← Back to blog

110 Required CMMC Level 2 Controls for Small U.S. Defense Contractors

August 30, 2026
110 Required CMMC Level 2 Controls for Small U.S. Defense Contractors

CMMC Level 2 controls are the 110 security requirements pulled directly from NIST SP 800-171 Rev.2, and your contract language decides whether you self-assess or need third-party C3PAO certification. Either path requires a complete System Security Plan, organized evidence, and an entry in SPRS. Certification, once earned, holds for three years but demands an annual affirmation to stay valid.


TL;DR:

  • Organizations should prioritize completing a detailed System Security Plan, as an incomplete SSP can cause assessment failure regardless of technical controls.
  • Building to C3PAO standards from the start can reduce overall rework and costs, especially with Phase 2 requirements expanding in November 2026.
  • Evidence must be precise and well-organized, including logs, configuration exports, and training records with timestamps, to pass assessment.
  • The minimum score for Conditional status is 88 points out of 110, with all POA&M items closed within six months; certain foundational controls cannot be deferred.
  • Small contractors should focus first on remediating access control and configuration management gaps, while preparing for either self-assessment or third-party certification.

Table of Contents

What Do the CMMC Level 2 Controls Actually Cover?

The 110 requirements come straight from NIST SP 800-171 Revision 2, with no additions or substitutions at Level 2. If you have already mapped your environment to 800-171, you have done the hard part of the CMMC Level 2 assessment guide work already.

Those 110 requirements sort into 14 control families, each targeting a different slice of how Controlled Unclassified Information moves through your systems:

  • Access Control — who can reach CUI and under what conditions
  • Awareness and Training — what staff need to know before they touch sensitive data
  • Audit and Accountability — logging who did what, and when
  • Configuration Management — locking down system baselines
  • Identification and Authentication — verifying users and devices
  • Incident Response — detecting and reporting breaches
  • Maintenance — controlling how systems get serviced
  • Media Protection — securing physical and digital storage
  • Personnel Security — screening and offboarding
  • Physical Protection — controlling facility access
  • Risk Assessment — finding weaknesses before attackers do
  • Security Assessment — testing that controls actually work
  • System and Communications Protection — segmenting and encrypting traffic
  • System and Information Integrity — patching and monitoring for malicious activity

Behind those 110 requirements sit roughly 320 assessment objectives defined in NIST SP 800-171A. Each objective breaks a single requirement into the specific proof an assessor wants to see, which is why your gap analysis needs to work at the objective level, not just the requirement level.

Self-Assessment or C3PAO: Which Path Applies to You?

Your contract decides this, not your preference. DFARS 252.204-7021 and its companion clause 252.204-7025 tell you, inside the solicitation language, whether the government requires Level 2 self-assessment or third-party certification through a Certified Third-Party Assessment Organization.

Self-assessment works like this: your organization evaluates itself against all 110 requirements, a senior official signs the results, and you submit the score into the Supplier Performance Risk System. No outside party checks your work before submission.

C3PAO assessment looks different:

  1. An accredited C3PAO reviews your SSP and evidence independently.
  2. Assessors test your controls against the 320 objectives in NIST SP 800-171A.
  3. Results get logged into the CMMC enclave (often called eMASS) and reflected in SPRS.
  4. DoD contracting officers can view your certification status directly.

Pro Tip: If your contract doesn't specify a path yet, prepare as if C3PAO is coming. Redriver's analysis of the CMMC final rule notes that Phase 2 rollout, expanding third-party requirements across more contracts, takes effect in November 2026, and retrofitting a self-assessment posture into C3PAO readiness later almost always costs more than building to that standard from day one.

Scoring follows a subtractive model: you start at 110 points and lose 1, 3, or 5 points per unmet requirement depending on severity. Conditional CMMC status generally requires a score of at least 88 out of 110, with the rest closed through an approved POA&M.

Diagram of CMMC Level 2 scoring and POA&M role

How Do You Prepare for a Level 2 Assessment?

Your System Security Plan is the document assessors read first, and if it is incomplete, the assessment can fail regardless of how strong your actual technical controls are. The SSP has to define your CUI system boundary clearly and describe, requirement by requirement, exactly how you implement each of the 110 controls.

Gap analysis means testing your environment against all 320 assessment objectives, not just the 110 headline requirements. Two organizations can both claim they meet an access control requirement, but only one can produce the evidence an assessor will accept.

Evidence that typically holds up:

  • Firewall and router configuration exports
  • Access control lists and account provisioning logs
  • Security awareness training records with sign-off dates
  • Incident response plans with documented tabletop exercises
  • Patch management logs showing remediation timelines
  • Multi-factor authentication configuration screenshots

Pro Tip: Run a mock assessment before the real one. Walk through each control family as an outside assessor would, and build a folder structure that mirrors the 14 families so nothing gets buried when someone asks for proof on the spot.

