CMMC Level 2 is the certification tier that applies to the largest share of defense contractors and subcontractors, and it’s the one most organizations in the Defense Industrial Base actually need to understand well. It sits in the middle of the framework’s three-tier structure — more rigorous than Level 1, but not as demanding as Level 3 — and that middle position is exactly what makes it worth understanding in context, not just in isolation.

This guide covers what Level 2 requires, what distinguishes it from Level 1 below it and Level 3 above it, and what a Level 2 certification does and doesn’t tell a contracting officer about your organization’s security posture.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Level 2 self-assessment requirements remain in force. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

CMMC Level 2

Executive Summary

Main Idea: CMMC Level 2 requires implementation of all 110 NIST SP 800-171 controls to protect Controlled Unclassified Information (CUI), verified through self-assessment or third-party C3PAO certification depending on program criticality. It’s a substantial step up from Level 1’s 17 basic safeguards, but doesn’t include the enhanced NIST SP 800-172 controls that Level 3 adds for the most sensitive national security programs.

Why You Should Care: Choosing or assuming the wrong level is one of the most common and costly mistakes contractors make. Under-preparing for Level 2 when your contract requires it disqualifies your bid. Over-investing in Level 3-grade controls when your contract only requires Level 2 wastes budget you didn’t need to spend. Knowing exactly what Level 2 covers — and doesn’t — is what lets you calibrate your compliance investment correctly.

Key Takeaways

  1. Level 2 is defined by what data you handle: Controlled Unclassified Information. If your organization handles only Federal Contract Information, you need Level 1, not Level 2. Level 2 applies specifically to contractors and subcontractors that process, store, or transmit CUI under a DoD contract.
  2. Level 2 requires all 110 NIST SP 800-171 controls — Level 1 requires only 17. This is the biggest single jump in the CMMC framework. Level 1’s basic safeguarding practices cover foundational hygiene; Level 2 requires comprehensive implementation across all 14 NIST SP 800-171 control domains, a substantially larger and more rigorous undertaking.
  3. Level 2 verification depends on program criticality — not every Level 2 contract requires the same assessment type. Programs involving information critical to national security require third-party C3PAO certification. A subset of Level 2 programs not meeting that threshold may qualify for annual self-assessment with a senior leadership affirmation instead — a meaningful practical distinction for contractors trying to estimate their compliance timeline and cost.
  4. Level 2 certifies NIST SP 800-171 implementation — it does not include Level 3’s enhanced controls. Level 3, reserved for the highest-priority programs, adds a further set of controls drawn from NIST SP 800-172 on top of the full Level 2 baseline. A Level 2 certification does not indicate readiness for Level 3-tier programs, and contractors bidding on the most sensitive national security work should not assume Level 2 is sufficient.
  5. Level 2 unlocks contract eligibility that Level 1 alone does not. Any DoD contract involving CUI requires Level 2, regardless of how well a contractor has implemented Level 1’s basic safeguards. Organizations that only pursue Level 1 are structurally excluded from the majority of substantive DoD contract opportunities, since most defense work involves CUI at some point in the contract lifecycle.

How CMMC’s Three Levels Relate to Each Other

CMMC 2.0’s three levels form a hierarchy tied directly to the sensitivity of the data a contractor handles — not to organization size, revenue, or any other business characteristic. Understanding where Level 2 sits in that hierarchy is the fastest way to determine whether it’s actually the right target for your organization.

Level 1 (Foundational) applies to contractors handling only Federal Contract Information — information provided by or generated for the government under a contract, not intended for public release, but not rising to the sensitivity of CUI. Level 1 requires 17 basic safeguarding practices drawn from FAR 52.204-21, verified through annual self-assessment. There is no third-party certification requirement at Level 1 under any circumstance.

Level 2 (Advanced) applies to contractors handling CUI — a broader and more sensitive category covering technical drawings, export-controlled data, and other information requiring safeguarding under law, regulation, or government-wide policy. Level 2 requires all 110 security controls specified in NIST SP 800-171, verified through self-assessment or third-party C3PAO certification depending on the specific program’s criticality.

Level 3 (Expert) applies to the highest-priority programs handling the most sensitive CUI — typically those most attractive to sophisticated nation-state adversaries. Level 3 requires the full Level 2 baseline plus a subset of enhanced security requirements from NIST SP 800-172, verified through government-led assessment rather than a C3PAO.

The practical takeaway: each level is additive. Level 2 doesn’t replace Level 1’s requirements — it encompasses them and adds substantially more. Level 3 doesn’t replace Level 2 — it builds on top of it. An organization certified at Level 2 has, in effect, already satisfied Level 1’s requirements as a subset of the broader Level 2 control set.

What Level 2 Requires That Level 1 Doesn’t

The jump from Level 1 to Level 2 is substantial — not an incremental step, but a significant expansion in both scope and rigor.

Level 1’s 17 practices cover basic cyber hygiene: identifying and authenticating users, limiting physical access, controlling information posted publicly. It’s a meaningful floor, but a low one, designed for the least sensitive category of government-related information.

Level 2’s 110 controls span all 14 NIST SP 800-171 domains: Access Control, Audit and Accountability, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. This includes requirements Level 1 doesn’t touch at all — audit logging sufficient to trace individual user actions, encryption of CUI at rest and in transit using FIPS-validated cryptography, formal incident response capability with mandatory reporting timelines, and documented risk assessment conducted on an ongoing basis.

