← Back to blog

U.S. Contractors: Prove 110 CMMC Level 2 Controls Your Contract Needs

September 6, 2026
U.S. Contractors: Prove 110 CMMC Level 2 Controls Your Contract Needs

CMMC Level 2 requires implementing the 110 NIST SP 800-171 Rev 2 security requirements and proving them through the assessment path your contract mandates. Your immediate move is to confirm whether that contract requires a self-assessment or a C3PAO certification, then define your CUI scope. A score of 88 out of 110 gets you Conditional status; Final status demands every applicable requirement is fully MET.


TL;DR:

  • Achieving Level 2 compliance requires fully meeting all 110 NIST SP 800-171 requirements, not just partial implementation.
  • The assessment path—self or third-party—determines the workload, document requirements, and results submission system used.
  • Correct scoping of CUI assets is crucial for controlling costs, focusing on data flow, environment segmentation, and asset categorization.
  • Evidence must be specific, current, and exportable, including SSP, POA&M, configuration exports, and operational logs, to satisfy assessor requirements.
  • Maintaining compliance involves annual reaffirmation, continuous monitoring, and scope updates triggered by organizational changes.

Table of Contents

What Are the CMMC Level 2 Requirements Under NIST SP 800-171?

CMMC Level 2 is not a new set of controls invented by the Department of Defense. It's the direct adoption of the 110 security requirements published in NIST SP 800-171 Revision 2, written into federal rule at 32 CFR § 170.14. If your organization handles Controlled Unclassified Information, this is the control set you're building toward, full stop.

Those 110 requirements sort into 14 families, and each one carries a distinct evidence burden. Assessors don't just want a policy binder. They want proof the control operates day to day.

Control FamilyWhat It CoversTypical Evidence
Access ControlLimiting system and data access to authorized usersRole-based access lists, account review logs
Awareness & TrainingSecurity training for personnel handling CUITraining completion records, curriculum
Audit & AccountabilityLogging and reviewing system activitySIEM logs, audit review tickets
Configuration ManagementBaseline configs and change controlConfig exports, change tickets
Identification & AuthenticationVerifying user and device identity, MFAMFA logs, identity provider configs
Incident ResponseDetecting, reporting, and recovering from incidentsIR plan, tabletop exercise records
MaintenanceControlling system maintenance activitiesMaintenance logs, vendor access records
Media ProtectionProtecting digital and physical media containing CUIMedia sanitization logs, encryption configs
Personnel SecurityScreening personnel with CUI accessScreening records, offboarding checklists
Physical ProtectionControlling physical access to facilities and equipmentBadge logs, visitor logs
Risk AssessmentIdentifying and evaluating risk to CUIRisk assessment reports, vulnerability scans
Security AssessmentTesting and monitoring control effectivenessInternal assessment reports, POA&Ms
System & Communications ProtectionBoundary protection and encrypted transmissionFirewall rules, network diagrams
System & Information IntegrityMalware protection and flaw remediationEDR/AV logs, patch records

Assessors don't grade against the 110 requirements directly. They use NIST SP 800-171A, which breaks those requirements into roughly 320 discrete assessment objectives. Each objective gets evaluated through one or more of three methods: examine (documents), interview (personnel), and test (technical verification). A single requirement, like multifactor authentication, might carry four or five sub-objectives an assessor checks independently. That's why a "we have MFA" statement never survives an assessment on its own. You need documentation, a person who can explain the process, and a technical demonstration that lines up.

How Do the Level 2 Self and C3PAO Assessment Paths Differ?

Your contract decides this for you. The solicitation or the DFARS clause flowed down to you specifies whether you self-assess or bring in a Certified Third-Party Assessment Organization, and that single line item changes your entire compliance workload.

Level 2 (Self):

  • The Organization Seeking Assessment conducts its own assessment against all 110 requirements.
  • Results get entered directly into the Supplier Performance Risk System (SPRS).
  • A senior company official affirms the score, and that affirmation repeats annually.
  • The assessment cycle runs periodically, requiring reassessment and reaffirmation on a regular schedule, with affirmations required annually in between.

