Compliance / CMMC Level 2
CMMC Level 2 is 110 controls, verified by someone who doesn't work for you.
If your contract carries CUI, Level 2 is almost certainly your bar. It takes the 110 NIST 800-171 controls, breaks them into 320 assessment objectives, and has an independent C3PAO check every one.
Level 2 at a glance
110
Controls, from NIST 800-171 Rev 2
320
Assessment objectives checked
14
Control families in scope
3yr
Certification, with annual affirmation
Most CUI programs require a C3PAO assessment; some Level 2 scopes permit self-assessment. Source: 32 CFR Part 170; CMMC L2 Assessment Guide v2.13.
What's in scope
The fourteen control families.
AC
Access Control
22 controls
AT Awareness & Training
3 controls
AU Audit & Accountability
9 controls
CM Configuration Management
9 controls
IA Identification & Authentication
11 controls
IR Incident Response
3 controls
MA Maintenance
6 controls
MP Media Protection
9 controls
PS Personnel Security
2 controls
PE Physical Protection
6 controls
RA Risk Assessment
3 controls
CA Security Assessment
4 controls
SC System & Communications Protection
16 controls
SI System & Information Integrity
7 controls
= 110
controls total
The 110 controls expand into 320 assessment objectives each checked by an independent C3PAO
Getting there
The path from clause to certificate is a known quantity.
Scope the CUI, implement the 110 controls, document them in an SSP, post your SPRS score, then sit the C3PAO assessment. We walk the whole thing with you — Enclave builds it, Cadence keeps it real, Attest gets you to the door.
See the full certification path →Have a Level 2 assessment date?
A readiness check maps your current state to all 110 controls and tells you what's left.