CMMC Level 2 Requirements in 2026: The Complete Guide for Defense Contractors
CMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active.
July 13, 2026 update: The Department of War suspended the Phase II transition and pending and future implementation milestones. All Phase I self-assessment requirements remain in place, and the Department says it will enforce NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments during the review.
What CMMC Level 2 Requires During the Reform Review
The Cybersecurity Maturity Model Certification (CMMC) Level 2 baseline uses all 110 security requirements from NIST SP 800-171 Revision 2. During the Phase II pause, Phase I self-assessments remain active and selected government-led assessments continue.
The underlying duty is still contractual. DFARS 252.204-7012 continues to require covered contractor systems to safeguard covered defense information, and applicable DFARS 7019/7020 provisions still govern NIST assessment information and government review.
The fixed November clock is gone. The implementation gap is not. Contractors should plan against the clauses in their actual solicitations and contracts, prime flow-downs, selected government assessments, and the revised program that follows the 60-day review.
This guide covers everything you need to know: the 110 controls organized by family, the assessment process, realistic cost estimates, common failure points, and how to build a path to certification that holds up under C3PAO scrutiny.
The 14 Control Families: What C3PAOs Actually Examine
NIST SP 800-171 organizes its 110 controls into 14 families. Each family addresses a distinct security domain. A C3PAO assessor will evaluate your implementation of every control within every family - there is no partial credit on individual controls.
Access Control (AC) - 22 Controls
Access Control is the largest family and the one most frequently cited in assessment failures. It governs who can access your systems, what they can do, and how access decisions are enforced.
Key requirements include:
- AC.L2-3.1.1: Limit system access to authorized users, processes, and devices
- AC.L2-3.1.5: Employ the principle of least privilege
- AC.L2-3.1.7: Prevent non-privileged users from executing privileged functions
- AC.L2-3.1.12: Monitor and control remote access sessions
The most common failure point is privilege creep - users accumulating permissions over time without regular access reviews. Cloud environments are especially prone to this because IAM policies are often copied from templates and never pruned.
Audit & Accountability (AU) - 9 Controls
C3PAOs look for centralized, tamper-resistant audit logging with defined retention periods. The critical question is not whether you collect logs, but whether you review them systematically and can demonstrate you've acted on findings.
Configuration Management (CM) - 9 Controls
Baseline configurations must be documented, enforced, and monitored for drift. In cloud environments, this means Infrastructure as Code (IaC) templates with continuous drift detection - not periodic manual reviews.
Identification & Authentication (IA) - 11 Controls
Multi-factor authentication for all privileged and remote access. FIPS 140-2 validated cryptographic modules. Password complexity and rotation policies. These controls have specific technical requirements that must be verifiable in your cloud configuration.
Incident Response (IR) - 3 Controls
A documented, tested incident response plan. Note: DFARS 7012 requires 72-hour notification to the DoD Cyber Crime Center (DC3) for cyber incidents involving CUI. Your IR plan must explicitly address this requirement.
System & Communications Protection (SC) - 16 Controls
The second-largest family. Encryption at rest and in transit using FIPS 140-2 validated modules. Network segmentation. CUI boundary definition. These controls are where cloud architecture decisions have the most impact.
The Remaining Families
- Awareness & Training (AT): 3 controls - role-based security training with tracking
- Maintenance (MA): 6 controls - controlled maintenance with authorized personnel
- Media Protection (MP): 9 controls - CUI marking, sanitization, and destruction
- Physical & Environmental (PE): 6 controls - facility access and environmental controls
- Personnel Security (PS): 2 controls - screening and termination procedures
- Risk Assessment (RA): 3 controls - periodic vulnerability scanning and risk assessment
- Security Assessment (CA): 4 controls - ongoing assessment with POA&M management
- System & Information Integrity (SI): 7 controls - flaw remediation, monitoring, and alerting
The C3PAO Assessment Process: What Actually Happens
A CMMC Level 2 third-party assessment follows a structured process:
1. Pre-assessment preparation (3-6 months before) Your organization prepares a System Security Plan (SSP) mapping every control to your implementation, a POA&M for any open items, and evidence packages for each control family.
2. Assessment scheduling You select a C3PAO from the CMMC Accreditation Body's marketplace and schedule the assessment. Current wait times range from 2-6 months depending on the C3PAO's backlog.
3. On-site assessment (1-2 weeks) Certified assessors review documentation, examine system configurations, interview personnel across roles, and test controls through direct observation. They are evaluating technical reality, not documentation intent.
