CMMC Guide · Level 2
CMMC Level 2: Requirements, Assessment Options and What Applies Now
CMMC Level 2 applies to companies that handle Controlled Unclassified Information (CUI). It requires all 110 security requirements of NIST SP 800-171 Revision 2, verified every three years by a self-assessment or a C3PAO certification assessment, plus a yearly affirmation. While Phase 2 is suspended, new contracts may require only the self-assessment.
Level 2 at a glance
- Who needs it
- Contractors and subcontractors that handle CUI
- Requirements
- 110, identical to NIST SP 800-171 Rev 2
- Assessment
- Self-assessment or C3PAO certification assessment, every three years
- To pass
- All 110 met, or a score of at least 88 with a limited plan of action closed within 180 days
- Ongoing
- Affirmation in SPRS every year by a senior official
- Key document
- A system security plan (SSP), required and never deferrable
What do the 110 requirements cover?
The requirements are organized into 14 families. Access control, system protection and authentication account for almost half:
| Family | Count | Family | Count |
|---|---|---|---|
| Access Control | 22 | Media Protection | 9 |
| System and Communications Protection | 16 | System and Information Integrity | 7 |
| Identification and Authentication | 11 | Maintenance | 6 |
| Audit and Accountability | 9 | Physical Protection | 6 |
| Configuration Management | 9 | Security Assessment | 4 |
| Awareness and Training | 3 | Risk Assessment | 3 |
| Incident Response | 3 | Personnel Security | 2 |
What each family requires: CMMC requirements by domain.
Self-assessment or C3PAO assessment?
The contract decides. Both check the same 110 requirements; what differs is who does the checking.
Level 2 (Self)
Your company assesses itself, enters the score and scope in SPRS and affirms the result. This is the only Level 2 type new contracts may require while Phase 2 is suspended.
Level 2 (C3PAO)
An authorized Certified Third-Party Assessment Organization assesses your environment and submits the results to the government. This was planned to become common in Phase 2 and is currently paused.
How is Level 2 scored?
The maximum score is 110. Each requirement that is not met subtracts 1, 3 or 5 points depending on its importance, so a score can fall below zero.
- Final status: all 110 requirements met.
- Conditional status: a score of at least 88, with only certain lower-weighted requirements on a plan of action (POA&M). The system security plan and a few other requirements can never be deferred.
- 180 days: open POA&M items must be closed and confirmed within 180 days, or the conditional status expires.
The full rules: CMMC assessments and POA&Ms · How SPRS scores work
What should a Level 2 company do now?
Treat the self-assessment as if a third party will check it, because one eventually may. Your score and affirmation are representations the government relies on, and the government can still assess contractors on its own. Close gaps, keep your SSP current and make sure your people complete the security awareness and role-based training the Awareness and Training family requires.
Training for your team: CMMC training.
Questions about CMMC Level 2
Does a Level 2 status also cover Level 1?
Yes. A Level 2 status satisfies the Level 1 requirement for the same systems, so you do not need a separate Level 1 self-assessment for that scope.
Can we pass Level 2 with open items?
Only in a limited way. With a score of at least 88 and only eligible lower-weighted items open, you receive a Conditional status and have 180 days to close them.
How is the Level 2 self-assessment different from our SPRS score?
Both use the same point values out of 110. A CMMC Level 2 self-assessment also records the assessment scope and any plan of action, and it must be backed by an annual affirmation.
Handle CUI? Let’s get your Level 2 ready.
CMMCMARK helps defense contractors close Level 2 gaps, document their controls and prepare their teams.
Prefer the phone? Call +1 (202) 867-8444.
Sources
- 32 CFR Part 170 (§ 170.16–170.17 Level 2, § 170.21 POA&M, § 170.24 scoring)
- NIST SP 800-171 Revision 2
- DoW CIO, Implementing Suspension of CMMC Phase II (July 13, 2026)
