CMMC Compliance

What you actually need for CMMC Level 2? The Complete Breakdown

By Christina Sentry · September 18, 2026 · 9 views

CMMC Level 2 explained: the 110 NIST 800-171 requirements, 320 assessment objectives, scoring, POA&M rules, scoping categories, and what the Phase II suspension changes about the path to certification.

Level 2 is the main character of the CMMC universe. It's the one with the third party assessments, the readiness budgets, the panicked LinkedIn posts, and the consultants circling like seagulls at a beach picnic. If Level 1 is the kiddie pool, Level 2 is the part where the floor drops away and you find out real fast whether you can actually swim.

Good news: the deep end is completely survivable. You just need to know what's actually down there, because most of what sinks contractors isn't the requirements. It's the surprises.

Let's remove the surprises. First, is this even your level?

Level 2 is for anyone who processes, stores, or transmits Controlled Unclassified Information. CUI is the government's "sensitive but not classified" tier: technical drawings, specs, export controlled data, the stuff that flows through defense contracts with markings on it. Sometimes it can even be unmarked, can be simple as SBOMs, Names, Delivery schedules etc. It's hard to figure out.

Only touching Federal Contract Information? Congratulations, you're a Level 1 shop, and we wrote you your own post. But if CUI shows up anywhere in your environment, welcome to the deep end. And "anywhere" is a load bearing word here. Hold that thought until we get to scoping.

The number everyone knows, and the number that actually matters

Ask anyone what Level 2 requires and they'll say 110. All 110 security requirements of NIST SP 800-171 Rev 2, across 14 families. True!

Also not the number that decides your fate.

Assessors don't assess 110 requirements. They assess the 320 assessment objectives of NIST 800-171A, because every requirement splits into smaller objectives, and every single one has to be met before its parent requirement counts. Think of each requirement as a boss fight with multiple health bars. Knocking out four of five bars gets you nothing. The boss is still standing and it took your certification budget with it.

Here's the cheat code, and it's hiding in plain sight: read the verbs. An objective that says define is satisfied by your SSP or a policy. Identify wants a list or a diagram. Enforce or limit? Only the actual configuration counts, and you'd better be able to pull up the console and show it. Contractors who look fully done at the requirement level get absolutely wrecked at the objective level, and the objective level is the only one on the scoreboard. It's such a common wipe that we gave it its own post: the number one reason contractors fail.

Your score, aka the number with your name on it

Level 2 runs on the DoD Assessment Methodology. You start at a perfect 110 and lose points for every unmet requirement, weighted 1, 3, or 5. And because someone at the DoD has a sense of humor, the scale doesn't stop at zero. It goes all the way down to minus 203. Yes, you can be 203 points worse than nothing. No, you don't want to find out how.

That score gets posted to SPRS with a senior official's affirmation attached, which makes it a representation to the federal government, not a vibe. In today's enforcement environment, where self-assessments are carrying more weight than ever, an inflated SPRS score isn't optimistic marketing. It's a liability with a timestamp.

Who checks your homework

Two paths. Some contracts allow a triennial self-assessment with annual affirmations. Most CUI contracts were headed for certification assessments by a C3PAO, valid three years.

Then July happened. The Phase II suspension paused the third party certification rollout while a Reform Task Force takes 60 days to rethink the program. What it didn't pause: the 110 requirements, your self-assessment obligations, DFARS 252.204-7012, or the government's ability to show up and assess you itself. NIST 800-171 is still the standard, the referee just changed jerseys. We broke down the whole thing in our suspension analysis, but the strategy takeaway fits in one sentence: the pause is free practice time, and the contractors using it to close gaps will be warming up at the front of the line when third party assessments come back in whatever form the task force cooks up.

POA&Ms: the world's shortest hall pass

Unlike Level 1, Level 2 lets you certify with a few things still in progress. Before anyone gets excited, look at the fine print. You need a score of at least 88 out of 110 to even qualify. Only certain low weight requirements are eligible. The heavy hitters have to be done at assessment time. And everything on the POA&M has to close within 180 days, verified, or your conditional status turns back into a pumpkin.

So a POA&M is a hall pass for a program that's 95 percent finished. It is not, despite what some contractors seem to believe, a parking garage for every hard problem you'd rather not deal with.

Scoping, or: the size of your problem is up to you

Here's the part almost nobody tells you up front. Before anyone assesses a single control, someone draws a line around what gets assessed, and that line is the single biggest cost decision in your entire CMMC journey.

The scoping rules sort your assets into categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Everything inside the line has to be implemented, documented, and provable across every applicable objective.

Let CUI wander your whole network like a golden retriever off leash, and congratulations, your whole network is the assessment. Herd it into a tight enclave or a managed virtual desktop, and the assessment shrinks to that enclave. Same certificate at the end. Wildly different invoice. Scope discipline is cost discipline, and it's the very first thing we work on in every engagement, because every dollar saved there compounds through everything after it.

The paper trail that saves you

Level 2 runs on evidence, and three things anchor it. Your System Security Plan, which is the first document any assessor opens, so it'd better match reality. Your POA&M, tracking the short list of stragglers. And underneath both, the evidence itself, mapped objective by objective: policies for the define objectives, lists and diagrams for the identify objectives, live configurations for the enforce objectives.

The contractors who pass can answer any question in about a minute with a document name and section, or a console they can pull up on the spot. The contractors who scramble did much of the same work but can't produce it on demand, and here's the brutal part: evidence you can't produce scores exactly the same as work you never did.

The bottom line

All 110 requirements, proven at the level of 320 objectives, scored honestly into SPRS, scoped like your budget depends on it (it does), written into an SSP that matches reality, and backed by evidence you can put your hands on in under a minute. That's Level 2. The suspension changed the schedule, not the assignment, and the deep end is a lot friendlier when you learn to swim before the lifeguards come back.

Want to know exactly where you'd score today, before it's your name on the affirmation? Cipher Sentinel gap assessments are CCA led, built for small and mid-sized contractors, and considerably cheaper than finding out the hard way. Let's talk before the 60 days run out.

Christina Sentry writes about CMMC, NIST 800-171, and defense industrial base compliance for the Cipher Sentinel blog. Cipher Sentinel is a CCA led CMMC compliance consultancy helping DoD contractors reach and maintain compliance faster and at lower cost.

Last edited by Christina Sentry · September 20, 2026 at 1:03 AM

Ready to get compliant?

Talk to a CCA today about your specific environment.

Contact Us