GovCon Cybersecurity | | 26 min read
CMMC Level 2 Compliance: 110 Controls and the Evidence That Proves Them
Key Takeaways
CMMC Level 2 compliance is an operating system, not 110 separate documents.
Protect one defensible boundary
CUI flows and asset categories decide where the 110 requirements must operate and what the assessor can examine.
Make each claim testable
Every requirement needs an owner, a mechanism, an operating frequency, an exception path, and records.
Prepare for three methods
A strong record can be examined, explained by the operator, and connected to a working technical or procedural mechanism.
Keep preparing
Phase II timing changed in July 2026. DFARS duties, NIST preparation, scope, and evidence work did not disappear.
CMMC Level 2 compliance is not 110 documents. It is 110 security requirements operating across one defensible CUI boundary.
The paperwork matters because it records the claim. The control matters because it protects the information. The evidence matters because an assessor must be able to examine the record, interview the operator, and test the mechanism. Miss any one of those layers and a polished binder will not rescue the result.
There is also a current timing issue that older CMMC checklists miss. On July 13, 2026, the Department of Defense suspended Phase II CMMC requirements pending further review. Phase I self assessment requirements remain. That pause changes when some contracts will demand Level 2 certification status. It does not erase existing DFARS duties, the NIST baseline, current contract clauses, or the need to know where CUI moves.
Use this walkthrough with the CMMC resource hub, the complete CMMC compliance guide, and our NIST SSP guide.
CMMC Level 2 Timing Changed in July 2026
The current Department of Defense CMMC resources page says Phase II requirements were suspended effective July 13, 2026, pending further review. It also says Phase I self assessment requirements remain in place. This is the operating fact as of July 25, 2026.
Do not turn a program pause into a security pause. DFARS 252.204-7012 can still require adequate security, incident reporting, evidence preservation, and specific external cloud conditions. DFARS 252.204-7019 and 252.204-7020 can still require a current NIST SP 800-171 assessment and SPRS score. Solicitation and contract language still governs the work in front of you.
The practical response is simple. Separate the certification date from the control program. Track current CMMC timing through official sources. Continue boundary, implementation, SSP, evidence, supplier, and remediation work against the requirements that already apply. If the contract changes, you will be ready to respond from a known state rather than restarting discovery.
What CMMC Level 2 Actually Requires
CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. They are organized across 14 families. The requirements cover access, awareness, audit, configuration, identification, incident response, maintenance, media, personnel, physical protection, risk, assessment, communications, and information integrity.
Access Control is the largest family with 22 requirements. System and Communications Protection has 16. Identification and Authentication has 11. Audit and Accountability, Configuration Management, and Media Protection each have nine. System and Information Integrity has seven. Maintenance and Physical Protection each have six. Security Assessment has four. Awareness and Training, Incident Response, and Risk Assessment each have three. Personnel Security has two.
That count does not equal effort. One requirement can reach every endpoint, identity, network path, administrator, and provider in the scope. Another may be narrow and procedural. The Level 2 assessment guide also breaks requirements into assessment objectives. A requirement is satisfied only when every applicable objective is met.
Start by reading the requirement, not a product checklist. Then write an implementation statement that names the scoped assets, responsible role, mechanism, operating event or frequency, evidence, and exception path. A tool can support a mechanism. It cannot decide the scope, own the procedure, explain the exception, or accept the risk.
Original Research: The GS Evidence Friction Index
GS Consulting built the CMMC Level 2 Evidence Friction Index to answer an operator question: which families create the most combined implementation and proof pressure? We counted the 110 public requirements by family, then scored system reach, live test demand, and recurring evidence demand on documented one to five planning scales.
The base formula assigns 30 percent to normalized requirement count, 25 percent to system reach, 25 percent to live test demand, and 20 percent to recurring evidence. The sensitivity case moves five points from count to system reach. These are planning weights, not official CMMC weights. The model sequences work. It does not grade compliance.
Access Control scores 100.0. System and Communications Protection follows at 91.8. Identification and Authentication scores 85.0. Audit and Accountability and Configuration Management both score 82.3. System and Information Integrity scores 79.5. Those six families form the heavy technical and evidence foundation.
The sensitivity case keeps the same foundation. System and Communications Protection rises to 93.2, Identification and Authentication to 87.5, and the two 82.3 families to 85.2. No family jumps from the bottom into the foundation. That stability supports a practical decision: resolve identity, access, network protection, configuration, logging, and flaw response early because later evidence depends on them.
