COMPLIANCE POSTURE

CMMC Level 2

The CMMC tier for contractors handling Controlled Unclassified Information, assessed against the NIST SP 800-171 requirement set by self-assessment or by an authorized third-party assessor.

Also called CMMC L2

Last reviewed

What is CMMC Level 2?

CMMC Level 2 is the tier that applies when a contractor handles Controlled Unclassified Information on Department of War work. It is where the great majority of technology companies in the defense supply chain land, and it is the level with real assessment consequences attached.

Level 1 is a short list of fundamental practices, self-assessed annually, for Federal Contract Information. Level 2 is a full security program: the 110 requirements of the NIST standard for protecting CUI in nonfederal systems, implemented, documented, and evidenced. The difference in effort between the two is not incremental.

Self-assessment or certification

Level 2 has two assessment paths, and the contract decides which one applies:

  • Self-assessment. The contractor evaluates its own environment against the requirement set, records the result, and a senior official affirms it. Lower cost, same requirements, same legal exposure for an inaccurate affirmation.
  • Certification. An authorized third-party assessment organization — a C3PAO — performs the assessment and issues the certification. Phase 2 would have made this the required path on applicable contracts; that requirement was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023 and has no replacement date. A contract can still specify it, so read the solicitation rather than the program schedule.

Companies sometimes read the self-assessment path as the easy one. It is cheaper, not easier: the requirements are identical, and the affirmation is a representation to the government.

What the 110 requirements cover

Fourteen families, and the practical burden is unevenly distributed across them:

  • Access control, identification and authentication — usually the largest engineering lift, particularly multifactor everywhere and privileged-access separation.
  • Audit and accountability — centralized logging with protected storage and demonstrable review, not just logs that exist.
  • Configuration management — baselines, change control, and evidence that drift is detected.
  • Incident response — tested procedures with defined reporting paths.
  • Media protection, physical protection, personnel security — often straightforward for a cloud-native company, occasionally not.
  • System and communications protection, system and information integrity — encryption in transit and at rest, boundary protection, flaw remediation.

The requirement set is keyed to Revision 2 of the standard in the CMMC rule. A later revision has been published and reorganizes the requirements, so read the specific solicitation rather than assuming which version applies.

Scoping is the whole game

The single largest cost driver is how much of your company falls inside the assessment scope. A company that runs CUI through its general corporate environment has scoped its entire business into the assessment. A company that built a separate enclave — a distinct environment where CUI lives, with controlled paths in and out — has scoped a fraction of it.

The enclave approach costs real engineering effort up front and reliably costs less than the alternative. It is the same discipline as drawing a tight authorization boundary for FedRAMP, applied to a different program.

Conditional status and the closeout clock

A conditional outcome — certified with a plan of action for a limited set of open requirements — is available, but it is narrower than companies expect. The highest-weighted requirements cannot be deferred, and the plan carries a firm closeout deadline. Treat conditional status as a mechanism for finishing genuine edge cases, not as a strategy.

What it means for your pipeline

If defense work is on your roadmap, Level 2 is not a compliance project with a due date set by the government. It is a prerequisite with a due date set by the first opportunity you want to bid — and since the suspension of Phase 2 there is no government date to work backwards from at all. Work backwards from the opportunity. Your pipeline is what tells you when this becomes yours.

COMMON QUESTIONS

What is the difference between Level 2 self-assessment and Level 2 certification?

The requirement set is the same; who confirms it is not. Self-assessment means the contractor evaluates its own environment and a senior official affirms the result. Certification means an authorized third-party assessment organization performs the assessment. Which one applies is set by the contract, based on the sensitivity of the information involved. The Phase 2 step that would have made certification mandatory across applicable contracts was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023 with no replacement date, so the contract is now the only thing that decides.

How many requirements does Level 2 involve?

The CMMC rule is keyed to the 110 security requirements of NIST SP 800-171 Revision 2, organized into fourteen families covering access control, audit, configuration management, incident response, media protection, and more. A later revision of the standard reorganizes the requirement set, so confirm which revision a specific solicitation invokes rather than assuming.

What is a C3PAO?

An organization authorized to conduct CMMC Level 2 certification assessments. It plays the same independent-assessor role that a 3PAO plays in FedRAMP, but under the CMMC accreditation ecosystem. The two accreditations are separate — a FedRAMP 3PAO is not automatically a C3PAO.

Can I pass with open findings?

Only within limits. A conditional status with a plan of action for a defined subset of requirements is possible, but the highest-value requirements must be met outright, and the plan carries a hard closeout deadline. Planning to certify conditionally and finish later is a way to inherit a deadline you did not choose.

HOW GOVEXPRESS SCORES THIS

Compliance Posture

Level 2 is where Compliance Posture becomes binary for defense work — either the required assessment exists and is current, or the company is not eligible for the contract regardless of how good its product is.

One of the 12 categories in the Federal Readiness Score. The methodology is public — including the things this platform will never claim.

CMMC Level 2 is one signal. See all of them.

Get your free score