
How to Meet CMMC Level 2 Compliance Requirements + Checklist
Emily Bonnie
Senior Content Marketing Manager
Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
This post was originally published in May 2025 and was last updated in July 2026 to reflect the DoD's suspension of the CMMC Phase 2 transition.
CMMC Level 2 is the compliance bar for defense contractors that handle Controlled Unclassified Information (CUI). It requires implementing all 110 security requirements in NIST SP 800-171, documenting how you meet them, and attesting to that implementation. Since November 2025, it has been a contractual condition of doing business with the Department of Defense (DoD).
The program itself is in flux. In July 2026, the DoD suspended its planned transition to mandatory third-party assessments while a Reform Task Force reviews the CMMC program. What that suspension didn't touch is the underlying cybersecurity requirements: NIST 800-171 still applies, self-assessments are still required, and an accurate SPRS score with an annual affirmation is still a condition of award.
Meanwhile, most of the DIB is still working toward that bar. In CyberSheath’s 2025 State of the DIB report, only 42% of surveyed contractors had submitted an SPRS score at all, despite a current score being a condition of contract award, and the median score sat at 60 against the 110 that represents full implementation. Closing that gap is a significant challenge: meeting and documenting all 110 NIST 800-171 requirements is complex and time-consuming, and the CMMC Level 2 self-assessment process is still new territory for many organizations.
This guide breaks down everything you need to know, including what CMMC Level 2 compliance requires, who needs it, and how to streamline the process.
The CMMC 2.0 Levels: How do Level 2 requirements compare to other levels?
The CMMC framework is divided into three levels. The DoD designed this tiered structure to strike a balance between strengthening cybersecurity across the entire defense supply chain and making compliance achievable for organizations of all sizes, especially small businesses.
Not every contractor handles the same type or volume of sensitive information. A company that builds software for internal DoD use will have very different cybersecurity needs than a subcontractor that simply repairs parts or manages logistics. By tailoring the requirements to the type of data a company handles, the DoD ensures that every organization has to meet an appropriate level of security.
The DoD defined CMMC level requirements in the CMMC Level Determination Guide released in a memo in January 2025.
CMMC Level 1 is the most basic level of cybersecurity posture for organizations handling the least sensitive type of defense information known as Federal Contract Information (FCI). This includes proposals, progress reports, and internal communications related to defense contracts. The DoD expects approximately 63% of the DIB to fall under Level 1.
CMMC Level 2 represents a significant step up in cybersecurity maturity from Level 1. It requires organizations to implement more advanced protections and complete an assessment to validate their security posture. The DoD expects approximately 37% of the DIB to fall under Level 2.
CMMC Level 3 represents the most advanced cybersecurity practices and is reserved for contractors that must safeguard CUI associated with mission critical or unique technologies and programs. The DoD expects less than 1% of the DIB to fall under Level 3.

Here’s a recap of each level’s security and assessment requirements:
Level 1 (Foundational):
- For DoD contractors handling only FCI
- Aligns with 15 baseline requirements specified in Federal Acquisition Regulation (FAR) Clause 52.204-21 (renumbered FAR 52.240-93 under the 2026 FAR overhaul)
- Assessed annually via self-assessment
Level 2 (Advanced):
- For contractors handling CUI
- Aligns with the 110 requirements from NIST SP 800-171, as specified by DFARS Clause 252.204-7012
- Assessed every three years, currently via self-assessment (C3PAO requirement is suspended pending DoD review)
Level 3 (Expert):
- For contractors handling highly sensitive CUI and facing advanced persistent threats (APTs)
- Includes all Level 2 requirements plus 24 additional practices from NIST SP 800-172
- Requires a government-led assessment every three years, conducted by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
Recommended reading
Why is CMMC Important? Benefits of CMMC Certification
Which defense contractors and subcontractors need CMMC Level 2?
