Most of what gets sold as CMMC readiness is a binder. The binder is not the point. Level 2 is a question about whether your shop can protect the government's information inside the work you already do, and a 50-person manufacturer answers that question in the way it runs the floor, not in a folder of PDFs the auditor will never see running.
This is the operational version of the playbook. It treats the 110 controls as work to be designed into the process, scopes the data so you are not assessing the whole company, and builds toward a clean assessment instead of a rushed one.
What does CMMC Level 2 actually require?
CMMC Level 2 requires you to implement all 110 security controls in NIST SP 800-171 Revision 2. As of July 2026 those controls are verified by a self-assessment every three years plus an annual affirmation of compliance, because on July 13, 2026 the Department suspended CMMC Phase II, the phase that would have made third-party certification a contract condition. NIST SP 800-171 (the National Institute of Standards and Technology publication that defines how non-federal organizations protect Controlled Unclassified Information) is the substance of Level 2. CMMC (Cybersecurity Maturity Model Certification) is the program the Department of Defense built to verify that you actually did it.
The controls did not change. The way they get checked did.
The 110 controls are grouped into 14 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. They cover both your IT systems and the people who touch them.
The trigger for all of this is Controlled Unclassified Information, or CUI. CUI is government information that is sensitive but not classified, things like technical drawings, specifications, and process data marked for protection under a contract. If a prime sends you CUI to make a part, Level 2 is on your road map.
How do I scope a CUI enclave instead of spreading CUI everywhere?
You scope a CUI enclave by deciding, on purpose, exactly which systems and people are allowed to store, process, or transmit CUI, then keeping it out of everywhere else. This single decision drives the cost and the difficulty of the entire assessment.
When CUI is allowed to spread across every laptop, every shared drive, and every machine controller on the floor, your assessment boundary becomes the whole company. Every device in that boundary has to meet all 110 controls. When you draw a tight enclave, a defined set of systems where the protected work lives, the assessor evaluates the enclave and the supporting infrastructure, not the entire shop.
The enclave decision is the highest-leverage move you make. A wide boundary turns a manageable project into a company-wide overhaul. A tight, deliberate boundary keeps the spend on the systems that actually hold protected data.
In practice this means:
- One defined place for CUI to live, with controlled access, instead of email attachments and desktop folders.
- A data flow that you can draw on one page: where CUI enters, who touches it, where it rests, how it leaves.
- The rest of the company kept outside the boundary by policy and by technical control, so it stays out of scope.
I architect this enclave before any control gets implemented, because implementing 110 controls against the wrong boundary is the most expensive mistake a shop can make.
What are the SSP and POA&M, and why do they matter?
The System Security Plan, or SSP, is the written description of how your systems meet each of the 110 controls, and the Plan of Action and Milestones, or POA&M, is the documented schedule for closing any control you have not fully met yet. Together they are the spine of your assessment package.
The SSP is not marketing copy. It states, control by control, what is in place, how it is implemented, and who owns it. An assessor reads the SSP first and then verifies that reality matches it.
The POA&M exists because few shops meet all 110 controls on day one. CMMC permits a limited set of controls to be open at assessment time, provided each one is on a POA&M with a remediation date, and provided you close them inside the allowed window. The catch is that the highest-weighted controls cannot sit on a POA&M, so the plan has to be honest about which gaps are allowed and which are blockers.
Your SPRS score ties directly into this. The Supplier Performance Risk System holds your self-assessed NIST SP 800-171 score, calculated by subtracting points for unmet controls from a baseline of 110. The DoD can see it, and a prime cannot award you a covered subcontract until you have a current one on file. A score that does not match your SSP is a defect waiting to be found, and under the DFARS clauses (Defense Federal Acquisition Regulation Supplement) a false affirmation is a False Claims Act exposure the Department of Justice Civil Cyber-Fraud Initiative has shown it will pursue. In June 2026 a Huntsville defense contractor paid $507,144 to settle exactly that case, after a government assessment scored its environment at negative 170.
What is the path to a defensible Level 2 assessment?
The path runs from scoping to an honest self-assessment to gap remediation to an affirmation you can defend, and as of July 2026 it ends there rather than at a third-party certificate. The sequence matters as much as the controls, and the suspension of Phase II did not remove a single step from it.
A defensible order looks like this:
- Scope the enclave and draw the CUI data flow.
- Self-assess against all 110 controls and post an honest SPRS score.
- Write the SSP to reflect actual implementation, not aspiration.
- Remediate the gaps, closing the highest-weighted controls first, and put the rest on a POA&M with real dates.
- Run a readiness review to confirm the SSP matches the floor. Your annual affirmation says it does, and you are the one signing it.
- Affirm annually and re-assess every three years, which is what Level 2 requires as of July 2026, keeping the SPRS score current as the environment changes.
The timing is still not optional, and the reason changed on July 13, 2026. That day the Department suspended CMMC Phase II, the phase originally scheduled for November 10, 2026 that would have made Level 2 third-party certification a contract condition, and stood up a reform task force to review the program. Phase I stayed. In the Department's own words, the action "does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012." During the review the Department enforces NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments.