What Can (and Cannot) Go on a POA&M?

Plans of Action and Milestones let you defer certain unmet requirements while still qualifying for Conditional status, but the allowance is narrow. The only encryption-related flexibility involves SC.L2-3.13.11, and even that is a limited exception, not a blanket pass on cryptographic protections.

Six control areas cannot go on a POA&M under any circumstances, because DoD guidance treats them as foundational to everything else in the assessment:

  • Having a complete System Security Plan in place
  • Basic access control enforcement (AC-related baseline items)
  • Specified physical protection (PE) requirements
  • Specified security assessment and authorization (CA) items
  • Core identification and authentication safeguards
  • Foundational configuration management baselines

Miss any of these, and Conditional status is off the table entirely. If you do earn Conditional status with an approved POA&M elsewhere, you have 180 days to close every open item. Miss that window, and your certification lapses.

How Long and How Much Does Level 2 Readiness Cost?

Straightforward environments (a single office, modest IT footprint, few third-party integrations) can reach readiness in three to six months. Contractors with multiple sites, legacy systems, or a tangle of CUI-touching vendors should plan for nine to eighteen months.

By the numbers: Conditional status requires a minimum score of 88 out of 110 points under the subtractive scoring model, and any approved POA&M items must close within six months.

C3PAO assessments carry real cost, scoped to system complexity and scheduling demand, and self-assessment carries internal labor cost even without an assessor's invoice. Building to C3PAO standards from the outset tends to reduce total rework compared with patching a self-assessment posture later, once a prime contractor or new solicitation demands third-party proof.

Your 90/180/360-Day Level 2 Action Plan

A phased plan beats a scramble every time. Here's a sequence that works for most small contractors:

  1. Days 1 to 90 (IT lead + compliance owner): Scope your CUI boundary, complete a full gap analysis against all 320 objectives, and draft the SSP skeleton.
  2. Days 91 to 180 (IT lead + department managers): Remediate the highest point-value gaps first, deploy MFA and endpoint protection where missing, and start collecting evidence in a standardized folder structure.
  3. Days 181 to 270 (compliance owner + senior official): Run a mock assessment, close remaining POA&M-eligible gaps, and finalize the SSP for internal sign-off.
  4. Days 271 to 360 (senior official): Submit self-assessment scores to SPRS, or schedule and complete your C3PAO assessment, then file the annual affirmation.

Focus remediation dollars on access control and configuration management first. Those two families touch the most assessment objectives, so progress there moves your score faster than isolated fixes elsewhere. Keep evidence organized by control family with dated file names. Retain records for the full three-year certification cycle at minimum.

Practitioner Notes on Evidence and Common Missteps

Michael has spent years helping small manufacturers and aerospace suppliers at Symmetry Network Management untangle CMMC preparation, and the pattern repeats: companies build technical controls but never document them consistently. Small contractors often assume a firewall rule or a training slide deck is "enough" evidence. It usually isn't without a timestamp and a clear link back to the specific requirement it satisfies.

Hands labeling firewall hardware port

Name evidence files by control number, not by vague descriptions. "3.1.1_AccessControlList_2026-03.pdf" survives a C3PAO review far better than "IT_stuff_folder3."

The Uncomfortable Truth About Level 2 Readiness

Most guidance on this topic treats self-assessment and C3PAO certification as two equally valid endpoints, and technically they are. But that framing hides a real risk: an honest self-assessment that documents its own gaps will survive scrutiny far better than an optimistic score built to look good on paper. The two paths test the same 110 requirements. Only one has an outside party checking your math.

The conventional advice, "figure out which path your contract requires, then prepare for that one," is backwards for most small contractors. Solicitation language changes between contract cycles, and Phase 2 expansion means more contracts will require C3PAO over time, not fewer. Building to self-assessment minimums now just means rebuilding later under time pressure.

What the reader should prioritize first isn't a specific control. It's the SSP. An incomplete plan derails an assessment regardless of how solid your technical environment is, and it's the one artifact every path requires on day one. Get that document right before chasing individual control fixes.

— Michael

Get a Free CMMC Readiness Assessment from Symmetry Network Management

Reaching 88 points on your own, while running a manufacturing floor or an engineering shop, is a lot to carry alone. Symmnet built its managed IT and cybersecurity services specifically for small aerospace, manufacturing, and professional services firms navigating exactly this kind of federal requirement, without the overhead of hiring a full internal compliance team.

Symmnet

That means SSP development support, 24/7 monitoring, endpoint security, network segmentation mapped to your CUI boundary, and organized evidence collection built around the 14 control families from the start. Symmnet's free assessment identifies exactly which of the 110 requirements you already meet, which ones need work, and which POA&M items carry the tightest deadlines, so you walk away with a prioritized plan instead of a generic checklist.

Request the free CMMC readiness assessment and find out where your organization actually stands before your next contract renewal forces the question.

Sources