What is CMMC Level 2?
CMMC Level 2 is the Cybersecurity Maturity Model Certification level for defense contractors that handle Controlled Unclassified Information; it requires implementing the 110 security requirements in NIST SP 800-171 Revision 2.
CMMC is the Department of Defense’s program for verifying that contractors actually do what DFARS 252.204-7012 has required for years. The program rule is codified at 32 CFR Part 170; the contract clause that puts it into solicitations is DFARS 252.204-7021. The authoritative source for current details is the DoD CIO CMMC site.
Do we need CMMC Level 1 or Level 2?
If you only handle Federal Contract Information (FCI), you likely need Level 1; if you handle Controlled Unclassified Information (CUI), you need Level 2. The solicitation states the required level.
Level 1 covers 15 basic safeguarding requirements from FAR 52.204-21 and is satisfied with an annual self-assessment. Level 2 is a large step up. Level 3 applies to a small number of programs facing advanced threats and is assessed by the government.
If you are unsure whether you hold CUI, look for CUI markings on the documents you receive, check your contracts for DFARS 252.204-7012, and ask your prime. Guessing low is a common and expensive mistake.
Can we self-assess for CMMC Level 2, or do we need a C3PAO?
It depends on the contract: some Level 2 requirements allow a self-assessment, but most contracts involving CUI are expected to require a certification assessment by an authorized third party (a C3PAO), repeated every three years.
Either way, the bar is the same 110 requirements. A self-assessment is not an easier standard — it is a different assessor, and an affirmation by a senior company official that carries legal weight under the False Claims Act if it is wrong.
A consultant who helps you prepare cannot also be your C3PAO assessor. We get clients ready and support them through the assessment; certification itself comes from an accredited C3PAO.
When does CMMC become required in contracts?
The DFARS rule took effect on November 10, 2025, starting a four-phase rollout: self-assessment requirements first, Level 2 C3PAO requirements from November 10, 2026, and full implementation across applicable contracts by November 2028.
During the rollout, contracting officers can include CMMC requirements earlier than the phase schedule requires, and primes often flow requirements down to subcontractors ahead of the government’s own timeline. Check the current schedule on the DoD CIO site and, more importantly, ask your primes what they will require of you and when.
What is an SPRS score?
An SPRS score is the result of a NIST SP 800-171 self-assessment using the DoD Assessment Methodology, reported in the Supplier Performance Risk System; it ranges from −203 to 110, where 110 means every requirement is met.
DFARS 252.204-7019 and -7020 already require contractors handling CUI to post a current score. Primes and contracting officers look at it. A low but honest score with a credible plan is far better than a high score you cannot defend.
Can we pass CMMC Level 2 with open gaps (a POA&M)?
Only limited ones: you need at least 80% of the assessment score, certain high-value requirements cannot be left open, and every open item must be closed within 180 days to keep the resulting conditional status.
In practice that means a POA&M is a small bridge for minor gaps, not a strategy. Plan to be substantially complete before the assessment.
How can a small company reduce the cost of CMMC Level 2?
Shrink the scope: keep CUI in a clearly defined enclave — a subset of users, devices, and cloud services — so only that environment has to meet all 110 requirements.
Many small contractors handle CUI in a handful of workflows used by a handful of people. Putting those workflows in a dedicated, properly configured environment (for example, a government-cloud tenant for email and files) can be much cheaper than bringing the entire company up to Level 2. The trade-off is discipline: CUI has to stay inside the enclave, and that has to be enforced, not hoped for.
How long does CMMC Level 2 readiness take?
For a small company starting from little formal security, readiness commonly takes several months to a year; a company already following NIST SP 800-171 may need only a gap assessment and targeted fixes.
The work is usually: confirm where CUI lives and set the scope; run a gap assessment against all 110 requirements; remediate (identity, MFA, logging, configuration management, and incident response are frequent gaps); write the System Security Plan; and gather evidence an assessor will accept. Our Zero Trust rollout plan covers much of the identity groundwork.
We support CMMC readiness for contractors across the Triangle and Northern Virginia. A short scoping call is the fastest way to find out where you stand.
Part of the Llab Technologies Insights series. This article is general guidance, not legal advice; confirm requirements against your contract and current DoD guidance.