Skip to content

CMMC Level 2 Requirements: The Full Checklist

Every CMMC Level 2 requirement by family, with the evidence an assessor asks for and the rows a penetration test or validated scan can prove.

Invadel TeamReviewed by Omar Khandaker, Senior Security Consultant30 min read

CMMC Level 2 is 110 security requirements: the full set in NIST SP 800-171 Revision 2. This checklist lists all 110 by family. Each row shows the requirement, its point value, the evidence an assessor asks for, and whether a penetration test or a validated vulnerability scan can prove it. Use it to run a self-assessment, check your SPRS score, or get ready for a C3PAO.

One thing up front. Invadel supplies testing evidence: the penetration tests and validated scans that several of these requirements lean on. We are not a C3PAO, and we do not write System Security Plans or run CMMC programs. The checklist is free either way, and you can download it as a spreadsheet.

Status as of September 26, 2026: C3PAO certification as a condition of contract award is paused while the Department reviews the program. Self-assessments, DFARS 252.204-7012 and SPRS posting are still in force. The details are in the rollout section below.

CMMC levels at a glance

Level Who needs it Requirements Assessment
Level 1 Contractors that handle Federal Contract Information (FCI) only 15, from FAR 52.204-21 Annual self-assessment
Level 2 Contractors that handle Controlled Unclassified Information (CUI) 110, identical to NIST SP 800-171 Rev. 2 Self-assessment or C3PAO certification every three years, with an annual affirmation
Level 3 Contractors on the most sensitive programs Level 2 plus 24 from NIST SP 800-172 Government-led assessment by DIBCAC

The CMMC rule is explicit that the Level 2 requirements are “identical to the requirements in NIST SP 800-171 R2” (32 CFR 170.14). NIST published Revision 3 in May 2024, but it is not what a CMMC assessment checks. Our NIST SP 800-171 guide covers the version question, and the CMMC Level 2 penetration testing page covers the levels in more depth.

How to use this checklist

Record four things for every requirement:

  • Status. MET, NOT MET or N/A. A requirement is MET only when every one of its assessment objectives is met. NIST SP 800-171A splits the 110 requirements into 320 objectives, and one NOT MET objective fails the whole requirement. N/A counts as MET.
  • Evidence. Assessors use three methods: they examine documents and settings, interview the people who run the control, and test that it works. Evidence must be final. The Assessment Guide rules out drafts, working papers and unapproved policies.
  • Owner. One named person per requirement, with a target date for any gap.
  • POA&M eligibility. Whether a gap may sit on a Plan of Action and Milestones. That depends on the point value, as the POA&M section below explains.

The Points column is what a NOT MET requirement subtracts from your score under 32 CFR 170.24. The last column flags the rows testing can evidence:

  • Test: a penetration test report is direct evidence for some of the requirement’s objectives.
  • Scan: a validated vulnerability scan evidences it.
  • Test + scan: both apply.

A flag is not a pass. The policy and procedure objectives in a flagged row still need their own documents.

The 110 CMMC Level 2 requirements

Requirement text is NIST SP 800-171 Rev. 2. Identifiers and titles follow the DoD CMMC Assessment Guide for Level 2.