The verification burden also changes substantially. Level 1 is always self-assessed. Level 2, depending on program criticality, may require an accredited C3PAO to conduct a rigorous third-party assessment — reviewing documentation, conducting interviews, and performing on-site or virtual inspection of systems. That’s a materially more demanding and more costly process than Level 1’s self-assessment ever requires.

What Level 2 Doesn’t Cover That Level 3 Does

It’s just as important to understand Level 2’s limits as its requirements — particularly for contractors who might assume Level 2 certification signals readiness for any DoD work, including the most sensitive national security programs.

Level 3 adds enhanced security requirements from NIST SP 800-172, designed specifically to address advanced persistent threats — sophisticated, often nation-state-affiliated adversaries with the resources and patience to target the most valuable defense information over extended periods. These enhanced requirements go beyond NIST SP 800-171’s baseline in areas like advanced threat hunting capability, more rigorous supply chain risk management, and enhanced protections against insider threats.

Level 3 also changes who conducts the assessment. Rather than a C3PAO, Level 3 verification is government-led — reflecting the heightened sensitivity of the programs this level protects. A Level 2 certification, however rigorously earned, does not indicate readiness for this tier, and contractors should not present Level 2 certification as sufficient for a program that specifically requires Level 3.

In practice, only a small subset of DIB contracts require Level 3 — those involving the most sensitive, high-value national security information. Most contractors handling CUI will find Level 2 is both necessary and sufficient for the work they’re pursuing.

Determining Which Level Applies to Your Organization

The level required for a given contract is determined by the type of data involved and is generally specified in the contract or solicitation itself, not left to the contractor’s own judgment. Check your prime contractor’s flow-down requirements or your direct contract language for the specific level required.

For a Level 2 program specifically, confirm whether your contract falls into the subset permitting self-assessment or requires full C3PAO third-party certification — this distinction significantly affects your compliance timeline and cost, and it isn’t always obvious without reviewing the specific program requirements closely. For the detailed process of preparing for and completing a Level 2 assessment, see our CMMC Level 2 Assessment Guide. For the broader sequence of getting from initial gap assessment to certification, see our CMMC 2.0 Roadmap, and for a working, domain-by-domain checklist of the controls Level 2 requires, see our CMMC 2.0 Compliance Checklist.

How Kiteworks Supports CMMC Level 2 Compliance

Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box, consolidating the channels through which CUI moves — secure email, secure file sharing, managed file transfer, SFTP, secure data forms, and APIs — onto a single governed platform with a unified Data Policy Engine.

AES-256 encryption at the file and disk level, with FIPS 140-3 validated cryptographic modules and customer-owned encryption keys, directly addresses Level 2’s System and Communications Protection requirements. A single, consolidated, immutable audit trail across every channel provides the evidence base for Level 2’s Audit and Accountability requirements, giving both self-assessment documentation and C3PAO assessors a unified record rather than fragments scattered across disconnected systems. Kiteworks also holds FedRAMP Moderate Authorization, independently assessed since June 2017, providing documented control inheritance that compresses assessment scope for Level 2 certification specifically.

To see how Kiteworks supports your organization’s path to CMMC Level 2 certification, schedule a custom demo.

Frequently Asked Questions

Level 1 applies to contractors handling only Federal Contract Information and requires 17 basic safeguarding practices verified through annual self-assessment. Level 2 applies to contractors handling Controlled Unclassified Information (CUI) and requires all 110 security controls from NIST SP 800-171, verified through self-assessment or third-party C3PAO certification depending on program criticality. The jump from Level 1 to Level 2 is substantial in both scope and rigor — Level 2 covers all 14 NIST SP 800-171 control domains, including audit logging, encryption, and formal incident response capability that Level 1 doesn’t require at all.

Level 2 requires all 110 NIST SP 800-171 controls and is verified through self-assessment or C3PAO certification. Level 3 requires the full Level 2 baseline plus enhanced security requirements from NIST SP 800-172, designed to address advanced persistent threats targeting the most sensitive national security programs. Level 3 assessment is government-led rather than conducted by a C3PAO. A Level 2 certification does not indicate readiness for Level 3 requirements — the two are not interchangeable, and only a small subset of the most sensitive DIB contracts require Level 3.

No. The assessment type required for Level 2 depends on the specific program’s criticality. Programs involving information critical to national security generally require full third-party assessment by an accredited C3PAO. A subset of Level 2 programs not meeting that threshold may permit annual self-assessment coupled with an affirmation of compliance from senior company leadership instead. Contractors should confirm which assessment type their specific contract requires rather than assuming either path applies by default.

CMMC Level 2 requires implementation of all 110 security controls specified in NIST SP 800-171, spanning 14 control domains including Access Control, Audit and Accountability, Configuration Management, Incident Response, and System and Communications Protection. These controls are not unique to CMMC — they derive directly from the pre-existing NIST SP 800-171 standard, which DFARS 252.204-7012 has required defense contractors handling CUI to implement since 2017. CMMC’s contribution is a formal verification mechanism confirming that implementation, rather than creating a new set of technical requirements.

Yes, to a meaningful degree. CMMC’s levels are additive — Level 2’s 110 controls encompass the foundational hygiene that Level 1’s 17 practices establish, plus substantially more. An organization with a mature Level 1 program has already built some of the access control and basic security awareness foundation that Level 2 builds on, but Level 1 certification alone is not sufficient for any contract involving CUI. Organizations moving from Level 1 to Level 2 should expect a significant additional compliance effort, not an incremental one, particularly around encryption, audit logging, incident response, and the other domains Level 1 doesn’t address at all.

Back to Risk & Compliance Glossary

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks