CMMC Level 2 (Advanced)
CMMC Level 2 (Advanced) is the middle tier of the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) 2.0 program, intended for organizations that handle Controlled Unclassified Information (CUI). It is built around a set of security requirements that a contractor must meet to demonstrate it can adequately protect this sensitive information. Depending on the circumstances, an organization may show compliance through a self-assessment or a third-party assessment, and this determination should be verified against current DoD guidance.
CMMC Level 2 (Advanced) is the intermediate of the three levels defined under the CMMC 2.0 program, which is administered by the Department of Defense (DoD CIO) and is intended to provide broad protection of Controlled Unclassified Information (CUI). Per DoD CIO materials, Level 2 is associated with 110 security requirements, and the program describes an assessment cadence involving assessment (in some cases described as self-assessment every three years) together with annual affirmation of compliance; assessment method and frequency may vary by contract and program revision, so practitioners should confirm the applicable requirements against current authoritative sources. Note that CMMC assessment is distinct from any Authority to Operate (ATO) process, that certification at Level 2 addresses CUI protection rather than classified systems under the NISPOM, and that the CMMC 2.0 program continues to evolve through a phased rollout, meaning specific requirement counts, assessment types, and effective dates should be verified against current DoD guidance and the governing rule text.
Why it matters
For defense contractors and subcontractors that handle Controlled Unclassified Information (CUI), CMMC Level 2 (Advanced) represents the tier at which the Department of Defense expects demonstrable, verifiable protection of that information rather than an informal assurance. Because a large portion of the defense industrial base processes, stores, or transmits CUI in the course of contract performance, Level 2 is likely to be the most commonly applicable certification level for organizations in this space. Failing to meet the applicable Level 2 requirements can affect a contractor's ability to be awarded or continue performing on contracts that require it, so the stakes are both operational and commercial.
A critical point that experts routinely emphasize is that a CMMC assessment, whether self-assessment or third-party, is not the same as being permanently "secure" or "compliant" in perpetuity. Level 2 is described as involving an assessment cadence together with annual affirmation of compliance, which reflects the reality that safeguarding CUI is an ongoing obligation, not a one-time milestone. Practitioners should also avoid conflating CMMC certification with an Authority to Operate (ATO); the two arise from distinct processes and address different concerns. Likewise, Level 2 addresses CUI protection and should not be confused with the handling of classified systems governed by the NISPOM.
Because the CMMC 2.0 program continues to evolve through a phased rollout, the specific requirement counts, the type of assessment applicable to a given contract, and effective dates are subject to change. Organizations that treat an early determination as fixed risk being caught out when contract clauses or program guidance are updated. For this reason, confirming the applicable obligations against current DoD guidance and the governing rule text is essential before relying on any particular interpretation.
Who it's relevant to
Inside CMMC L2
Common questions
Answers to the questions practitioners most commonly ask about CMMC L2.