Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Guide

CMMC Level 2 and NIST SP 800-171: readiness basics

CMMC Level 2 requirements are the 110 security requirements of NIST SP 800-171 Rev. 2, applied to the systems that handle Controlled Unclassified Information (CUI) under defense contracts. This guide explains the CMMC levels, FCI and CUI, system security plans and POA&Ms, SPRS and the DFARS clauses, and how to prepare.

Compliance9 min read

By Security Inspect · Sources checked

Key takeaways

  • CMMC Level 2 uses the 110 requirements of NIST SP 800-171 Rev. 2 (32 CFR 170.14(c)(3)), even though NIST withdrew Rev. 2 on May 14, 2024 and replaced it with Rev. 3.
  • Level 1 protects Federal Contract Information with the 15 requirements of FAR 52.204-21 and allows no POA&M; Level 2 protects CUI.
  • A current system security plan is the foundation: a DFARS Basic Assessment starts from it, and SPRS records the plan's name, version and date with the score.
  • Assessment results and the Affirming Official's affirmations are recorded in SPRS, the Supplier Performance Risk System.
  • 32 CFR 170.8(b)(17)(ii)(G) requires the Accreditation Body to bar CMMC ecosystem members who consulted to prepare an organization for any CMMC assessment within 3 years from its Level 2 certification assessment process.

Note: Program status

CMMC program update — September 26, 2026: CMMC implementation remains paused in Phase 1 following the suspension of Phase II on July 13, 2026. Phase I self-assessment requirements remain in force. During the suspension, procurement requirements may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC).

CMMC levels in brief

The CMMC Program rule, 32 CFR Part 170, defines three levels. The level in a solicitation or contract sets both the requirements and who assesses them.

CMMC levels, requirements and assessments under 32 CFR Part 170
LevelInformationRequirementsAssessment
Level 1Federal Contract Information (FCI)15 requirements in FAR 52.204-21(b)(1)Self-assessment and affirmation every year; no POA&M allowed
Level 2Controlled Unclassified Information (CUI)110 requirements of NIST SP 800-171 Rev. 2Self-assessment or a certification assessment by an authorized C3PAO, as the solicitation or contract specifies, every three years, with annual affirmation
Level 3CUI, for programs that require Level 3Level 2 plus 24 selected requirements from NIST SP 800-172Certification assessment by DCMA DIBCAC every three years, after reaching Final Level 2 (C3PAO)

Use the exact status name

Part 170 records each result as a CMMC Status, such as Final Level 1 (Self), Conditional Level 2 (Self) or Final Level 2 (C3PAO). When you describe your result to a customer or prime contractor, use that exact status name and date rather than a general label.

FCI vs CUI

Federal Contract Information is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. It excludes information the Government provides to the public and simple transactional information, such as what is needed to process payments. FAR 52.204-21 sets 15 basic safeguarding requirements for contractor systems that hold it.

Controlled Unclassified Information, as defined in 32 CFR 2002.4(h), is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation or Government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. The CUI program was established by Executive Order 13556, and the National Archives hosts the CUI Registry, the Government-wide online repository for CUI policy and practice.

Your contract documents tell you what you hold. When a contract includes DFARS 252.204-7012, covered contractor information systems that handle covered defense information are subject to the security requirements in NIST SP 800-171, whatever CMMC level the contract also names.

NIST SP 800-171 Rev. 2 vs Rev. 3

NIST published SP 800-171 Rev. 3 in May 2024 and withdrew Rev. 2 on May 14, 2024; on NIST's site, Rev. 3 supersedes Rev. 2. CMMC didn't change with it. 32 CFR 170.14(c)(3) states that the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2, and the DoW CIO's CMMC page describes Level 2 as the 110 requirements of Rev. 2.

Both facts hold at once: Rev. 2 is withdrawn by NIST and is still the CMMC Level 2 baseline. For CMMC work, implement and assess against Rev. 2 using the assessment procedures in NIST SP 800-171A (June 2018), which Part 170 references for Level 2 assessments.

Rev. 3 reorganizes the requirements into 17 families instead of 14, so a Rev. 3 mapping isn't a substitute for a Rev. 2 assessment. Watch the DoW CIO site and the Federal Register for any change to Part 170 rather than relying on secondhand reports.

CMMC Level 2 requirements: the 14 families in Rev. 2

NIST SP 800-171 Rev. 2 organizes its requirements into 14 families. Each family has basic requirements drawn from FIPS 200 and derived requirements drawn from the security controls in NIST SP 800-53.

  • 3.1 Access Control and 3.2 Awareness and Training
  • 3.3 Audit and Accountability and 3.4 Configuration Management
  • 3.5 Identification and Authentication and 3.6 Incident Response
  • 3.7 Maintenance and 3.8 Media Protection
  • 3.9 Personnel Security and 3.10 Physical Protection
  • 3.11 Risk Assessment and 3.12 Security Assessment
  • 3.13 System and Communications Protection and 3.14 System and Information Integrity

Three topics folded into other families

Rev. 2 leaves out the contingency planning, system and services acquisition, and planning families, with three exceptions folded in elsewhere: protecting the confidentiality of backup CUI (media protection), the system security plan (security assessment) and security engineering principles (system and communications protection).

