Great Plains NetworkingGreat Plains NetworkingGet Support

CMMC 2.0 Requirements: What DoD Contractors Must Do Now

Understand the CMMC 2.0 requirements and what DoD contractors must do to secure Controlled Unclassified Information effectively.

13 min readBy Great Plains Networking
CMMC 2.0 Requirements: What DoD Contractors Must Do Now — Great Plains Networking
cmmc 2.0 requirements

CMMC 2.0 Requirements: What DoD Contractors Must Do Now

Hands connecting network cables in server rack
Hands connecting network cables in server rack

If your work touches Controlled Unclassified Information, CMMC 2.0 requires you to fully implement all 110 NIST SP 800-171 Rev. 2 controls at Level 2, and your solicitation, not your preference, decides whether a self-assessment or a third-party C3PAO certification satisfies that requirement.

Your first move this week should be:

  • Pull the actual DFARS clause from your solicitation or prime slowdown to see which level and assessment type apply to you
  • Start (or finish) your System Security Plan and confirm your SPRS entry is current
  • Scope exactly where CUI lives in your network before you assess anything

One number matters more than any other right now: 88 out of 110. That's the minimum score for Conditional Level 2 status, and a false affirmation of a score you haven't earned carries real legal exposure under the False Claims Act.

Key Takeaways

CMMC 2.0 compliance hinges on correctly scoping CUI, fully implementing all 110 NIST SP 800-171 controls, and submitting an honest, documented score to SPRS.

PointDetails
Level determines everythingConfirm whether your solicitation requires Level 1, Level 2 self-assessment, or Level 2 C3PAO certification before doing any other work.
88/110 is the floorConditional Level 2 status requires a minimum score of 88 out of 110, with limited POA&M eligibility for the rest.
SSP is a gate, not paperworkControl CA.L2-3.12.4 requires a current System Security Plan before any assessment can proceed.
POA&Ms close in 180 daysApproved Plan of Action & Milestones items must be remediated and closed within 180 days or Conditional status lapses.
Local help closes the gapGreat Plains Networking offers monitoring, MFA rollout, SSP support, and readiness audits tailored to Oklahoma defense contractors.

Table of Contents

Understanding CMMC 2.0 Requirements Across the Three Levels

CMMC 2.0 sorts contractors by the sensitivity of the data they handle, not by company size or revenue. That single distinction, Federal Contract Information versus Controlled Unclassified Information, decides almost everything downstream: which controls apply, who assesses you, and how often.

Diagram comparing CMMC 2.0 levels and requirements
Diagram comparing CMMC 2.0 levels and requirements

Level 1 covers contractors handling only Federal Contract Information (FCI). It requires 15 basic safeguarding practices and an annual self-attestation. No outside assessor, no SPRS scoring math, just a documented affirmation.

Level 2 applies once CUI enters your environment. It requires full implementation of all 110 requirements in NIST SP 800-171 Rev. 2, the same standard DFARS 252.204-7012 has required contractors to safeguard CUI against for years. Depending on your contract, this level is either a self-assessment or a formal C3PAO certification.

Level 3 is reserved for contractors supporting the most sensitive DoD programs. It layers select NIST SP 800-172 enhanced controls on top of Level 2 and is assessed directly by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a government team, not a commercial assessor.

What Does Level 2 Actually Require Under NIST SP 800-171?

Level 2 is where most contractors handling CUI will live, and it's substantially heavier than Level 1. Assessors verify implementation of 110 security requirements spread across 14 control families, using NIST SP 800-171A as the assessment methodology. That standard breaks the 110 requirements into 320 individual assessment objectives, each one a specific, checkable statement of what "implemented" actually looks like.

A handful of these controls carry outsized weight because they're either high point value or flatly non-deferrable:

  • Multi-factor authentication for privileged and remote access
  • Encryption of CUI at rest and in transit
  • Boundary protection separating CUI systems from the rest of your network
  • Access control tied to least privilege, not blanket admin rights
  • Audit logging sufficient to reconstruct a security incident after the fact

One detail trips up contractors who've been reading outdated guidance: despite talk of a Rev. 3 update, current DoD rulemaking and class deviations still hold assessments to Rev. 2 of NIST SP 800-171. Build your program against Rev. 2 unless your contracting officer tells you otherwise in writing.

Self-Assessment, C3PAO, or DIBCAC: Who Checks Your Work?

The contract, not your comfort level, picks your assessment path. Three routes exist, and they check the identical 110 controls; only the verifier and the paperwork trail differ.