If your organization works with the DoD and handles Controlled Unclassified Information (CUI), you’ll need to achieve at least CMMC Level 2 certification. This includes both prime contractors and subcontractors that receive, process, store, or transmit CUI on behalf of the government or other contractors.
What is CUI?
CUI is sensitive information the federal government has deemed requires safeguarding but does not rise to the level of classified information. More sensitive in nature than FCI, CUI is often related to national security, infrastructure, law enforcement, or other critical functions.
Examples include:
- Export controlled information
- Technical drawings and blueprints
- Law enforcement records
- HIPAA-regulated health data
- Personally identifiable information (PII)
- Critical defense system specifications
- Security protection data
Documents that contain CUI are often marked with DoD distribution statements, which must be properly safeguarded according to a combination of DoD directives, DFARS clauses, and broader federal regulations.
Since handling CUI comes with significantly higher compliance responsibilities under CMMC, Level 2 compliance is required.

Recommended reading
Who Needs CMMC Certification?
CMMC Level 2 assessment
Under the initial CMMC program design, most organizations pursuing Level 2 would undergo a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) every three years, with self-assessment reserved for the small share of contracts involving CUI deemed non-critical to national security.
As of July 13, 2026, the third-party requirement is suspended: the DoD paused the Phase 2 transition while it reviews the program, and during the suspension, Level 2 requirements in new solicitations are met through a triennial self-assessment with an annual affirmation.
As defined in the DoD’s CMMC Level 2 Assessment Guide, a Level 2 assessment involves testing or evaluating your organization’s security controls to determine the extent to which the controls are:
- implemented correctly,
- operating as intended, and
- meeting the 110 security requirements and 320 assessment objectives in NIST SP 800-171 Revision 2.
Since these assessments are intended to provide increased assurance to the DoD that an organization can adequately protect CUI at a level commensurate with the adversarial risk, assessment results, along with your score and an annual affirmation of compliance, must be submitted in the Supplier Performance Risk System (SPRS). Those with a passing score will achieve a current CMMC Level 2 status. DoD program managers and prime contractors must verify you have this status prior to awarding or renewing your contract.
Those who have fully implemented all requirements and have a score of 110 will achieve a Final Level 2 status.
Those with a score between 88 and 109 can achieve a conditional CMMC Level 2 status as long as any unmet requirements are documented in a Plan of Action and Milestones (POA&M) and are not listed as prohibited in 32 CFR 170.21(a)(2)(iii). These POA&M items must be remediated no later than six months after the conditional status was issued to achieve a final Level 2 certification, otherwise the CMMC status will expire.
You can see all the requirements for CMMC Level 2 and how they’re calculated in your SPRS score in the Requirement Explorer tool on CMMC.com.
Recommended reading
CMMC Self-Assessment Guide: Level 1 and Level 2 Process
When will CMMC Level 2 be enforced?
Since Phase 1 of the CMMC rollout kicked off on November 10, 2025, DoD program managers and prime contractors are already embedding or flowing down CMMC Level 2 requirements in solicitations and contract awards across the defense supply chain.
Phase 1 enforcement focuses on self-assessments for Levels 1 and 2. Early in the rollout, some high-priority contracts also carried Level 2 (C3PAO) requirements, but as of July 13, 2026, Program Managers may no longer designate Level 2 (C3PAO) in new solicitations, and existing C3PAO requirements are being removed from active solicitations and contracts during the DoD's program review.
This enforcement is happening while readiness remains critically low. Out of the roughly 80,000 organizations estimated to ultimately require CMMC Level 2, fewer than 0.6% (only 459 organizations) had achieved certification as of the November Cyber AB Town Hall.
To ensure you understand and are prepared for the different CMMC deadlines, here’s an overview of what to expect during each phase of enforcement:
Phase 1 (Started November 10, 2025, still in effect)
- CMMC Level 1 and Level 2 self-assessment requirements are being inserted into new DoD solicitations.
