CMMC Level 2 Compliance: Meet All 110 NIST 800-171 Controls
CMMC Level 2, sometimes still called CMMC 2.0 Level 2, is written into defense contracts under 48 CFR. Secureframe Defense pairs a compliance automation platform with expert advisory to take you from scoping to an assessment-ready package, without hiring a compliance department.
Get the Level 2 checklistWhat CMMC Level 2 actually requires
CMMC Level 2 compliance applies to contractors handling Controlled Unclassified Information (CUI). It requires all 110 requirements in NIST SP 800-171 Rev 2, grouped into 14 families, with 320 assessment objectives behind them.
Who verifies depends on the type of CUI. Non-Defense categories take the self-assessment form. Defense categories, like Controlled Technical Information, take a third-party (C3PAO) assessment every three years, and that path has been on hold since July 13, 2026. The 110 requirements are identical either way. Only the verifier changes.
Anything that touches CUI is in scope: where it's stored, what it moves through, who opens it. So are the systems protecting those assets, like your firewall and identity provider. Scope drives cost and timeline more than any other decision, which is why enclave vs. full environment comes first.
New to the program? Start with our plain language guide to what CMMC is and where it stands, or see the CMMC framework overview.

Your SSP and POA&M carry the assessment
Your System Security Plan (SSP) describes how you meet each of the 110 requirements. It's the document your assessor works from. If a control or piece of evidence is missing from it, that requirement can be marked NOT MET, and an incomplete SSP is one of the most common reasons assessments stall.
An assessor does three things: reads your documentation, interviews your people from executives to engineers, and tests your systems directly. Screenshots gathered the week before don't survive that.
A Plan of Action and Milestones (POA&M) lets you carry a limited set of gaps past assessment. You need a score of at least 88, nothing on the list worth more than 1 point, and every item closed and verified within 180 days or your conditional status expires.
Secureframe generates and maintains both from your live environment instead of a static document that goes stale.
The full path from scoping to submission, including where the paused C3PAO step sits, is on our CMMC certification page.
Timeline and cost: what actually moves them
Three things drive it: how big your scope is, how mature your current environment is, and whether you have security expertise in house. Most companies spend 8 to 17 months getting ready. In a Redspin survey, 68% took more than a year, and 77% of those already had solid NIST 800-171 and DFARS practices in place.
Primes set their own deadlines regardless of the government's schedule, so work backward from your contract pipeline rather than the rollout calendar. Not sure where you stand? Take the free CMMC readiness assessment.
Get the CMMC Level 2 compliance checklist
A control-by-control worksheet for planning your Level 2 effort: scoping questions, the 14 control families, SSP and POA&M prep, and assessment logistics.
What you'll get:
- Break down CMMC Level 2 compliance into clear, actionable steps
- See what actions you’ll need to take as you prepare for, achieve, and maintain compliance
- Check off tasks to stay organized and gauge your assessment readiness
Why contractors choose Secureframe over point solutions
MSPs run your IT but rarely own your compliance documentation. Enclave vendors solve where CUI lives but not the other controls around it. Secureframe Defense covers the full 110-requirement lifecycle in one platform, and Secureframe holds a CMMC Level 2 certification of its own.
Deploy and manage secure infrastructure
Secureframe stands up a CMMC-compliant environment in Microsoft GCC High or Google Workspace, with devices configured for the access control, logging, monitoring, notification, and segmentation that NIST 800-171 Rev 2 requires for storing and accessing CUI.
Implement and document controls following Defense Navigator
The 110 requirements and 320 assessment objectives become a guided implementation workflow, generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than from templates.
Maintain continuous monitoring and operational guardrails
Ongoing control testing, automated evidence collection, drift detection, risk assessments, and vendor tracking keep your SPRS score aligned with your real posture, so the executive signing the annual affirmation has a record behind it.
Frequently Asked Questions
The data you handle. Level 1 covers Federal Contract Information and requires 15 basic safeguards, self-assessed annually. Level 2 applies when you handle Controlled Unclassified Information and requires all 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives, assessed every three years.
Right now, contracting officers can only require the self-assessment form of Level 2, because third-party requirements have been on hold since July 13, 2026 pending a program review. When the rollout resumes, the solicitation and the CUI category decide: CUI in non-Defense registry categories takes Level 2 (Self), and CUI in Defense categories such as Controlled Technical Information takes Level 2 (C3PAO). A prime can still require certification from its suppliers either way.
Most organizations spend 8 to 17 months getting ready for a Level 2 self-assessment. In a Redspin survey, 68% took more than a year, even though 77% already reported strong NIST 800-171 and DFARS implementation. Preparation dominates the timeline, not the assessment, and starting before Level 2 appears in an RFP is the only reliable way to avoid losing bids.
Yes, conditionally. A score of at least 88 out of 110 qualifies for Conditional status, provided no requirements listed in 32 CFR 170.21(a)(2)(iii) are outstanding and nothing on your POA&M is worth more than 1 point, except CUI encryption awaiting FIPS validation. Every item must be closed and verified within 180 days or the Conditional status expires.
If CUI flows down to you, yes. Primes must flow CMMC requirements into every subcontract where CUI is processed, stored, or transmitted, and many are asking for evidence now. You cannot rely on your prime's certification; you demonstrate compliance for your own systems.
