CMMC levels in brief
The CMMC Program rule, 32 CFR Part 170, defines three levels. The level in a solicitation or contract sets both the requirements and who assesses them.
| Level | Information | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 requirements in FAR 52.204-21(b)(1) | Self-assessment and affirmation every year; no POA&M allowed |
| Level 2 | Controlled Unclassified Information (CUI) | 110 requirements of NIST SP 800-171 Rev. 2 | Self-assessment or a certification assessment by an authorized C3PAO, as the solicitation or contract specifies, every three years, with annual affirmation |
| Level 3 | CUI, for programs that require Level 3 | Level 2 plus 24 selected requirements from NIST SP 800-172 | Certification assessment by DCMA DIBCAC every three years, after reaching Final Level 2 (C3PAO) |
Use the exact status name
Part 170 records each result as a CMMC Status, such as Final Level 1 (Self), Conditional Level 2 (Self) or Final Level 2 (C3PAO). When you describe your result to a customer or prime contractor, use that exact status name and date rather than a general label.
FCI vs CUI
Federal Contract Information is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. It excludes information the Government provides to the public and simple transactional information, such as what is needed to process payments. FAR 52.204-21 sets 15 basic safeguarding requirements for contractor systems that hold it.
Controlled Unclassified Information, as defined in 32 CFR 2002.4(h), is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation or Government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. The CUI program was established by Executive Order 13556, and the National Archives hosts the CUI Registry, the Government-wide online repository for CUI policy and practice.
Your contract documents tell you what you hold. When a contract includes DFARS 252.204-7012, covered contractor information systems that handle covered defense information are subject to the security requirements in NIST SP 800-171, whatever CMMC level the contract also names.
NIST SP 800-171 Rev. 2 vs Rev. 3
NIST published SP 800-171 Rev. 3 in May 2024 and withdrew Rev. 2 on May 14, 2024; on NIST's site, Rev. 3 supersedes Rev. 2. CMMC didn't change with it. 32 CFR 170.14(c)(3) states that the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2, and the DoW CIO's CMMC page describes Level 2 as the 110 requirements of Rev. 2.
Both facts hold at once: Rev. 2 is withdrawn by NIST and is still the CMMC Level 2 baseline. For CMMC work, implement and assess against Rev. 2 using the assessment procedures in NIST SP 800-171A (June 2018), which Part 170 references for Level 2 assessments.
Rev. 3 reorganizes the requirements into 17 families instead of 14, so a Rev. 3 mapping isn't a substitute for a Rev. 2 assessment. Watch the DoW CIO site and the Federal Register for any change to Part 170 rather than relying on secondhand reports.
CMMC Level 2 requirements: the 14 families in Rev. 2
NIST SP 800-171 Rev. 2 organizes its requirements into 14 families. Each family has basic requirements drawn from FIPS 200 and derived requirements drawn from the security controls in NIST SP 800-53.
- 3.1 Access Control and 3.2 Awareness and Training
- 3.3 Audit and Accountability and 3.4 Configuration Management
- 3.5 Identification and Authentication and 3.6 Incident Response
- 3.7 Maintenance and 3.8 Media Protection
- 3.9 Personnel Security and 3.10 Physical Protection
- 3.11 Risk Assessment and 3.12 Security Assessment
- 3.13 System and Communications Protection and 3.14 System and Information Integrity
Three topics folded into other families
Rev. 2 leaves out the contingency planning, system and services acquisition, and planning families, with three exceptions folded in elsewhere: protecting the confidentiality of backup CUI (media protection), the system security plan (security assessment) and security engineering principles (system and communications protection).
System security plans and POA&Ms
Requirement 3.12.4 asks organizations to develop, document and periodically update system security plans that describe system boundaries, environments of operation, how security requirements are implemented, and connections to other systems. Requirement 3.12.2 asks for plans of action that correct deficiencies and reduce or eliminate vulnerabilities.
NIST divides the work between them: enduring exceptions to the requirements are described in the system security plan, while individual, isolated or temporary deficiencies are managed through plans of action. Part 170 defines a plan of action and milestones (POA&M) as a document that identifies tasks to be accomplished, the resources required, milestones and scheduled completion dates.
CMMC limits POA&Ms. Level 1 allows none. At Level 2, 32 CFR 170.21 permits a Conditional status only if the assessment score divided by the total number of Level 2 requirements is at least 0.8, only requirements worth 1 point can be deferred (with a narrow exception for encryption that isn't FIPS-validated), and six named requirements can never be deferred. A closeout assessment must confirm the items closed within 180 days of the Conditional CMMC Status Date.
- The system boundary and every component inside it, including cloud services and external connections
- The environment of operation: locations, networks, users and the flow of CUI
- For each requirement, how it's implemented, who owns it and where the evidence lives
- Any enduring exceptions, with the reasoning
- A version, date and approver, since SPRS records the plan's name, version and date
SPRS scores and the DFARS clauses
Four DFARS clauses connect NIST SP 800-171 and CMMC to defense contracts:
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting: makes covered contractor information systems subject to the security requirements in NIST SP 800-171.
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements: an offeror required to implement NIST SP 800-171 must have a current assessment, not more than 3 years old unless the solicitation sets a shorter period, for each relevant system, with summary level scores posted in SPRS.
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements: defines the Basic Assessment as the contractor's self-assessment and the Medium and High Assessments as assessments by Government personnel, and flows down to subcontractors.
- DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements: requires the CMMC status the contract names, annual affirmations in SPRS, and flow-down to subcontractors that handle FCI or CUI.
How SPRS and scoring work
SPRS doesn't perform assessments; it stores results. For NIST SP 800-171 Basic Assessments it records the assessment date, score, scope, plan of action completion date, CAGE codes, the system security plan's name, version and date, and the confidence level.
Part 170's scoring starts at a maximum equal to the number of Level 2 requirements and subtracts 1, 3 or 5 points for each requirement not met, so a score can fall below zero. The Affirming Official, the senior representative responsible for the organization's compliance, affirms in SPRS that it has implemented and will maintain the applicable requirements, with each assessment, annually and after a POA&M closeout.
Readiness steps for CMMC Level 2
A practical sequence for an organization that handles CUI, whichever assessment type its contracts call for:
- Confirm the requirement: read the solicitation or contract for the CMMC level, assessment type, DFARS clauses and CUI designations, and check the dated program update on this page.
- Scope the environment: find where CUI is received, stored, processed and transmitted, and decide whether to protect the whole network or a smaller, separate enclave.
- Run a gap assessment against the 110 requirements using the NIST SP 800-171A assessment objectives, and score it with the CMMC scoring method.
- Write or update the system security plan so it matches how the environment actually works.
- Build a POA&M for the gaps, fixing first the items Part 170 won't allow on a POA&M.
- Collect evidence for each requirement: configurations, logs, access reviews, training records and policies.
- Rehearse the assessment with someone who didn't build the controls, then have the Affirming Official review the results before anything goes into SPRS.
Enclaves and scope
An enclave reduces the systems and people in scope, but only if CUI stays inside it. Mapping how CUI actually moves, including email, file sharing and exchanges with subcontractors, usually decides whether an enclave is practical.
Independence: preparing and assessing are separate roles
Part 170 separates advisory work from certification assessment. 32 CFR 170.8(b)(17)(ii)(G) requires the Accreditation Body to prohibit CMMC ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.
For an organization planning a Level 2 certification assessment, that means choosing its C3PAO with its advisers' history in mind. The people who helped prepare the environment can support readiness, but they can't take part in that certification assessment.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.