CMMC Level 2 Requirements: The 110 Practices Explained
Why Level 2 Matters
Most DoD contractors fall into CMMC Level 2 because it applies to any organization that handles Controlled Unclassified Information (CUI). Level 2 aligns with NIST SP 800-171 Revision 2, which organizes 110 security practices into 14 control domains.
The 14 NIST SP 800-171 Domains
- Access Control: Limit system access to authorized users, processes, and devices, and restrict what they can do based on least privilege.
- Awareness and Training: Ensure personnel are aware of security risks and trained to carry out their information security responsibilities.
- Audit and Accountability: Create, protect, and retain system audit logs sufficient to trace unauthorized activity to individual users.
- Configuration Management: Establish and maintain baseline configurations and enforce secure settings across systems.
- Identification and Authentication: Uniquely identify users and authenticate their identities before granting access, including multifactor authentication where required.
- Incident Response: Establish an operational incident-handling capability covering preparation, detection, analysis, containment, and reporting.
- Maintenance: Perform system maintenance and control the tools, techniques, and personnel used to conduct it.
- Media Protection: Protect, sanitize, and control media containing CUI, both digital and physical.
- Personnel Security: Screen individuals before authorizing access and protect CUI during personnel actions such as transfers and terminations.
- Physical Protection: Limit physical access to systems, equipment, and operating environments to authorized individuals.
- Risk Assessment: Periodically assess risk to operations and assets, and scan for vulnerabilities.
- Security Assessment: Assess security controls, develop and implement plans of action, and monitor controls on an ongoing basis.
- System and Communications Protection: Monitor and protect communications at system boundaries and use encryption to protect CUI in transit.
- System and Information Integrity: Identify and correct flaws, provide protection from malicious code, and monitor system security alerts.
System Security Plan (SSP) Requirement
CMMC Level 2 requires a System Security Plan documenting how each of the 110 practices is implemented across your environment. The SSP is a primary artifact evaluated by the C3PAO during assessment. Critically, it must reflect actual practice — not aspirational documentation. An SSP that describes controls you have not implemented will fail against evidence.
Plan of Action and Milestones (POA&M)
Practices that are not yet fully implemented must be captured in a Plan of Action and Milestones with realistic remediation timelines. Some POA&Ms are acceptable at assessment — not all 110 practices must be fully implemented on assessment day — but this is bounded by criticality, and certain high-weighted practices cannot be deferred.
Exceleor provides CMMC Level 2 gap assessment and SSP development support. Learn more at exceleor.com/cmmc →
Need an EHS Audit?
Veteran-led, certified lead auditors covering ISO 14001, ISO 45001, RC14001, CFATS and more. Get a tailored proposal within 24 hours.
Request Your AssessmentFree EHS Compliance Checklist
Download our 50-point EHS Audit Readiness Checklist — the same framework our auditors use.
Download Free ChecklistMore Free Resources
Fortify Your Compliance Today
Don't wait for an audit finding to reveal your gaps. Partner with the Southeast's most comprehensive EHS and security audit team.