Read that carefully, because it is the opposite of a reprieve. The certificate paused. The safeguarding clause, the self-assessment, the annual affirmation, and the SPRS score your primes have to ask you for are all in force today. Boeing has already told suppliers in writing that the specified CMMC level will be a condition of winning a contract award. A shop that reads the suspension as permission to wait is a shop carrying a live DFARS clause, a stale score, and no assessor on the calendar to tell it so.
On cost, most small defense manufacturers spend roughly 100,000 to 200,000 dollars to reach Level 2, per CMMC.com. The DoD's own published assessment estimates put a Level 2 self-assessment at 37,000 to 49,000 dollars and a Level 2 C3PAO assessment at 105,000 to 118,000 dollars, before remediation. With third-party assessment suspended, the self-assessment line is the one on your budget today, and the remediation behind it is unchanged. Whether that money buys a working system or a binder depends entirely on how the controls get implemented.
How do I hardwire CMMC into daily workflow instead of a binder?
You hardwire CMMC by building each control into the process step where the work already happens, so the evidence is generated as a by-product of running the shop rather than assembled before an audit. This is the difference between compliance that holds and compliance that decays the day after the assessor leaves.
A binder approach writes a policy, files it, and hopes people follow it. It produces a clean folder and a floor that does something else. The hardwired approach makes the secure path the only path:
- Access control lives in how accounts are provisioned when an employee starts, not in a sign-in sheet.
- Audit logging runs continuously across the systems in the enclave, so the records exist whether or not anyone remembers to collect them.
- Media protection and configuration management are built into how machines and drives are set up, so a new asset enters the boundary already configured to the standard.
- Incident response is a rehearsed routine with named owners, not a paragraph nobody has read.
When I install this, the control is the work. The assessor walks the floor and finds the practices already running, with evidence accumulating on its own. That is what turns a six-figure compliance spend into an operating capability instead of a one-time event.
The bottom line
CMMC Level 2 for a 50-person shop is an operations project wearing a cybersecurity label. Scope a tight CUI enclave first, write an SSP that matches reality, keep an honest SPRS score, and build the 110 controls into the daily workflow so the evidence generates itself. Start the sequence on the strength of a DFARS clause that binds today rather than a date on a calendar, and Level 2 becomes a capability you keep rather than a binder you shelve.
Sources
- DoD CIO, About CMMC. The July 13, 2026 suspension of Phase II, the reform task force, the Phase 1 pause, and Level 2 as a self-assessment every three years with annual affirmation against the 110 security requirements in NIST SP 800-171 Revision 2. Also the source for the 110 count and for the CUI definition at 32 CFR 2002.4(h). Retrieved July 16, 2026.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. The clause that imposes the NIST SP 800-171 requirement and that the suspension explicitly leaves in force. Retrieved July 16, 2026.
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements. The requirement to hold a current assessment, not more than three years old, to be considered for award, and to verify the score is posted in SPRS. Retrieved July 16, 2026.
- NIST SP 800-171 Revision 2. The 14 control families listed in this article, and the passage permitting a shop to limit scope by isolating CUI in a separate security domain, which is the enclave approach. Note that NIST withdrew Revision 2 in May 2024 in favor of Revision 3; it still governs DoD work because 32 CFR 170 incorporates Revision 2 by reference.
- 32 CFR 170.21, Plan of Action and Milestones requirements. The POA&M rules: the 80 percent threshold, the bar on POA&M items worth more than one point, the six requirements that may never sit on a POA&M, and the 180-day closeout window.
- 32 CFR 170.24, CMMC Scoring Methodology. How the score is computed, the 5, 3, and 1 point deductions, and the rule that an assessment cannot be completed without a current SSP.
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1. The scoring baseline: a score of 110 when every requirement is implemented, reduced by the value of each one that is not, which may result in a negative score.
- CMMC Program final rule, 89 FR, October 15, 2024. The DoD assessment cost estimates cited here. The published three-year figures are $37,196 for a small-entity Level 2 self-assessment rising to $48,827 for a larger entity, and $104,670 for a small-entity Level 2 certification assessment rising to $117,768. They cover assessment and affirmation only, not remediation, because implementing NIST SP 800-171 was already required.
- CMMC.com, The True Cost of CMMC 2.0. The $100,000 to $200,000 all-in budget range. A vendor estimate, not a government figure, and cited as such. Retrieved July 16, 2026.
- Boeing supplier letter on CMMC. Boeing telling suppliers that, as a condition of winning a contract award, those handling FCI and CUI will be required to hold the CMMC level named in the solicitation. Retrieved July 16, 2026.
- DOJ, Alabama defense contractor pays $507,144 to resolve False Claims Act cybersecurity liability. The June 18, 2026 LOGZONE settlement, including the government assessment that scored the contractor at negative 170 against a possible range of negative 203 to 110.
- 31 U.S.C. § 3729. The False Claims Act, including treble damages and the per-claim civil penalty behind the affirmation risk described here.
