CMMC Level 2 Explained: What DoD Contractors Need to Know

CMMC Compliance

Written by

David Bradshaw

Category

Compliance

Date

Share this article

Why CMMC Level 2 Exists

CMMC Level 2 is centered on the 110 security requirements in NIST SP 800-171 Revision 2, covering areas such as access control, awareness and training, configuration management, identification and authentication, incident response, risk assessment, system and communications protection, and system and information integrity.

But meeting Level 2 is more than checking 110 boxes. Organizations must demonstrate that applicable security requirements are implemented correctly, operating as intended, and producing the desired security outcomes. Your environment, systems, people, and processes must collectively support the protection of Controlled Unclassified Information (CUI).

The first step is therefore understanding where CUI enters, moves, resides, and leaves your environment. That means identifying the systems, applications, endpoints, cloud services, external providers, and subcontractors that interact with CUI. A well-defined assessment scope becomes the foundation for determining which assets, controls, policies, and evidence need to be addressed.

Documentation is equally important. Your System Security Plan (SSP) should accurately describe the environment and how security requirements are implemented, while your Plan of Action & Milestones (POA&M) should clearly track permitted remediation activities. Level 2 POA&Ms are subject to specific limitations and generally must be closed within 180 days when permitted.

What Level 2 Actually Requires

Many contractors begin with the controls before understanding their environment.

That creates unnecessary work.

If you don't know exactly where CUI exists, which systems process it, which users can access it, or which third parties support those systems, it's difficult to determine the true CMMC assessment boundary.

Common scoping challenges include:

  1. Unidentified CUI repositories

  2. Unclear data flows

  3. Shared corporate environments

  4. Personal or unmanaged devices

  5. Cloud services processing CUI

  6. External service providers

  7. Subcontractor access

  8. Inconsistent asset inventories

  9. Unclear system boundaries

CMMC assessment scope is directly tied to the assets and systems involved in protecting CUI.

Documentation Becomes the Second Bottleneck

A spreadsheet showing “implemented” isn't enough.

Assessors need to understand how controls actually operate within your environment and evaluate whether the requirements are implemented correctly and producing the intended outcomes.

That makes documentation a critical part of readiness.

Your program may require evidence such as:

  • System Security Plan

  • POA&M

  • Policies and procedures

  • Network and data-flow diagrams

  • Asset inventories

  • Access reviews

  • Vulnerability assessments

  • Incident-response documentation

  • Security awareness records

  • Configuration evidence

  • Audit logs

  • Vendor assessments

  • Backup and recovery evidence

  • Control testing results

The strongest organizations don't create this evidence at the end. They build evidence collection into the way their security program operates.

Where Contractors Get Stuck

Treat CMMC as a Program, Not an Audit

The contractors that move efficiently don't wait until an assessment is approaching to begin preparing.

They establish a structured path:

01 — Define the Boundary

Identify CUI, map its movement, establish the assessment scope, and identify every system and service supporting the environment.

02 — Assess the Gaps

Evaluate the 110 requirements against your actual implementation. Prioritize gaps based on security impact, assessment risk, dependencies, and remediation effort.

03 — Build the Foundation

Strengthen policies, technical controls, governance processes, access management, incident response, vulnerability management, configuration management, and other required capabilities.

04 — Document the Evidence

Build an SSP that accurately reflects the environment and establish repeatable evidence collection for implemented controls.

05 — Remediate & Validate

Address deficiencies, validate that controls operate as intended, and continuously test the effectiveness of your implementation.

06 — Prepare for Assessment

Conduct an assessment-readiness review before engaging the applicable assessment organization or completing the required self-assessment.

Getting Certified Without Losing Momentum

Don't Let CMMC Become a Business Bottleneck

CMMC readiness shouldn't require your organization to stop building products, serving customers, or pursuing new contracts.

The goal is to create a repeatable security foundation that protects CUI while supporting the way your business actually operates.

A mature approach connects:

CUI Mapping → Scope → Risk → Controls → Evidence → Assessment → Continuous Compliance

And because CMMC requirements and implementation are evolving, contractors should validate the requirements that apply to their specific solicitation and contract rather than relying on a generic certification timeline. The DoD currently states that Phase II implementation has been suspended while the program undergoes review, while existing safeguarding obligations remain in place.

Build CMMC Readiness Into Your Operations

Know your scope. Close your gaps. Prove your controls. Stay ready.

Share Blog