System security plans and POA&Ms

Requirement 3.12.4 asks organizations to develop, document and periodically update system security plans that describe system boundaries, environments of operation, how security requirements are implemented, and connections to other systems. Requirement 3.12.2 asks for plans of action that correct deficiencies and reduce or eliminate vulnerabilities.

NIST divides the work between them: enduring exceptions to the requirements are described in the system security plan, while individual, isolated or temporary deficiencies are managed through plans of action. Part 170 defines a plan of action and milestones (POA&M) as a document that identifies tasks to be accomplished, the resources required, milestones and scheduled completion dates.

CMMC limits POA&Ms. Level 1 allows none. At Level 2, 32 CFR 170.21 permits a Conditional status only if the assessment score divided by the total number of Level 2 requirements is at least 0.8, only requirements worth 1 point can be deferred (with a narrow exception for encryption that isn't FIPS-validated), and six named requirements can never be deferred. A closeout assessment must confirm the items closed within 180 days of the Conditional CMMC Status Date.

  • The system boundary and every component inside it, including cloud services and external connections
  • The environment of operation: locations, networks, users and the flow of CUI
  • For each requirement, how it's implemented, who owns it and where the evidence lives
  • Any enduring exceptions, with the reasoning
  • A version, date and approver, since SPRS records the plan's name, version and date

SPRS scores and the DFARS clauses

Four DFARS clauses connect NIST SP 800-171 and CMMC to defense contracts:

  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting: makes covered contractor information systems subject to the security requirements in NIST SP 800-171.
  • DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements: an offeror required to implement NIST SP 800-171 must have a current assessment, not more than 3 years old unless the solicitation sets a shorter period, for each relevant system, with summary level scores posted in SPRS.
  • DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements: defines the Basic Assessment as the contractor's self-assessment and the Medium and High Assessments as assessments by Government personnel, and flows down to subcontractors.
  • DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements: requires the CMMC status the contract names, annual affirmations in SPRS, and flow-down to subcontractors that handle FCI or CUI.

How SPRS and scoring work

SPRS doesn't perform assessments; it stores results. For NIST SP 800-171 Basic Assessments it records the assessment date, score, scope, plan of action completion date, CAGE codes, the system security plan's name, version and date, and the confidence level.

Part 170's scoring starts at a maximum equal to the number of Level 2 requirements and subtracts 1, 3 or 5 points for each requirement not met, so a score can fall below zero. The Affirming Official, the senior representative responsible for the organization's compliance, affirms in SPRS that it has implemented and will maintain the applicable requirements, with each assessment, annually and after a POA&M closeout.

Readiness steps for CMMC Level 2

A practical sequence for an organization that handles CUI, whichever assessment type its contracts call for:

  • Confirm the requirement: read the solicitation or contract for the CMMC level, assessment type, DFARS clauses and CUI designations, and check the dated program update on this page.
  • Scope the environment: find where CUI is received, stored, processed and transmitted, and decide whether to protect the whole network or a smaller, separate enclave.
  • Run a gap assessment against the 110 requirements using the NIST SP 800-171A assessment objectives, and score it with the CMMC scoring method.
  • Write or update the system security plan so it matches how the environment actually works.
  • Build a POA&M for the gaps, fixing first the items Part 170 won't allow on a POA&M.
  • Collect evidence for each requirement: configurations, logs, access reviews, training records and policies.
  • Rehearse the assessment with someone who didn't build the controls, then have the Affirming Official review the results before anything goes into SPRS.

Enclaves and scope

An enclave reduces the systems and people in scope, but only if CUI stays inside it. Mapping how CUI actually moves, including email, file sharing and exchanges with subcontractors, usually decides whether an enclave is practical.

Independence: preparing and assessing are separate roles

Part 170 separates advisory work from certification assessment. 32 CFR 170.8(b)(17)(ii)(G) requires the Accreditation Body to prohibit CMMC ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.

For an organization planning a Level 2 certification assessment, that means choosing its C3PAO with its advisers' history in mind. The people who helped prepare the environment can support readiness, but they can't take part in that certification assessment.

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

Where our work fits

  • CMMC Level 1 and Level 2 readiness — preparation for self-assessment or a certification assessment by an authorized C3PAO.
  • Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.

Questions

Which revision of NIST SP 800-171 should we implement?

For CMMC Level 2, implement and assess against Rev. 2, the version 32 CFR 170.14(c)(3) names. Rev. 3 is NIST's current publication and useful for planning, but a Rev. 3 mapping doesn't replace a Rev. 2 assessment for CMMC. Check each contract for any other revision it names.

Can we have open POA&M items?

Not at Level 1: Part 170 allows no POA&M for Level 1 self-assessments. At Level 2, a POA&M is allowed only for a Conditional status that meets the conditions in 32 CFR 170.21, including a minimum score and limits on which requirements can be deferred, and it must be closed out within 180 days.

Who posts results to SPRS?

For CMMC self-assessments, the organization submits its results and the Affirming Official completes affirmations in SPRS. For certification assessments, the C3PAO or DCMA DIBCAC submits results through the CMMC instance of eMASS, which transmits them to SPRS. For DFARS Basic Assessments, the contractor's summary level scores are entered in SPRS; for Government Medium and High Assessments, DoD posts the scores.

Primary sources

Related guides

Terms in this guide

More on this site

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Talk through your situation with a practitioner

Every engagement begins with a written scope and proposal.

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.