Quick answer
CMMC Level 2 requires defense contractors handling Controlled Unclassified Information to implement all 110 security requirements of NIST SP 800-171 and, for most programs, undergo triennial third-party assessments.
CMMC Level 2 is the tier that affects the largest number of defense prime contractors and subcontractors. It aligns directly with NIST SP 800-171 and introduces external verification for contractors on sensitive programs, replacing years of self-reported compliance that proved inadequate.
What is CMMC Level 2?
CMMC Level 2 requires contractors to implement all 110 security requirements across 14 domains defined in NIST SP 800-171. These domains cover access control, incident response, configuration management, audit and accountability, identification and authentication, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, system and information integrity, maintenance, and awareness and training. For contracts involving programs deemed critical to national security (typically determined by the DoD program office), Level 2 requires a triennial assessment by a Certified Third Party Assessment Organization (C3PAO). For less critical programs, an annual self-assessment with SPRS affirmation and senior-official certification is permitted. The third-party assessment process includes a review of the contractor's System Security Plan, interviews with key personnel, and testing of implemented controls.
Why CMMC Level 2 matters for government contractors
Most DoD contracts above the simplified acquisition threshold that involve access to technical data, engineering drawings, or program information will require CMMC Level 2. The investment in achieving and maintaining Level 2 certification is substantial but is increasingly a prerequisite for participating in the defense market. Contractors who begin the assessment process early gain a competitive advantage over those who treat it as a last-minute compliance checkbox.
Example
A mid-tier defense engineering firm receives a DFARS 252.204-7012 clause in a new contract, indicating it handles CUI. The firm already has a NIST SP 800-171 self-assessment score of 87 out of 110 in SPRS. To prepare for CMMC Level 2 third-party assessment, it engages a C3PAO, identifies 12 remaining gaps, implements remediation over four months, and successfully completes the assessment before the contract option year.
Frequently Asked Questions
How much does a CMMC Level 2 third-party assessment cost?
Assessment costs vary by organization size and complexity. Industry estimates range from $30,000 to over $100,000 for the assessment itself, not including remediation costs.
What is a Plan of Action and Milestones (POA&M) in the Level 2 context?
A POA&M documents security requirements that are not yet fully implemented along with the planned remediation timeline. CMMC 2.0 allows contractors to enter assessment with a limited number of open POA&M items if they can demonstrate a credible remediation plan.
Can a contractor receive a conditional CMMC Level 2 certification?
Under CMMC 2.0, contractors can receive a conditional certification if they have a limited number of unimplemented requirements with acceptable POA&M timelines. Final certification requires closing those items.
Does Level 2 apply to subcontractors?
Yes. Prime contractors must flow CMMC requirements down to subcontractors that handle CUI on the program. Subcontractors must meet Level 2 requirements independently.
What happens if a contractor fails a Level 2 assessment?
The contractor receives a list of deficiencies and must remediate before retaking the assessment. Failing a Level 2 assessment makes the contractor ineligible for award on contracts requiring that level until certification is achieved.
How Bidovate helps
Bidovate puts CMMC Level 2 to work inside your capture and proposal workflow.
Solicitation analysisSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
CMMC Level 3
CMMC Level 3 is the highest tier of the Cybersecurity Maturity Model Certification, requiring implementation of NIST SP 800-172 controls in addition to all 800-171 requirements, with government-led assessments for contractors on the most critical defense programs.
ViewNIST SP 800-171
NIST SP 800-171 is the federal cybersecurity standard defining 110 security controls that contractors must implement to protect Controlled Unclassified Information in non-federal systems.
ViewCMMC Level 1
CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, requiring 17 basic cybersecurity practices and annual self-assessment for contractors that handle Federal Contract Information.
ViewSection 889 (Huawei/ZTE Ban)
Section 889 of the FY2019 National Defense Authorization Act prohibits federal contractors from using or providing telecommunications equipment or services from Huawei, ZTE, and three other designated Chinese companies.
View