Skip to main content
Truvisory
Federal

CMMC Level 2: Requirements, Self-Assessment, and What the Suspension Changed

Tony Adams11 min read

CMMC Level 2 is the tier of the CMMC program built to protect CUI — and it is defined by exactly one thing: the 110 security requirements of NIST SP 800-171 Rev. 2. That number did not change on July 13, 2026, when the Department of War suspended CMMC Phase II, the mandatory third-party assessment rollout. What changed is how Level 2 compliance gets verified: the C3PAO certification path is paused, and the Level 2 self-assessment is now one of only two CMMC postures a contracting officer may designate at all.

That makes this a strange, useful moment to understand Level 2 properly. The headlines say the audit is gone. The requirements, the annual affirmation, DFARS 252.204-7012, and the FedRAMP-Moderate cloud rule for CUI all still bind — and the firms that treat the review window as preparation time, rather than a reprieve, will be the ones positioned well whichever way the review lands.

This is the evergreen guide: what Level 2 is, what the requirements actually are, how the self-assessment differs from the paused certification path, who needs Level 2 versus Level 1, and how to prepare while the 60-day review runs.

What is CMMC Level 2?

CMMC — the Cybersecurity Maturity Model Certification program, codified in the CMMC final rule (32 CFR Part 170) — sets three levels of cybersecurity posture for defense contractors, matched to the sensitivity of the information they handle:

  • Level 1 protects Federal Contract Information (FCI) with the 15 basic safeguarding requirements of FAR 52.204-21. It is always self-assessed, annually, with no POA&Ms permitted at any time (32 CFR § 170.21(a)(1)). If FCI is new territory, start with what counts as Federal Contract Information.
  • Level 2 protects Controlled Unclassified Information with the 110 requirements of NIST SP 800-171 Rev. 2 — the subject of this guide.
  • Level 3 adds 24 requirements from NIST SP 800-172 for a select set of programs handling the most sensitive CUI, assessed by the government’s own DIBCAC — and it requires a completed Level 2 first.

So Level 2 is the workhorse tier: it is where most contractors who touch CUI live, and it is the level the whole Phase II controversy was about. The distinction that matters most in 2026 is that “Level 2” is one set of requirements with two verification methods — a self-assessment and a third-party (C3PAO) certification — and only one of those methods is currently available.

CMMC Level 2 requirements: the same 110 controls

The CMMC Level 2 requirements are not a CMMC invention. They are, verbatim, the 110 security requirements of NIST SP 800-171 Rev. 2, spanning 14 domains — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Assessments walk the objectives in NIST SP 800-171A, the companion assessment-procedures document.

Three things about the requirements are worth being precise on:

They are unchanged by the suspension. The July 13 announcement paused the third-party assessment phase; it did not amend, waive, or reduce a single control. If your system processes, stores, or transmits CUI, the 110 requirements apply through DFARS 252.204-7012 exactly as they did on July 12.

Level 2 is scored; Level 1 is not. Level 2 uses a point-scored methodology against the 800-171A objectives (a perfect score is 110), and it permits a conditional status — a minimum passing score with the remaining items on a plan of action, alongside a system security plan. That is a meaningful contrast to Level 1, where the 15 requirements are assessed MET or NOT MET in their entirety and POA&Ms are not permitted at any time.

Rev. 2 is the baseline — for now. NIST has published SP 800-171 Rev. 3, but the Department adopts it only through future rulemaking, and a DFARS class deviation keeps CMMC assessments against Rev. 2 until then. The proposed government-wide CUI rule published in June 2026 points in the Rev. 3 direction, so the transition is a when, not an if — but building genuinely to Rev. 2 today is not wasted work. The two revisions overlap heavily, and a real Rev. 2 implementation converts; a paper one doesn’t.

CMMC Level 2 self-assessment vs Level 2 (C3PAO)

The requirements are identical either way. What differs is who does the verifying — and, since July 13, 2026, which path you’re allowed to use.

Level 2 (Self) — the CMMC Level 2 self-assessment — means your organization assesses its own implementation of the 110 requirements against the NIST SP 800-171A objectives, submits the results to SPRS, and then affirms. The affirmation is not a formality: it comes from your Affirming Official, defined in 32 CFR § 170.22(a)(1) as the senior level representative from within the Organization Seeking Assessment who is responsible for ensuring compliance and who has the authority to affirm the organization’s continuing compliance with the security requirements. That affirmation recurs annually, and a false one is exactly the kind of statement the Justice Department’s Civil Cyber-Fraud Initiative exists to prosecute.

Level 2 (C3PAO) — the certification path — means an accredited CMMC Third-Party Assessment Organization performs the assessment and issues the certification. This was the heart of CMMC Phase II, scheduled to start appearing in solicitations November 10, 2026 — and it is what the Department suspended. Under the implementing memo (26-P-1023), contracting officers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self) while the review runs; they may not designate Level 2 (C3PAO) or Level 3 (DIBCAC), and no waivers will be issued. A CMMC Reform Task Force has 60 days to review the program, informed by a public RFI with responses due August 14, 2026.

