CMMC Level 2 Explained: What DoD Contractors Need to Know
CMMC Compliance
Written by
David Bradshaw
Category
Compliance
Date
Share this article
Why CMMC Level 2 Exists
CMMC Level 2 is centered on the 110 security requirements in NIST SP 800-171 Revision 2, covering areas such as access control, awareness and training, configuration management, identification and authentication, incident response, risk assessment, system and communications protection, and system and information integrity.
But meeting Level 2 is more than checking 110 boxes. Organizations must demonstrate that applicable security requirements are implemented correctly, operating as intended, and producing the desired security outcomes. Your environment, systems, people, and processes must collectively support the protection of Controlled Unclassified Information (CUI).
The first step is therefore understanding where CUI enters, moves, resides, and leaves your environment. That means identifying the systems, applications, endpoints, cloud services, external providers, and subcontractors that interact with CUI. A well-defined assessment scope becomes the foundation for determining which assets, controls, policies, and evidence need to be addressed.
Documentation is equally important. Your System Security Plan (SSP) should accurately describe the environment and how security requirements are implemented, while your Plan of Action & Milestones (POA&M) should clearly track permitted remediation activities. Level 2 POA&Ms are subject to specific limitations and generally must be closed within 180 days when permitted.
What Level 2 Actually Requires
Many contractors begin with the controls before understanding their environment.
That creates unnecessary work.
If you don't know exactly where CUI exists, which systems process it, which users can access it, or which third parties support those systems, it's difficult to determine the true CMMC assessment boundary.
Common scoping challenges include:
Unidentified CUI repositories
Unclear data flows
Shared corporate environments
Personal or unmanaged devices
Cloud services processing CUI
External service providers
Subcontractor access
Inconsistent asset inventories
Unclear system boundaries
CMMC assessment scope is directly tied to the assets and systems involved in protecting CUI.
Documentation Becomes the Second Bottleneck
A spreadsheet showing “implemented” isn't enough.
Assessors need to understand how controls actually operate within your environment and evaluate whether the requirements are implemented correctly and producing the intended outcomes.
That makes documentation a critical part of readiness.
Your program may require evidence such as:
System Security Plan
POA&M
Policies and procedures
Network and data-flow diagrams
Asset inventories
Access reviews
Vulnerability assessments
Incident-response documentation
Security awareness records
Configuration evidence
Audit logs
Vendor assessments
Backup and recovery evidence
Control testing results
The strongest organizations don't create this evidence at the end. They build evidence collection into the way their security program operates.
Where Contractors Get Stuck
Treat CMMC as a Program, Not an Audit
The contractors that move efficiently don't wait until an assessment is approaching to begin preparing.
They establish a structured path:
01 — Define the Boundary
Identify CUI, map its movement, establish the assessment scope, and identify every system and service supporting the environment.
02 — Assess the Gaps
Evaluate the 110 requirements against your actual implementation. Prioritize gaps based on security impact, assessment risk, dependencies, and remediation effort.
03 — Build the Foundation
Strengthen policies, technical controls, governance processes, access management, incident response, vulnerability management, configuration management, and other required capabilities.
04 — Document the Evidence
Build an SSP that accurately reflects the environment and establish repeatable evidence collection for implemented controls.
05 — Remediate & Validate
Address deficiencies, validate that controls operate as intended, and continuously test the effectiveness of your implementation.
06 — Prepare for Assessment
Conduct an assessment-readiness review before engaging the applicable assessment organization or completing the required self-assessment.
Getting Certified Without Losing Momentum
Don't Let CMMC Become a Business Bottleneck
CMMC readiness shouldn't require your organization to stop building products, serving customers, or pursuing new contracts.
The goal is to create a repeatable security foundation that protects CUI while supporting the way your business actually operates.
A mature approach connects:
CUI Mapping → Scope → Risk → Controls → Evidence → Assessment → Continuous Compliance
And because CMMC requirements and implementation are evolving, contractors should validate the requirements that apply to their specific solicitation and contract rather than relying on a generic certification timeline. The DoD currently states that Phase II implementation has been suspended while the program undergoes review, while existing safeguarding obligations remain in place.
Build CMMC Readiness Into Your Operations
Know your scope. Close your gaps. Prove your controls. Stay ready.
Share Blog