The lower scores do not mean optional. Personnel Security scores 39.7 because it has two requirements and narrower system reach, not because it can fail. Every applicable objective still matters. The index tells a program manager where shared mechanisms and evidence pipelines deserve early attention.
A Control Must Survive Examine, Interview, and Test
The CMMC assessment guide uses three methods from NIST SP 800-171A: examine, interview, and test. Examine reviews documents, records, configurations, diagrams, logs, and other artifacts. Interview checks whether responsible people understand and perform the stated work. Test checks the mechanism or activity under selected conditions.
Build the claim and the proof together. If the requirement calls for disabling inactive accounts, define who decides the inactivity period, how the system identifies accounts, who reviews exceptions, what action runs, and what record is retained. Then make sure the operator can explain the process and the assessor can test a sample.
Do not confuse a screenshot with operating evidence. A screenshot may prove a setting existed at one moment. It may not prove the setting covered every scoped asset, stayed active across the period, generated the required alerts, or received review. Use configurations for state, reports and logs for operation, tickets for action, and approvals for accountable decisions.
Keep evidence close enough to the source that it stays reliable, but indexed well enough that a reviewer can retrieve it. Record the source system, owner, collection method, covered period, retention rule, integrity protection, and last review date. That metadata turns a file into evidence.
The Five Asset Categories Define the Assessment Boundary
Current Level 2 scoping guidance distinguishes CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out of scope assets. Classification changes how an asset is documented, treated, and assessed. It does not come from where the asset appears on an organization chart.
CUI assets process, store, or transmit controlled information. Security protection assets provide security functions for the assessed environment. Contractor risk managed assets are capable of CUI use but are kept outside that use by policy and practice. Specialized assets can include operational technology, Internet of Things devices, restricted systems, and test equipment. Out of scope assets cannot process, store, or transmit CUI and do not provide security protection for the boundary.
The fastest route to a bad scope is to start with a network diagram and guess. Start with the contract and information types. Build a CUI data flow map from entry through storage, processing, sharing, backup, and exit. Reconcile the flow to the asset inventory, identity paths, administration tools, logging services, remote access, and external providers.
Document why each asset category is correct. For anything claimed out of scope, show the technical and procedural conditions that prevent CUI use and security protection duties. If the boundary depends on a rule that nobody monitors, the boundary is only a diagram.
A Practical CMMC Level 2 Implementation Sequence
Do not assign 110 rows to 14 policy owners and wait. Build the shared foundations first, then complete requirement detail against them.
- Confirm authority and information. Read the solicitation, award, DFARS clauses, flowdowns, CUI categories, and current CMMC timing. Record the controlling baseline and required status.
- Define the boundary. Complete the CUI flow, asset categories, inventory, connections, users, providers, and administration paths.
- Stabilize identity and access. Establish identity sources, roles, approval, privileged access, remote access, multifactor authentication, session control, and review records.
- Stabilize platforms and networks. Set configuration baselines, change control, segmentation, communications protection, flaw response, malware protection, and monitoring.
- Write the SSP and control matrix. Connect every requirement to scope, owner, mechanism, evidence, exception, and provider responsibility.
- Run an internal assessment. Apply the official objectives and selected examine, interview, and test methods. Record facts, not optimistic percentages.
- Close gaps and rehearse proof. Remediate allowed gaps, verify completion, refresh evidence, and have operators demonstrate selected controls without scripts.
Use a requirement matrix as the working spine. One row should identify the requirement, assessment objectives, scoped implementation, responsible owner, supporting services, evidence sources, last test, result, and approved remediation. That matrix should point into the SSP and evidence repository. It should not become a second SSP with conflicting prose.
The Minimum CMMC Level 2 Evidence Packet
A readiness review needs enough material to reconstruct the boundary, the implementation claim, and the operating record. Eight items form a practical minimum.
The CUI flow and asset inventory establish scope. The SSP and control matrix establish the claim. Operating evidence shows the mechanisms ran. The internal assessment record shows what was examined, who was interviewed, what was tested, and what failed. The plan of action records allowed gaps and closure proof. The affirmation record identifies the accountable official and the represented status.