Access Control (AC): 22 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
AC.L2-3.1.1 Authorized Access Control 5 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). List of authorized users, processes and devices; account approval records; a directory export reconciled to the staff list Test
AC.L2-3.1.2 Transaction & Function Control 5 Limit system access to the types of transactions and functions that authorized users are permitted to execute. Role definitions, group-to-permission mappings, and screenshots of role limits in each CUI system Test
AC.L2-3.1.3 Control CUI Flow 1 Control the flow of CUI in accordance with approved authorizations. CUI data flow diagram, firewall and data loss prevention rules, email and file-sharing limits for CUI Test
AC.L2-3.1.4 Separation of Duties 1 Separate the duties of individuals to reduce the risk of malevolent activity without collusion. Duty matrix showing no single person can both request and approve critical functions
AC.L2-3.1.5 Least Privilege 3 Employ the principle of least privilege, including for specific security functions and privileged accounts. Privileged account list with a reason for each, access review records, local admin rights removed from users Test
AC.L2-3.1.6 Non-Privileged Account Use 1 Use non-privileged accounts or roles when accessing nonsecurity functions. Separate admin and everyday accounts for administrators, and the policy requiring them
AC.L2-3.1.7 Privileged Functions 1 Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. Controls that stop standard users running admin functions, and logs of privileged function use Test
AC.L2-3.1.8 Unsuccessful Logon Attempts 1 Limit unsuccessful logon attempts. Account lockout settings in the directory, VPN and CUI applications
AC.L2-3.1.9 Privacy & Security Notices 1 Provide privacy and security notices consistent with applicable CUI rules. Logon banner screenshots with wording consistent with CUI rules
AC.L2-3.1.10 Session Lock 1 Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. Screen lock timeout settings with a pattern-hiding display
AC.L2-3.1.11 Session Termination 1 Terminate (automatically) a user session after a defined condition. The conditions that end a session and the matching settings in VPN, remote access and applications
AC.L2-3.1.12 Control Remote Access 5 Monitor and control remote access sessions. List of permitted remote access methods, gateway logs, and how remote sessions are monitored Test
AC.L2-3.1.13 Remote Access Confidentiality 5 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. Encryption settings for VPN and every remote access protocol in use Scan
AC.L2-3.1.14 Remote Access Routing 1 Route remote access via managed access control points. Network diagram showing all remote access passes through managed access control points
AC.L2-3.1.15 Privileged Remote Access 1 Authorize remote execution of privileged commands and remote access to security-relevant information. Approval records for remote privileged commands and the restricted paths admins use
AC.L2-3.1.16 Wireless Access Authorization 5 Authorize wireless access prior to allowing such connections. Authorization records for wireless connections and a list of approved access points
AC.L2-3.1.17 Wireless Access Protection 5 Protect wireless access using authentication and encryption. Wireless authentication and encryption settings (enterprise authentication, not shared keys)
AC.L2-3.1.18 Mobile Device Connection 5 Control connection of mobile devices. Mobile device management rules and the list of devices allowed to connect
AC.L2-3.1.19 Encrypt CUI on Mobile 3 Encrypt CUI on mobile devices and mobile computing platforms. Device encryption settings enforced through mobile device management
AC.L2-3.1.20 External Connections [CUI Data] 1 Verify and control/limit connections to and use of external systems. Inventory of external systems and the terms or technical controls that limit their use
AC.L2-3.1.21 Portable Storage Use 1 Limit use of portable storage devices on external systems. Policy and technical controls limiting portable storage on external systems
AC.L2-3.1.22 Control Public Information [CUI Data] 1 Control CUI posted or processed on publicly accessible systems. Named people authorized to post publicly and the review step that keeps CUI off public sites

Awareness and Training (AT): 3 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
AT.L2-3.2.1 Role-Based Risk Awareness 5 Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. Security awareness content and completion records for managers, admins and users
AT.L2-3.2.2 Role-Based Training 5 Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. Role-specific training for staff with security duties, with completion records
AT.L2-3.2.3 Insider Threat Awareness 1 Provide security awareness training on recognizing and reporting potential indicators of insider threat. Insider threat module in the training program, with completion records

Audit and Accountability (AU): 9 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
AU.L2-3.3.1 System Auditing 5 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. Logging policy, the list of logged events, retention settings and sample log records Test
AU.L2-3.3.2 User Accountability 3 Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions. Logs that tie actions to named individual accounts, with no shared logins
AU.L2-3.3.3 Event Review 1 Review and update logged events. Records showing the logged event list is reviewed and updated
AU.L2-3.3.4 Audit Failure Alerting 1 Alert in the event of an audit logging process failure. Alert configuration for logging failures and a record of a test alert
AU.L2-3.3.5 Audit Correlation 5 Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. Log platform or SIEM correlation rules and records of investigations they started
AU.L2-3.3.6 Reduction & Reporting 1 Provide audit record reduction and report generation to support on-demand analysis and reporting. A demonstration of querying and reporting on logs on demand
AU.L2-3.3.7 Authoritative Time Source 1 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. Time synchronization settings pointing systems at an authoritative source
AU.L2-3.3.8 Audit Protection 1 Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Access controls on logs and logging tools, and protection from change or deletion
AU.L2-3.3.9 Audit Management 1 Limit management of audit logging functionality to a subset of privileged users. The short list of privileged users who can change logging settings