  1. Level 1 self-attestation happens annually, entered directly by an affirming official into SPRS. No outside party reviews it.
  2. Level 2 (Self) lets you assess your own environment against all 110 requirements, but you still submit the score to the Supplier Performance Risk System (SPRS) and affirm it annually, with a full reassessment every three years.
  3. Level 2 (C3PAO) requires an accredited Certified Third-Party Assessment Organization to conduct the assessment and upload results through eMASS into SPRS, with certification valid for three years. Level 3 assessments are performed directly by DIBCAC.

Scoring runs on a 110-point scale, one point per fully met requirement, and Conditional Level 2 status requires a minimum score of 88 out of 110. Not every unmet requirement qualifies for a Plan of Action & Milestones. Only lower-point requirements are POA&M eligible; several high-value items, including the SSP itself, must be fully implemented before assessment, no exceptions. Any approved POA&M items must close out within 180 days under 32 CFR part 170, or your Conditional status lapses.

How Do You Scope and Document Your CMMC Assessment?

Scoping determines what an assessor actually looks at, and getting it wrong either overloads your assessment scope or leaves gaps an assessor will flag immediately. The DoD CIO's CMMC Scoping Guide for Level 2 breaks your environment into five asset categories:

  • CUI assets that process, store, or transmit CUI directly
  • Security protection assets like firewalls and SIEM tools that safeguard the CUI environment
  • Contractor risk-managed assets that could touch CUI but aren't intentionally in scope
  • Specialized assets such as IoT devices or test equipment with unique handling needs
  • Out-of-scope assets genuinely isolated from CUI, with segmentation evidence to prove it

Your System Security Plan has to map every one of these categories, and it needs a network diagram showing how CUI actually moves through your systems. This isn't optional paperwork. Control CA.L2-3.12.4 makes a current SSP a gating requirement, meaning an assessment cannot proceed without one on file.

Pro Tip: Retain every assessment artifact, screenshots, configuration exports, policy documents, for six years. Assessors and DIBCAC audits can request evidence well after your certification date, and a missing artifact months later is far more expensive than saving it now.

Once your assessment concludes, your affirming official submits the score into SPRS and signs the annual affirmation. That signature carries legal weight; affirming a score you can't substantiate is the fastest way to trigger a False Claims Act inquiry.

What Should Contractors Do First to Stay Award-Eligible?

Readiness isn't a single project, it's a sequence, and doing these out of order wastes both time and money.

  1. Read your actual clause. Pull the DFARS language from your solicitation or prime flowdown to confirm your required level and assessment type.
  2. Scope your CUI environment. Identify every asset category before you touch a single control.
  3. Build your SSP and network diagram. This is your assessment gate, not a nice-to-have.
  4. Run a full gap analysis against all 110 controls, not a sample.
  5. Implement controls and document evidence as you go, not retroactively.
  6. Identify only POA&M-eligible gaps. Everything else needs to be fixed before assessment.
  7. Run a mock assessment internally or with outside help to catch what you missed.
  8. Submit your score to SPRS and affirm.

Timelines vary widely by starting point, but contractors with reasonably mature IT environments typically spend three to six months on Level 2 self-assessment prep, and often longer when a C3PAO certification is required, since third-party scheduling adds lead time on top of remediation work. Self-assessment and C3PAO paths require the identical implementation work; the only thing you save by self-assessing is the assessor's fee, not the labor of actually meeting 110 controls.

Pro Tip: Front-load the non-deferrable, high-point controls, MFA, encryption, and your SSP, before spending time on lower-value items. A perfect score on minor controls means nothing if a non-negotiable control isn't done.

Where a Managed IT Partner Fits Into CMMC Readiness

Hands installing network security device
Hands installing network security device

Most small defense contractors don't have a full-time compliance staff, which is exactly where a managed IT partner earns its keep. The work maps almost one-to-one onto the checklist above: continuous monitoring and logging for your audit trail, MFA rollout across privileged accounts, backup and recovery aligned to your incident response plan, SSP drafting support, and structured evidence collection so artifacts don't get lost six months before an assessment.

Great Plains Networking built its model around 24/7 monitoring and same-day response for small businesses in Norman, Moore, and Oklahoma City, several of them defense subcontractors juggling CMMC alongside HIPAA or IRS compliance work.

A readiness audit isn't about selling more services. It's about telling a contractor, in plain language, exactly which of the 110 controls are missing before an assessor does.

If you're evaluating any provider for CMMC work, ask about direct experience with NIST SP 800-171 implementation, documented artifact workflows, response-time SLAs, and references from other defense contractors, not just general IT clients.

