What is CMMC Level 2?
CMMC Level 2 is the tier that applies when a contractor handles Controlled Unclassified Information on Department of War work. It is where the great majority of technology companies in the defense supply chain land, and it is the level with real assessment consequences attached.
Level 1 is a short list of fundamental practices, self-assessed annually, for Federal Contract Information. Level 2 is a full security program: the 110 requirements of the NIST standard for protecting CUI in nonfederal systems, implemented, documented, and evidenced. The difference in effort between the two is not incremental.
Self-assessment or certification
Level 2 has two assessment paths, and the contract decides which one applies:
- Self-assessment. The contractor evaluates its own environment against the requirement set, records the result, and a senior official affirms it. Lower cost, same requirements, same legal exposure for an inaccurate affirmation.
- Certification. An authorized third-party assessment organization — a C3PAO — performs the assessment and issues the certification. Phase 2 would have made this the required path on applicable contracts; that requirement was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023 and has no replacement date. A contract can still specify it, so read the solicitation rather than the program schedule.
Companies sometimes read the self-assessment path as the easy one. It is cheaper, not easier: the requirements are identical, and the affirmation is a representation to the government.
What the 110 requirements cover
Fourteen families, and the practical burden is unevenly distributed across them:
- Access control, identification and authentication — usually the largest engineering lift, particularly multifactor everywhere and privileged-access separation.
- Audit and accountability — centralized logging with protected storage and demonstrable review, not just logs that exist.
- Configuration management — baselines, change control, and evidence that drift is detected.
- Incident response — tested procedures with defined reporting paths.
- Media protection, physical protection, personnel security — often straightforward for a cloud-native company, occasionally not.
- System and communications protection, system and information integrity — encryption in transit and at rest, boundary protection, flaw remediation.
The requirement set is keyed to Revision 2 of the standard in the CMMC rule. A later revision has been published and reorganizes the requirements, so read the specific solicitation rather than assuming which version applies.
Scoping is the whole game
The single largest cost driver is how much of your company falls inside the assessment scope. A company that runs CUI through its general corporate environment has scoped its entire business into the assessment. A company that built a separate enclave — a distinct environment where CUI lives, with controlled paths in and out — has scoped a fraction of it.
The enclave approach costs real engineering effort up front and reliably costs less than the alternative. It is the same discipline as drawing a tight authorization boundary for FedRAMP, applied to a different program.
Conditional status and the closeout clock
A conditional outcome — certified with a plan of action for a limited set of open requirements — is available, but it is narrower than companies expect. The highest-weighted requirements cannot be deferred, and the plan carries a firm closeout deadline. Treat conditional status as a mechanism for finishing genuine edge cases, not as a strategy.
What it means for your pipeline
If defense work is on your roadmap, Level 2 is not a compliance project with a due date set by the government. It is a prerequisite with a due date set by the first opportunity you want to bid — and since the suspension of Phase 2 there is no government date to work backwards from at all. Work backwards from the opportunity. Your pipeline is what tells you when this becomes yours.