Configuration Management (CM): 9 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
CM.L2-3.4.1 System Baselining 5 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles. Hardware, software and firmware inventory, plus documented baseline configurations
CM.L2-3.4.2 Security Configuration Enforcement 5 Establish and enforce security configuration settings for information technology products employed in organizational systems. Hardening standards in use and authenticated scan results showing systems match them Scan
CM.L2-3.4.3 System Change Management 1 Track, review, approve or disapprove, and log changes to organizational systems. Change tickets showing review, approval or rejection, and logging
CM.L2-3.4.4 Security Impact Analysis 1 Analyze the security impact of changes prior to implementation. Security impact analysis recorded on changes before they go live
CM.L2-3.4.5 Access Restrictions for Change 5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. Who may make changes, physically and logically, and how that is enforced
CM.L2-3.4.6 Least Functionality 5 Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. Baselines showing only essential capabilities are enabled
CM.L2-3.4.7 Nonessential Functionality 5 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. List of allowed programs, ports, protocols and services, and scan results showing the rest are off Scan
CM.L2-3.4.8 Application Execution Policy 5 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. Application allowlisting or blocklisting policy and the tool configuration that enforces it
CM.L2-3.4.9 User-Installed Software 1 Control and monitor user-installed software. Policy on user-installed software and monitoring of installs

Identification and Authentication (IA): 11 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
IA.L2-3.5.1 Identification [CUI Data] 5 Identify system users, processes acting on behalf of users, and devices. Unique identifiers for users, service accounts and devices, shown in a directory export
IA.L2-3.5.2 Authentication [CUI Data] 5 Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. Authentication methods for users, processes and devices, with the settings behind them Test
IA.L2-3.5.3 Multifactor Authentication 5 (3 if MFA covers only remote and privileged users) Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. MFA policy and enforcement settings for privileged and network access, with any exceptions listed Test
IA.L2-3.5.4 Replay-Resistant Authentication 1 Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. Authentication protocols in use and evidence that legacy protocols are disabled
IA.L2-3.5.5 Identifier Reuse 1 Prevent reuse of identifiers for a defined period. Policy and practice preventing reuse of identifiers for a defined period
IA.L2-3.5.6 Identifier Handling 1 Disable identifiers after a defined period of inactivity. Setting that disables inactive accounts, and proof it runs
IA.L2-3.5.7 Password Complexity 1 Enforce a minimum password complexity and change of characters when new passwords are created. Password policy settings for length, complexity and character change
IA.L2-3.5.8 Password Reuse 1 Prohibit password reuse for a specified number of generations. Password history setting
IA.L2-3.5.9 Temporary Passwords 1 Allow temporary password use for system logons with an immediate change to a permanent password. Setting that forces a change of temporary passwords at first logon
IA.L2-3.5.10 Cryptographically-Protected Passwords 5 Store and transmit only cryptographically-protected passwords. Evidence that passwords are stored hashed and sent only over encrypted channels
IA.L2-3.5.11 Obscure Feedback 1 Obscure feedback of authentication information. Screenshots showing password entry is masked

Incident Response (IR): 3 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
IR.L2-3.6.1 Incident Handling 5 Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. Incident response plan covering preparation, detection, analysis, containment, recovery and user response
IR.L2-3.6.2 Incident Reporting 5 Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. Incident tracking records and the procedure for reporting to DoD within 72 hours under DFARS 252.204-7012
IR.L2-3.6.3 Incident Response Testing 1 Test the organizational incident response capability. Records of a tabletop or exercise that tested the incident response capability

Maintenance (MA): 6 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
MA.L2-3.7.1 Perform Maintenance 3 Perform maintenance on organizational systems. Maintenance schedule and completed maintenance records
MA.L2-3.7.2 System Maintenance Control 5 Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance. Approved maintenance tools, techniques and personnel
MA.L2-3.7.3 Equipment Sanitization 1 Ensure equipment removed for off-site maintenance is sanitized of any CUI. Sanitization records for equipment sent off-site for repair
MA.L2-3.7.4 Media Inspection 3 Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. Procedure and records for checking diagnostic media for malicious code before use
MA.L2-3.7.5 Nonlocal Maintenance 5 Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. MFA on remote maintenance sessions and settings that end them when work is done
MA.L2-3.7.6 Maintenance Personnel 1 Supervise the maintenance activities of maintenance personnel without required access authorization. Supervision records for maintenance staff who lack access authorization