Level 2 (C3PAO):

  • An accredited third-party assessor evaluates your environment against the same 110 requirements, using the same NIST SP 800-171A objectives.
  • Results are entered into the Enterprise Mission Assurance Support Service (eMASS), then transmitted to SPRS.
  • You still need a senior official affirmation, but now it sits on top of a formal, documented third-party assessment.
  • C3PAOs expect evidence packaged in advance. Assessors move fast when your SSP, asset inventory, and technical exports are organized before day one, and slow to a crawl when they aren't.

The flow-down consequence matters more than most prime contractors explain to their subs. If your contract requires C3PAO certification because you handle CUI directly, any subcontractor who touches that same CUI generally inherits the same requirement, not a lighter version of it. Primes are increasingly pushing that obligation downstream in subcontract language, so read your flow-down clauses carefully rather than assuming Level 1 or self-assessment applies by default. A regional MSP breakdown of CMMC 2.0 obligations walks through how this plays out for smaller subcontractors who assumed they were out of scope and weren't.

How Do You Scope a CMMC Level 2 Assessment Correctly?

Scope is the single biggest lever you have over cost and timeline. Assess your entire network when only a fraction of it touches CUI, and you'll pay for an assessment three or four times larger than it needs to be. The CMMC Level 2 Scoping Guide defines five asset categories, and where each system lands changes how deeply it gets examined.

  • CUI assets process, store, or transmit Controlled Unclassified Information directly and get assessed against all applicable requirements.
  • Security protection assets provide security functions for the CUI environment, such as your SIEM or identity provider, and are assessed for their security role.
  • Specialized assets include IoT devices, operational technology, government-furnished equipment, and restricted information systems. They're documented in your SSP but not always assessed the same way as CUI assets.
  • Contractor risk-managed assets can process CUI but are managed under your risk-based security policy rather than assessed control-by-control.
  • Out-of-scope assets don't touch CUI or the security protection functions around it, and they stay outside the assessment boundary entirely, provided you can prove that separation.

Correctly categorizing assets requires four artifacts an assessor will ask for on day one: a complete asset inventory, a CUI data-flow map showing exactly where that information travels, a network diagram, and a written scope narrative that explains your logic. Skip the narrative and you leave the assessor to guess why a system sits where it does.

The practical decision most contractors face is whether to build a dedicated CUI enclave or manage CUI in place across a broader environment. An enclave, a segmented network zone with tighter controls and defined boundaries, often shrinks your assessed footprint dramatically. It costs more up front to build but usually costs less over the life of your triennial assessment cycle, especially if your business processes CUI on a narrow set of workflows.

Pro Tip: Before you spend a dollar on remediation, spend a week mapping exactly which systems touch CUI. Contractors who scope first and remediate second routinely cut their assessed environment by more than half.

What Evidence Do Assessors Actually Require at Level 2?

A tool sitting configured on a server tells an assessor nothing. What they're evaluating is whether a control functions in daily operation, and that means specific, dated, exportable evidence tied to each requirement.

  1. System Security Plan (SSP). This is your foundational document, required as a prerequisite under requirement 3.12.4, and it describes your environment, your boundaries, and how each of the 110 requirements is implemented. An outdated or generic SSP is one of the fastest ways to stall an assessment before it starts.
  2. Plan of Action and Milestones (POA&M). This tracks any requirement not yet fully implemented, along with remediation steps and target dates. Not every unmet requirement qualifies for a POA&M, a distinction that trips up a lot of first-time contractors.
  3. Technical evidence. Screenshots of configuration screens, exported firewall and access control rules, MFA authentication logs, EDR or antivirus detection logs, and vulnerability scan outputs with remediation timestamps.
  4. Operational evidence. Help desk ticket trails showing incident response in action, completed training records tied to named employees, tabletop exercise logs, and, where subcontractors or vendors handle any part of your environment, a documented responsibility matrix showing who owns which control.
  5. Configuration exports. Baseline configurations for servers, network devices, and endpoint protection tools, dated close to the assessment window so the assessor can verify currency.

The Level 2 Assessment Guide explicitly maps acceptable evidence types to each assessment objective, and contractors who build their evidence library against that mapping, rather than against a generic security checklist, waste far less time during the actual assessment window.

What Are the SPRS Scoring Rules and POA&M Limits?

