A prime flowed down 7012. All 110 requirements are now yours.
The email says CMMC Level 2 and the prime wants a date. MacTech draws your CUI boundary small enough to defend, maps every requirement to the evidence an assessor will open, and keeps on the POA&M only what the rule lets it carry.
We ran it on our own enclave first and publish its SPRS score, dated, lower numbers included. See our own numbers.
The contractors who succeed at Level 2 do three things
- Shrink CUI to a defined enclave instead of letting it sprawl across corporate IT.
- Inherit controls from FedRAMP-Moderate-aligned infrastructure - shorter SSP, faster assessment.
- Author the SSP and POAM as evidence accumulates, not in a panic the month before the C3PAO arrives.
01 - The bar
What CMMC Level 2 actually requires
110 controls, all in scope
Every control in NIST 800-171 Rev 2 applies. There is no Level 2 with a subset; partial credit only delays certification.
CUI boundary, defined and defended
You must identify every system that touches CUI and explain - in writing - how CUI is kept inside that boundary at rest, in transit, and during processing.
Third-party assessment every 3 years
A C3PAO assesses your implementation against a published methodology and submits results to the DoD via eMASS. Self-attestation is not enough.
02 - The path
A four-phase path from gap to certificate
Scope & boundary
Define exactly where CUI is allowed. Document the enclave. Identify external service providers and inherited controls. Outcome: a defensible system-boundary diagram and an asset inventory the assessor can read in one sitting.
Gap assessment
Score every one of the 110 controls against current evidence. Categorize as IMPLEMENTED, PARTIAL, or NOT IMPLEMENTED. Outcome: a prioritized remediation backlog and a quantified SPRS score to plan against.
Remediate & document
Close gaps in priority order: technical controls first (because they unlock evidence), policy controls second, training last. Author the SSP and POAM as you go - not at the end. Outcome: a complete artifact set, not a binder of TODOs.
Mock assessment
Run a dress-rehearsal assessment against the NIST SP 800-171A objectives a C3PAO scores, using MacTech's assessment-day runbook. Outcome: every would-be finding surfaced and sequenced while there is still time to fix it. CMMC Phase II has been suspended since 13 July 2026, so no C3PAO assessment can be designated until it resumes.
See the arithmetic
Six open requirements. What does a POA&M actually get you?
This is the CMMC MCP server MacTech publishes, answering from the DoD Assessment Methodology and 32 CFR 170.21. Run it yourself before you talk to anyone.
What this proves: Four 5-point gaps and two partial ones score 84, below the 88 floor, so every item must close before the assessment; the one exception in 170.21 (3.13.11, partial) is the only line a POA&M could ever have carried.
$ calculate_sprs_score not_implemented=[3.11.2, 3.14.1, 3.1.12, 3.3.1] partially_implemented=[3.5.3, 3.13.11] scoring 110 requirements against Annex A … done sprs_score: 84 scale: -203 to 110 deducted: 26 meets_conditional_level_2_threshold: false 3.11.2 -5 · 3.14.1 -5 · 3.1.12 -5 · 3.3.1 -5 · 3.5.3 -3 (partial) · 3.13.11 -3 (partial) $ generate_poam_entries gaps=[…same six…] poam_permitted: false eligible: 1 must_close_before_assessment: 5 No POA&M is permitted. Conditional CMMC Status requires a score of at least 88; this scores 84. POAM-001 3.13.11 eligible — the one exception in 170.21: encryption employed, not FIPS-validated (3 pts) POAM-002 3.11.2 not eligible — worth 5 points; nothing over 1 point may appear on a Level 2 POA&M POAM-006 3.5.3 not eligible — 3 points in its partial state, and MFA is not excepted closeout: one 180-day window from the Conditional CMMC Status Date, confirmed by a closeout assessment
03 - What you get
The MacTech CMMC Level 2 stack
CUI Enclave
Boundary + inheritanceFIPS 140-3 controlled boundary that isolates CUI from your general IT. Inherits the maximum possible controls from the underlying platform so your SSP gets shorter, not longer.
Trust Codex
Evidence + SSP authoringLiving crosswalk of all 110 NIST 800-171 controls to your implementation evidence, with assessment-ready exports, POAM tracking, and shared-responsibility matrices.
IR Tabletop & AAR Evidence Kit
IR drills + evidencePre-built incident response tabletops with AI scenario generation, after-action reports, and the artifact set C3PAO assessors expect to see for IR-related controls.
Hardening & Validation Suite
Configuration assuranceAutomated STIG compliance for RHEL, Windows, and Cisco. Continuous validation feeds your evidence library so configuration drift is detected before the assessor does.
