TroutTrout
Back to Glossary
CMMC Level 2Advanced Cyber Hygiene

CMMC Level 2

4 min read

CMMC Level 2 is the tier of the Cybersecurity Maturity Model Certification for defense contractors that store, process, or transmit Controlled Unclassified Information (CUI). It requires the 110 security controls of NIST SP 800-171 Rev 2, and for most CUI contracts a third-party assessment by a C3PAO. It is the level the large majority of the Defense Industrial Base has to reach.

What is CMMC Level 2?

The Department of Defense built CMMC to verify that contractors actually implement the safeguards they have been contractually required to have since the DFARS clause 252.204-7012 took effect in 2017. Self-attestation proved unreliable, so CMMC adds a certification gate.

Level 1 covers Federal Contract Information with 17 basic safeguarding practices and stays self-assessed. Level 2 is a different order of rigor: 110 controls drawn directly from NIST SP 800-171, grouped into 14 families, aimed squarely at protecting CUI. Level 3 adds a subset of NIST SP 800-172 controls for the highest-priority programs and is assessed by the government itself.

What does CMMC Level 2 require?

The 110 controls span 14 domains, including Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, and System and Communications Protection. In practice, the controls that consume the most effort are the ones that touch the network:

  • Access control and least privilege. Users and devices get only the access their role requires, and access to CUI is limited and logged.
  • Boundary protection and segmentation. CUI is separated from the rest of the enterprise, typically inside a CUI enclave, with monitored boundaries.
  • Audit and accountability. Every access to CUI ties back to an authenticated identity, with logs retained as assessment evidence.

Meeting the letter of the control is not enough. A C3PAO wants the artifacts: the System Security Plan, the policies, and the logs that prove the control operates day to day.

Who needs CMMC Level 2?

Any contractor or subcontractor that handles CUI on a DoD contract. That includes prime contractors, but the requirement flows down the supply chain, so a small machine shop producing parts to a controlled technical drawing is in scope just as much as the prime above it. The DFARS clause 252.204-7021 sets the certification requirement, and the phased rollout began appearing in solicitations in 2025. Once a contract names Level 2, no certificate means no award.

Why does CMMC Level 2 matter for OT?

Defense manufacturing runs on operational technology: CNC machines, PLCs, test stands, and the historians that feed them. Those systems often hold or move CUI in the form of technical data packages and machine programs, yet they cannot run endpoint agents or take frequent patches. Scoping them into a compliant boundary is the hard part of a Level 2 assessment. The practical answer is to put the enforcement in the network rather than on the fragile asset, so segmentation and access control satisfy the controls without touching the controller.

How is CMMC Level 2 different from Level 1?

Level 1 protects Federal Contract Information with 17 self-assessed practices. Level 2 protects CUI with 110 controls and, for CUI, a mandatory external assessment on a three-year cycle with annual affirmations. The jump is not incremental. Level 1 asks for basic hygiene; Level 2 asks for a documented, audited security program mapped control-by-control to NIST SP 800-171.

How Access Gate helps

Access Gate carves a CUI enclave out of a flat plant network as an identity-enforced overlay, so you get the segmentation, least-privilege access, and session logging that Level 2 wants without re-cabling the shop floor or putting agents on OT gear. See CMMC compliance for the control mapping.

Related terms