Add supplier and cloud records where responsibility crosses the boundary. Keep contracts, service descriptions, responsibility matrices, relevant assessment packages, customer configurations, incident duties, support paths, and evidence delivery terms. A provider certification can support inherited controls. It does not prove the contractor configured identities, endpoints, sharing, retention, or monitoring correctly.
Protect the evidence package. It can expose system structure, accounts, security settings, weaknesses, and remediation. Apply access control, version control, retention, integrity protection, and secure transfer. Limit duplicate exports because uncontrolled copies become both a security risk and a review problem.
Seven CMMC Level 2 Failures That Repeat
- The scope starts with tools. The team buys an enclave before tracing the contract data and later discovers unsupported workflows, providers, or administrative paths.
- The SSP repeats requirements. The prose says what should happen but does not name the mechanism, owner, scope, evidence, or exception.
- The inventory and diagram disagree. Assets, names, connections, and categories differ across records, so the assessor cannot trust the boundary.
- Evidence is a collection of screenshots. The package shows configuration moments but not recurring operation, review, response, or covered periods.
- Operators depend on one author. The consultant or compliance lead can explain the control, but the person who runs it cannot.
- Provider responsibility is vague. The SSP says a cloud service handles the control without naming the inherited part and the customer part.
- The SPRS score leads the program. A number becomes the goal while scope errors, weak evidence, and incomplete objectives remain hidden.
Run a fact based internal assessment before any external review. Sample evidence across time. Interview the actual operators. Test mechanisms in the scoped environment. Record unmet objectives individually so a remediation owner knows what must change and what proof will close the finding.
Research Sources and Caveats
The GS CMMC Level 2 Evidence Friction Index is a GS Consulting derived planning tool based on cited public sources and documented analyst assumptions. It is not an official legal, audit, compliance, NIST, CMMC, Department of Defense, FedRAMP, or regulatory determination. Scores sequence implementation and evidence work. They do not measure compliance or predict an assessment result.
The model uses NIST SP 800-171 Revision 2 because the current CMMC Level 2 assessment guide maps to its 110 requirements. Program timing and contract obligations can change. Confirm the current rule, official guidance, solicitation, award, clauses, and flowdowns for the system being assessed.
- Department of Defense: CMMC resources and current implementation notice
- Department of Defense: CMMC Assessment Guide Level 2
- Department of Defense: CMMC Scoping Guide Level 2
- NIST SP 800-171 Revision 2
- NIST SP 800-171A
- DFARS 252.204-7012
- DFARS 252.204-7020
- 32 CFR Part 170
Frequently Asked Questions About CMMC Level 2 Compliance
What is required for CMMC Level 2 compliance?
CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. A contractor must define the assessment scope, operate each applicable requirement across that scope, maintain an accurate system security plan, and produce adequate evidence for the applicable assessment methods. Contract clauses and current program timing still determine when a particular assessment status is required.
How many controls are in CMMC Level 2?
CMMC Level 2 contains 110 security requirements across 14 NIST families. People often call them controls, but the official NIST publication calls them requirements. Assessment objectives in NIST SP 800-171A break those requirements into more granular determinations.
Is CMMC Phase II active in July 2026?
No. The Department of Defense CMMC resources page states that Phase II requirements were suspended on July 13, 2026, pending further review. Phase I self assessment requirements remain in place. Contractors should confirm current solicitation and contract language because this program timing does not remove existing DFARS or NIST duties.
Does a perfect SPRS score prove CMMC Level 2 compliance?
No. An SPRS score is a required representation under applicable DFARS clauses, but a score does not replace assessment scope, implementation evidence, interviews, tests, or the required CMMC status when a contract specifies one.
Can a contractor keep some CMMC Level 2 gaps on a plan of action?
Only within the limits of the governing CMMC rule and contract. Some requirements cannot be left open for a conditional status, and allowed items have score and closure constraints. Treat a plan of action as a controlled exception with an owner, resources, milestones, and completion evidence, not as a permanent substitute for implementation.
Related Reading
- CMMC Resource Hub
- CMMC Compliance: The Complete Guide
- CMMC Levels and Assessment Paths
- NIST SSP Guide
- How to Build a CUI Data Flow Map
- FedRAMP vs CMMC vs NIST 800-171
- Secure AI Automation for Regulated Organizations
Make the control story match the operating facts.
GS Consulting helps defense contractors define the CUI boundary, repair the shared control foundation, and build evidence that operators can explain and assessors can test.
Request a CMMC Level 2 Readiness Review