The intermediate certification tier under CMMC 2.0, required for most defense contractors and subcontractors that handle Controlled Unclassified Information (CUI). Level 2 aligns directly with the 110 security requirements outlined in NIST SP 800-171, covering areas such as access control, incident response, audit logging, configuration management, and encryption.

This level represents a significant step up from Level 1 (Foundational), which only requires 15 basic safeguards for Federal Contract Information (FCI). At Level 2, organizations must demonstrate that their cybersecurity program can adequately protect sensitive data flowing through the Defense Industrial Base (DIB).

Certification involves either a self-assessment (for select lower-risk programs) or a third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) for contracts deemed higher risk by the DoD. Because CUI is so central to defense operations, Level 2 is expected to be the most common requirement across DoD contracts.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.