Skip to main content
Category: CMMC & DIB Assessment

CMMC Level 2 (Advanced)

Also known as: CMMC L2, CMMC 2.0 Level 2, Level 2 (Advanced), CMMC Level 2 Advanced
Simply put

CMMC Level 2 (Advanced) is the middle tier of the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) 2.0 program, intended for organizations that handle Controlled Unclassified Information (CUI). It is built around a set of security requirements that a contractor must meet to demonstrate it can adequately protect this sensitive information. Depending on the circumstances, an organization may show compliance through a self-assessment or a third-party assessment, and this determination should be verified against current DoD guidance.

Formal definition

CMMC Level 2 (Advanced) is the intermediate of the three levels defined under the CMMC 2.0 program, which is administered by the Department of Defense (DoD CIO) and is intended to provide broad protection of Controlled Unclassified Information (CUI). Per DoD CIO materials, Level 2 is associated with 110 security requirements, and the program describes an assessment cadence involving assessment (in some cases described as self-assessment every three years) together with annual affirmation of compliance; assessment method and frequency may vary by contract and program revision, so practitioners should confirm the applicable requirements against current authoritative sources. Note that CMMC assessment is distinct from any Authority to Operate (ATO) process, that certification at Level 2 addresses CUI protection rather than classified systems under the NISPOM, and that the CMMC 2.0 program continues to evolve through a phased rollout, meaning specific requirement counts, assessment types, and effective dates should be verified against current DoD guidance and the governing rule text.

Why it matters

For defense contractors and subcontractors that handle Controlled Unclassified Information (CUI), CMMC Level 2 (Advanced) represents the tier at which the Department of Defense expects demonstrable, verifiable protection of that information rather than an informal assurance. Because a large portion of the defense industrial base processes, stores, or transmits CUI in the course of contract performance, Level 2 is likely to be the most commonly applicable certification level for organizations in this space. Failing to meet the applicable Level 2 requirements can affect a contractor's ability to be awarded or continue performing on contracts that require it, so the stakes are both operational and commercial.

A critical point that experts routinely emphasize is that a CMMC assessment, whether self-assessment or third-party, is not the same as being permanently "secure" or "compliant" in perpetuity. Level 2 is described as involving an assessment cadence together with annual affirmation of compliance, which reflects the reality that safeguarding CUI is an ongoing obligation, not a one-time milestone. Practitioners should also avoid conflating CMMC certification with an Authority to Operate (ATO); the two arise from distinct processes and address different concerns. Likewise, Level 2 addresses CUI protection and should not be confused with the handling of classified systems governed by the NISPOM.

Because the CMMC 2.0 program continues to evolve through a phased rollout, the specific requirement counts, the type of assessment applicable to a given contract, and effective dates are subject to change. Organizations that treat an early determination as fixed risk being caught out when contract clauses or program guidance are updated. For this reason, confirming the applicable obligations against current DoD guidance and the governing rule text is essential before relying on any particular interpretation.

Who it's relevant to

Defense Contractors and Subcontractors Handling CUI
Organizations across the defense industrial base that process, store, or transmit Controlled Unclassified Information are the primary audience for Level 2 (Advanced). Because Level 2 is designed specifically for companies that deal with CUI, these organizations should determine whether their contracts require it and confirm whether a self-assessment or third-party assessment applies to their situation under current DoD guidance.
Compliance Officers and Information System Security Managers
Personnel responsible for building and maintaining a contractor's security program need to understand that Level 2 is associated with 110 security requirements and generally requires documenting processes to guide compliance efforts. They should also plan for the ongoing nature of the obligation, including the annual affirmation of compliance described in DoD materials, rather than treating certification as a one-time event.
Contract and Acquisition Professionals
Those managing bids, awards, and contract performance must track which contracts invoke CMMC Level 2 and what assessment method applies, since these can vary by contract and program revision. Given the phased rollout of CMMC 2.0, they should verify effective dates and applicable requirements against current authoritative sources before making commitments that depend on a specific interpretation.
Assessors and Auditors
Professionals conducting or preparing organizations for assessments should distinguish carefully between assessment and authorization, and between CMMC certification and an ATO. They should also confirm the current applicable assessment type and requirement set, since the program's specifics continue to evolve and should be checked against the governing rule text.

Inside CMMC L2

Alignment to NIST SP 800-171 Security Requirements
CMMC Level 2 is generally built around the security requirements for protecting Controlled Unclassified Information (CUI) specified in NIST SP 800-171, as maintained by NIST. Practitioners should confirm the applicable revision of NIST SP 800-171 against current official DoD and NIST sources, since requirement sets and mappings can change across revisions.
Advanced Level within the CMMC Model
Level 2 is positioned as the 'Advanced' tier in the tiered CMMC model administered under the direction of the DoD CIO, sitting above the foundational level and generally intended for contractors handling CUI. The model has been subject to a phased rollout and revisions, so the precise level structure should be verified against the current CMMC program guidance.
Assessment and Certification Path
Level 2 contemplates conformity assessment against the applicable requirements, which in many implementations may involve third-party assessment through the CMMC ecosystem overseen by the CMMC Accreditation Body, or self-assessment in certain cases. Assessment is distinct from authorization, and the applicable assessment method should be confirmed against current program rules.
Relationship to DFARS Contractual Obligations
CMMC Level 2 relates to, but is not identical to, existing DFARS safeguarding and cyber incident reporting obligations. CMMC is a distinct verification mechanism and does not by itself replace the contractual clauses; readers should confirm specific clause references and their applicability against the current DFARS text.
Scope Tied to CUI Handling
Level 2 applies in contexts where a contractor or subcontractor stores, processes, or transmits CUI in connection with DoD work. Obligations for classified systems under the NISPOM and for civilian agency systems under FISMA differ, and the CUI scope for a given contract should be confirmed with the contracting activity.

