CMMC LEVEL 2
CYBERSECURITY MATURITY MODEL CERTIFICATION - LEVEL 2
CMMC Level 2 demonstrates an organization’s ability to safeguard Controlled Unclassified Information (CUI) and meet the cybersecurity requirements associated with sensitive Department of Defense missions.
Level 2 is aligned with the 110 security requirements of NIST SP 800-171 Revision 2, covering critical areas such as access control, incident response, system integrity, configuration management, identification and authentication, risk assessment, security monitoring, and protection of sensitive information.
For organizations supporting the Defense Industrial Base, CMMC Level 2 provides an important foundation for performing contracts that require the processing, storage, or transmission of CUI. Depending on the specific DoD requirement, Level 2 compliance may be validated through either a self-assessment or an assessment by an authorized Certified Third-Party Assessment Organization (C3PAO). A final Level 2 status is generally valid for three years, subject to required annual affirmations of continued compliance.
Holding the required CMMC Level 2 status can provide federal customers with greater confidence that their sensitive information is supported by an organization operating within an established, independently assessable cybersecurity framework. It demonstrates that cybersecurity controls are integrated into the contractor’s information systems, operational processes, and approach to protecting government information—not treated simply as an administrative requirement.
From an acquisition perspective, CMMC is increasingly important because DoD contracting officers cannot award contracts, task orders, or delivery orders containing a specified CMMC requirement to an offeror that does not possess the required current CMMC status at the time of award. Contractors must also maintain the applicable status throughout performance when required by the contract.
For government customers, partnering with a CMMC Level 2 organization can provide several advantages, including stronger protection of CUI, reduced cybersecurity and supply-chain risk, greater confidence in contractor information systems, and access to a partner prepared to support cybersecurity-sensitive DoD programs. CMMC requirements may also flow down to subcontractors and other contractual partners whose information systems process, store, or transmit applicable FCI or CUI, helping strengthen cybersecurity throughout the defense supply chain.
CMMC Level 2 reflects a commitment to protecting sensitive government information, maintaining cybersecurity discipline, and supporting mission-critical defense requirements in an increasingly complex threat environment. For customers, it provides assurance that the contractor has established the processes and safeguards necessary to securely support programs involving CUI while meeting applicable Department of Defense cybersecurity requirements.