What Is CMMC Level 2? Requirements, Timeline, and How to Prepare
First developed as part of our LinkedIn content series, June 2026. Expanded and updated for this site.
A machine shop in Huntsville self-attested to NIST 800-171 compliance three years ago, submitted a SPRS score of 97, and won a $14M subcontract manufacturing precision components for a missile program. When the C3PAO arrived for their CMMC Level 2 assessment, the assessor asked for evidence of multi-factor authentication on their CUI enclave. The IT manager pointed to a sticky note on the server room door with the shared admin password. Their actual score was negative 30. The contract is now at risk, and the DoJ has opened a False Claims Act inquiry into the original self-attestation.
This is not hypothetical. The Department of Justice has made clear that inflated SPRS scores constitute false claims, and enforcement actions are underway across the Defense Industrial Base. CMMC Level 2 exists precisely because self-attestation failed — organizations claimed compliance without operational evidence, and DoD lost patience.
Why This Matters Now
CMMC Phase 2 inserts Level 2 certification requirements into solicitations beginning November 2026. Any DIB organization that handles Controlled Unclassified Information and wants to compete for new contracts after that date must hold a valid C3PAO assessment or be in active assessment. There is no grace period for organizations that have not started preparation.
Three converging pressures make this urgent:
C3PAO assessor shortage. The number of accredited C3PAOs cannot absorb the demand from 80,000+ DIB organizations needing assessment. Current booking backlogs exceed six months. Organizations that wait until Q3 2026 to schedule may not achieve certification before contracts require it.
False Claims Act enforcement. DoJ has publicly stated that SPRS scores submitted to SPRS represent certifications to the government. Scores that overstate compliance are actionable under the False Claims Act, with treble damages. Multiple qui tam lawsuits are in progress.
Subcontractor flow-down. Prime contractors are requiring CMMC Level 2 certification from subcontractors ahead of the government mandate. The supply chain is already constraining, and primes are selecting certified subcontractors over uncertified ones regardless of whether the solicitation formally requires it yet.
What CMMC Level 2 Actually Requires
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171 Rev 2, organized across 14 control families. But here is the critical distinction that most organizations miss:
CMMC Level 2 is not 110 controls — it is 110 EVIDENCED controls. The difference between self-attestation and C3PAO assessment is the difference between claiming and proving.
Under self-attestation, an organization could state "we implement multi-factor authentication" and check the box. Under C3PAO assessment, the assessor will ask: show me the MFA configuration. Show me the logs proving it is enforced. Show me the policy requiring it. Show me what happens when someone attempts access without it. Show me how you handle exceptions. Show me your last access review.
Every single control requires operational evidence — not a policy document stating intent, but proof of implementation, enforcement, and monitoring.
The 110 Practices by Control Family
The 110 security requirements span 14 families from NIST 800-171:
| Family | Controls | Key Evidence Areas |
|---|---|---|
| Access Control (AC) | 22 | Account management logs, access enforcement configs, remote access policies, session controls |
| Awareness and Training (AT) | 3 | Training records, role-based training curricula, completion tracking |
| Audit and Accountability (AU) | 9 | Audit configurations, log retention evidence, review procedures, alert configs |
| Configuration Management (CM) | 9 | Baseline configurations, change control records, least functionality evidence |
| Identification and Authentication (IA) | 11 | MFA configs, password policies, identifier lifecycle, authenticator management |
| Incident Response (IR) | 3 | IR plans, test results, handling procedures, reporting mechanisms |
| Maintenance (MA) | 6 | Maintenance logs, tool approvals, remote maintenance controls |
| Media Protection (MP) | 9 | Media handling procedures, sanitization records, marking evidence, transport logs |
| Personnel Security (PS) | 2 | Screening procedures, termination checklists with system access revocation |
| Physical Protection (PE) | 6 | Access logs, monitoring systems, visitor procedures, alternate work site controls |
| Risk Assessment (RA) | 3 | Assessment reports, vulnerability scan results, risk determinations |
| Security Assessment (CA) | 4 | Assessment plans, POA&M management, system connections documentation |
| System and Communications Protection (SC) | 16 | Boundary protection configs, encryption implementation, CUI separation evidence |
| System and Information Integrity (SI) | 7 | Patch management records, malware protection configs, monitoring alerts |
The C3PAO Assessment Process
Understanding what the assessment actually looks like helps organizations prepare effectively:
Phase 1: Scoping and Preparation
The assessment begins with scoping — defining which systems, networks, and facilities process, store, or transmit CUI. This is where CUI enclave strategy becomes critical. Organizations that have properly segmented their CUI environment into a defined enclave reduce their assessment surface dramatically.
Your System Security Plan (SSP) defines the boundary. Everything inside that boundary is in scope. The assessor will verify that your SSP accurately reflects your environment — if CUI flows outside the documented boundary, that is a finding.
