CMMC Level 2 Requirements: The Complete 2026 Guide for DIB Contractors
A current guide to CMMC Level 2, the 110 NIST SP 800-171 Rev 2 requirements, SPRS scoring, assessment types, and the 2026 Phase 2 suspension.
Table of Contents(20 sections)
Updated August 1, 2026: DoD suspended the transition to CMMC Phase 2 and future implementation milestones on July 13, 2026. During the suspension, DoD directs program managers and requiring activities to designate only Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3 (DIBCAC), and to remove those higher assessment designations from active solicitations and contracts. Phase 1 remains in effect, and there is no current authoritative November 2026 Phase 2 deadline.
What Is CMMC Level 2?
CMMC Level 2 uses all 110 security requirements from NIST SP 800-171 Revision 2. A CMMC requirement applies when an applicable solicitation or contract includes DFARS 252.204-7021 and specifies the required level and assessment type. Separate contractual duties to protect CUI and maintain a current NIST SP 800-171 assessment may also apply.
Unlike CMMC Level 1 (which covers 15 basic practices from FAR 52.204-21), Level 2 demands a comprehensive cybersecurity program with documented policies, trained personnel, and verifiable evidence.
Who Needs CMMC Level 2?
Organizations that process, store, or transmit CUI should review the applicable solicitation, contract, contract modifications, and flow-down terms. The regulatory framework permits either a Level 2 Self or C3PAO assessment when specified, but current DoD suspension direction permits only Level 2 Self designations. Potentially in-scope organizations include:
- Prime contractors with direct DoD contracts involving CUI
- Subcontractors who receive CUI flow-down from primes
- Suppliers who manufacture components with CUI markings
- IT service providers who manage systems containing CUI
How to Know If You Handle CUI
Review the contract, security classification guidance, CUI markings, data flows, and any DFARS clauses. DFARS 252.204-7012 is included broadly in non-COTS DoD acquisitions, so its presence alone does not prove that you receive CUI or establish a particular CMMC assessment type. DFARS 252.204-7021, when included, specifies the contractual CMMC requirement.
The 110 Controls Organized by Family
NIST SP 800-171 organizes its 110 controls into 14 families:
| Family | Code | Controls | Description |
|---|---|---|---|
| Access Control | AC | 22 | Limit system access to authorized users and functions |
| Awareness & Training | AT | 3 | Ensure personnel understand security responsibilities |
| Audit & Accountability | AU | 9 | Create, protect, and review system audit logs |
| Configuration Management | CM | 9 | Establish and maintain system configurations |
| Identification & Authentication | IA | 11 | Verify identities of users, processes, and devices |
| Incident Response | IR | 3 | Detect, report, and respond to security incidents |
| Maintenance | MA | 6 | Perform timely system maintenance |
| Media Protection | MP | 9 | Protect and control system media |
| Personnel Security | PS | 2 | Screen personnel and protect CUI during changes |
| Physical Protection | PE | 6 | Limit physical access to systems and facilities |
| Risk Assessment | RA | 3 | Identify and manage organizational risk |
| Security Assessment | CA | 4 | Assess security controls and monitor continuously |
| System & Communications Protection | SC | 16 | Protect communications and system boundaries |
| System & Information Integrity | SI | 7 | Identify and correct system flaws promptly |
SPRS Score: What It Is and Why It Matters
Your Supplier Performance Risk System (SPRS) score is an assessment result representing implementation of the applicable NIST SP 800-171 requirements. It is not, by itself, a compliance determination or CMMC status. The score ranges from -203 to 110:
- 110 = all controls fully implemented
- 0 = a score reflecting substantial unmet requirements; it is not an official readiness threshold
- Negative scores = deductions for NOT MET requirements exceed the 110-point starting value; the score alone does not characterize risk or determine CMMC status
The DoD assessment methodology assigns each requirement a deduction value of 1, 3, or 5 points, with special scoring rules for certain requirements. Point value is not a universal security-severity rating.
How SPRS Is Calculated
- Start at 110 (perfect score)
- For each applicable requirement assessed as NOT MET, subtract its DoD weight
- A POA&M documents remediation but does not prevent the score deduction
- Validate special scoring cases, including MFA and FIPS requirements, against the current DoD Assessment Methodology
If DFARS 252.204-7019 applies and you are required to implement NIST SP 800-171, you must have a current assessment in SPRS before award. CMMC Command provides an estimate from user-entered statuses; validate the final score and submission obligation against the contract and current DoD methodology.
