The Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) 2.0 is transitioning from rule-making to active enforcement. For subcontractors handling Controlled Unclassified Information (CUI), CMMC Level 2 compliance is no longer a future goal—it is a current operational prerequisite.
What is CMMC Level 2?
CMMC Level 2 is designed to protect Controlled Unclassified Information (CUI). Its requirements are completely aligned with the 110 security controls of NIST SP 800-171. Unlike Level 1, which allows for self-assessments, Level 2 will require triennial third-party assessments (conducted by a C3PAO) for subcontractors managing critical national security datasets.
Key Control Families Covered
The 110 controls span 14 domains, but four specific control families represent the vast majority of contractor gaps:
- Access Control (AC): Restricting system access to authorized users and enforcing separation of duties.
- Identification & Authentication (IA): Requiring Multi-Factor Authentication (MFA) for local and network access to systems processing CUI.
- Incident Response (IR): Tracking, documenting, and reporting security incidents to the DoD within 72 hours.
- System & Communications Protection (SC): Setting up encrypted boundaries, protecting organizational networks, and managing cryptographic keys.
Building Your System Security Plan (SSP)
Your SSP is the core document that details how your system satisfies each of the 110 NIST controls. If any control is not met, it must be documented in a Plan of Action & Milestones (POA&M) with clear remediation timelines. Under CMMC 2.0, certain high-priority controls cannot be on a POA&M, and any remaining POA&M items must be fully resolved within 180 days of the assessment.
Auditor Expectations & Evidence Binders
C3PAO auditors will not take policy statements at face value. They operate on the principle of *"Show Me, Don't Tell Me."* For every control, you must provide two types of evidence:
- Documentation: Written policies, operations manuals, and configuration baselines.
- Technical Proof: System logs, active directories, screen captures, or live system demonstrations showing the control in active execution.
Prepare for your C3PAO audit
Our virtual CISOs conduct complete NIST SP 800-171 gap assessments, compile your SSP, and prepare your team for external auditors.
Request Scoping Assessment arrow_forwardCMMC Deliverables
- System Security Plans (SSPs)
- POA&M Remediation Roadmaps
- Enclave Isolation Configs
- Technical Evidence Gathering