13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not →

A prime flowed down 7012. All 110 requirements are now yours.

The email says CMMC Level 2 and the prime wants a date. MacTech draws your CUI boundary small enough to defend, maps every requirement to the evidence an assessor will open, and keeps on the POA&M only what the rule lets it carry.

We ran it on our own enclave first and publish its SPRS score, dated, lower numbers included. See our own numbers.

The contractors who succeed at Level 2 do three things

  • Shrink CUI to a defined enclave instead of letting it sprawl across corporate IT.
  • Inherit controls from FedRAMP-Moderate-aligned infrastructure - shorter SSP, faster assessment.
  • Author the SSP and POAM as evidence accumulates, not in a panic the month before the C3PAO arrives.

01 - The bar

What CMMC Level 2 actually requires

110 controls, all in scope

Every control in NIST 800-171 Rev 2 applies. There is no Level 2 with a subset; partial credit only delays certification.

CUI boundary, defined and defended

You must identify every system that touches CUI and explain - in writing - how CUI is kept inside that boundary at rest, in transit, and during processing.

Third-party assessment every 3 years

A C3PAO assesses your implementation against a published methodology and submits results to the DoD via eMASS. Self-attestation is not enough.

02 - The path

A four-phase path from gap to certificate

01

Scope & boundary

Define exactly where CUI is allowed. Document the enclave. Identify external service providers and inherited controls. Outcome: a defensible system-boundary diagram and an asset inventory the assessor can read in one sitting.

02

Gap assessment

Score every one of the 110 controls against current evidence. Categorize as IMPLEMENTED, PARTIAL, or NOT IMPLEMENTED. Outcome: a prioritized remediation backlog and a quantified SPRS score to plan against.

03

Remediate & document

Close gaps in priority order: technical controls first (because they unlock evidence), policy controls second, training last. Author the SSP and POAM as you go - not at the end. Outcome: a complete artifact set, not a binder of TODOs.

04

Mock assessment

Run a dress-rehearsal assessment against the NIST SP 800-171A objectives a C3PAO scores, using MacTech's assessment-day runbook. Outcome: every would-be finding surfaced and sequenced while there is still time to fix it. CMMC Phase II has been suspended since 13 July 2026, so no C3PAO assessment can be designated until it resumes.

See the arithmetic

Six open requirements. What does a POA&M actually get you?

This is the CMMC MCP server MacTech publishes, answering from the DoD Assessment Methodology and 32 CFR 170.21. Run it yourself before you talk to anyone.

What this proves: Four 5-point gaps and two partial ones score 84, below the 88 floor, so every item must close before the assessment; the one exception in 170.21 (3.13.11, partial) is the only line a POA&M could ever have carried.

$ calculate_sprs_score not_implemented=[3.11.2, 3.14.1, 3.1.12, 3.3.1] partially_implemented=[3.5.3, 3.13.11]
scoring 110 requirements against Annex A … done
sprs_score: 84   scale: -203 to 110   deducted: 26
meets_conditional_level_2_threshold: false
3.11.2 -5 · 3.14.1 -5 · 3.1.12 -5 · 3.3.1 -5 · 3.5.3 -3 (partial) · 3.13.11 -3 (partial)

$ generate_poam_entries gaps=[…same six…]
poam_permitted: false   eligible: 1   must_close_before_assessment: 5
No POA&M is permitted. Conditional CMMC Status requires a score of at least 88; this scores 84.
POAM-001 3.13.11 eligible  — the one exception in 170.21: encryption employed, not FIPS-validated (3 pts)
POAM-002 3.11.2  not eligible — worth 5 points; nothing over 1 point may appear on a Level 2 POA&M
POAM-006 3.5.3   not eligible — 3 points in its partial state, and MFA is not excepted
closeout: one 180-day window from the Conditional CMMC Status Date, confirmed by a closeout assessment

03 - What you get

The MacTech CMMC Level 2 stack

CUI Enclave

Boundary + inheritance

FIPS 140-3 controlled boundary that isolates CUI from your general IT. Inherits the maximum possible controls from the underlying platform so your SSP gets shorter, not longer.