Read those two paragraphs together and the practical picture for 2026 is clear: the CMMC Level 2 self-assessment is currently one of only two designatable CMMC postures — and the only Level 2 posture. A contractor pursuing defense work involving CUI doesn’t wait on an assessor backlog anymore; it assesses honestly, submits, affirms, and carries the liability of its own signature. The full same-day analysis of what that shift means — for program offices, primes, and small firms — is in our CMMC Phase 2 suspension breakdown; this guide stays on the evergreen question of what Level 2 is.

Who needs Level 2 — and who only needs Level 1

The level you need is decided by the information your systems handle, not by your size or your ambition:

  • FCI only — information provided by or generated for the government under contract, not intended for public release: Level 1.
  • Any CUI — information requiring safeguarding under law, regulation, or government-wide policy (export-controlled data, controlled technical information, and the rest of the CUI Registry): at least Level 2. “At least,” because select high-sensitivity programs require Level 3 on top of it.
// CMMC Level 1 vs Level 2 at a glance
CMMC Level 1CMMC Level 2
Information protectedFCICUI (and FCI)
Requirements15, from FAR 52.204-21110, from NIST SP 800-171 Rev. 2
AssessmentSelf-assessment, annuallySelf-assessment; C3PAO certification (paused since Jul 13, 2026)
ScoringMET / NOT MET in their entirety — no partial creditPoint-scored against 800-171A objectives (110 max)
POA&MsNot permitted at any time (32 CFR § 170.21(a)(1))Limited — a conditional status with a plan of action is possible
Annual affirmation in SPRSRequiredRequired

Here is the part small contractors consistently miss: Level 1 is your Level 2 foundation. Every one of the 15 Level 1 safeguards has a direct counterpart among the 110 — limit system access, authenticate users, sanitize media, control physical access, protect boundaries, remediate flaws. A firm that has honestly implemented and documented Level 1 has already built the habits, the evidence discipline, and the first tranche of controls that Level 2 demands. If you haven’t locked that floor down yet, run our free CMMC Level 1 self-assessment — it walks the 15 requirements objective by objective and generates the document package — before you spend a dollar on Level 2 gap analysis.

What the July 13 suspension changed — and what still binds

The suspension is covered in depth in the CMMC Phase 2 suspension analysis; here is the Level 2-relevant core, briefly.

Changed: the mandatory Level 2 (C3PAO) certification — Phase II, which was to appear in solicitations from November 10, 2026 — is suspended, along with the later Level 3 milestones. Solicitations already carrying third-party requirements are to be amended. A 60-day review, with an RFI open until August 14, 2026, will determine what comes next; officials did not rule out cancelling the program, and did rule out issuing waivers in the meantime.

Not changed — still fully binding for anyone touching CUI:

  • DFARS 252.204-7012 — implement NIST SP 800-171, report cyber incidents within 72 hours.
  • NIST SP 800-171 Rev. 2 — all 110 requirements, now enforced through self-assessment and government-led assessment.
  • The annual affirmation (32 CFR 170.22) and the CMMC clause itself, DFARS 252.204-7021, which remains prescribed for use until November 9, 2028.
  • The SPRS Basic score — DFARS 252.204-7019/-7020 have required a current NIST SP 800-171 self-assessment score in SPRS since 2020, independent of CMMC.
  • FedRAMP Moderate for CUI in the cloud — DFARS 252.204-7012 requires any cloud service storing, processing, or transmitting covered defense information to meet FedRAMP Moderate, authorized or equivalent. The suspension didn’t touch it.
  • False Claims Act exposure — with the audit paused, self-attestation is the mechanism, and DOJ’s Civil Cyber-Fraud Initiative continues. The paperwork got lighter; the liability did not.

For buyers, that last pair is the whole story: verification shifted from an assessor’s badge to the contractor’s signature — which is why verifying a contractor’s FedRAMP and security claims yourself matters more now, not less.

How to prepare for CMMC Level 2 during the review window

Whether the review restores third-party assessments, restructures them, or ends the program, the 110 requirements survive in every scenario — they predate CMMC and bind through DFARS 7012 regardless. That makes the preparation path robust to the outcome:

  1. Classify your data honestly

    Establish whether you actually handle CUI, or only FCI. This single answer decides whether you need Level 2 at all — and misclassifying in either direction is expensive. Start with what is FCI and your contracts’ markings and clauses.

  2. Lock down Level 1 first

    If FCI is in scope — and it is for essentially every defense contractor — complete a real Level 1 self-assessment before scaling to 110 controls. Level 1 is your Level 2 foundation, and the free CMMC Level 1 self-assessment gets you a documented baseline in an afternoon.