05 - Questions
CMMC Level 2 - frequently asked
What is CMMC Level 2 and who needs it?
CMMC 2.0 Level 2 is the certification tier required for any defense contractor or subcontractor that stores, processes, or transmits Controlled Unclassified Information (CUI). It maps to all 110 controls in NIST SP 800-171 Rev 2. If your DoD contract or any flowdown clause references DFARS 252.204-7012, you are on the hook for Level 2.
How long does CMMC Level 2 certification take?
Long enough that the honest answer is "it depends on your scope", and anyone quoting you a number of days without seeing your environment is guessing. The variables that actually move it are how much of your estate touches CUI, how much of your existing evidence was produced contemporaneously rather than reconstructed, and how many requirements end up on a POA&M. A defined enclave shortens it because the boundary stops moving and the inherited controls are documented once - not because there is a fixed timetable to compress.
How much does CMMC Level 2 cost?
The whole programme depends on your scope: every system you leave inside the CUI boundary is a system somebody has to implement, evidence, and keep evidencing. Each phase of it does not. Once scoped, each is a fixed-price engagement, with its price and duration shown above, and part or all of each fee is credited toward the next step up. For the whole programme, DoD publishes its own estimates: the cost analysis in the CMMC Program final rule (32 CFR part 170, 89 FR 83092, 15 October 2024) models assessment and affirmation costs for small and other-than-small entities at each level, and it is the figure a contracting officer will recognise. The cost estimator at /cmmc-cost-estimator puts DoD's figures beside your own open requirements and shows the three-year range on the page.
Source: DoD cost estimates - CMMC Program final rule, 89 FR 83092 ↗
Do I have to use a C3PAO?
Yes for Level 2 certification on contracts that require it. Self-assessment is only permitted under specific conditions defined in the CMMC rule; most prime flowdowns now require third-party certification by a Cyber AB-authorized C3PAO. MacTech is not a C3PAO - we get you assessment-ready and partner with C3PAOs for the formal assessment.
What is a CUI boundary and why does it matter?
A CUI boundary is the defined set of systems, networks, and physical spaces where CUI is allowed to exist. A tight, documented boundary shrinks the scope of your assessment, reduces ongoing compliance cost, and makes incident response far easier. MacTech's CUI Enclave is a FIPS 140-3 controlled boundary designed to keep CUI off your general corporate IT entirely.
What is a System Security Plan (SSP) for CMMC Level 2?
The SSP is the primary document a C3PAO assessor reads. It describes your system, defines the CUI boundary, and explains how each of the 110 NIST 800-171 controls is implemented - including inherited controls, shared responsibilities, and any planned remediation captured in your POAM. A weak SSP is the #1 reason contractors fail Level 2 assessments.
Can a small business afford CMMC Level 2?
Yes, if scope is managed. The contractors who get hurt are the ones who try to certify their entire enterprise. The contractors who succeed isolate CUI to a small, defined enclave and inherit as many controls as possible from an underlying platform (FedRAMP Moderate IaaS, an authorized SaaS, etc.). MacTech's Compliance Package was built specifically for small DIB subs operating on tight margins.
What is the difference between CMMC Level 1 and Level 2?
Level 1 covers Federal Contract Information (FCI) only - 17 basic safeguarding controls, self-assessed annually. Level 2 covers CUI - all 110 NIST 800-171 controls, third-party assessed every three years by a C3PAO. Most prime contracts flow down Level 2 because primes treat any meaningful technical data as CUI.
From the newsletter
CMMC Level 2, from the field
An Incident Response Tabletop Exercise That Satisfies 3.6.3
An incident response tabletop exercise counts for NIST 800-171 3.6.3 only if it leaves evidence. How to seat, script, and document one an assessor accepts.
NIST 800-171 Rev 3 vs Rev 2: It Depends Who Signed the Contract
NIST 800-171 Rev 3 vs Rev 2: DoD still binds and scores Rev 2 while civilian CUI heads to Rev 3. What changed, the ID trap, and how to map once.
CMMC Class Deviation: The Phase 2 Pause Is Now in the Rulebook
The CMMC class deviation moved the Phase 2 pause from a policy memo into DFARS. A dated timeline of what each step changed, and what stays in force.
From MacZine
Level 2, written out at length
Three MacZine issues that go further into the decisions this page summarises.
Start with a readiness scan
Tell us your contract posture and current CUI footprint. We will return a Level 2 readiness score, a prioritized remediation backlog, and a realistic timeline to your C3PAO assessment.