CMMC LEVEL 2 — WHAT THE REQUIREMENTS ACTUALLY MEAN

CMMC Level 2 is the certification level most often associated with protecting Controlled Unclassified Information (CUI) in the Defense Industrial Base.

At a high level, Level 2 expectations align to the 110 security requirements in NIST SP 800-171 Rev. 2. This page is an educational overview — not a sales pitch for a specific engagement. If you need help preparing, start from the CMMC hub.

CMMC Level 2 Requirements

In plain terms, Level 2 asks whether your organization can:

• Identify where CUI lives and who can access it
• Implement safeguarding practices aligned to NIST SP 800-171 Rev. 2’s 110 requirements (across 14 control families)
• Document how those practices work in your environment (typically via an SSP and related artifacts)
• Demonstrate practices through assessment methods (examine / interview / test) when required

Official certification assessments are performed by an Authorized C3PAO. brs prepares your organization for assessment. Official certification is performed by an Authorized C3PAO.

What Level 2 Is Asking

Access Control · Awareness & Training · Audit & Accountability · Configuration Management · Identification & Authentication · Incident Response · Maintenance · Media Protection · Personnel Security · Physical Protection · Risk Assessment · Security Assessment · System & Communications Protection · System & Information Integrity

This is a map of the 14 families, not a complete guide to each requirement.

Control Families

Policies alone are not enough. Level 2 readiness usually means:

• An accurate System Security Plan (SSP) that describes the in-scope environment
• Where applicable, POA&M items that track real gaps with owners and milestones
• Evidence that operations match what the documents claim

Documentation and Evidence

Depending on contract requirements and program rules, organizations may face self-assessment / reporting expectations and/or a third-party (C3PAO) certification assessment. CMMC program timelines can change. Your contract still decides whether you self-assess or need a C3PAO. If you’re unsure which path applies, talk it through — guessing is expensive.

Assessment-Path Awareness

We don’t replace reading the requirements. We help organizations apply them: clarify likely obligations, connect understanding to a practical path (readiness → gap → remediation/docs → mock → assessment prep), and coordinate toward formal assessment with an Authorized C3PAO when you’re ready.

Certified CMMC Professionals (CCPs) on the brs team help translate assessment expectations into practical prep.

brs is not a C3PAO. Official certification assessments are performed by an Authorized C3PAO.

How This Connects to brs

Ask About Your Level 2 Path

Contact brs

Closing

Learn next: NIST SP 800-171 Rev. 2
Prepare: Readiness · Gap analysis · Consulting
Hub: /cmmc · Canada path: /cpcsc

Related Resources