CMMC Ready Now
Back to Knowledge Center
The Framework6 min read

CMMC Level 2: Advanced

110 practices aligned to all of NIST SP 800-171 Rev 2. Required for any contractor handling CUI. Most contracts require a C3PAO third-party assessment every three years.

CMMC Level 2 is the most common certification level and applies to the vast majority of DoD contractors handling CUI. It encompasses all 110 security requirements from NIST SP 800-171 Revision 2 across 14 control families.

Third-party vs. self-assessment at Level 2

  • Prioritized acquisitions: contracts for programs of critical national security importance. These require a C3PAO third-party assessment every three years, plus annual affirmations in between.
  • Non-prioritized acquisitions: contracts determined by the DoD Program Manager to have lower criticality. These may allow a Level 2 self-assessment. The contracting officer specifies which applies.

The 110 controls at a glance

DomainControls
Access Control (AC)22
Awareness & Training (AT)3
Audit & Accountability (AU)9
Configuration Management (CM)9
Identification & Authentication (IA)11
Incident Response (IR)3
Maintenance (MA)6
Media Protection (MP)9
Personnel Security (PS)2
Physical Protection (PE)6
Risk Assessment (RA)3
Security Assessment (CA)4
System & Comm. Protection (SC)16
System & Info. Integrity (SI)7

Certification cycle

A Level 2 C3PAO certification is valid for three years. During that period, the contractor must submit an annual affirmation confirming that the security controls remain in place.

POA&M under Level 2

Conditional certification is available for Level 2 — an organization can receive a time-limited certification while completing remediation of remaining gaps. All POA&M items must be closed within 180 days of initial certification. Certain controls (MFA, CUI encryption, incident response) are not POA&M-eligible.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.