Understand What CMMC Level 2 Actually Requires
CMMC Level 2 certification is required for any defense contractor that handles Controlled Unclassified Information (CUI). It maps directly to all 110 practices in NIST SP 800-171. Unlike the previous self-attestation model, Level 2 requires a third-party assessment by an accredited C3PAO. You cannot certify yourself.
Who Is Required to Certify at Level 2?
- Any contractor with a DoD contract containing DFARS 252.204-7021
- Subcontractors who receive CUI from prime contractors under a DoD program
- Manufacturers, engineers, IT service providers, and professional services firms handling technical drawings, specifications, or program data
Phase 1 is active. CMMC clauses began appearing in DoD contracts on November 10, 2025. If your contract contains DFARS 252.204-7021, the certification requirement is already in effect for your next award.
Level 2 vs Level 1: Know the Difference
Level 1 covers 17 basic cybersecurity practices and allows annual self-attestation. Level 2 covers all 110 NIST 800-171 practices and requires a C3PAO third-party assessment. If you handle CUI, you almost certainly need Level 2. See our full breakdown: CMMC Level 1 vs Level 2.
Conduct an Honest Gap Assessment
Before you can remediate, you need to know exactly where you stand against all 110 NIST 800-171 practices. A gap assessment is the process of scoring each practice as fully implemented, partially implemented, or not implemented, and documenting the evidence for each.
Do not guess. Many contractors submitted SPRS scores of 110 based on assumptions, not evidence. Under the DoJ's Civil Cyber-Fraud Initiative, an inflated score is a potential False Claims Act liability. Your gap assessment must be based on actual evidence, not intent.
What a Gap Assessment Covers
- Access Control (22 practices): Who can access CUI systems, how access is provisioned and reviewed, MFA enforcement
- Audit & Accountability (9 practices): What events are logged, how long logs are retained, who reviews them
- Configuration Management (9 practices): Baseline configurations, change control, software inventory
- Identification & Authentication (11 practices): Password policies, MFA, privileged account management
- Incident Response (3 practices): IR plan, incident reporting procedures, breach response capability
- Maintenance (6 practices): Controlled maintenance, remote maintenance oversight
- Media Protection (9 practices): CUI on portable devices, media sanitization, physical media controls
- Personnel Security (2 practices): Screening, termination procedures
- Physical Protection (6 practices): Physical access to CUI systems and facilities
- Risk Assessment (3 practices): Periodic risk assessments, vulnerability scanning
- Security Assessment (4 practices): Periodic system assessments, plan of action tracking
- System & Communications Protection (16 practices): Network segmentation, encryption in transit and at rest
- System & Information Integrity (7 practices): Malware protection, security alerts, patch management
Output of a Gap Assessment
Your gap assessment should produce three deliverables: an updated SPRS score reflecting your current posture, a gap list identifying every partially or not-implemented practice, and a prioritized remediation roadmap. Start with our free self-assessment tool to get an initial baseline.
Build Your Documentation Package
Documentation is where most CMMC assessments are won or lost. Your C3PAO assessor reads your System Security Plan before they run a single test. If the documentation does not support your security posture, the controls do not get credited.
The Four Core Documents
- System Security Plan (SSP): Describes your CUI boundary, asset inventory, CUI data flows, and how each of the 110 practices is implemented in your specific environment. Must be organization-specific; generic templates fail assessor scrutiny immediately.
- Plan of Action & Milestones (POA&M): Documents every gap from your assessment with a planned completion date, assigned owner, and resource allocation. Items must be closed within 180 days of conditional certification.
- Policies and Procedures: Written policies for each NIST 800-171 control family: Access Control, Incident Response, Configuration Management, and others. Every policy needs an owner, effective date, version number, and review date.
- Evidence Package: Screenshots, system-generated reports, training completion records, and audit logs that prove each control is implemented as described in the SSP.
Organize by control family. Structure your documentation package so each section contains: the relevant policy, the SSP description, supporting evidence, and any open POA&M items. Assessors who cannot find evidence during a time-boxed assessment may note findings simply because they ran out of time.
Critical Documentation Gaps That Fail Assessments
- No CUI data flow diagram showing where CUI enters, moves, and exits your environment
- SSP uses template language that does not describe your actual systems and controls
- Policies without approval dates, version numbers, or owner signatures
- No user training completion records with names and dates
- Missing FIPS 140-2 validated encryption documentation
- POA&M items with no assigned owner or past-due dates with no update
Remediate Gaps Before Your Assessment
Not all gaps are equal. Some practices are POA&M-eligible, meaning you can defer them to a 180-day post-certification window. Others must be fully implemented before a C3PAO will issue certification. Knowing which is which before your assessment saves significant time and money.
Prioritize by Risk and POA&M Eligibility
Focus remediation effort in this order:
- Non-deferrable practices first: Multi-factor authentication, incident reporting to the DoD, and CUI boundary controls are typically required before certification is granted. These cannot be left open on a POA&M.
- High-weighted practices second: Access Control and System & Communications Protection carry the highest point values in SPRS scoring. Gaps here have an outsized impact on your score.
- POA&M-eligible items third: Lower-risk practices that have a clear remediation path can be deferred, but must have a credible timeline and assigned owner in your POA&M.
Common Remediation Actions for Manufacturers
- Implement and enforce MFA on all systems that store, process, or transmit CUI
- Segment CUI systems onto a dedicated VLAN isolated from the general corporate network
- Deploy and configure endpoint detection and response (EDR) on all CUI endpoints
- Establish a formal patch management process with documented remediation timelines
- Enable audit logging on all CUI systems with 90-day retention
- Conduct and document annual security awareness training for all CUI-handling staff
- Implement FIPS 140-2 validated encryption for CUI at rest and in transit
Reactive remediation costs more. Contractors who attempt to remediate on the contract's budget after winning an award face a closed window. Plan and fund remediation before your next DoD solicitation cycle.
Prepare for and Pass Your C3PAO Assessment
A C3PAO assessment is a structured, multi-day evaluation. Assessors use the NIST SP 800-171A assessment methodology to examine each practice through three methods: examination (reviewing documentation), interviews (talking to your staff), and testing (technical verification). Understanding how assessors work lets you prepare more effectively.
What Assessors Do Before the On-Site Visit
- Review your SSP in full, which sets expectations for everything that follows
- Request your documentation package: policies, evidence, POA&M
- Identify control families where your SSP descriptions are vague or unsupported
What Assessors Do During the Assessment
- Cross-reference SSP claims against observed configurations
- Interview IT staff and managers about how controls are actually implemented
- Test technical controls: MFA enforcement, logging, patch status, network segmentation
- Request evidence artifacts for any control not fully documented in advance
Before the C3PAO Arrives: Final Checklist
- SSP is complete, current, and organization-specific
- All non-deferrable controls are fully implemented with documented evidence
- POA&M is up to date with no overdue items and no missing owners
- Documentation package is organized by control family and clearly labeled
- IT staff have reviewed the SSP and can explain each control accurately
- CUI data flow diagram is accurate and up to date
- Security awareness training completion records are available for all CUI-handling staff
- Vulnerability scan reports are current with documented remediation status
Run a mock assessment first. A pre-assessment readiness review with your consultant, simulating the C3PAO's examination methodology, is the single most effective way to find and close gaps before they become assessment findings.
Ready to Start Your CMMC Journey?
Our team works with defense manufacturers, aerospace subcontractors, and DoD suppliers to achieve Level 2 certification. Gap assessment to C3PAO: we handle the process.