- During the suspension, Program Managers may only designate Level 1 (Self) or Level 2 (Self).
Phases 2 through 4 (Suspended as of July 13, 2026)
- Phase 2 would have made C3PAO assessments a condition of award for all applicable Level 2 contracts starting November 10, 2026, with Phase 3 (2027) introducing Level 3 assessments and Phase 4 (2028) completing the rollout.
- The DoD suspended the Phase 2 transition and all pending and future CMMC implementation milestones on July 13, 2026, with no revised timeline. A CMMC Reform Task Force will deliver recommendations within 60 days, and further guidance will follow.
Recommended reading
The Complete Rulemaking Process for CMMC, Explained
CMMC Level 2 compliance requirements
At Level 2, the DoD expects contractors to demonstrate a mature and well-documented approach to security, grounded in the 110 requirements and associated 320 assessment objectives defined by NIST 800-171. Below, we’ll walk through the key requirements that organizations must implement and maintain to achieve CMMC Level 2 certification.
1. Define scope
Before you implement controls or take other readiness steps, you first need a clear picture of what’s in scope for a CMMC Level 2 assessment. At this level, scoping is about identifying where CUI lives, how it flows through your environment, and which assets can impact their security.
As defined in 32 CFR § 170.19(c)(1), the following asset categories will be assessed for a Level 2 assessment:
- CUI assets: Systems that directly process, store, or transmit CUI. These are the core focus of your implementation and are assessed against all Level 2 requirements.
- Security Protection Assets (SPAs): Tools and systems (e.g., firewalls, SIEM, MDM, IAM, SOC services) that enforce or support security controls for CUI assets and the CUI environment. While these don’t necessarily touch CUI, SPAs often handle SPD such as configs, logs, and credentials. They may be assessed against relevant Level 2 requirements, depending on their security functions and capabilities and FedRAMP authorization status.
- Contractor Risk Managed Assets (CRMAs): Assets that could access CUI or SPD but are not intended to and are restricted by risk-based policies, segmentation, or technical controls. If they’re properly risk-managed and documented in your SSP, they may not be assessed against other Level 2 requirements or only be assessed in limited check(s).
- Specialized assets: Operational Technology (OT) systems, IoT/IoTT devices, government-furnished equipment, and other hard-to-secure systems that may interact with CUI. These must be documented and explained in your SSP and data flow diagrams, but are not fully assessed against other CMMC requirements.
- Out-of-scope assets – Systems that do not store, process, transmit, or protect CUI or SPD. These don’t need to be evaluated but you must be able to justify why they’re excluded.
Scoping your environment is a crucial first step toward CMMC certification and can result in unnecessary work and costs if done incorrectly. To ensure you get this step right, consult the DoD’s DoD’s CMMC Level 2 Scoping Guidance or check out our on-demand webinar led by an expert with actual experience scoping for a CMMC Level 2 assessment.
2. Implement all 110 NIST 800-171 security requirements
CMMC Level 2 requirements include all 110 security requirements and 320 assessment objectives outlined in NIST 800-171. These span 14 control families:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
On average, an organization will need to implement over 450 controls to fully meet these requirements, but the exact number will depend on the assessment scope, size of the organization, current level of cybersecurity maturity, and other factors.
Consult the DoD’s CMMC Level 2 assessment guide for a description of all the requirements in each NIST 800-171 control family as well as implementation guidance and assessment criteria.
3. Create and maintain a System Security Plan (SSP)
Your SSP is a comprehensive document that outlines how your organization meets each of the 110 requirements. It should include details on system boundaries, hardware and software inventories, network architecture, and policies like a CUI policy.
Recommended reading
How to Write a System Security Plan for CMMC + SSP Template
4. Develop a Plan of Action and Milestones (POA&M)
If there are any gaps between your current state and full compliance, those should be documented in a POA&M. This document outlines how and when you plan to close those gaps, and you can find a downloadable POA&M template here.
Keep in mind: The CMMC Final Rule makes it clear that a POA&M cannot be used to defer required controls during a certification assessment, they will only give you 180 additional days to remediate the issue and meet that requirement. But even though you can’t be certified with open items on your POA&M, it’s an essential document for tracking issues and prioritizing remediation work as you prepare for assessment.
5. Perform regular risk assessments
You need a documented, repeatable process for identifying, evaluating, and mitigating risks to CUI. This includes assessing threats, vulnerabilities, and potential impacts on your systems. Risk assessments should be updated regularly, or anytime there’s a significant change in your environment.
6. Ensure personnel complete security training
Your team plays a critical role in protecting CUI. That’s why CMMC Level 2 requires security awareness, insider threat, and role-based training for all employees with access to CUI or security systems. Training should cover topics like insider threats, phishing, password hygiene, and incident reporting, and it needs to be reviewed and refreshed at least annually.
7. Document and test your incident response plans
You need a documented incident response plan that outlines how you’ll detect, respond to, and recover from security incidents involving CUI. That plan also needs to be tested regularly (e.g., through tabletop exercises) so your team is prepared when it matters most.
8. Apply role-based access controls
CUI should only be accessible to people who need it to do their jobs. That means implementing the principle of least privilege and assigning access based on user roles. This includes defining roles clearly, limiting administrative privileges, and ensuring access is revoked when employees leave or change roles.
9. Maintain audit logs and continuously monitor systems
Your systems should generate audit logs that track user activity, system changes, and access to sensitive data. More importantly, your systems need to be continuously monitored and those logs need to be reviewed regularly for suspicious activity. Automated tools can help here, but human oversight is essential too.
10. Encrypt CUI at rest and in transit
Whether stored on a hard drive or transmitted over the internet, CUI must be encrypted using FIPS-validated cryptographic methods. This protects data even if it falls into the wrong hands. Don’t forget to include mobile devices, backups, and cloud storage in your encryption strategy.
11. Perform regular vulnerability scans and apply patches
You need to continuously evaluate your environment for weaknesses, which includes running vulnerability scans, reviewing the results, and applying patches or other fixes in a timely manner. Unpatched systems are one of the most common ways attackers gain access.
12. Complete a self-assessment
During the Phase 2 suspension, Level 2 requirements in DoD solicitations are met through a self-assessment. Your team evaluates your implementation of all 110 NIST 800-171 requirements and 320 assessment objectives, then reports the results in SPRS.
Here's what the process looks like:
- Assess each requirement: Use the DoD's CMMC Level 2 Assessment Guide to evaluate every requirement and assessment objective within your defined scope as MET, NOT MET, or NOT APPLICABLE, based on what's actually been implemented (not what's planned).
- Score your results: Each unmet requirement subtracts a weighted value of 1, 3, or 5 points from a perfect 110, producing an SPRS score between -203 and 110.
- Determine your status: A score of 110 earns Final Level 2 (Self) status. A score of 88 or above can earn Conditional Level 2 (Self) status, as long as every unmet requirement is documented in a POA&M and none appear on the list of requirements that can't be deferred under 32 CFR 170.21(a)(2)(iii).
- Close out your POA&M (if conditional): You have 180 days from your conditional status date to remediate all NOT MET requirements and complete a POA&M closeout self-assessment. If the window closes, your conditional status expires and you become ineligible for new awards with a Level 2 (Self) requirement.
- Submit and affirm in SPRS: In the CMMC Level 2 (Self) module, enter a compliance status for each of the 110 requirements, and SPRS calculates your score and CMMC status from those entries. If the result qualifies for Conditional or Final status, your Affirming Official (a senior company executive) affirms compliance. Reassess and resubmit at least every three years.
13. Affirm compliance annually
You must submit an annual affirmation that your organization is still meeting the required controls. This affirmation must come from a senior executive and submitted to the SPRS via eMASS to reflect your organization’s ongoing commitment to securing CUI.

