What is CMMC Level 2?

Short answer

CMMC Level 2 is the Department of Defense cybersecurity tier for contractors that handle Controlled Unclassified Information (CUI). It requires the 110 security requirements of NIST SP 800-171 Revision 2, verified by self-assessment or by an authorized third-party assessor (C3PAO). Since a July 13, 2026 memo suspended Phase 2, new DoD solicitations may only call for the self-assessment version.

Who needs Level 2

CMMC has three levels. Level 1 covers Federal Contract Information (FCI) only. Level 2 applies when your company processes, stores or transmits CUI, such as controlled technical drawings, specifications or other information the DoD marks or identifies in your contract. Level 3 adds enhanced requirements for a small set of high-priority programs.

Most manufacturers, machine shops, engineering firms and subcontractors in the defense supply chain that touch technical data land at Level 2.

What Level 2 actually requires

The 32 CFR Part 170 rule, effective December 16, 2024, ties Level 2 to NIST SP 800-171 Revision 2 and its 110 security requirements. NIST withdrew Rev 2 in favor of Rev 3 in May 2024, but the CMMC rule states that Rev 3 is not currently applicable, and the July 2026 suspension memo restates that Level 2 is aligned with Rev 2.

You must document a System Security Plan (SSP), score yourself using the DoD methodology, post results in the Supplier Performance Risk System (SPRS), and have a senior official affirm compliance.

  • Assessment validity: three years, with an affirmation every year.
  • Conditional status is possible with a score of at least 80 percent (88 of 110 points) and a POA&M limited to lower-weighted items.
  • Open POA&M items must be closed within 180 days of conditional status.
  • Some requirements, including the System Security Plan itself, can never be placed on a POA&M.

Self-assessment vs. C3PAO, and where the rollout stands

The DFARS rule implementing CMMC in contracts took effect November 10, 2025, starting Phase 1, which uses self-assessments. Under the original schedule, Phase 2 would have begun requiring C3PAO certification assessments on November 10, 2026.

On July 13, 2026 the Department of War suspended the Phase 2 transition and started a 60-day program review. Program offices may now designate only Level 1 (Self) or Level 2 (Self), and existing C3PAO or Level 3 requirements are being removed from solicitations and contracts. DFARS Class Deviation 2026-O0025 carries this into contracting rules. DFARS 252.204-7012 and the NIST SP 800-171 Rev 2 baseline remain in effect.

What this means for your company

The suspension changes how compliance is verified, not what you must protect. Your SPRS score is affirmed by a senior official, and DoD keeps the ability to run government-led assessments. Treat Level 2 as a live obligation: finish your SSP, close gaps, and keep evidence ready so you can move quickly when the review concludes and third-party certification returns in whatever form DoD decides.

Common follow-up questions

Is CMMC Level 2 the same as NIST SP 800-171?

Level 2 uses the 110 requirements of NIST SP 800-171 Revision 2, but CMMC adds the assessment, scoring, SPRS posting, annual affirmation and POA&M rules defined in 32 CFR Part 170. Meeting 800-171 is the substance; CMMC is how DoD verifies it.

Does CMMC Level 2 use NIST SP 800-171 Rev 3?

No. The CMMC rule specifies Revision 2 and states that Revision 3 is not currently applicable. The July 2026 Phase 2 suspension memo again describes Level 2 as aligned with NIST SP 800-171 Rev 2.

Do I still need Level 2 while Phase 2 is suspended?

If your contracts involve CUI, yes. Level 2 self-assessments and DFARS 252.204-7012 remain in force. Only the requirement for third-party C3PAO certification in new solicitations has been suspended pending the Department of War review.

Need help with this?

LAN Service Group runs CMMC and NIST SP 800-171 programs led by a certified Information System Security Officer (ISSO), covering readiness, SSP and POA&M development, remediation and assessment preparation.

Talk to LAN Service Group (888) 281-7243

Sources