Every Level 2 assessment starts at a perfect score of 110 and loses points from there. Unmet requirements are deducted at three different weights, either 5, 3, or 1 point, depending on how the Federal Register final rule categorizes that specific requirement's risk contribution.

CMMC 110-point score and deduction weights

A score of 88 out of 110 is the floor for a Conditional assessment outcome. Fall below it, and you don't pass, period. Final status requires every applicable requirement to be fully MET, with no open items at all. Conditional status exists as a bridge, not a finish line.

POA&Ms give you that bridge, but within tight limits:

  • Only a subset of requirements, generally the ones weighted at 1 point, can be placed on a POA&M at all.
  • One notable exception exists for FIPS-validated cryptography, which the rule treats separately given the complexity of achieving full validation.
  • A Conditional assessment allows a limited time period to close every item on your POA&M. Missing that window causes your certification status to revert.
  • Six specific high-risk requirements, tied to the most severe security gaps identified in the underlying NIST framework, can never appear on a POA&M under any circumstance. They must be MET before an assessor will even consider a Conditional outcome.

That last rule catches contractors off guard more than any other part of the scoring model. Contractors sometimes assume a POA&M can defer any weak spot. It can't defer the ones that matter most.

What's the Practical Timeline to Get Assessor-Ready?

Readiness for CMMC Level 2 compliance follows a sequence, and skipping steps to save time almost always costs more time later. Here's the order that works, based on how the industry's own sequencing guidance consistently frames it.

  1. Confirm your assessment path and document CUI scope (1 to 2 weeks). Read your contract and any flowed-down DFARS clauses to determine self-assessment or C3PAO certification. Map every system that touches CUI before you touch a single technical control.
  2. Build or update your SSP, asset inventory, and network diagrams (2 to 6 weeks). Timeline depends heavily on scope. A tightly segmented CUI enclave documents faster than an environment where CUI touches half your network.
  3. Remediate technical gaps, prioritized by point weight (4 to 12 weeks typical). Fix the 5-point deductions first: multifactor authentication, encryption, endpoint detection, patch management. These carry the most scoring risk and usually take the longest to implement properly, especially MFA rollout across legacy systems.
  4. Collect evidence, run an internal dry-run audit, and build your POA&M (2 to 4 weeks). This is where most organizations discover gaps between what they think is documented and what actually exists in exportable form. A dry-run against the NIST SP 800-171A objectives, not a generic checklist, catches the gaps an assessor will find anyway.
  5. Complete the final assessment, submit results to SPRS or eMASS, and set your annual affirmation calendar. This step is largely administrative once steps one through four are solid, but missing the affirmation deadline the following year can undo everything you built.

Pro Tip: Run your internal dry-run against the actual NIST SP 800-171A assessment objectives, not a simplified internal checklist. Contractors who test against a watered-down version of the requirements consistently pass their own dry-run and then fail the real thing on evidence granularity.

Total time to assessor-ready varies based on starting posture and scope size, often ranging from a few months to half a year or longer for complex environments.

What's the Practical Timeline to Get Assessor-Ready? — overview diagram

What Mistakes Slow Down CMMC Level 2 Compliance?

Most Level 2 failures trace back to a handful of repeating mistakes, and none of them are exotic. Contractors chase the hard technical controls while the paperwork and scope decisions quietly sink the assessment.

Incorrect scope tops the list. Organizations either assess too much, driving up cost and assessment time unnecessarily, or too little, leaving CUI-touching systems outside the documented boundary where an assessor will eventually find them anyway.

Missing or thin SSP content comes next. A System Security Plan copied from a template and never customized to the actual environment is one of the fastest ways to lose assessor confidence before the technical review even begins.

Tool-installed-but-not-operational evidence gaps are the quiet killer. A vulnerability scanner running with no one reviewing the output, or MFA enabled for some accounts but not others, reads to an assessor as a control that exists on paper but not in practice.

POA&M misuse rounds out the common failures, whether that's attempting to defer a requirement that isn't POA&M-eligible or building a remediation plan with no real target date behind it.

  • Fix scope errors by mapping data flow before touching a single control.
  • Fix SSP gaps by writing to the actual environment, not a generic template, and updating it every time the environment changes.
  • Fix operational evidence gaps by pulling exports and logs monthly, well before assessment season, so gaps surface early.
  • Fix POA&M misuse by checking eligibility against the rule's point-weighting before assuming any item can be deferred.

