Skip to content
ActaCyber

CMMC Level 2: requirements, assessment, and automation

CMMC Level 2 is the middle tier of the Department of Defense's Cybersecurity Maturity Model Certification, built directly on the 110 security requirements in NIST SP 800-171, and it is the tier that reaches the largest share of the defense industrial base because it is triggered by controlled unclassified information rather than by federal contract information alone, the narrower trigger for Level 1 under the broader CMMC program. Most Level 2 contracts eventually require an independent certification assessment from an accredited third-party assessor, not a self-attestation, and getting that distinction right starts with one plain question: does CUI actually touch your systems?

What CMMC Level 2 is

CMMC Level 2, Advanced, is the assessment level built on the 110 security requirements defined in NIST SP 800-171, organized across fourteen requirement families that cover everything from access control to system and information integrity. It sits in the middle of the three-level CMMC structure: more demanding than Level 1's seventeen FAR-based practices, less demanding than Level 3's enhanced NIST SP 800-172 requirements reserved for the highest-priority defense programs.

What makes Level 2 different from a plain NIST 800-171 obligation is not the requirements themselves, which are identical, but the verification mechanism layered on top: a defined subset of Level 2 contracts can be satisfied with a company's own self-assessment, but the majority, particularly those involving higher-priority programs, require a certification assessment performed by a Certified Third-Party Assessment Organization, a C3PAO, accredited through the program's own accreditation body.

The certification, once issued, is not permanent. It runs on a triennial cycle, meaning the C3PAO assessment repeats roughly every three years, with an annual affirmation required in between to confirm the company's posture has not slipped.

Who needs CMMC Level 2

The dividing line between Level 1 and Level 2 is the type of information a contractor's systems actually handle, not the size of the company or the value of its contract.

  • A subcontractor several tiers removed from the prime that receives technical drawings, specifications, or program documentation marked as controlled unclassified information.
  • A software or cloud vendor whose platform stores or processes CUI on behalf of a defense program, even where the vendor's own business card says 'SaaS company' rather than 'defense contractor.'
  • A manufacturer or engineering firm that generates its own CUI as a byproduct of designing to a government specification, whether or not the originating document was marked.

The practical test is this: if a contract or a prime's flow-down never puts information marked as, or reasonably understood to be, controlled unclassified information on your systems, Level 1 covers you. The moment CUI is present, whether it arrives as a marked document, unmarked technical data that meets the CUI definition, or program information a reasonable person would recognize as sensitive, Level 2 applies, and a federal-contract-information-only self-assessment is no longer enough.

CMMC Level 2 requirements, by control family

Requirement familyWhat it covers
Access ControlWho can reach CUI and under what conditions
Awareness and TrainingRole-based security training for anyone touching CUI
Audit and AccountabilityLogging, log review, and accountability for actions on CUI systems
Configuration ManagementBaseline configurations and controlled change
Identification and AuthenticationVerifying the identity of users and devices before granting access
Incident ResponseDetecting, reporting, and responding to security incidents
MaintenanceControlling maintenance activities on systems that touch CUI
Media ProtectionProtecting and sanitizing media that stores CUI
Personnel SecurityScreening and offboarding for CUI access
Physical ProtectionControlling physical access to facilities and equipment
Risk AssessmentPeriodic assessment of risk to CUI
Security AssessmentOngoing assessment of the security program itself
System and Communications ProtectionBoundary protection and encryption in transit
System and Information IntegrityFlaw remediation, malicious code protection, monitoring

Those fourteen families add up to 110 individual requirements, each carrying a point value in the scoring methodology used for both the CMMC self-assessment and the broader NIST 800-171 self-assessment that DoD contracts have required since well before CMMC existed; a company implementing one is, in practice, implementing the other.

Not every unmet requirement can simply sit on a Plan of Action and Milestones while a company works toward full compliance. The Level 2 assessment rules limit which open items are POA&M-eligible to a defined subset of lower-weighted requirements, require a minimum overall score before POA&M eligibility applies at all, and set a fixed closeout window, currently 180 days, for clearing whatever is left open. Because this detail lives in the CMMC Program rule at 32 CFR Part 170 and has been refined as the rule matured, confirm the current POA&M eligibility list and closeout window against the latest rule text before planning around it.