CMMC Level 2 Compliance Checklist
Use this checklist listing all 110 CMMC Level 2 requirements and 320 assessment objectives to organize your compliance efforts, identify gaps, and implement controls.
The true cost of CMMC level 2 compliance
According to the DoD’s regulatory impact analysis, the estimated costs for preparing, conducting, and reporting CMMC Level 2 self-assessments are $37,000–$49,000 every three years.
In response to public comment feedback on the interim CMMC rule indicating that cost estimates were too low, estimates now account for outsourced services and more time dedicated to preparing for the assessment and complete administrative tasks like submitting assessment results to the SPRS. However, they are still likely low since they still do not account for the far more resource-intensive work of implementing, remediating, and maintaining the security requirements themselves.
That’s because the DoD assumes organizations have already implemented the security requirements for CMMC Level 2, which have been prescribed in the existing DFARS 7012 regulation since 2017.
However, this is likely not true for many organizations given that one of the catalysts of the entire CMMC program was a report from the DoD Inspector General (IG) in 2019 uncovering widespread noncompliance with DoD-mandated cybersecurity requirements, which has been supported by more recent reports. For example, in CyberSheath’s 2025 State of the DIB on CMMC Compliance report released in October, only 1% of defense contractors said they felt fully prepared for upcoming CMMC assessments.
As a result of this lack of readiness, many organizations will need to factor in the one-time cost of implementing CMMC Level 2 security requirements and the recurring costs of maintaining these requirements and remediating POA&Ms for any unimplemented ones.
While these cost estimates are not included in the DoD’s regulatory impact analysis for Level 2, they are for CMMC Level 3 certification. According to DoD estimates, Level 3 organizations may face $2.7 million to $21.1 million in one-time implementation costs and $490,000 to $4.12 million in recurring annual maintenance costs.
Although most DIB organizations will never pursue Level 3 and Level 2 security requirements are less complex, these Level 3 cost projections help emphasize the gap between the DoD’s assessment-only estimates and the true cost of compliance when factoring in the implementation and maintenance of security requirements.
The true total cost of CMMC Level 2 compliance is likely double or triple the DoD’s cost estimate, ranging from $100,000-$200,000 at least.

This estimated range is supported by Redspin’s most recent survey, which showed that the vast majority of DIB organizations spent upwards of $100,000 getting ready for CMMC:
- 26% spent between $100,000-$250,000
- 32% spent more than $250,000
- 15% spent more than $500,000
Recommended reading
How Much Does CMMC 2.0 Certification Cost?
CMMC Level 2 compliance automation tools
Managing hundreds of security controls, organizing assessment evidence, and creating required documents can quickly become a resource-intensive and costly process.
While consultants can help shoulder the operational burden, they typically don’t reduce the manual effort and drive up costs related to compliance. Traditional federal tools are another option to simplify parts of the process, but are typically limited to documenting your point-in-time compliance status and planning remediation.
That’s why many organizations are turning to CMMC Level 2 compliance automation tools. These tools can dramatically reduce the cost and complexity of getting CMMC ready by centralizing and automating key compliance tasks, such as:
- Gap analysis and readiness assessments
- Automated evidence collection and validation with AI
- Role-based access logs and audit trails
- Document management for SSPs, POA&Ms, security policies, and procedures
- Automated risk assessments and vulnerability tracking
- Remediation workflows for failed controls
- Continuous monitoring of control performance and compliance posture
However, these tools are not all alike. Traditional GRC tools are typically not aligned to CMMC and can’t automate much of the process.
That’s why the best platform to achieve certification is an end-to-end CMMC solution that’s purpose-built for DIB organizations to streamline documentation, track remediation, and ensure continuous compliance to maintain contract-eligibility year-round.