Media Protection (MP): 9 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
MP.L2-3.8.1 Media Protection 3 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. Locked storage and handling rules for paper and digital CUI media
MP.L2-3.8.2 Media Access 3 Limit access to CUI on system media to authorized users. Access list for CUI media and the storage that holds it
MP.L2-3.8.3 Media Disposal [CUI Data] 5 Sanitize or destroy system media containing CUI before disposal or release for reuse. Sanitization or destruction records, such as certificates of destruction
MP.L2-3.8.4 Media Markings 1 Mark media with necessary CUI markings and distribution limitations. Examples of CUI-marked media and the marking procedure
MP.L2-3.8.5 Media Accountability 1 Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas. Transport logs and chain-of-custody records for CUI media
MP.L2-3.8.6 Portable Storage Encryption 1 Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards. Encryption settings for portable media carrying CUI outside controlled areas
MP.L2-3.8.7 Removable Media 5 Control the use of removable media on system components. Technical controls restricting removable media on system components
MP.L2-3.8.8 Shared Media 3 Prohibit the use of portable storage devices when such devices have no identifiable owner. Policy and controls blocking portable storage devices with no identifiable owner
MP.L2-3.8.9 Protect Backups 1 Protect the confidentiality of backup CUI at storage locations. Encryption and access controls for backups that hold CUI

Personnel Security (PS): 2 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
PS.L2-3.9.1 Screen Individuals 3 Screen individuals prior to authorizing access to organizational systems containing CUI. Screening records completed before access to CUI systems
PS.L2-3.9.2 Personnel Actions 5 Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. Offboarding and transfer checklists showing access removed and equipment returned

Physical Protection (PE): 6 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
PE.L2-3.10.1 Limit Physical Access [CUI Data] 5 Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals. Access lists for the facility, server rooms and equipment areas
PE.L2-3.10.2 Monitor Facility 5 Protect and monitor the physical facility and support infrastructure for organizational systems. Alarm, camera or guard monitoring records for the facility and support infrastructure
PE.L2-3.10.3 Escort Visitors [CUI Data] 1 Escort visitors and monitor visitor activity. Visitor escort policy and the practice an assessor can observe
PE.L2-3.10.4 Physical Access Logs [CUI Data] 1 Maintain audit logs of physical access. Visitor logs and badge access logs, retained
PE.L2-3.10.5 Manage Physical Access [CUI Data] 1 Control and manage physical access devices. Key and badge inventory and records of lock or combination changes
PE.L2-3.10.6 Alternative Work Sites 1 Enforce safeguarding measures for CUI at alternate work sites. Safeguards required for CUI at home and other alternate work sites

Risk Assessment (RA): 3 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
RA.L2-3.11.1 Risk Assessments 3 Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. A periodic risk assessment covering operations, assets and people, with its date
RA.L2-3.11.2 Vulnerability Scan 5 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. Defined scan frequency, scan results for systems and applications, and scans run after new advisories Scan
RA.L2-3.11.3 Vulnerability Remediation 1 Remediate vulnerabilities in accordance with risk assessments. Remediation records ranked by risk, and rescans or retests showing the fixes held Test + scan

Security Assessment (CA): 4 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
CA.L2-3.12.1 Security Control Assessment 5 Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. Defined assessment frequency and the assessment reports themselves Test
CA.L2-3.12.2 Operational Plan of Action 3 Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. Plans of action listing each deficiency, owner, milestone and progress
CA.L2-3.12.3 Security Control Monitoring 5 Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. The ongoing monitoring process and its recent outputs
CA.L2-3.12.4 System Security Plan No SSP, no assessment Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. A current SSP covering boundaries, environment, how each requirement is met, and connections

