Skip to main content
Free Resource

CMMC Level 2 Readiness Guide

The complete playbook for defense contractors preparing for CMMC Level 2 certification. Gap analysis, documentation, remediation, and C3PAO assessment readiness.

Guide delivered to your inbox

Understand What CMMC Level 2 Actually Requires

CMMC Level 2 certification is required for any defense contractor that handles Controlled Unclassified Information (CUI). It maps directly to all 110 practices in NIST SP 800-171. Unlike the previous self-attestation model, Level 2 requires a third-party assessment by an accredited C3PAO. You cannot certify yourself.

110
Security practices required for Level 2
3yr
Certification cycle with annual affirmations
180d
Maximum POA&M deferral window

Who Is Required to Certify at Level 2?

Phase 1 is active. CMMC clauses began appearing in DoD contracts on November 10, 2025. If your contract contains DFARS 252.204-7021, the certification requirement is already in effect for your next award.

Level 2 vs Level 1: Know the Difference

Level 1 covers 17 basic cybersecurity practices and allows annual self-attestation. Level 2 covers all 110 NIST 800-171 practices and requires a C3PAO third-party assessment. If you handle CUI, you almost certainly need Level 2. See our full breakdown: CMMC Level 1 vs Level 2.

Conduct an Honest Gap Assessment

Before you can remediate, you need to know exactly where you stand against all 110 NIST 800-171 practices. A gap assessment is the process of scoring each practice as fully implemented, partially implemented, or not implemented, and documenting the evidence for each.

Do not guess. Many contractors submitted SPRS scores of 110 based on assumptions, not evidence. Under the DoJ's Civil Cyber-Fraud Initiative, an inflated score is a potential False Claims Act liability. Your gap assessment must be based on actual evidence, not intent.

What a Gap Assessment Covers

Output of a Gap Assessment

Your gap assessment should produce three deliverables: an updated SPRS score reflecting your current posture, a gap list identifying every partially or not-implemented practice, and a prioritized remediation roadmap. Start with our free self-assessment tool to get an initial baseline.

Build Your Documentation Package

Documentation is where most CMMC assessments are won or lost. Your C3PAO assessor reads your System Security Plan before they run a single test. If the documentation does not support your security posture, the controls do not get credited.

The Four Core Documents

  1. System Security Plan (SSP): Describes your CUI boundary, asset inventory, CUI data flows, and how each of the 110 practices is implemented in your specific environment. Must be organization-specific; generic templates fail assessor scrutiny immediately.
  2. Plan of Action & Milestones (POA&M): Documents every gap from your assessment with a planned completion date, assigned owner, and resource allocation. Items must be closed within 180 days of conditional certification.
  3. Policies and Procedures: Written policies for each NIST 800-171 control family: Access Control, Incident Response, Configuration Management, and others. Every policy needs an owner, effective date, version number, and review date.
  4. Evidence Package: Screenshots, system-generated reports, training completion records, and audit logs that prove each control is implemented as described in the SSP.

Organize by control family. Structure your documentation package so each section contains: the relevant policy, the SSP description, supporting evidence, and any open POA&M items. Assessors who cannot find evidence during a time-boxed assessment may note findings simply because they ran out of time.

Critical Documentation Gaps That Fail Assessments

Remediate Gaps Before Your Assessment

Not all gaps are equal. Some practices are POA&M-eligible, meaning you can defer them to a 180-day post-certification window. Others must be fully implemented before a C3PAO will issue certification. Knowing which is which before your assessment saves significant time and money.

Prioritize by Risk and POA&M Eligibility

Focus remediation effort in this order:

  1. Non-deferrable practices first: Multi-factor authentication, incident reporting to the DoD, and CUI boundary controls are typically required before certification is granted. These cannot be left open on a POA&M.
  2. High-weighted practices second: Access Control and System & Communications Protection carry the highest point values in SPRS scoring. Gaps here have an outsized impact on your score.
  3. POA&M-eligible items third: Lower-risk practices that have a clear remediation path can be deferred, but must have a credible timeline and assigned owner in your POA&M.

Common Remediation Actions for Manufacturers

Reactive remediation costs more. Contractors who attempt to remediate on the contract's budget after winning an award face a closed window. Plan and fund remediation before your next DoD solicitation cycle.

Prepare for and Pass Your C3PAO Assessment

A C3PAO assessment is a structured, multi-day evaluation. Assessors use the NIST SP 800-171A assessment methodology to examine each practice through three methods: examination (reviewing documentation), interviews (talking to your staff), and testing (technical verification). Understanding how assessors work lets you prepare more effectively.

What Assessors Do Before the On-Site Visit

What Assessors Do During the Assessment

Before the C3PAO Arrives: Final Checklist

Run a mock assessment first. A pre-assessment readiness review with your consultant, simulating the C3PAO's examination methodology, is the single most effective way to find and close gaps before they become assessment findings.

Ready to Start Your CMMC Journey?

Our team works with defense manufacturers, aerospace subcontractors, and DoD suppliers to achieve Level 2 certification. Gap assessment to C3PAO: we handle the process.

Talk to Our CMMC Team

Subscribe to our Newsletter: