CMMC Level 2 Requirements

CMMC has evolved over the past few years, and while the program has seen adjustments, the core expectations for CMMC Level 2 requirements have remained consistent. Level 2 is built directly on NIST SP 800‑171r2, and it requires contractors handling Controlled Unclassified Information (CUI) to implement a full set of 110 security practices. Unlike Level 1, which focuses on basic cyber hygiene for protecting Federal Contract Information (FCI), Level 2 represents a significant step up in maturity, documentation, and assessments. For many contractors, this is the point where cybersecurity becomes a formal, structured program rather than a collection of basic safeguards.

It’s important to understand that Level 2 is not simply “Level 1 plus more requirements.” It is a fundamentally different compliance landscape. Level 1 protects FCI. Level 2 protects CUI. Level 1 has 17 practices. Level 2 has 110. Level 1 uses annual self‑assessments. Level 2 pairs self-assessment with independent C3PAO verification — a milestone currently suspended during DoW’s review. The jump is real, but it’s also structured, predictable, and achievable with the right cloud environment and guidance.

At Abel Solutions, we help contractors interpret Level 2 requirements, align them with Microsoft’s government cloud offerings, and prepare for the assessment process. This guide breaks down what Level 2 requires, how it differs from Level 1, and how Microsoft 365 GCC and GCC High support CUI handling.

CMMC Level 2 Requirements at a Glance

Before diving into the details, here are the core CMMC Level 2 requirements every contractor should know:

  • 110 practices
  • 14 requirement families
  • Based entirely on NIST SP 800‑171r2
  • CUI protection required
  • Self-assessment, SPRS score, and annual affirmation in effect today
  • Government cloud alignment strongly recommended

These elements define Level 2. They also explain why contractors handling CUI need a more mature security posture than those handling only FCI.

How Level 2 Differs from Level 1

Many contractors begin their research with Level 1, so it’s important to understand the shift when moving to Level 2. Level 1 is intentionally simple: 17 practices, basic cyber hygiene, and an annual self‑assessment. Level 2 is built for organizations handling sensitive information that requires structured protection.

The differences include:

  • Scope of information:
    • Level 1 protects FCI
    • Level 2 protects CUI
  • Number of practices:
    • Level 1: 17
    • Level 2: 110
  • Framework:
    • Level 1: Basic safeguards
    • Level 2: Full NIST SP 800‑171r2 alignment
  • Assessment:
    • Level 1: Self‑assessment
    • Level 2: Self-assessment now; C3PAO verification when the milestone resumes
  • Cloud requirements:
    • Level 1: Commercial cloud acceptable
    • Level 2: GCC or GCC High recommended depending on sensitivity

This distinction matters because CUI requires stronger protections, more documentation, and a more formal approach to cybersecurity.

The Foundation: NIST SP 800‑171r2

CMMC Level 2 is not a standalone framework. It is a direct implementation of NIST SP 800‑171r2, which outlines how contractors must protect CUI in non‑federal systems. Although NIST has since published Revision 3, CMMC assessments are conducted against Revision 2, as specified in the CMMC Program rule (32 CFR Part 170). The 110 practices are organized into 14 families, including:

  • Access Control
  • Awareness & Training
  • Audit & Accountability
  • Configuration Management
  • Identification & Authentication
  • Incident Response
  • Maintenance
  • Media Protection
  • Personnel Security
  • Physical Protection
  • Risk Assessment
  • Security Assessment
  • System & Communications Protection
  • System & Information Integrity

Each family contains multiple practices that work together to create a comprehensive security framework. For contractors new to NIST SP 800‑171r2, the volume can feel overwhelming. But the structure is logical, and the requirements are designed to be implemented in a predictable, repeatable way. Assessments go one level deeper: NIST SP 800-171A breaks the 110 requirements into 320 assessment objectives — the detail an assessor evaluates.

How Level 2 Is Assessed — and What Changed on July 13

Under the CMMC rule, CMMC Level 2 requirements can be met through two assessment paths: self-assessment for a limited set of contracts, and — for most contracts involving CUI — a triennial assessment by a Certified Third-Party Assessment Organization (C3PAO). This is a formal, third‑party evaluation conducted by a certified assessor who verifies that your organization has implemented all 110 practices correctly. The assessment includes documentation review, interviews, evidence collection, and validation of technical controls.

On July 13, 2026, DoW suspended the C3PAO milestone — previously set for November 10, 2026 — and opened a 60-day program review. During the review, new contracts carry only self-assessment requirements. What did not change matters more: the Level 2 self-assessment, its SPRS score (scaled from −203 to 110), and the annual affirmation by a senior company official remain fully in force — and NIST SP 800-171 remains contractually mandatory wherever DFARS 252.204-7012 appears. Your self-assessment is the compliance story today, and an affirmation you cannot evidence carries False Claims Act exposure now.

A C3PAO assessment ensures:

  • Your environment meets NIST SP 800‑171r2
  • Your documentation accurately reflects your controls implementation
  • Your processes are consistent and repeatable
  • Your cloud environment aligns with CUI handling requirements

Level 1 stops at the annual self-assessment and affirmation. Level 2 adds an external validation layer when the C3PAO milestone resumes, which means contractors must be prepared to demonstrate compliance, not just claim it.

Microsoft Cloud Alignment for CUI

Handling CUI requires a cloud environment that meets federal security expectations. For most contractors, this means choosing between Microsoft 365 GCC and Microsoft 365 GCC High. Both are designed for government workloads, but they serve different levels of CUI data sensitivity.

Microsoft 365 GCC

GCC is appropriate for many Level 2 environments. It provides:

  • FedRAMP Moderate compliance
  • Segregated government cloud infrastructure
  • Enhanced auditing and logging
  • Support for NIST SP 800‑171r2 controls
  • Secure collaboration for CUI

GCC is often the right fit for contractors handling CUI that is not export-controlled and does not require DoW IL4 or IL5 protections.

Microsoft 365 GCC High

GCC High is designed for higher‑sensitivity CUI and DoD workloads. It provides:

  • FedRAMP High compliance
  • DoD IL4 alignment
  • U.S. citizenship‑based support and operations
  • Stronger isolation and boundary protections
  • Full support for NIST SP 800‑171r2 and CMMC Level 2

Contractors handling export-controlled data (ITAR/EAR) or supporting DoW work at higher impact levels typically need GCC High to meet assessment expectations.

Why the Cloud Matters

Level 2 practices require:

  • Strong identity controls
  • Advanced auditing
  • Secure collaboration
  • Controlled data boundaries
  • Consistent configuration management
  • Reliable incident response capabilities

Government cloud environments provide these capabilities natively, reducing the burden on contractors and simplifying assessment preparation.

Preparing for Level 2 Compliance

Meeting CMMC Level 2 requirements takes a structured approach. Contractors should expect to:

  • Identify where CUI is processed, stored, or transmitted — that scope, often a purpose-built enclave, defines the assessment boundary
  • Review all 110 practices
  • Map each practice to their environment
  • Close implementation gaps
  • Document policies and procedures
  • Prepare evidence for assessment
  • Align cloud environments with CUI requirements
  • Conduct internal readiness reviews

This process takes time, but it becomes far more manageable when built on a government‑aligned cloud foundation.

One more distinction in CMMC Level 2 requirements: unlike Level 1, a limited Plan of Action and Milestones (POA&M) is permitted — score at least 88 of 110 for Conditional status, then 180 days to close remaining items and reach Final. A defined runway for gaps, not an open-ended pass.

At Abel Solutions, we help contractors:

  • Interpret NIST SP 800‑171r2
  • Map requirements to Microsoft 365 GCC or GCC High
  • Implement required security features
  • Build documentation and evidence
  • Prepare for assessment — today’s self-assessment and the C3PAO when it resumes

Our goal is to make Level 2 achievable, predictable, and aligned with the tools you already use.

CMMC Level 2 Requirements with Abel Solutions

For organizations handling Controlled Unclassified Information, CMMC Level 2 applies when a DoW solicitation or contract requires it — July’s suspension paused the milestone, not the obligation. Still, you don’t have to navigate the 110 practices alone. With the right cloud environment and guidance, Level 2 becomes a structured, manageable process.

We help contractors understand CMMC Level 2 requirements, align their Microsoft cloud environments with CUI, and prepare for assessments. If you’d like to know where you stand, a scoping conversation is the right first step — our CMMC consulting services team can help you pin down where CUI lives, what your assessment must cover, and what to close before you affirm.

STAY INFORMED, STAY INSPIRED!

  • This field is for validation purposes and should be left unchanged.
  • Use the form below to sign up for Microsoft 365 emails and receive industry-leading insights directly in your inbox.

READY TO GET STARTED?

CONTACT US TODAY!

Fill out the form below and within one business day a member of our team will reach out to schedule a call to learn more about your needs.

  • This field is for validation purposes and should be left unchanged.
  • Protected by reCAPTCHA. Google Privacy Policy and >Terms of Service apply.

Scroll to Top