Trust Codex

Evidence + SSP authoring

Living crosswalk of all 110 NIST 800-171 controls to your implementation evidence, with assessment-ready exports, POAM tracking, and shared-responsibility matrices.

IR Tabletop & AAR Evidence Kit

IR drills + evidence

Pre-built incident response tabletops with AI scenario generation, after-action reports, and the artifact set C3PAO assessors expect to see for IR-related controls.

Hardening & Validation Suite

Configuration assurance

Automated STIG compliance for RHEL, Windows, and Cisco. Continuous validation feeds your evidence library so configuration drift is detected before the assessor does.

05 - Questions

CMMC Level 2 - frequently asked

What is CMMC Level 2 and who needs it?

CMMC 2.0 Level 2 is the certification tier required for any defense contractor or subcontractor that stores, processes, or transmits Controlled Unclassified Information (CUI). It maps to all 110 controls in NIST SP 800-171 Rev 2. If your DoD contract or any flowdown clause references DFARS 252.204-7012, you are on the hook for Level 2.

How long does CMMC Level 2 certification take?

Long enough that the honest answer is "it depends on your scope", and anyone quoting you a number of days without seeing your environment is guessing. The variables that actually move it are how much of your estate touches CUI, how much of your existing evidence was produced contemporaneously rather than reconstructed, and how many requirements end up on a POA&M. A defined enclave shortens it because the boundary stops moving and the inherited controls are documented once - not because there is a fixed timetable to compress.

How much does CMMC Level 2 cost?

The whole programme depends on your scope: every system you leave inside the CUI boundary is a system somebody has to implement, evidence, and keep evidencing. Each phase of it does not. Once scoped, each is a fixed-price engagement, with its price and duration shown above, and part or all of each fee is credited toward the next step up. For the whole programme, DoD publishes its own estimates: the cost analysis in the CMMC Program final rule (32 CFR part 170, 89 FR 83092, 15 October 2024) models assessment and affirmation costs for small and other-than-small entities at each level, and it is the figure a contracting officer will recognise. The cost estimator at /cmmc-cost-estimator puts DoD's figures beside your own open requirements and shows the three-year range on the page.

Source: DoD cost estimates - CMMC Program final rule, 89 FR 83092 ↗

Do I have to use a C3PAO?

Yes for Level 2 certification on contracts that require it. Self-assessment is only permitted under specific conditions defined in the CMMC rule; most prime flowdowns now require third-party certification by a Cyber AB-authorized C3PAO. MacTech is not a C3PAO - we get you assessment-ready and partner with C3PAOs for the formal assessment.

What is a CUI boundary and why does it matter?

A CUI boundary is the defined set of systems, networks, and physical spaces where CUI is allowed to exist. A tight, documented boundary shrinks the scope of your assessment, reduces ongoing compliance cost, and makes incident response far easier. MacTech's CUI Enclave is a FIPS 140-3 controlled boundary designed to keep CUI off your general corporate IT entirely.

What is a System Security Plan (SSP) for CMMC Level 2?

The SSP is the primary document a C3PAO assessor reads. It describes your system, defines the CUI boundary, and explains how each of the 110 NIST 800-171 controls is implemented - including inherited controls, shared responsibilities, and any planned remediation captured in your POAM. A weak SSP is the #1 reason contractors fail Level 2 assessments.

Can a small business afford CMMC Level 2?

Yes, if scope is managed. The contractors who get hurt are the ones who try to certify their entire enterprise. The contractors who succeed isolate CUI to a small, defined enclave and inherit as many controls as possible from an underlying platform (FedRAMP Moderate IaaS, an authorized SaaS, etc.). MacTech's Compliance Package was built specifically for small DIB subs operating on tight margins.

What is the difference between CMMC Level 1 and Level 2?

Level 1 covers Federal Contract Information (FCI) only - 17 basic safeguarding controls, self-assessed annually. Level 2 covers CUI - all 110 NIST 800-171 controls, third-party assessed every three years by a C3PAO. Most prime contracts flow down Level 2 because primes treat any meaningful technical data as CUI.

Start with a readiness scan

Tell us your contract posture and current CUI footprint. We will return a Level 2 readiness score, a prioritized remediation backlog, and a realistic timeline to your C3PAO assessment.