CMMC LEVEL 2 — WHAT THE REQUIREMENTS ACTUALLY MEAN
CMMC Level 2 is the certification level most often associated with protecting Controlled Unclassified Information (CUI) in the Defense Industrial Base.
At a high level, Level 2 expectations align to the 110 security requirements in NIST SP 800-171 Rev. 2. This page is an educational overview — not a sales pitch for a specific engagement. If you need help preparing, start from the CMMC hub.
CMMC Level 2 Requirements
In plain terms, Level 2 asks whether your organization can:
• Identify where CUI lives and who can access it
• Implement safeguarding practices aligned to NIST SP 800-171 Rev. 2’s 110 requirements (across 14 control families)
• Document how those practices work in your environment (typically via an SSP and related artifacts)
• Demonstrate practices through assessment methods (examine / interview / test) when required
Official certification assessments are performed by an Authorized C3PAO. brs prepares your organization for assessment. Official certification is performed by an Authorized C3PAO.
What Level 2 Is Asking
Access Control · Awareness & Training · Audit & Accountability · Configuration Management · Identification & Authentication · Incident Response · Maintenance · Media Protection · Personnel Security · Physical Protection · Risk Assessment · Security Assessment · System & Communications Protection · System & Information Integrity
This is a map of the 14 families, not a complete guide to each requirement.
Control Families
Policies alone are not enough. Level 2 readiness usually means:
• An accurate System Security Plan (SSP) that describes the in-scope environment
• Where applicable, POA&M items that track real gaps with owners and milestones
• Evidence that operations match what the documents claim
Documentation and Evidence
Depending on contract requirements and program rules, organizations may face self-assessment / reporting expectations and/or a third-party (C3PAO) certification assessment. CMMC program timelines can change. Your contract still decides whether you self-assess or need a C3PAO. If you’re unsure which path applies, talk it through — guessing is expensive.
Assessment-Path Awareness
We don’t replace reading the requirements. We help organizations apply them: clarify likely obligations, connect understanding to a practical path (readiness → gap → remediation/docs → mock → assessment prep), and coordinate toward formal assessment with an Authorized C3PAO when you’re ready.
Certified CMMC Professionals (CCPs) on the brs team help translate assessment expectations into practical prep.
brs is not a C3PAO. Official certification assessments are performed by an Authorized C3PAO.
How This Connects to brs
Ask About Your Level 2 Path
Closing
Learn next: NIST SP 800-171 Rev. 2
Prepare: Readiness · Gap analysis · Consulting
Hub: /cmmc · Canada path: /cpcsc