Common questions

Answers to the questions practitioners most commonly ask about CMMC L2.

Does achieving a CMMC Level 2 assessment mean my systems are secure?
No. A CMMC Level 2 assessment evaluates whether an organization has implemented a defined set of security requirements, but compliance and security are not the same thing. Meeting the assessment criteria demonstrates conformance to the practices in scope as of the assessment date; it does not guarantee that a system is free from vulnerabilities or that its security posture remains adequate over time. Security requires ongoing effort, and organizations should treat a favorable assessment as evidence of conformance at a point in time rather than as a permanent state of being secure. Verify current expectations against the applicable official CMMC and DoD sources.
If I already hold a FedRAMP authorization, does that automatically satisfy CMMC Level 2?
Not automatically. FedRAMP and CMMC are distinct programs with different governing bodies, scopes, and purposes, and a FedRAMP authorization does not by itself establish CMMC Level 2 conformance. The two may involve overlapping control content in some areas, but they are assessed and administered separately, and DoD requirements are not necessarily met by a civilian-oriented cloud authorization. Organizations should confirm how, if at all, an existing authorization maps to their CMMC obligations by consulting current authoritative guidance rather than assuming equivalence.
Which information determines whether CMMC Level 2 applies to a given contract?
CMMC Level 2 is generally associated with the handling of Controlled Unclassified Information (CUI), but the specific level required is driven by contract terms rather than by an organization's own determination. Because requirements are applied through contractual mechanisms and can vary, contractors should review the actual solicitation and contract language, and confirm the applicable level and its effective requirements against current official DoD and CMMC sources. This entry does not address the contractual or legal specifics of any particular award.
How do I determine the scope of my CMMC Level 2 environment?
Scoping generally focuses on the assets that store, process, or transmit the relevant Controlled Unclassified Information, along with the components that provide security functions for or connect to those assets. Because scope decisions affect both the assessment effort and the ongoing obligations, organizations typically document their environment, data flows, and boundaries carefully. Precise scoping categories and their treatment can evolve across CMMC revisions, so confirm current scoping guidance against the applicable official CMMC documentation before finalizing a boundary.
What is the difference between a self-assessment and a third-party assessment at Level 2?
At CMMC Level 2, some situations may involve a self-assessment while others may require an assessment conducted by an authorized third party, depending on the applicable requirements. It is important to distinguish assessment from authorization: an assessment evaluates whether requirements are met, but it is not itself the contractual eligibility decision. Which path applies, and by whom an assessment must be performed, is subject to the governing program requirements, which have been rolled out and revised in phases. Verify the current requirement for your specific circumstances against official sources.
Once we meet CMMC Level 2, are we finished?
No. Conformance is not a one-time, permanent achievement. Organizations are generally expected to sustain their implemented requirements over time, which involves ongoing monitoring, maintenance, and periodic reassessment consistent with the program's provisions. Treating a favorable result as a permanent status, rather than as a time-bound demonstration subject to continued upkeep and future reassessment, is a common mistake. Confirm the applicable duration, reassessment expectations, and any continuing obligations against current authoritative CMMC and DoD guidance.

Common misconceptions

Achieving CMMC Level 2 means a system or organization is fully secure.
Compliance and certification are not the same as security. CMMC Level 2 reflects conformity to a defined set of requirements at a point in time and does not guarantee protection against all threats; ongoing security management remains necessary.
A FedRAMP authorization automatically satisfies CMMC Level 2 requirements.
FedRAMP, administered by the FedRAMP PMO, addresses cloud service authorization for federal use and does not by itself satisfy DoD CMMC obligations. The two serve different purposes, and CMMC applicability must be evaluated separately against current DoD program requirements.
A CMMC assessment result is permanent once achieved.
As with an Authority to Operate, a favorable assessment or certification is time-bound and subject to the program's continuous monitoring and re-assessment expectations. Practitioners should verify current validity periods and maintenance requirements against official CMMC program sources.

Best practices

Confirm the applicable revision of NIST SP 800-171 and the current CMMC program rules before scoping an assessment, since requirements and level structures have been subject to revision and phased rollout.
Define and document the CUI boundary precisely, identifying where CUI is stored, processed, or transmitted, and coordinate scope questions with the contracting activity.
Treat assessment and authorization as distinct activities, and plan for time-bound validity and continuous monitoring rather than assuming certification is permanent.
Do not rely on a FedRAMP authorization or existing DFARS compliance as automatic satisfaction of CMMC Level 2; evaluate each obligation independently against current authoritative sources.
Verify the correct assessment method (third-party versus self-assessment) applicable to your contract against current CMMC program guidance rather than assuming a single path.
Maintain compliance evidence and security practices as an ongoing program, recognizing that meeting the requirements does not by itself ensure the system is secure.