Why CMMC 2.0 Simplified the Rules (and Why That's Not the Same as Easier)

The original CMMC 1.0 model, published in 2020, had five levels and required third-party certification at every tier above Level 1. It was expensive, slow to roll out, and drew heavy industry pushback over cost and assessor availability. The DoD suspended it in 2021 for a full rulemaking overhaul.

CMMC 2.0 cut that structure to three levels and realigned Level 2 directly with existing NIST SP 800-171 instead of a custom CMMC-specific standard. That's the single biggest shift: contractors already meeting DFARS 252.204-7012 obligations had a real head start, because Level 2 essentially formalizes verification of a standard many were already supposed to follow.

The second major change was restoring self-assessment as an option for a subset of Level 2 contracts, rather than mandating third-party certification across the board. That reduced cost for lower-risk contracts but didn't lower the bar. You still need all 110 controls implemented; you just might not need a C3PAO to verify them.

The final rule for CMMC published October 15, 2024, with a December 16, 2024 effective date, and Phase 1 self-assessment requirements became enforceable on November 10, 2025. As of 2026, DoD paused further phase rollout expanding C3PAO requirements pending review, but that pause doesn't touch your underlying DFARS and NIST obligations. Contracting officers are already including CMMC clauses in new solicitations, so treating the pause as a reason to wait is a mistake that catches up with contractors at award time.

What Happens After Your CMMC Assessment Is Complete?

Passing an assessment is a milestone, not a finish line. If you scored below 110 but above the 88-point threshold with approved POA&M items, the clock starts immediately: those gaps need remediation and closure within 180 days, verified and documented, or your Conditional status expires.

Beyond POA&M closeout, compliance is ongoing, not a one-time event. Level 2 self-assessments require annual affirmation and a full reassessment every three years; C3PAO certifications run on the same three-year cycle. In between, your environment doesn't stand still: new employees need MFA enrollment, software gets patched, vendors change, and every one of those changes can quietly drift a control out of compliance.

Continuous monitoring closes that gap. Logging and alerting tools that flag configuration drift, unauthorized access attempts, or lapsed patches give you a running record instead of a once-a-year scramble. Platforms like Sentrix's GRC tooling can help automate evidence mapping and control tracking between assessment cycles, which matters most for contractors managing dozens of controls across multiple contracts.

Artifact retention runs six years from the date generated, so your evidence workflow needs to survive staff turnover and system migrations, not just the assessment week. Treat compliance as an operating rhythm: quarterly internal reviews, updated SSPs when your architecture changes, and a standing habit of documenting evidence as you go rather than reconstructing it under deadline pressure before your next reassessment.

The Compliance Gap Nobody Talks About Enough

Most CMMC guidance treats this like a paperwork exercise: fill out the SSP, hit 88 points, submit to SPRS, done. That framing undersells the actual risk. The real gap isn't in contractors who ignore CMMC entirely, it's in contractors who assume Level 1 practices are "close enough" to Level 2, or who self-assess against controls they've misread.

Here's what the conventional checklists gloss over: 32 CFR part 170 and the DFARS rule aren't parallel tracks, they're the same legal machine. The DFARS clause in your contract is what activates the CMMC requirement; 32 CFR part 170 is what defines how that requirement gets verified. Contractors who treat SPRS as a form to fill out, rather than a legal affirmation with False Claims Act exposure behind it, are the ones who get burned.

If I had to prioritize one thing for a contractor starting today, it's this: don't build controls before you scope. Half the rework I see in this space comes from implementing security measures across a network that was never properly bounded, then discovering the CUI touches three more systems than anyone accounted for. Scope first. Everything else gets cheaper and faster once that boundary is honest.

— Nicholas

Get Your CMMC Readiness Assessed Before Your Next Award

Building CMMC readiness alone, on top of running a small defense business, is where most contractors lose momentum. Great Plains Networking gives Oklahoma contractors a local alternative to guessing your way through 110 controls: same-day response, no long-term contracts, and a team that already speaks NIST SP 800-171 fluently instead of translating jargon after the fact.

Greatplainsnetworking
Greatplainsnetworking

That readiness work lines up directly with the checklist above. Great Plains Networking's managed IT support covers the continuous monitoring, logging, and MFA rollout that Level 2 controls demand, while dedicated cybersecurity services handle boundary protection and encryption. For contractors still working out exactly where they stand, start with a straightforward next step: request a readiness audit and get a clear picture of which of the 110 controls need attention before an assessor finds them for you.

Sources

Recommended

Free Network Assessment

Want help putting this into practice?

We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.