Phase 2: Evidence Review
The C3PAO reviews documentation and evidence for each of the 110 practices:
- Policies and procedures (necessary but not sufficient)
- System configurations and screenshots
- Audit logs demonstrating enforcement
- Training records
- Incident response test results
- Network diagrams showing CUI flow
- Access control lists and reviews
Phase 3: Assessment Interviews and Observation
Assessors interview personnel at multiple levels — IT staff, system administrators, users who handle CUI, and management. They observe processes in action. They may ask a random user to demonstrate how they handle CUI, or ask a system administrator to show how they process a configuration change request.
Phase 4: Findings and Determination
Each practice receives a status: MET, NOT MET, or NOT APPLICABLE. The assessor documents findings, including the specific evidence (or lack thereof) supporting each determination.
SPRS Score: The Numeric Reality Check
Before any C3PAO assessment, organizations must maintain a current SPRS score in the Supplier Performance Risk System. The scoring methodology:
- Start at 110 (all practices fully implemented)
- Subtract weighted values for each unmet practice (1, 3, or 5 points depending on criticality)
- Minimum possible score is -203
The critical insight: Your SPRS score is a legal representation to the federal government. Submitting an inflated score is not merely embarrassing — it is potentially a False Claims Act violation carrying treble damages and criminal liability.
Organizations should calculate their SPRS score honestly, submit it accurately, and use the gap between current score and 110 as their remediation roadmap. A score of 80 is not shameful — it is honest, and it demonstrates a clear path to compliance. A score of 110 submitted by an organization with open gaps is a legal liability.
POA&M Rules: The 180-Day Clock
CMMC Level 2 permits Plans of Action and Milestones (POA&Ms) for some practices — but with strict constraints:
- POA&Ms are generally limited to the lowest-weighted (1-point) practices, with narrow exceptions -- the highest-weighted practices (5-point deductions) are not allowed on a POA&M
- Practices eligible for POA&Ms must be closed within 180 days of the assessment date
- POA&Ms must include specific milestones, resource allocations, and completion dates
- Failure to close POA&Ms within 180 days revokes conditional certification
This is not a loophole for deferring hard work. It is a mechanism for addressing a small number of in-progress remediations at the time of assessment. Eligibility is capped by score: conditional status requires a minimum assessment score of 88 out of 110, which strictly limits how many items can remain open.
Conditional Certification
Organizations can receive conditional CMMC Level 2 certification while POA&M items remain open, subject to:
- All 5-point practices must be fully MET (no POA&Ms allowed)
- The assessment score must be at least 88 out of 110
- The organization must demonstrate a credible remediation plan
- The 180-day closure clock starts at conditional certification date
- Failure to close within 180 days results in revocation and re-assessment
Conditional certification allows organizations to compete for contracts while completing final remediation work, but it is not a strategy — it is a safety valve.
Scoping: The CUI Enclave Strategy
The single most impactful decision in CMMC Level 2 preparation is scoping. Every system that touches CUI is in scope. The most effective approach is a CUI enclave — a clearly defined, segmented environment where CUI is processed, stored, and transmitted, isolated from the broader corporate network.
Benefits of enclave scoping:
- Reduces the number of systems requiring all 110 controls
- Simplifies evidence collection and monitoring
- Creates clear boundaries that assessors can verify
- Limits the blast radius of compliance failures
- Reduces cost by narrowing the hardening surface
Enclave architecture typically includes:
- Dedicated network segment with boundary protection (firewalls, ACLs)
- Separate identity management or strict MFA boundary
- Dedicated endpoints or virtual desktops for CUI processing
- Encrypted storage and transmission within the enclave
- Monitoring and logging concentrated on the enclave boundary
Organizations that attempt to make their entire enterprise CMMC Level 2 compliant face exponentially higher costs and complexity. Scoping is not cutting corners — it is sound security architecture.
Cost and Timeline Expectations
Realistic preparation timelines and costs for a mid-size DIB subcontractor (100-500 employees):
Timeline:
- Gap assessment: 2-4 weeks
- Remediation (depends on gap severity): 3-12 months
- SSP and documentation development: 4-8 weeks (concurrent with remediation)
- Pre-assessment readiness review: 2-4 weeks
- C3PAO scheduling and assessment: 2-6 weeks (plus 6+ month booking lead time)
- Total realistic timeline: 9-18 months from start to certification
Cost ranges:
- Technology remediation (MFA, SIEM, endpoint protection, encryption): $50K-$300K
- Consulting and gap assessment: $15K-$75K
- C3PAO assessment fees: $30K-$100K (depends on scope size)
- Ongoing compliance maintenance: $3K-$10K/month
- Total first-year investment: $100K-$500K for most mid-size organizations
Organizations that claim CMMC Level 2 can be achieved for $10K are selling self-attestation templates, not operational compliance. The cost reflects real security implementation — the controls are not bureaucratic theater, they are defensive measures against real adversaries targeting the defense supply chain.