Best platform to achieve CMMC Level 2 certification
Secureframe Defense is the best platform to achieve CMMC Level 2 compliance at a fraction of the time and cost. Implementing and documenting the 110 NIST 800-171 requirements manually typically takes 6–12+ months and costs upwards of $100,000, and that work is required whether you're completing a Level 2 self-assessment today or preparing for whatever validation model follows the DoD's program review. With Secureframe Defense, defense contractors can cut that time in half while saving hundreds of thousands of dollars.
Secureframe Defense gives you everything you need to build, prove, and maintain compliance in one platform:
- Defense Navigator: Most contractors lose their first months (and first consulting dollars) figuring out which CMMC requirements apply to them. Defense Navigator walks you through scoping your environment and determining which requirements apply, then guides you step by step through implementing controls with guidance built on the first-hand experience of former federal assessors. You get an accurate picture of your posture from day one and a clear path forward without paying consultants to map it manually.
- Automated Cloud Provisioning: Deploy a pre-configured, CMMC-compliant CUI enclave accessed through Azure Virtual Desktops or a Federal MDM. Keeping CUI contained in a purpose-built environment shrinks your assessment scope, which is one of the biggest levers on both compliance cost and self-assessment effort.
- Support from experts with first-hand experience: One of Secureframe's biggest differentiators is that we're not just building and offering federal tooling. We've gone through a CMMC Level 2 certification assessment ourselves, which means we understand the complexity, pressure, and nuance of Level 2 requirements and use that experience to improve the platform and help customers navigate the process. We have over 25 CMMC Registered Practitioners (RPs) and have been listed as a CMMC Registered Practitioner Organization (RPO) in the CyberAB Marketplace since March 2025.
- Automated Evidence Collection: One of the biggest challenges with CMMC Level 2 is the amount of documentation required to prove compliance. Secureframe Defense automates evidence collection across your tech stack, including AWS GovCloud, Azure Government, Google Workspace, Microsoft GCC High, and other government cloud services, so you can continuously pull artifacts from systems and reduce manual effort. Your documentation stays current and ready for review during your self-assessment or annual affirmation.
- Automated Documentation: Generate and maintain your SSP, POA&M, policies, and procedures in one place, mapped to the 110 requirements and 320 assessment objectives of Level 2 and filled in automatically with data from your actual environment. POA&M items are tied to specific CMMC requirements with remediation owners and deadlines, so nothing slips past your 180-day conditional window.
- Real-time SPRS Scoring: Secureframe Defense tracks and calculates your SPRS score based on the implementation status of each Level 2 requirement and its assessment objectives, updating as you close gaps. When you enter your compliance statuses in SPRS and it calculates your score and CMMC status, you’re not met with a surprise. That matters more than ever now that a senior executive is affirming that score without a third-party assessor in between.
- Cross-Framework Mapping: Many DIB contractors need to comply with multiple frameworks, like SOC 2, ISO 27001, NIST 800-53, and FedRAMP. Secureframe maps overlapping controls across frameworks so your efforts scale, saving time, reducing duplication, and streamlining evidence collection across all your cybersecurity initiatives.
Ready to see how Secureframe can streamline your path to Level 2 certification? Schedule a demo with one of our product experts today.
Simplify CMMC Level 2 compliance with Secureframe Defense
FAQs
What are the CMMC Level 2 requirements?
CMMC Level 2 requirements for a final certification are:
- Implementing controls to meet all 110 security requirements and 320 assessment objectives from NIST 800-171 R2 designed to protect CUI in non-federal systems.
- Achieving a MET result for all NIST 800-171 R2 requirements during an assessment, resulting in a maximum score of 110, every three years
- Submitting self-assessment results and score into the SPRS or having C3PAO post results into the CMMC instantiation of eMASS
- Submitting an executive affirmation of compliance into the SPRS annually
How many controls are in CMMC 2.0 Level 2?
Typically, an organization will need to implement over 400 controls on average to meet the 110 requirements and 320 assessment objectives for CMMC Level 2. The exact number of controls you implement to fully meet this level’s security requirements may vary depending on your assessment scope and the complexity of your infrastructure and organization.
