The intermediate tier under CMMC 2.0, CMMC Level 2 applies to most defense contractors and subcontractors that handle Controlled Unclassified Information (CUI). Level 2 aligns directly with the 110 security requirements in NIST SP 800-171, spanning areas such as access control, incident response, audit logging, configuration management, and encryption. Meeting these requirements is essential for contractors subject to DFARS 252.204-7012 and other DoD cybersecurity obligations.
Level 2 represents a significant step up from Level 1 (Foundational), which applies to Federal Contract Information (FCI) and requires only 15 basic safeguards. At Level 2, organizations must demonstrate that their cybersecurity program can effectively protect sensitive data throughout the Defense Industrial Base (DIB). Achieving this level requires not only technical controls, but also documented policies, procedures, and evidence that those controls are operating as intended.
Depending on contract requirements, CMMC Level 2 compliance may be validated through self-affirmation for select lower-risk programs or through a third-party assessment conducted by a CMMC Third-Party Assessor Organization (C3PAO) for higher-risk contracts. Because CUI is central to most DoD programs, Level 2 is expected to be the most common requirement across future DoD contracts.
Preparing for a CMMC Level 2 assessment requires a comprehensive and defensible approach to security—one that can withstand documentation review, interviews, and technical validation.