4. Findings and remediation The C3PAO issues findings categorized as MET, NOT MET, or NOT APPLICABLE. You may have a limited window to remediate NOT MET findings before a final determination.
5. Certification If all 110 controls are MET (or documented in an approved POA&M with remediation timeline), you receive your CMMC Level 2 certification, valid for 3 years.
Realistic Cost Estimates
CMMC Level 2 certification costs vary significantly based on organization size and current posture:
| Component | Small Contractor (< 50 employees) | Mid-size (50-500) |
|---|---|---|
| Gap assessment | $15,000 - $30,000 | $30,000 - $75,000 |
| Remediation (tools + implementation) | $50,000 - $150,000 | $150,000 - $500,000 |
| C3PAO assessment fee | $30,000 - $60,000 | $60,000 - $150,000 |
| Ongoing compliance (annual) | $20,000 - $50,000 | $50,000 - $200,000 |
These figures include necessary tooling (SIEM, vulnerability scanning, configuration management), professional services for remediation, and the assessment itself. Organizations starting from scratch should expect the higher end of these ranges.
The 5 Most Common Assessment Failures
Based on publicly available C3PAO assessment data and industry reporting:
1. Incomplete CUI boundary definition - Contractors cannot clearly identify where CUI resides, flows, and is processed. Without a defined boundary, no control can be properly scoped.
2. Missing or outdated SSP - The SSP exists but hasn't been updated to reflect current cloud architecture, recent changes, or actual control implementations.
3. Inadequate logging and monitoring - Logs are collected but not reviewed. Alerting thresholds are not defined. There is no evidence of systematic audit log review.
4. Configuration drift - Baseline configurations exist in documentation but the actual cloud environment has drifted significantly. No continuous monitoring is in place to detect drift.
5. Insufficient access reviews - Least privilege is documented in policy but IAM roles and permissions have accumulated without regular review cycles.
Building Your Path to Certification
If you have 8+ months before your next contract or assessment target:
- Define your CUI boundary - Identify every system, network segment, and cloud resource that stores, processes, or transmits CUI
- Conduct a gap assessment - Evaluate each of the 110 controls against your actual technical implementation
- Build your POA&M - Document every gap with a realistic remediation timeline
- Implement automated monitoring - Deploy continuous compliance monitoring to catch drift before assessors do
- Confirm the assessment path - Schedule a C3PAO only when your contract, prime, or planned certification path calls for one
If you have less than 6 months:
You need to move fast. Prioritize the most common failure points above, invest in automation to accelerate evidence collection, and consider whether a platform like PolicyCortex can compress your timeline by automating continuous monitoring and evidence generation across all 110 controls.
The November Phase II date is suspended. The contractors in the strongest position will use the review window to make their Rev. 2 implementation and SPRS evidence accurate, then adapt from a clean baseline when the Department publishes the reformed path.
PolicyCortex continuously monitors all 110 NIST 800-171 controls, auto-collects evidence, and generates C3PAO-ready documentation. Book a 15-minute demo to see how it works for your environment.
- What are the CMMC Level 2 requirements?
- CMMC Level 2 requires implementing all 110 security controls from NIST SP 800-171, documented in a System Security Plan (SSP), with any gaps tracked in a Plan of Action and Milestones (POA&M). Most contractors handling CUI must pass a third-party assessment by an authorized C3PAO every three years, with an annual senior-official affirmation in SPRS.
- Who needs CMMC Level 2 certification?
- Contractors and subcontractors that store, process, or transmit CUI generally fall within the Level 2 model, but the Department suspended the Phase II certification rollout on July 13, 2026. Verify the clauses in the actual solicitation or contract and any current prime direction.
- How many controls are in CMMC Level 2?
- 110 controls, drawn directly from NIST SP 800-171 Revision 2, organized across 14 control families including Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, and System and Communications Protection.
- Do I need a C3PAO or can I self-assess for Level 2?
- During the Phase II suspension, all Phase I self-assessment requirements remain in place. Do not assume a C3PAO assessment is currently required or unnecessary: check the applicable solicitation, contract, prime flow-down, and any Department guidance issued after the reform review.
Replace 4 tools with one platform.
See how PolicyCortex consolidates compliance, security, AI governance, and cost — autonomously.
- R-01CMMC Phase II Is Suspended: What Defense Contractors Still Have to DoThe Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place.
- R-02The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act EvidenceDOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment. Phase II is paused, but the risk of an unsupported score remains.
- R-03The C3PAO Capacity Math After the CMMC Phase II SuspensionThe Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans. Here is how to use the dated 2026 market snapshot without planning from a suspended milestone.