The CMMC Level 2 assessment process, step by step

A Level 2 assessment splits into a preparation phase the company controls and a certification phase a C3PAO controls, and the two phases run on very different clocks.

  1. Confirm Level 2 applies: Walk through the CUI-versus-FCI decision logic against actual contract flow-down language and data handling, not assumption; typically one to three weeks.
  2. Build or update the System Security Plan: Document how each of the 110 requirements is implemented across the defined boundary, referencing actual configurations rather than intended ones; often eight to fourteen weeks starting close to zero.
  3. Run the self-assessment scoring methodology: Score the environment using the same 110-point methodology used for the standalone NIST 800-171 obligation, identifying exactly which requirements are fully met, partially met, or not met.
  4. Remediate and document POA&M items: Close as many gaps as possible, and document the remainder as Plan of Action and Milestones entries, keeping in mind that only a limited set of lower-weighted requirements are POA&M-eligible under the current rule.
  5. Select and engage a C3PAO: Choose from the growing but still limited marketplace of accredited Certified Third-Party Assessment Organizations and schedule the assessment; lead time varies widely by region and season, sometimes several months out.
  6. Undergo the certification assessment: The C3PAO's certified assessors review evidence, interview personnel, and test the implemented requirements against the SSP, typically one to three weeks of active fieldwork depending on environment size.
  7. Close any assessment-identified POA&M items within the window: Clear any remaining eligible open items inside the fixed closeout window before the certification is finalized.
  8. Affirm annually and reassess triennially: Submit the annual affirmation in SPRS between full assessments, and plan for the next C3PAO assessment roughly three years out.

How long does CMMC Level 2 take and what does it cost?

Level 2 timelines split cleanly into two phases: getting the environment assessment-ready, and then getting an assessment scheduled and completed, and the second phase is increasingly the bottleneck as demand for C3PAO capacity outpaces supply.

Preparation, from a standing start with no mature 800-171 program, commonly runs six to twelve months for a mid-size supplier, faster for a company already running disciplined self-assessments under existing DFARS clauses, slower where meaningful technical remediation, such as replacing end-of-life systems or building centralized logging, is required.

C3PAO certification assessment fees vary by environment size and boundary complexity: a small business with a tightly scoped enclave commonly sees $30,000 to $60,000, a mid-size supplier with a broader boundary $60,000 to $120,000, and a large or complex environment $120,000 to $250,000 or more. Advisory support to prepare the SSP and run the internal self-assessment, if not done in-house, typically adds $20,000 to $75,000. Scheduling lead time with an accredited C3PAO can itself add one to several months on top of the fieldwork, depending on regional assessor availability.

ACTA is licensed per environment, and every engagement starts with a conversation. What ACTA automates is the preparation side: scoping, evidence collection, and SSP and POA&M generation, not the C3PAO's own independent certification fee, which is a separate, non-negotiable cost of the program.

Common failure points

Level 2's failure points cluster around the assessment mechanics themselves, not just general security hygiene.

  • Treating a self-assessment score as equivalent to certification readiness when the contract in question actually requires C3PAO certification.
  • Putting an ineligible, higher-weighted requirement on a POA&M when only a limited set of lower-weighted items qualify under the current rule.
  • Missing the minimum overall score threshold a company must clear before POA&M eligibility applies at all.
  • Evidence collected for the SSP that no longer matches what is actually configured by the time the C3PAO shows up.
  • Letting the annual affirmation between triennial assessments lapse because nobody owns the calendar reminder.
  • Assuming last cycle's score and evidence carry forward untouched without a fresh review of what changed in the environment since.

How ACTA automates CMMC Level 2

ACTA's federal pack library includes CMMC, covering Level 2 specifically, and ships with every license: a supplier moving from self-assessment readiness to full certification does not pay a separate fee to unlock the pack that covers the next level up. The pack is editable YAML, so control narratives can be tuned per requirement rather than left generic.

For the 110 requirements specifically, ACTA generates control narratives and an evidence binder mapped requirement by requirement, drawn from the live environment rather than assembled by hand after the fact, aimed at shortening the fieldwork time a certification assessment otherwise spends chasing down evidence one requirement at a time.

ACTA runs on goRapide, BMD's deterministic causal engine, with no LLMs, no agents, and no probabilistic scoring anywhere in the path, so re-running the same environment through the same assessment methodology after a C3PAO's own review produces the identical score it produced before, evidence included, with an inspectable causal chain behind each of the 110 individual determinations. Nothing in the output depends on which day the tool ran or who ran it.