System and Communications Protection (SC): 16 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
SC.L2-3.13.1 Boundary Protection [CUI Data] 5 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. Diagram of external and key internal boundaries, firewall rules, and boundary monitoring Test + scan
SC.L2-3.13.2 Security Engineering 5 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. Documented architecture and development practices that apply security principles
SC.L2-3.13.3 Role Separation 1 Separate user functionality from system management functionality. Separate interfaces and accounts for administration and everyday use
SC.L2-3.13.4 Shared Resource Control 1 Prevent unauthorized and unintended information transfer via shared system resources. Controls that stop information leaking through shared system resources
SC.L2-3.13.5 Public-Access System Separation [CUI Data] 5 Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. A separate subnet (DMZ) for public-facing systems and the rules around it Test
SC.L2-3.13.6 Network Communication by Exception 5 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). Default-deny firewall rules with each exception documented Test
SC.L2-3.13.7 Split Tunneling 1 Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). VPN configuration that prevents split tunneling Test
SC.L2-3.13.8 Data in Transit 3 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. TLS and VPN settings that protect CUI in transit Scan
SC.L2-3.13.9 Connections Termination 1 Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. Idle timeout settings for network sessions
SC.L2-3.13.10 Key Management 1 Establish and manage cryptographic keys for cryptography employed in organizational systems. Key management procedure and an inventory of keys and certificates
SC.L2-3.13.11 CUI Encryption 5 (3 if encryption is not FIPS-validated) Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. FIPS 140 validation certificate numbers for the cryptographic modules that protect CUI
SC.L2-3.13.12 Collaborative Device Control 1 Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device. Settings that block remote activation of cameras and microphones and show when they are in use
SC.L2-3.13.13 Mobile Code 1 Control and monitor the use of mobile code. Policy and controls on mobile code such as macros and scripts
SC.L2-3.13.14 Voice over Internet Protocol 1 Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. VoIP inventory, configuration and monitoring
SC.L2-3.13.15 Communications Authenticity 5 Protect the authenticity of communications sessions. Controls that protect session authenticity, such as certificates and signing
SC.L2-3.13.16 Data at Rest 1 Protect the confidentiality of CUI at rest. Encryption or other protection for stored CUI

System and Information Integrity (SI): 7 requirements

Requirement Points What it requires Evidence an assessor asks for Test or scan
SI.L2-3.14.1 Flaw Remediation [CUI Data] 5 Identify, report, and correct system flaws in a timely manner. Patch process, patch compliance reports and time-to-fix records Test + scan
SI.L2-3.14.2 Malicious Code Protection [CUI Data] 5 Provide protection from malicious code at designated locations within organizational systems. Endpoint protection coverage report for the designated locations
SI.L2-3.14.3 Security Alerts & Advisories 5 Monitor system security alerts and advisories and take action in response. Advisory sources monitored and records of action taken
SI.L2-3.14.4 Update Malicious Code Protection [CUI Data] 5 Update malicious code protection mechanisms when new releases are available. Automatic update settings for endpoint protection
SI.L2-3.14.5 System & File Scanning [CUI Data] 3 Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed. Scheduled scan settings and real-time scanning of downloaded or opened files
SI.L2-3.14.6 Monitor Communications for Attacks 5 Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. Inbound and outbound monitoring tools, their alerts, and who reviews them Test
SI.L2-3.14.7 Identify Unauthorized Use 3 Identify unauthorized use of organizational systems. A definition of authorized use and the monitoring that spots unauthorized use Test

Requirements a penetration test or validated scan can prove

Twenty-three of the 110 rows are flagged. They fall into five groups.

Security control assessment (CA.L2-3.12.1). The requirement is to assess, on a schedule, whether your controls work. A penetration test is that assessment, run against the live controls rather than the paperwork. It is also the requirement to point to when a prime asks why you test.

Vulnerability scanning and remediation (RA.L2-3.11.2, RA.L2-3.11.3, SI.L2-3.14.1). Scans must run at a defined frequency on systems and applications, and again when new vulnerabilities are announced. The Assessment Guide says every in-scope asset must be scanned, including laptops that rarely connect to the network. For custom software it adds that analysis “may require a penetration tester to properly test and validate findings.” Validated scans, plus rescans after the fixes, cover the scanning and remediation rows.