Relationship to Level 1 and Level 3
CMMC Level 1 covers Federal Contract Information (FCI) — information not intended for public release but not classified as CUI. It requires 15 basic safeguarding requirements (from FAR 52.204-21) and permits self-assessment. Most organizations handling only FCI need Level 1.
CMMC Level 2 covers CUI and requires all 110 NIST 800-171 practices with C3PAO assessment for critical programs (self-assessment path exists for non-critical CUI, but fewer contracts will qualify for that path).
CMMC Level 3 adds practices from NIST 800-172 (enhanced security requirements) and requires government-led assessment (DIBCAC). Level 3 applies to the most sensitive programs and contracts involving high-value CUI.
The key decision: if your contract involves CUI (look for DFARS 252.204-7012 in your contract clauses), you almost certainly need Level 2. If it involves only FCI, Level 1 suffices. If you are unclear, your contracting officer can clarify the CUI designation.
Common Preparation Mistakes
Mistake 1: Treating CMMC as a documentation exercise. Organizations that write beautiful policies without implementing the underlying controls will fail assessment. Assessors verify implementation, not documentation.
Mistake 2: Ignoring scoping. Attempting to make an entire enterprise compliant when CUI only flows through a subset of systems wastes budget and extends timelines.
Mistake 3: Inflating the SPRS score. The short-term benefit of a high score (contract eligibility) creates long-term legal liability when the actual security posture does not match.
Mistake 4: Waiting for the mandate. Organizations that begin preparation in late 2026 will face assessor backlogs, rushed implementations, and likely failure on first assessment.
Mistake 5: Assuming IT alone can achieve compliance. CMMC Level 2 spans physical security, personnel security, training, incident response, and media handling. It requires organizational commitment, not just an IT project.
Key Takeaways
- CMMC Level 2 requires operational evidence for all 110 NIST 800-171 practices — policies alone will not pass a C3PAO assessment
- Phase 2 solicitations begin November 2026; C3PAO booking backlogs already exceed 6 months — start now
- False Claims Act enforcement against inflated SPRS scores is active — submit honest scores and use the gap as your roadmap
- POA&Ms are permitted but must close within 180 days; they are a safety valve, not a strategy
- CUI enclave scoping is the highest-ROI preparation decision — reduce your assessment surface before hardening it
- Realistic preparation timeline is 9-18 months; realistic first-year cost is $100K-$500K for mid-size organizations
Frequently Asked Questions
What is the difference between CMMC Level 2 self-assessment and C3PAO assessment?
Self-assessment allows organizations to self-certify their NIST 800-171 implementation for contracts involving non-critical CUI. C3PAO assessment is a third-party evaluation required for contracts involving critical CUI (the majority of CUI-bearing contracts). The distinction is determined by the contracting agency based on the sensitivity of the information. Self-assessment requires affirmation by a senior official but does not involve external assessors.
How long is CMMC Level 2 certification valid?
Certification is valid for three years from the date of the final assessment report. Organizations must maintain their security posture throughout — a certification does not insulate against enforcement if controls degrade. Annual affirmations confirming continued compliance are required during the three-year period.
Can we use a cloud provider to achieve CMMC Level 2 compliance?
A FedRAMP Moderate (or equivalent) cloud environment can satisfy many technical controls, but CMMC compliance is organizational — not infrastructure-level. Cloud solves some controls (encryption, physical security, availability) but introduces others (shared responsibility, data handling, access management). You must ensure your cloud configuration meets CMMC requirements and that your shared responsibility boundaries are clearly documented in your SSP.
What happens if we fail the C3PAO assessment?
A failed assessment results in a NOT MET determination for the overall certification. The organization receives detailed findings identifying which practices were not met and why. There is no mandatory waiting period before re-assessment, but the C3PAO will expect to see evidence of remediation. Most organizations need 2-4 months to address findings and schedule a reassessment. The failed assessment is not publicly reported but is recorded in the CMMC system.
Do subcontractors need the same CMMC level as the prime contractor?
Not necessarily. Subcontractors need the CMMC level corresponding to the type of information they handle. If a subcontractor only receives FCI (not CUI), Level 1 suffices regardless of the prime's level. However, if CUI flows down to the subcontractor — which is common in engineering, manufacturing, and IT subcontracts — Level 2 is required. The prime's contract flow-down clauses and the specific data shared determine the requirement.
How Advisedly Helps
Advisedly continuously monitors your NIST 800-171 implementation across all 110 practices, auto-computes your SPRS score from real system evidence, generates your SSP from operational data rather than manual documentation, and tracks POA&M closure against the 180-day deadline — giving you and your assessor a single source of truth for C3PAO readiness. Contact begin@advisedly.ai to begin your CMMC Level 2 preparation.
<!-- LI hook: CMMC Level 2 is not 110 controls, it is 110 proofs -->