  3. Gap-assess against the 110

    Walk NIST SP 800-171 Rev. 2 requirement by requirement, using the SP 800-171A objectives as the test. Score honestly — the number that goes into SPRS is one you will affirm under signature.

  4. Maintain the system security plan and plan of action

    Level 2 runs on documentation: a current SSP describing your environment and a plan of action for anything not yet implemented. These are also the artifacts any future assessment — self or third-party — will open with.

  5. Fix the cloud question

    If CUI touches cloud infrastructure, that cloud must meet FedRAMP Moderate — authorized or equivalent. This is the requirement that quietly disqualifies otherwise-capable firms, and it is unaffected by the suspension.

  6. Submit, designate, affirm

    Submit your self-assessment results to SPRS, designate your Affirming Official — the senior level representative with the authority to affirm continuing compliance — and put the annual affirmation on the calendar. Under the suspension, this posture is what a contracting officer can actually designate.

Where Truvisory fits — stated plainly

Same disclosure we publish everywhere, because on a compliance topic it’s the only kind worth publishing.

Truvisory is not CMMC-certified, and CMMC certification is not something any contractor can grant — it comes from the program’s own assessment processes. Our documented posture is an active CMMC Level 1 (Self) status — self-assessed against the 15 FAR 52.204-21 requirements (59 NIST SP 800-171A objectives) and recorded in SPRS, CAGE 0HPQ0, UID available to contracting officers and prime partners on request. Level 2, covering the full 110 NIST SP 800-171 requirements, is on our roadmap and not yet self-assessed. We are also FedRAMP-aware, not FedRAMP-authorized — we build on Cloudflare’s government platform, which holds the FedRAMP Moderate authorization that DFARS 7012 requires for CUI in the cloud. No badge wall, no implied certifications; the posture the suspension just made central — honest self-assessment, real controls, verifiable claims — is the one we already held.

If you’re a program office or prime that needs working AI software from a small, security-serious firm — and you’d rather stress-test our claims in 30 minutes than read another compliance deck — book a Capability Briefing from any page of the federal practice.

Frequently asked

What is CMMC Level 2?
CMMC Level 2 is the tier of the Cybersecurity Maturity Model Certification program that protects Controlled Unclassified Information (CUI). It comprises the 110 security requirements of NIST SP 800-171 Rev. 2, verified either by self-assessment or — when that path resumes — by a C3PAO third-party assessment. Contractors whose systems process, store, or transmit CUI need it; FCI-only contractors need Level 1.
What are the CMMC Level 2 requirements?
The 110 security requirements of NIST SP 800-171 Rev. 2, spanning 14 domains — access control, identification and authentication, incident response, system and communications protection, and the rest. They are unchanged by the July 2026 suspension: the requirements stayed; only the third-party verification path was paused.
What's the difference between a CMMC Level 2 self-assessment and a Level 2 (C3PAO) assessment?
The requirements are identical — the same 110 NIST SP 800-171 Rev. 2 controls, assessed against the same NIST SP 800-171A objectives. What differs is who verifies. In a self-assessment, the organization assesses itself, submits results to SPRS, and its Affirming Official affirms compliance. In a Level 2 (C3PAO) assessment, an accredited third-party assessment organization performs the assessment and issues the certification. The C3PAO path is suspended as of July 13, 2026; the self-assessment path is fully active.
Who needs CMMC Level 2 instead of Level 1?
It depends on the information you handle. Federal Contract Information (FCI) only: Level 1, with its 15 FAR 52.204-21 requirements, self-assessed. Controlled Unclassified Information (CUI): at least Level 2, with the full 110 NIST SP 800-171 Rev. 2 requirements. A small set of programs handling the most sensitive CUI require Level 3, which adds 24 requirements from NIST SP 800-172 on top of a completed Level 2.
Is a CMMC Level 2 assessment still required after the suspension?
The self-assessment is. During the suspension, contracting officers may designate only CMMC Level 1 (Self) or Level 2 (Self) — so where a solicitation specifies Level 2, the contractor self-assesses against the 110 requirements, submits results to SPRS, and affirms annually. The third-party (C3PAO) assessment cannot be designated while the review runs.
Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?
Rev. 2, for now. A DFARS class deviation keeps assessments against Rev. 2 until the Department adopts Rev. 3 through future rulemaking, and a proposed government-wide CUI rule published in June 2026 points in the Rev. 3 direction. Build to Rev. 2 today and track the rulemaking — the two revisions overlap heavily, so genuine Rev. 2 implementation is not wasted work.
Are POA&Ms allowed at CMMC Level 2?
In limited form, yes. Level 2 uses a point-scored methodology and permits a conditional status with remaining items on a plan of action. Level 1 is the opposite: all 15 requirements are scored MET or NOT MET in their entirety, and POA&Ms are not permitted at any time (32 CFR § 170.21(a)(1)).
§ Field notes — monthly

One email a month. Not a vendor blog.

// Signing up gets you the AI pilot go/no-go checklist + one field-note a month — no drip, one-click unsub