A control that exists only in a vendor's marketing brochure is not a control an assessor will accept. The gap between "we bought the tool" and "we can prove it works" is where most Level 2 assessments stall.

This is precisely the gap a vCISO engagement is built to close. CisoSafe's approach pairs vCISO scoping work with an evidence-collection platform, so instead of chasing screenshots and log exports manually in the final weeks before assessment, contractors build an evidence trail continuously and align it to their SSP and POA&M as they go.

Pro Tip: If your team can't produce a dated MFA log, a patch record, or a training completion report in under five minutes, that's a sign your evidence process, not your security posture, needs the most immediate attention.

What Happens After the Assessment: Affirmation and Monitoring?

Passing your assessment isn't the finish line. It's the start of an operational cadence you have to sustain for the life of your contract.

  • SPRS and eMASS entry happens differently by path. Self-assessment results post directly to SPRS. C3PAO results land in eMASS first, then transmit to SPRS, and your organization should confirm that transmission actually completed rather than assuming it did.
  • Annual affirmation requires a senior company official, someone with the authority to attest on behalf of the organization, to confirm continuing compliance every year between full assessments. Missing this deadline can suspend your certification status even if your security posture hasn't changed.
  • Continuous monitoring should include a regular vulnerability scanning cadence, SSP updates whenever infrastructure or personnel changes, active tracking of any open POA&M items against their 180-day clock, and recurring security awareness training rather than a one-time onboarding event.
  • Re-scope triggers include mergers, new contracts that expand your CUI footprint, major infrastructure changes, or cloud migrations. Any of these should prompt a scope review well before your next triennial assessment window, not during it.

What Should Contractors Prioritize First?

If you're staring down a Level 2 requirement for the first time, the order of operations matters more than the order of urgency you feel. Confirm your contract's assessment path first. Scope your CUI environment second. Build the SSP third. Collect evidence fourth. Contractors who reverse that order, chasing technical fixes before scope is settled, end up remediating systems that should have been out of the assessment boundary from the start.

Bring in outside help when your team lacks a dedicated security function, when your contract deadline is inside six months, or when your CUI footprint spans multiple business units and nobody owns the full picture. A focused readiness engagement, done well, pays for itself by preventing the wasted remediation spend that comes from scoping mistakes and by catching evidence gaps months before an assessor does, not during the assessment window when there's no time left to fix them.

— vCISO

How CisoSafe Helps Contractors Reach CMMC Level 2 Readiness

A structured vCISO engagement built around exactly the sequence this article covers: confirming your assessment path, scoping CUI correctly, and building the SSP and evidence trail an assessor will actually accept can help replace the trial-and-error most contractors go through alone.

CisoSafe

Where most organizations lose weeks chasing manual screenshots and log exports in the final stretch before an assessment, an automated evidence collection platform can continuously update MFA logs, configuration exports, and training records to keep them current instead of becoming a scramble two weeks before an assessor arrives. Combined with hands-on vCISO scoping and policy development, such a pairing can shorten the path to assessor-ready compared to building an internal program from a blank SSP template. Contractors receive a security roadmap and readiness reviews aligned to the actual NIST SP 800-171A assessment objectives, not a generic checklist that leaves gaps an assessor will find anyway. Related work on security assessment scoping for mid-market companies shows the same enclave and segmentation thinking applied across other regulated industries.

If your contract deadline is approaching and your CUI scope isn't documented yet, book a readiness assessment with CisoSafe to find out exactly where your organization stands against the 110 requirements before an assessor does.

Where to Find the Official CMMC Level 2 Rules

Treat industry guides, including this one, as a map. The primary sources are the territory, and they're where exact wording and procedural detail carry legal weight.

The DoD CMMC Model Overview defines the model structure and its relationship to NIST SP 800-171. The Level 2 Assessment Guide details assessment methods and evidence expectations. The Federal Register final rule governs scoring, POA&M timelines, and affirmation requirements as binding law. NIST SP 800-171 Rev 2 itself remains the underlying control catalog, and CISA's CMMC 2.0 resource page offers program context worth reviewing before you dig into the denser documents.

Sources