What CMMC Level 2 actually requires
CMMC Level 2 is built on NIST SP 800-171. That means 110 security requirements across 14 families, and when an assessor evaluates them they do not look at 110 items. They look at 320 individual assessment objectives. Every objective has to be met, documented, and evidenced. A control that is "mostly" in place is a control that is scored as not met.
The Department of Defense scores your posture on a 110-point scale. You start at 110 and subtract 5, 3, or 1 point for each requirement you have not implemented. That score goes into the Supplier Performance Risk System (SPRS), and contracting officers can see it. A low or missing score is increasingly the reason a contract award goes somewhere else.
- Access Control, Awareness & Training, Audit & Accountability, Configuration Management
- Identification & Authentication, Incident Response, Maintenance, Media Protection
- Personnel Security, Physical Protection, Risk Assessment, Security Assessment
- System & Communications Protection, System & Information Integrity
How we run a Level 2 program
We do not start with a product pitch. We start by mapping where CUI enters your business, where it lands, who touches it, and where it leaves. That map determines everything else, including how much this is going to cost you.
Once scope is settled, we run a full gap assessment against all 320 objectives, produce a weighted score, and build a remediation plan sequenced by point value and effort. High-value, low-effort items go first so your SPRS score moves early while the heavier engineering work runs in parallel.
- Phase 1: CUI data-flow mapping and scope definition (in-scope assets, CRMA, specialized assets)
- Phase 2: Gap assessment against all 320 assessment objectives with a weighted SPRS score
- Phase 3: Remediation: identity, endpoints, logging, encryption, boundary, physical, policy
- Phase 4: Documentation: System Security Plan, POA&M, policies, procedures, evidence library
- Phase 5: Pre-assessment: mock assessment, evidence walkthrough, interview coaching
- Phase 6: Assessment support and post-assessment continuous compliance
The POA&M rules people get wrong
There is a persistent myth that you can certify with a long list of open items and fix them later. You cannot. A Plan of Action and Milestones is only permitted if you have already scored at least 88 of 110, it can only cover lower-weighted requirements, and it must be closed out within 180 days, verified by a follow-up assessment. The heaviest requirements, including multifactor authentication and FIPS-validated cryptography, can never sit on a POA&M.
That is why we sequence remediation around the requirements that can never be deferred. If those are not genuinely in place, nothing else matters.
Self-assessment or C3PAO: which applies to you
Not every Level 2 contract requires a third-party assessment. Some are satisfied by a self-assessment plus an annual affirmation from a senior official. Most CUI-bearing contracts, however, land in the certification bucket and require a CMMC Third-Party Assessment Organization.
We read your actual contract clauses and tell you which one you are facing before you spend money. If you only need a self-assessment, we will say so, and we will help you do it correctly rather than selling you a certification program you do not need.