Boundaries and segmentation (SC.L2-3.13.1, SC.L2-3.13.5, SC.L2-3.13.6, SC.L2-3.13.7, AC.L2-3.1.3). An external test proves what the internet can reach. An internal test from a foothold in the corporate network proves whether the CUI enclave boundary holds, whether traffic is denied by default, whether VPN clients can split-tunnel, and whether CUI can flow where it should not.

Access, authentication and detection (AC.L2-3.1.1, AC.L2-3.1.2, AC.L2-3.1.5, AC.L2-3.1.7, AC.L2-3.1.12, IA.L2-3.5.2, IA.L2-3.5.3, AU.L2-3.3.1, SI.L2-3.14.6, SI.L2-3.14.7). Testing shows whether access is limited to authorized users and functions, whether a standard user can gain admin rights, whether MFA is enforced where the requirement says it must be, and whether your logging and monitoring caught the test.

Configuration and encryption (CM.L2-3.4.2, CM.L2-3.4.7, AC.L2-3.1.13, SC.L2-3.13.8). An authenticated scan compares settings to your hardening standard, finds ports and services that should be off, and flags weak or missing encryption on remote access and data in transit. A scan cannot prove FIPS validation for SC.L2-3.13.11. That row needs the certificate numbers for your cryptographic modules.

Two more families can be checked on site, although their rows ask mainly for records. For wireless access (AC.L2-3.1.16, AC.L2-3.1.17), wireless penetration testing shows whether enterprise authentication and encryption hold. For physical protection (the PE family), a physical penetration test shows whether badge and visitor controls stop an outsider.

Our NIST SP 800-171 penetration testing guide explains how a test evidences each of these practices and how the findings feed the SSP and the POA&M.

SPRS scoring and the POA&M rules

The score starts at 110. Each NOT MET requirement subtracts its value of 5, 3 or 1 point. Forty-four requirements are worth 5 points, 14 are worth 3, and 51 are worth 1. The SSP requirement (CA.L2-3.12.4) carries no points, because without a current SSP the assessment cannot be completed. If every requirement were NOT MET, the score would be -203.

Two requirements allow partial credit:

  • IA.L2-3.5.3 Multifactor Authentication: 3 points off if MFA covers only remote and privileged users, 5 if it covers none.
  • SC.L2-3.13.11 CUI Encryption: 3 points off if encryption is used but is not FIPS-validated, 5 if there is no encryption.

A POA&M lets you reach Conditional status with some gaps still open. The limits come from 32 CFR 170.21:

Rule Detail
Minimum score At least 88, which is 80% of 110
Gaps that may stay open 1-point requirements only, plus SC.L2-3.13.11 when encryption is used but not FIPS-validated
Never on a POA&M AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5, and every 3-point or 5-point requirement
Deadline Close every item and confirm it in a closeout assessment within 180 days of the Conditional status date, or the status expires

In practice, every requirement worth 3 or 5 points must be MET on assessment day. The one exception is SC.L2-3.13.11 when encryption is in place but not FIPS-validated. Those requirements include MFA, vulnerability scanning, security control assessment and boundary protection. Those are the rows to test first, early enough to fix what the test finds.

Keep two plans apart. The operational plan of action under CA.L2-3.12.2 is an everyday management tool. The Assessment Guide and 32 CFR 170.24 both say temporary deficiencies handled properly in operational plans of action, and enduring exceptions described in the SSP, are assessed as MET. The assessment POA&M is the limited list of open gaps allowed at Conditional status.

Self-assessment or C3PAO, and where the rollout stands

Level 2 has two routes:

  • Level 2 (Self). You score yourself, post the result in SPRS, and a senior official affirms it at the time of the assessment and every year after. You repeat it every three years. POA&M items must be closed, and the closeout posted to SPRS, within 180 days (32 CFR 170.16).
  • Level 2 (C3PAO). A Certified Third-Party Assessment Organization checks every requirement against your evidence. Most contracts involving CUI were set to require this route.