The CMMC 2.0 Timeline
Key Milestones
- December 16, 2024: 32 CFR Part 170 takes effect
- November 10, 2025: Phase 1 begins with Level 1 and Level 2 self-assessment requirements in applicable solicitations and contracts
- July 13, 2026: DoD suspends the transition to Phase 2 and future implementation milestones while reviewing the program
- Future dates: No replacement Phase 2, Phase 3, or Phase 4 dates have been announced
What the Phase Timeline Means for You
Phase 1 remains in effect. During the current suspension, DoD directs program managers and requiring activities to designate only Level 1 (Self) or Level 2 (Self) and to amend active solicitations and contracts to remove Level 2 (C3PAO) and Level 3 designations. Check the latest solicitation, contract, and modification rather than relying on the former November 2026 schedule.
The Level 2 C3PAO Assessment Model
The regulatory model for a Level 2 C3PAO assessment typically involves the following steps. Current DoD suspension direction does not permit Level 2 C3PAO or Level 3 designations in solicitations or contracts, so treat this section as future-planning information and verify the latest contract modification.
- Pre-assessment: C3PAO reviews your SSP, any applicable POA&M, and evidence artifacts
- Assessment activities: Interviews, demonstrations, and evidence review; delivery method and duration depend on scope and the authorized assessor
- Conditional status, when eligible: A score of at least 88 points and compliance with POA&M restrictions can support Conditional CMMC Status. The remaining eligible items must be closed through a closeout assessment within 180 days.
- Results recorded: The authorized assessment organization records the assessment results and CMMC status in the DoD-designated system
- Status maintenance: Final Level 2 C3PAO status remains current for up to three years, subject to annual affirmation and the rule's status-maintenance conditions; Conditional status lasts no more than 180 days
What Assessors Look For
C3PAO assessors evaluate all 320 assessment objectives from the CMMC Level 2 Assessment Guide and NIST SP 800-171A. Each of the 110 requirements has one or more objectives, and every applicable objective must be MET for the requirement to be assessed as MET.
Key areas assessors focus on:
- Documented policies and procedures relevant to the applicable requirements and objectives
- Technical evidence that controls are implemented (screenshots, configurations, logs)
- Personnel awareness of security responsibilities
- Incident response capability and testing
- Continuous monitoring practices
Preparing for a Required Assessment: A Practical Sequence
There is no universal preparation duration. Set target dates from the assessed boundary, gap severity, staffing, dependencies, and the solicitation or contract.
Step 1: Baseline Assessment
Assess all 110 controls honestly. Mark each as Implemented, Partially Implemented, or Not Implemented. Calculate your SPRS score. This gives you a clear picture of your gaps.
Step 2: Gap Analysis & Prioritization
Use the 1-, 3-, and 5-point deductions as one prioritization input alongside security risk, contractual obligations, technical dependencies, POA&M eligibility, and implementation difficulty. Point value alone is not a security-severity ranking.
Step 3: Remediation
Close gaps systematically. Maintain accurate SSP narratives and objective evidence, and use a POA&M only for unresolved requirements when permitted and appropriate. Documentation supports, but does not substitute for, implementation.
Step 4: Evidence Collection (Ongoing)
Build your evidence vault: policy documents, configuration screenshots, training records, audit logs, incident response plans. Organize by control family.
Step 5: SSP & POA&M Review
Keep the System Security Plan current. If unresolved requirements are documented on a POA&M, confirm that the entries are accurate and eligible before a future C3PAO assessment. During the current suspension, verify any planned assessment against the latest solicitation or contract modification.
Step 6: Qualified Readiness Review
Run a readiness review. Can you answer assessor questions for every control? Is your evidence organized and accessible?
Common Mistakes That Delay a Supported Assessment Result
- Using a generic schedule: preparation time varies with scope, existing implementation, evidence quality, and the required assessment type
- Underestimating documentation: technical controls without evidence don't count
- Ignoring policies: relevant policies and procedures are one evidence source and must match actual implementation
- Not training staff: AT controls require documented awareness training
- Spreadsheet-based tracking: doesn't scale, prone to errors, no audit trail
How CMMC Command Helps
CMMC Command supports the preparation workflow:
- Free tier: Full 110-requirement assessment with estimated SPRS scoring
- Starter ($249/mo): Evidence vault, SSP/POA&M generation, policy templates
- Professional ($749/mo): 10 AI features, security tool integrations, remediation task board
The platform estimates an SPRS score using DoD weights, generates structured document drafts, and uses AI to identify possible gaps and recommend remediation steps. It does not determine compliance or guarantee an assessment result.
Start your free assessment today, no credit card required.
Related Resources
Organize your CMMC preparation
Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.