAQ

CMMC Level 2 Questions

What is CMMC Level 2?

CMMC Level 2 is the Advanced tier of CMMC 2.0 for contractors handling Controlled Unclassified Information (CUI), requiring all 110 NIST SP 800-171 Rev 2 controls in 14 families, verified by annual self-assessment with affirmation or a triennial C3PAO assessment depending on the contract.

How many controls are in CMMC Level 2?

CMMC Level 2 includes 110 security requirements from NIST SP 800-171 Rev 2 in 14 families, all of which must be implemented; partial implementation lowers the SPRS score and POA&Ms are limited by 32 CFR 170.21 with a 180-day closeout.

Do I need a C3PAO assessment or can I self-assess?

The need for a C3PAO assessment depends on the contract; some Level 2 contracts allow an annual self-assessment with a senior official affirmation in SPRS, while most programs require a C3PAO every three years, as determined by the DFARS clauses.

What is a SPRS score and why does it matter?

A SPRS score is a Supplier Performance Risk System score required by DFARS 252.204-7019 at offer, starting at 110 and subtracting 1, 3, or 5 points per unmet control, ranging from minus 203 to 110, visible to contracting officers; a free calculator can help determine the score.

What can go on a POA&M under CMMC Level 2?

Only not-met requirements within the limits of 32 CFR 170.21 can be included on a POA&M under CMMC Level 2, with a 180-day closeout, reviewed at least quarterly; the SSP describes the environment as it exists.

How long does CMMC Level 2 certification take?

The readiness build typically takes 12 to 14 weeks for a mid-size contractor with a defined enclave, and the full path from gap assessment to C3PAO-ready can take 6 to 18 months depending on starting posture and CUI complexity.

What is the difference between CMMC Level 2 and NIST 800-171?

CMMC Level 2 and NIST 800-171 include the same 110 controls; however, NIST SP 800-171 is the standard for protecting CUI, while CMMC Level 2 is the DoD program that verifies implementation with assessment, affirmation, and certification under 32 CFR Part 170.

Can Petronella Technology Group, Inc. also act as my C3PAO?

No, Petronella Technology Group, Inc. cannot act as a C3PAO because a C3PAO must be independent and cannot assess controls it implemented; as RPO #1449, we prepare and support clients through the independent assessment.

What happens if I affirm compliance but am not compliant?

Affirming compliance without being compliant carries legal weight under the civil False Claims Act, with potential settlements like those of Verizon, Penn State, Raytheon, and Georgia Tech; honest baseline and steady remediation protect eligibility.

Is CMMC Level 2 still required after the July 2026 Phase II suspension?

Yes, CMMC Level 2 is still required as Phase I self-assessments remain in force after the 2026-07-13 suspension of the Phase II deadline; DFARS 252.204-7012, 7019, and 7020 still apply.

Talk to a CMMC Registered Practitioner

Petronella Technology Group, Inc., 5540 Centerview Dr., Suite 200, Raleigh, NC 27606. Serving DoD contractors nationwide since 2002. Last updated September 10, 2026.