CMMC Level 2 Requirements: 110 Controls, POA&M Rules, and the Path to Certification
CMMC Level 2 requires implementing all 110 security requirements of NIST SP 800-171 Revision 2 everywhere Controlled Unclassified Information is stored, processed, or transmitted, and proving it against roughly 320 assessment objectives from NIST SP 800-171A. Verification takes one of two forms depending on the contract: a self-assessment posted in SPRS, or a certification assessment performed by a C3PAO, a CMMC Third Party Assessment Organization. Every requirement scores MET or NOT MET, with no partial credit. Meet all 110 and you earn final status, valid for three years with annual affirmations. Score at least 88 with every gap on an eligible POA&M and you earn conditional status with 180 days to close. Below that line, there is no status to post. If you handle Federal Contract Information only and no CUI, you need the much smaller Level 1 requirement set instead.
The 110 requirements, by family
NIST SP 800-171 organizes the 110 requirements into 14 families, sized very unevenly. Access Control is the largest at 22 requirements, covering least privilege, remote access, control of CUI flow, and portable storage. System and Communications Protection carries 16, including boundary defense and the FIPS validated cryptography requirement that fails more assessments than any other single control. Identification and Authentication holds 11, among them multifactor authentication, the heaviest requirement in the scoring methodology. Audit and Accountability, Configuration Management, and Media Protection have 9 each. System and Information Integrity has 7; Maintenance and Physical Protection have 6 each; Security Assessment has 4, including the System Security Plan requirement the entire assessment depends on. The small families still bite: Awareness and Training and Incident Response and Risk Assessment carry 3 each, and Personnel Security carries 2. An operational incident response capability is a three-requirement family that sinks assessments out of proportion to its size.
Every requirement applies to every asset inside the assessment boundary. That is why scoping is the first decision of the program rather than a detail: an environment where CUI is contained in an enclave carries the same 110 requirements across far fewer systems, and the checklist of which specific requirements assessors fail most often is a separate exercise from knowing the families.
Two categories of outside party come into scope with you. Cloud services that store, process, or transmit CUI need FedRAMP Moderate authorization or documented equivalency, which is why so many Level 2 programs move email and files into a government cloud tenant rather than defending a commercial one. Managed service providers no longer need their own CMMC certification under the final rule, but the services they run for you get assessed as part of your assessment, which means a written responsibility matrix stating who performs which control, and an MSP contract that obligates them to sit for interviews and produce evidence. Sorting both out early is far cheaper than renegotiating a vendor relationship with an assessment already scheduled.
Self-assessment or C3PAO certification
Which verification path applies is written into each contract. Level 2 self-assessment status comes from assessing your own environment against all 110 requirements, posting the result in SPRS, and having a senior official affirm it annually. Level 2 certification status requires a C3PAO to perform the assessment: one to two weeks of document review, interviews, live demonstration, and sampling, followed by the C3PAO's internal quality review and a status posted in SPRS. DoD has been clear that most contracts involving CUI are expected to require certification rather than self-assessment once the rollout completes.
As of August 2026, the rollout calendar sits in review. Phase 1, in force since November 10, 2025, puts self-assessment requirements into new contracts. Phase 2, which was scheduled to introduce C3PAO certification requirements in new solicitations from November 10, 2026, was suspended on July 13, 2026 pending a DoD program review. Self-assessment obligations remain fully in force, DFARS 252.204-7012 and its NIST SP 800-171 implementation requirement never paused, and primes continue to ask subcontractors about certification readiness because their own eligibility depends on the answer. The defensible posture is to keep preparing while the calendar sorts itself out, since the requirements themselves did not move.
The POA&M rules, precisely
The POA&M allowance at Level 2 is narrower than most teams assume, and it is spelled out in 32 CFR 170.21. Three conditions gate conditional status. First, the assessment score must be at least 88 of 110 under the DoD scoring methodology, which starts at 110 and deducts 5, 3, or 1 points for each unmet requirement. Second, only requirements worth 1 point may sit on the POA&M, with a single exception: SC.L2-3.13.11, FIPS validated cryptography, may be deferred at its 3 point weight when encryption is actually deployed and only the FIPS validation is missing. Every 5 point requirement, multifactor authentication and incident response capability among them, must be MET on assessment day. Third, six named requirements can never be deferred regardless of weight: control of connections to external systems (3.1.20), control of information posted on public systems (3.1.22), the System Security Plan itself (3.12.4), and the three physical access requirements covering visitor escort, access logs, and physical access devices (3.10.3, 3.10.4, and 3.10.5).
Meet those conditions and the result is conditional status, posted in SPRS and usable for eligibility, with a fixed 180 day clock attached. Close every POA&M item inside the window and pass the closeout assessment, performed by the C3PAO on the certification path or internally on the self-assessment path, and conditional converts to final. Miss the window and the conditional status expires, which means a full assessment again at full price. The practical reading: the POA&M is a short, funded punch list of administrative one-pointers with named owners, and anything heavier gets fixed before the assessment, because it has to be.
Scoring and SPRS
Behind the MET and NOT MET results sits the score that contracting officers and primes actually read. The methodology starts at 110 and subtracts weighted deductions, so a company missing twenty of the wrong requirements can sit below zero. Under DFARS 252.204-7019 a current score must be posted in SPRS before award on contracts involving covered defense information, and under CMMC the eventual assessed score lands in the same system next to your self-reported one, where the two get compared. An inflated self-score followed by an honest assessment is a documented overstatement with your affirmation history attached. How the weights work, what a given number signals, and the fastest legitimate ways to raise it are covered in SPRS scores explained.
The SSP the assessment runs on
The System Security Plan is a scored requirement, ineligible for any POA&M, and the first document a C3PAO reads. It needs to state, for each of the 110 requirements, how the control is implemented, on which systems, and who owns it, in the present tense. An SSP that restates requirements in the future tense describes a plan, and plans score NOT MET. An SSP that contradicts what an interview reveals is worse, because the mismatch itself tells the assessment team to probe everything harder. Structure, common failures, and what assessors expect from the document are in our SSP guide.
From gap assessment to assessment-ready
For a contractor starting from ordinary commercial IT, the realistic path to assessment readiness runs 6 to 12 months. Scoping and boundary design take the first two to six weeks and decide the cost of everything after. A gap assessment against all 110 requirements and their objectives takes another four to eight weeks and produces the SSP baseline, the POA&M, and a defensible score. Remediation is the long middle, three to nine months depending on the gap, with identity, cryptography, and logging as the usual pacing items. Then the controls need to run: assessors sample tickets, log reviews, access recertifications, and training records, so a quarter of operating history before assessment day is a sensible floor. A mock assessment at the end, run the way a C3PAO samples and interviews, is the cheapest place to find the problems that would otherwise surface with the clock running.
Who prepares, and who certifies
The certification assessment is performed by a C3PAO, and the program's conflict of interest rules keep assessors from consulting for the companies they assess. BD Emerson is not a C3PAO and does not certify anyone. We do the preparation side: scoping and enclave design, gap assessment, remediation, SSP development, POA&M management, and mock assessment through our CMMC consulting practice. The separation works in your favor, because a readiness firm with no stake in the scoring can tell you exactly which requirements would fail today and what closing them costs. The assessor decides the outcome. The preparation decides what there is to assess.

