CMMC Level 2 Compliance: The 110 Controls Explained
CMMC Level 2 is a set of 110 security controls, drawn directly from NIST SP 800-171 Revision 2 and grouped into 14 domains, that defense contractors must implement to handle controlled unclassified information. It exists to answer one question the Department of Defense now asks before it awards work: can you prove you protect the CUI you touch? If your contracts involve CUI, this is the bar. There is no partial credit at the contract level. You either meet it or you lose the work.
Most contractors approach this backward. They buy a tool, check a box, and assume they are covered. Then an assessor asks for evidence, and they find out a purchased product is not the same as an implemented control. Level 2 is not a shopping list. It is a documentation and discipline problem first, a technology problem second. This is the part of compliance readiness that decides whether you keep your defense revenue.
If you want the broader background on the program itself, start with our complete guide to CMMC 2.0 and come back here for the controls.
What CMMC Level 2 actually requires
At Level 2, you implement 110 security requirements across 14 domains, and you prove each one against 320 assessment objectives. The 110 controls map one to one with NIST SP 800-171 Revision 2, so there is no separate "CMMC control set" to learn. CMMC is the verification layer. NIST 800-171 is the substance. The Department of Defense confirms this alignment directly in its CMMC alignment to NIST standards document.
Who needs it? Any contractor or subcontractor that stores, processes, or transmits controlled unclassified information in the defense supply chain. If you only handle federal contract information and never touch CUI, Level 1 covers you. The moment CUI enters your environment, Level 2 applies. For a control-by-control view of how the two standards line up, our NIST 800-171 to CMMC crosswalk maps each one.
Here is the part teams underestimate. Each of the 110 controls expands into one or more objectives an assessor will test. That is where the real count lives. You are not proving 110 things. You are proving 320.
The 14 domains: how the 110 controls are organized
The 110 controls are grouped into 14 domains, also called control families. Each domain covers a category of risk, from who can log in to how you handle an incident. The list below shows the full breakdown, with the number of controls in each.

- Access Control (AC), 22 controls. Who can reach CUI, and what they can do once they are in.
- Awareness and Training (AT), 3 controls. Whether your people recognize threats and know their security duties.
- Audit and Accountability (AU), 9 controls. Logging activity so you can reconstruct who did what, and when.
- Configuration Management (CM), 9 controls. Controlling how systems are built, changed, and locked down.
- Identification and Authentication (IA), 11 controls. Verifying users and devices, including multi-factor authentication.
- Incident Response (IR), 3 controls. Detecting, reporting, and recovering from security events.
- Maintenance (MA), 6 controls. Performing system maintenance without opening a side door.
- Media Protection (MP), 9 controls. Protecting CUI on drives, backups, and paper, including disposal.
- Personnel Security (PS), 2 controls. Screening people and protecting CUI when they leave.
- Physical Protection (PE), 6 controls. Controlling physical access to systems and facilities.
- Risk Assessment (RA), 3 controls. Finding and prioritizing your own vulnerabilities.
- Security Assessment (CA), 4 controls. Testing controls and maintaining your System Security Plan.
- System and Communications Protection (SC), 16 controls. Protecting data in transit and at rest, including encryption.
- System and Information Integrity (SI), 7 controls. Patching flaws, blocking malicious code, and monitoring for threats.
The five domains assessors weight most
Not all 14 domains carry equal weight in an assessment. Five of them, Access Control, Identification and Authentication, Audit and Accountability, Incident Response, and System and Communications Protection, account for the highest assessment risk. They are heavily enforced, evidence-driven, and tied directly to how real breaches happen. If your program has gaps, this is where an assessor finds them first, because these are the controls attackers exploit and the ones that generate the most documentation to verify.
The practical read is simple. Do not spread your effort evenly across all 110. Weight your preparation toward access, identity, logging, and encryption. That is where points and findings concentrate.
How the 110 controls are scored
CMMC Level 2 uses a points-based score reported through the Supplier Performance Risk System, or SPRS. You start at 110, the perfect score, and you subtract points for every control you have not fully implemented. The methodology is defined in the DFARS clause 252.204-7020.
Three things about the math surprise people:
- Controls are weighted 1, 3, or 5 points. A missing 5-point control, like multi-factor authentication, costs far more than a missing 1-point control.
- There is no partial credit. A control is either fully met or it counts as not met. Half-finished does not earn half the points.
- The score can go negative. The range runs from negative 203 at the bottom to positive 110 at the top.
First self-assessments often land in negative territory, and that is not a reason to panic. It is a baseline. The point of the score is to tell you, honestly, how far you have to go before a contracting officer or an assessor looks at your number.
Self-assessment vs. C3PAO certification: which path applies to you
Level 2 has two assessment paths, and the difference is not optional. It is dictated by the kind of CUI your contract involves.
A self-assessment is an internal evaluation. You score your own implementation, submit it to SPRS, and sign an affirmation. You can hire help, but the result is still self-reported. A C3PAO certification is an independent assessment by a CMMC Third-Party Assessment Organization accredited by the DoD, which issues a formal Certificate of CMMC Status. For the higher-priority CUI categories, a self-score is not enough. You need the third-party certificate. The DoD lays out the testing procedures in its CMMC Level 2 Assessment Guide.
