HomeGlossaryCMMC Level 2
Cybersecurity Compliance

CMMC Level 2

CMMC Level 2 requires defense contractors handling Controlled Unclassified Information to implement all 110 security requirements of NIST SP 800-171 and, for most programs, undergo triennial third-party assessments.

Quick answer

CMMC Level 2 requires defense contractors handling Controlled Unclassified Information to implement all 110 security requirements of NIST SP 800-171 and, for most programs, undergo triennial third-party assessments.


CMMC Level 2 is the tier that affects the largest number of defense prime contractors and subcontractors. It aligns directly with NIST SP 800-171 and introduces external verification for contractors on sensitive programs, replacing years of self-reported compliance that proved inadequate.

What is CMMC Level 2?

CMMC Level 2 requires contractors to implement all 110 security requirements across 14 domains defined in NIST SP 800-171. These domains cover access control, incident response, configuration management, audit and accountability, identification and authentication, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, system and information integrity, maintenance, and awareness and training. For contracts involving programs deemed critical to national security (typically determined by the DoD program office), Level 2 requires a triennial assessment by a Certified Third Party Assessment Organization (C3PAO). For less critical programs, an annual self-assessment with SPRS affirmation and senior-official certification is permitted. The third-party assessment process includes a review of the contractor's System Security Plan, interviews with key personnel, and testing of implemented controls.

Why CMMC Level 2 matters for government contractors

Most DoD contracts above the simplified acquisition threshold that involve access to technical data, engineering drawings, or program information will require CMMC Level 2. The investment in achieving and maintaining Level 2 certification is substantial but is increasingly a prerequisite for participating in the defense market. Contractors who begin the assessment process early gain a competitive advantage over those who treat it as a last-minute compliance checkbox.

Example

A mid-tier defense engineering firm receives a DFARS 252.204-7012 clause in a new contract, indicating it handles CUI. The firm already has a NIST SP 800-171 self-assessment score of 87 out of 110 in SPRS. To prepare for CMMC Level 2 third-party assessment, it engages a C3PAO, identifies 12 remaining gaps, implements remediation over four months, and successfully completes the assessment before the contract option year.

Frequently Asked Questions

How much does a CMMC Level 2 third-party assessment cost?


Assessment costs vary by organization size and complexity. Industry estimates range from $30,000 to over $100,000 for the assessment itself, not including remediation costs.

What is a Plan of Action and Milestones (POA&M) in the Level 2 context?


A POA&M documents security requirements that are not yet fully implemented along with the planned remediation timeline. CMMC 2.0 allows contractors to enter assessment with a limited number of open POA&M items if they can demonstrate a credible remediation plan.

Can a contractor receive a conditional CMMC Level 2 certification?


Under CMMC 2.0, contractors can receive a conditional certification if they have a limited number of unimplemented requirements with acceptable POA&M timelines. Final certification requires closing those items.

Does Level 2 apply to subcontractors?


Yes. Prime contractors must flow CMMC requirements down to subcontractors that handle CUI on the program. Subcontractors must meet Level 2 requirements independently.

What happens if a contractor fails a Level 2 assessment?


The contractor receives a list of deficiencies and must remediate before retaking the assessment. Failing a Level 2 assessment makes the contractor ineligible for award on contracts requiring that level until certification is achieved.

How Bidovate helps

Bidovate puts CMMC Level 2 to work inside your capture and proposal workflow.

Solicitation analysis

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.