ACTA can also provision the environment itself as code, on AWS commercial, AWS GovCloud, Microsoft GCC High, Azure, Google Cloud, or bare metal, with a small environment standing up in roughly 25 minutes, and continuous monitoring afterward tracks credential health, evidence freshness, and drift from previously passing requirements between the annual affirmation and the next triennial assessment, refreshing a stale posture to current in two clicks.

CMMC Level 2 and adjacent frameworks

Level 2's 110 requirements are, verbatim, NIST 800-171. A company that already runs a mature 800-171 self-assessment program under existing DFARS obligations is not starting from zero when Level 2 certification becomes a contract requirement; it is adding a C3PAO's independent verification on top of work already done.

Level 2 is one tier inside the larger CMMC program, which also covers the lighter Level 1 self-assessment for FCI-only contractors and the Level 3 government-led assessment for the highest-priority programs; a company's obligations can shift level as its contract portfolio changes.

Some Level 2 candidates arrive with an existing SOC 2 Type 2 report and ask whether it substitutes for any part of the certification. It does not, formally: a SOC 2 engagement tests a different, broader trust-services scope with its own criteria, and a C3PAO assessor still independently tests all 110 CMMC requirements regardless of what a SOC 2 report already covers. A mature SOC 2 program can shorten the internal evidence-gathering effort, but it does not replace the assessment.

For the wider set of frameworks a defense contractor is likely to encounter alongside Level 2, including how it relates to cloud authorization and the department's broader risk posture, see the compliance framework library.

Frequently asked questions

Do I need CMMC Level 2?

If controlled unclassified information touches your systems, whether as a marked document, unmarked technical data meeting the CUI definition, or program information a reasonable person would treat as sensitive, Level 2 applies. If your contracts only ever involve federal contract information, Level 1's lighter self-assessment covers you instead.

What is the CMMC deadline?

There is no single fixed deadline. The CMMC Program rule and its DFARS clause are being phased into new DoD solicitations in stages, and the schedule has shifted before as the program matured. Confirm which of your specific contracts carry the clause today against current DFARS and CMMC Program guidance.

What does a C3PAO assessment cover?

A C3PAO's certified assessors review documented evidence, interview relevant personnel, and independently test all 110 NIST SP 800-171 requirements against what the System Security Plan claims is implemented. The assessment produces a certification decision, not a numeric score alone, and typically runs one to three weeks of active fieldwork.

Can I self-assess for CMMC Level 2?

A defined subset of Level 2 contracts allow self-assessment, but most, particularly higher-priority programs, require an independent C3PAO certification assessment instead. Which path applies is set by the specific contract requirement, so confirm it in your own contract language rather than assuming self-assessment is sufficient.

How many requirements are in CMMC Level 2?

110, organized across fourteen requirement families covering access control, audit and accountability, configuration management, incident response, and more, all drawn directly from NIST SP 800-171. The requirements themselves do not change between a standalone 800-171 obligation and a CMMC Level 2 certification.

How long is a CMMC Level 2 certification valid?

A Level 2 certification runs on a triennial cycle, meaning the full C3PAO assessment repeats roughly every three years. In the years between assessments, the company submits an annual affirmation in SPRS confirming its posture has not slipped, and a lapsed affirmation can put the certification at risk before the next full reassessment is even due.

What is a POA&M in CMMC Level 2?

A Plan of Action and Milestones documents a requirement that is not yet fully implemented and the plan to close it. Only a limited set of lower-weighted requirements are POA&M-eligible under the current CMMC Program rule, with a fixed closeout window, currently 180 days, to confirm against the latest rule text.

How much does a C3PAO assessment cost?

Fees scale with environment size and boundary complexity: roughly $30,000 to $60,000 for a small business with a tightly scoped enclave, $60,000 to $120,000 for a mid-size supplier, and $120,000 to $250,000 or more for a large or complex environment, before advisory support to prepare for the assessment.

Who accredits C3PAOs?

The CMMC program's own accreditation body accredits Certified Third-Party Assessment Organizations and the individual assessors who work under them. A company selecting a C3PAO should confirm current accreditation status directly with the accreditation body rather than relying solely on the assessor's own marketing.

Request a quote

Related frameworks