The cost gap is real. A self-assessment runs roughly $5,000 to $35,000. A C3PAO certification commonly runs $30,000 to $150,000 or more, before remediation. If you are not sure which path your contracts trigger, that question belongs at the top of your planning, not the end. Getting C3PAO readiness right early is cheaper than discovering the requirement during a bid.
POA&M and conditional certification: what you can and cannot defer
You do not always need a perfect 110 to move forward. CMMC allows a Plan of Action and Milestones, a POA&M, to document gaps you will close on a deadline. But the rules are narrow, and contractors get burned by assuming they are looser than they are.
To earn a conditional certification with open items, you have to score at least 80%, which is 88 of the 110 points. Below that line, a POA&M will not save you. The items you defer must be 1-point controls only, with one narrow exception: cryptographic protection of CUI (SC.L2-3.13.11) can sit on a POA&M if encryption exists but is not yet FIPS-validated. The high-value 3-point and 5-point controls cannot be deferred. As the team at Hive Systems documents, some gaps simply cannot go on a POA&M at all.
The clock matters too. A conditional status lasts 180 days. You must pass a closeout assessment within that window, or the conditional certification lapses. So a POA&M is not a way to avoid the work. It is a short, supervised runway to finish it. This is where a clean System Security Plan and POA&M earns its keep.
The compliance timeline: what is due and when
The program is live, not theoretical. The CMMC final rule (32 CFR) was published in the Federal Register on October 15, 2024, and took effect on December 16, 2024, as Forvis Mazars reported. It launched a phased rollout that runs over the following years.

- November 10, 2025: Phase 1. Most new DoD solicitations begin requiring a self-assessed Level 2 score in SPRS.
- November 10, 2026: Phase 2. Third-party (C3PAO) certification at Level 2 starts appearing as a requirement in new awards.
- 2027 and 2028: Phases 3 and 4. Certification requirements extend to contract renewals and, eventually, to effectively all DoD solicitations.
The phase-in is a courtesy, not a reprieve. Contracting officers can include CMMC requirements early, and the higher-risk programs are first in line. If you wait until a clause shows up in a bid you want, you are already months behind. For the detailed program dates, Secureframe maintains a current timeline.
What CMMC Level 2 costs and how long it takes
Budgets vary with your starting maturity, but the ranges are consistent enough to plan against. Small contractors typically spend somewhere between $116,000 and $138,000 in the first year, and the Department of Defense's own estimate puts the three-year cost for a small defense contractor near $488,000 across the full lifecycle, including reassessment.
Timeline is the same story. With sound IT already in place, 3 to 6 months is achievable. For most teams starting from a real baseline, 12 to 18 months is honest. And there is a penalty for rushing. Organizations compressing the work below 9 months tend to pay 30% to 60% more than those on a standard schedule, according to industry cost analysis. Speed is expensive. Starting early is not.
Where companies fail their Level 2 assessment
After enough readiness work, the failure patterns repeat. They are rarely exotic. They are almost always scope and documentation.
The most common one we see is the managed service provider. If your IT provider has administrative access to systems that touch CUI, that provider is in scope, full stop. Many contractors assume the vendor is "outside" their environment, or assume the vendor is already compliant. Neither assumption holds up. Without a documented Shared Responsibility Matrix, the responsibility for those controls defaults to you. The DoD's CMMC Level 2 Scoping Guide is explicit about how service providers pull into scope.
A few others worth naming directly:
- Email treated as out of scope. If contract data or CUI-adjacent communication flows through it, it is in scope.
- SSP and network diagram that disagree. When the System Security Plan says one thing and the diagram shows another, assessors notice immediately. Inconsistency reads as "they do not know their own environment."
- CUI assets misclassified as risk-managed assets. Mislabel an asset that handles CUI and you can fail outright.
The fix for all of these is the same, and it is not glamorous. Scope your environment honestly, write it down accurately, and make the documentation match reality before an assessor checks. A focused CMMC gap assessment finds these before they become findings.
One more thing on the horizon: NIST 800-171 Revision 3
You will hear about Revision 3, and you should know where it stands so you do not chase the wrong target. NIST has finalized 800-171 Revision 3. The Department of Defense has not authorized it for CMMC scoring, SPRS reporting, or assessments, and has not announced a transition date. Today, Level 2 is still scored against Revision 2.
That said, the DoD published the organization-defined parameters for Revision 3 in April 2025, which signals the transition is being prepared rather than shelved, as Holland & Knight noted. Build to Revision 2 now. Keep one eye on Revision 3 so the eventual switch is an update, not a rebuild.
How to start without boiling the ocean
You do not begin with 110 controls. You begin with two questions: where does CUI actually live in your environment, and which assessment path do your contracts require? Answer those, and the rest of the work organizes itself.
From there, the sequence is steady. Scope the environment. Run a gap assessment to get a real SPRS baseline. Fix the 5-point controls first, because they move your score the most and cannot be deferred. Write the System Security Plan as you go, not at the end. Then bring in a third party only when your own evidence would survive their questions.
Consilien runs this process for defense contractors and manufacturers across California, from the first scope review through CMMC compliance services and the broader managed cybersecurity that keeps those 110 controls in place after the certificate is issued. If you are staring at a negative SPRS score and a contract deadline, that is the right time to talk, not after.