How to get CMMC 2.0 Level 2 certification?
To get CMMC Level 2 certified, contractors must implement controls to meet all 110 security requirements in NIST 800-171 R2, prepare documentation including the SSP and POA&M, complete a self-assessment every three years, and submit an annual affirmation of compliance every year.
What is the difference between Level 2 in CMMC 1.0 and CMMC 2.0?
CMMC 1.0 had five levels. While Level 2 in this tiered model was one of the lowest maturity levels, it required organizations to implement all 110 security requirements outlined in NIST SP 800-171 and some CMMC-specific requirements and undergo a third-party assessment. CMMC 2.0 simplified the model to three levels, with Level 2 security requirements aligning only with the existing NIST SP 800-171 R2 and allowing self-assessments.
When will CMMC 2.0 Level 2 be required?
CMMC Level 2 is already required in DoD contracts and solicitations. As of November 10, 2025, Phase 1 of the rollout is in effect, and Level 2 self-assessment requirements are being implemented contractually.
On July 13, 2026, the DoD suspended the Phase 2 transition to mandatory C3PAO assessments, which had been scheduled for November 10, 2026, along with all pending implementation milestones. During the suspension, Level 2 requirements are met through self-assessment, and a CMMC Reform Task Force will recommend changes to the program within 60 days.
How much does it cost to get CMMC Level 2 certification?
Costs vary depending on the size and complexity of your organization, but most estimates range from $20,000 to $100,000+ for full CMMC Level 2 readiness and third-party assessment. This includes expenses for preparation, gap remediation, consultant support, and the assessment fee itself.
What is the difference between CMMC Level 2 and CMMC Level 3?
The CMMC program is organized as a maturity model. CMMC Level 2 focuses on protecting CUI using the 110 controls in NIST SP 800-171. Level 3 is for organizations handling the most sensitive information and facing advanced persistent threats by adding 24 additional requirements from NIST SP 800-172 and requiring a government-led assessment.
What is the difference between CMMC Level 1 and CMMC Level 2?
CMMC Level 1 and Level 2 differ primarily in data sensitivity, security requirements, and assessment rigor.
- Level 1 applies to contractors that handle only FCI and requires meeting 15 basic safeguarding requirements from FAR 52.204-21 and undergoing an annual self-assessment.
- Level 2 applies to companies that handle CUI and requires implementing all 110 NIST SP 800-171 requirements, with an assessment every three years and an annual affirmation. The program design requires a C3PAO assessment for most Level 2 contractors, but that requirement is suspended as of July 2026 while the DoD reviews the program, so Level 2 is currently assessed via self-assessment.
What is Security Protection Data?
Security Protection Data (SPD) is information that is generated by or used to configure the assets, information systems, and tools responsible for implementing an organization’s security controls, particularly those required under NIST 800-171 and CMMC Level 2. While SPD doesn’t directly involve CUI, it is critical to the protection of CUI and therefore falls under similar compliance requirements.
What are examples of SPD?
Examples of SPD include:
- Configuration files or rule sets from a SIEM or intrusion detection system
- Passwords or credentials that provide access to CUI systems
- VPN or firewall configuration data
- Logs and telemetry from Mobile Device Management (MDM) systems
- Network architecture details maintained by a co-located data center
- Access control settings within a cloud-based identity provider
What are Security Protection Assets?
Assets that store or process SPD are called Security Protection Assets (SPAs). These assets don’t necessarily touch CUI but support the implementation of security practices that protect CUI, so they must be treated with the same level of scrutiny.
SPAs must be listed in your asset inventory, included in your System Security Plan (SSP), and mapped in your network diagram. If an external vendor provides the SPA (e.g., a managed SIEM, hosted firewall, or identity provider), you must also document their service description and collect a Customer Responsibility Matrix (CRM).

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.

Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.