The timeline, as set out on our CMMC Level 2 page: 32 CFR Part 170 took effect on December 16, 2024. The DFARS rule that puts CMMC clauses into contracts took effect on November 10, 2025 and started a phased rollout. Phase 2, which would make C3PAO certification a condition of award for most Level 2 contracts, was due on November 10, 2026.

On July 13, 2026 the Department paused Phase 2 and the later phases and started a 60-day review (WilmerHale). Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev. 2 and SPRS posting stay in effect. The review’s report was due on September 11, 2026 and had not been made public by late September (Inside Government Contracts). Confirm the current phase with your contracting officer. A self-assessment done now is the same work a C3PAO will check later.

Using the Level 2 Assessment Guide

The CMMC Assessment Guide for Level 2 (version 2.13, September 2024) is the assessor’s reference for every row in this checklist. For each requirement it gives:

  • the assessment objectives from NIST SP 800-171A, lettered [a], [b] and so on;
  • what an assessor may examine, who they may interview, and what they may test;
  • a plain-language discussion and a short example;
  • assessment considerations, which read like the assessor’s own questions.

Work through the objectives for the 58 requirements worth 3 or 5 points first. The guide explains that interviews tell the assessor what staff believe is true, documents show the policies and procedures, and testing shows what has actually been done. It adds that most objectives will require testing.

Enclave scoping: the biggest cost lever

Many contractors, including the manufacturers and construction and engineering firms in the defense supply chain, keep CMMC affordable by scoping it to an enclave: a segmented environment where CUI lives, so the 110 requirements apply to a few dozen systems instead of the whole company. That works only if the segmentation is real. How to test the enclave boundary, and what assessors look for, is covered on our CMMC Level 2 penetration testing page.

Download the checklist

The spreadsheet has all 110 rows with the official requirement text, the number of assessment objectives, the point value, POA&M eligibility, the evidence list and the test or scan flag. It adds Status, Partial credit, Points deducted, Evidence location, Owner, Target date and Notes columns. A Summary sheet calculates your score as you mark rows and checks it against the 88-point and POA&M rules.

Download the CMMC Level 2 checklist (XLSX)

Testing evidence at a fixed price

Two tests scoped to the CUI environment cover most of the flagged rows: an external network penetration test from $4,200 and an internal network penetration test from $6,000. Validated vulnerability scanning for RA.L2-3.11.2 is $1,500 per scan for up to 250 devices, with a free re-scan of what you fix.

Every price is fixed in writing before work starts. Every penetration test includes a free retest, so the report shows the gaps closed. Each finding names the requirement it touches, ready for your SSP, your POA&M or your assessor. See CMMC Level 2 penetration testing for the full scope, or scope your test and get the price in writing.

Frequently asked questions

How many requirements are in CMMC Level 2? 110, in 14 families, identical to NIST SP 800-171 Rev. 2. They break down into 320 assessment objectives.

Does CMMC Level 2 use NIST SP 800-171 Revision 3? No. The CMMC rule ties Level 2 to Revision 2, and that is what assessors check today.

Can we be certified with gaps still open? Yes, as Conditional status, if the score is at least 88 and every open gap is allowed on a POA&M. That means a 1-point requirement that is not on the excluded list, or SC.L2-3.13.11 when encryption is used but not FIPS-validated. The gaps must be closed within 180 days.

Does CMMC Level 2 require a penetration test? Not by name. CA.L2-3.12.1 requires you to assess whether your controls work, and RA.L2-3.11.2 and RA.L2-3.11.3 require scanning and remediation. A penetration test and validated scans are the most direct evidence for those rows. Our compliance frameworks guide compares CMMC with the frameworks that name testing outright.

What is the difference between this checklist and a System Security Plan? The checklist tracks status, owners and evidence. The SSP is a required document (CA.L2-3.12.4) that describes your boundary, your environment and how each requirement is met. Without a current SSP there is no assessment.

Do we still need to do this while Phase 2 is paused? Yes. DFARS 252.204-7012 still requires the NIST SP 800-171 controls, self-assessments are still required, and primes are still asking suppliers for Level 2 evidence.

Can Invadel run our CMMC assessment? No. We are not a C3PAO and we do not write SSPs. We run the penetration tests and validated scans that give your assessor objective evidence, and we keep that work independent of your assessment.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation