CMMC Level 2 is 110 security requirements: the full set in NIST SP 800-171 Revision 2. This checklist lists all 110 by family. Each row shows the requirement, its point value, the evidence an assessor asks for, and whether a penetration test or a validated vulnerability scan can prove it. Use it to run a self-assessment, check your SPRS score, or get ready for a C3PAO.
One thing up front. Invadel supplies testing evidence: the penetration tests and validated scans that several of these requirements lean on. We are not a C3PAO, and we do not write System Security Plans or run CMMC programs. The checklist is free either way, and you can download it as a spreadsheet.
Status as of September 26, 2026: C3PAO certification as a condition of contract award is paused while the Department reviews the program. Self-assessments, DFARS 252.204-7012 and SPRS posting are still in force. The details are in the rollout section below.
CMMC levels at a glance
| Level | Who needs it | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Contractors that handle Federal Contract Information (FCI) only | 15, from FAR 52.204-21 | Annual self-assessment |
| Level 2 | Contractors that handle Controlled Unclassified Information (CUI) | 110, identical to NIST SP 800-171 Rev. 2 | Self-assessment or C3PAO certification every three years, with an annual affirmation |
| Level 3 | Contractors on the most sensitive programs | Level 2 plus 24 from NIST SP 800-172 | Government-led assessment by DIBCAC |
The CMMC rule is explicit that the Level 2 requirements are “identical to the requirements in NIST SP 800-171 R2” (32 CFR 170.14). NIST published Revision 3 in May 2024, but it is not what a CMMC assessment checks. Our NIST SP 800-171 guide covers the version question, and the CMMC Level 2 penetration testing page covers the levels in more depth.
How to use this checklist
Record four things for every requirement:
- Status. MET, NOT MET or N/A. A requirement is MET only when every one of its assessment objectives is met. NIST SP 800-171A splits the 110 requirements into 320 objectives, and one NOT MET objective fails the whole requirement. N/A counts as MET.
- Evidence. Assessors use three methods: they examine documents and settings, interview the people who run the control, and test that it works. Evidence must be final. The Assessment Guide rules out drafts, working papers and unapproved policies.
- Owner. One named person per requirement, with a target date for any gap.
- POA&M eligibility. Whether a gap may sit on a Plan of Action and Milestones. That depends on the point value, as the POA&M section below explains.
The Points column is what a NOT MET requirement subtracts from your score under 32 CFR 170.24. The last column flags the rows testing can evidence:
- Test: a penetration test report is direct evidence for some of the requirement’s objectives.
- Scan: a validated vulnerability scan evidences it.
- Test + scan: both apply.
A flag is not a pass. The policy and procedure objectives in a flagged row still need their own documents.
The 110 CMMC Level 2 requirements
Requirement text is NIST SP 800-171 Rev. 2. Identifiers and titles follow the DoD CMMC Assessment Guide for Level 2.
Access Control (AC): 22 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| AC.L2-3.1.1 Authorized Access Control | 5 | Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). | List of authorized users, processes and devices; account approval records; a directory export reconciled to the staff list | Test |
| AC.L2-3.1.2 Transaction & Function Control | 5 | Limit system access to the types of transactions and functions that authorized users are permitted to execute. | Role definitions, group-to-permission mappings, and screenshots of role limits in each CUI system | Test |
| AC.L2-3.1.3 Control CUI Flow | 1 | Control the flow of CUI in accordance with approved authorizations. | CUI data flow diagram, firewall and data loss prevention rules, email and file-sharing limits for CUI | Test |
| AC.L2-3.1.4 Separation of Duties | 1 | Separate the duties of individuals to reduce the risk of malevolent activity without collusion. | Duty matrix showing no single person can both request and approve critical functions | |
| AC.L2-3.1.5 Least Privilege | 3 | Employ the principle of least privilege, including for specific security functions and privileged accounts. | Privileged account list with a reason for each, access review records, local admin rights removed from users | Test |
| AC.L2-3.1.6 Non-Privileged Account Use | 1 | Use non-privileged accounts or roles when accessing nonsecurity functions. | Separate admin and everyday accounts for administrators, and the policy requiring them | |
| AC.L2-3.1.7 Privileged Functions | 1 | Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. | Controls that stop standard users running admin functions, and logs of privileged function use | Test |
| AC.L2-3.1.8 Unsuccessful Logon Attempts | 1 | Limit unsuccessful logon attempts. | Account lockout settings in the directory, VPN and CUI applications | |
| AC.L2-3.1.9 Privacy & Security Notices | 1 | Provide privacy and security notices consistent with applicable CUI rules. | Logon banner screenshots with wording consistent with CUI rules | |
| AC.L2-3.1.10 Session Lock | 1 | Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. | Screen lock timeout settings with a pattern-hiding display | |
| AC.L2-3.1.11 Session Termination | 1 | Terminate (automatically) a user session after a defined condition. | The conditions that end a session and the matching settings in VPN, remote access and applications | |
| AC.L2-3.1.12 Control Remote Access | 5 | Monitor and control remote access sessions. | List of permitted remote access methods, gateway logs, and how remote sessions are monitored | Test |
| AC.L2-3.1.13 Remote Access Confidentiality | 5 | Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. | Encryption settings for VPN and every remote access protocol in use | Scan |
| AC.L2-3.1.14 Remote Access Routing | 1 | Route remote access via managed access control points. | Network diagram showing all remote access passes through managed access control points | |
| AC.L2-3.1.15 Privileged Remote Access | 1 | Authorize remote execution of privileged commands and remote access to security-relevant information. | Approval records for remote privileged commands and the restricted paths admins use | |
| AC.L2-3.1.16 Wireless Access Authorization | 5 | Authorize wireless access prior to allowing such connections. | Authorization records for wireless connections and a list of approved access points | |
| AC.L2-3.1.17 Wireless Access Protection | 5 | Protect wireless access using authentication and encryption. | Wireless authentication and encryption settings (enterprise authentication, not shared keys) | |
| AC.L2-3.1.18 Mobile Device Connection | 5 | Control connection of mobile devices. | Mobile device management rules and the list of devices allowed to connect | |
| AC.L2-3.1.19 Encrypt CUI on Mobile | 3 | Encrypt CUI on mobile devices and mobile computing platforms. | Device encryption settings enforced through mobile device management | |
| AC.L2-3.1.20 External Connections [CUI Data] | 1 | Verify and control/limit connections to and use of external systems. | Inventory of external systems and the terms or technical controls that limit their use | |
| AC.L2-3.1.21 Portable Storage Use | 1 | Limit use of portable storage devices on external systems. | Policy and technical controls limiting portable storage on external systems | |
| AC.L2-3.1.22 Control Public Information [CUI Data] | 1 | Control CUI posted or processed on publicly accessible systems. | Named people authorized to post publicly and the review step that keeps CUI off public sites |
Awareness and Training (AT): 3 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| AT.L2-3.2.1 Role-Based Risk Awareness | 5 | Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. | Security awareness content and completion records for managers, admins and users | |
| AT.L2-3.2.2 Role-Based Training | 5 | Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. | Role-specific training for staff with security duties, with completion records | |
| AT.L2-3.2.3 Insider Threat Awareness | 1 | Provide security awareness training on recognizing and reporting potential indicators of insider threat. | Insider threat module in the training program, with completion records |
Audit and Accountability (AU): 9 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| AU.L2-3.3.1 System Auditing | 5 | Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. | Logging policy, the list of logged events, retention settings and sample log records | Test |
| AU.L2-3.3.2 User Accountability | 3 | Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions. | Logs that tie actions to named individual accounts, with no shared logins | |
| AU.L2-3.3.3 Event Review | 1 | Review and update logged events. | Records showing the logged event list is reviewed and updated | |
| AU.L2-3.3.4 Audit Failure Alerting | 1 | Alert in the event of an audit logging process failure. | Alert configuration for logging failures and a record of a test alert | |
| AU.L2-3.3.5 Audit Correlation | 5 | Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. | Log platform or SIEM correlation rules and records of investigations they started | |
| AU.L2-3.3.6 Reduction & Reporting | 1 | Provide audit record reduction and report generation to support on-demand analysis and reporting. | A demonstration of querying and reporting on logs on demand | |
| AU.L2-3.3.7 Authoritative Time Source | 1 | Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. | Time synchronization settings pointing systems at an authoritative source | |
| AU.L2-3.3.8 Audit Protection | 1 | Protect audit information and audit logging tools from unauthorized access, modification, and deletion. | Access controls on logs and logging tools, and protection from change or deletion | |
| AU.L2-3.3.9 Audit Management | 1 | Limit management of audit logging functionality to a subset of privileged users. | The short list of privileged users who can change logging settings |
Configuration Management (CM): 9 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| CM.L2-3.4.1 System Baselining | 5 | Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles. | Hardware, software and firmware inventory, plus documented baseline configurations | |
| CM.L2-3.4.2 Security Configuration Enforcement | 5 | Establish and enforce security configuration settings for information technology products employed in organizational systems. | Hardening standards in use and authenticated scan results showing systems match them | Scan |
| CM.L2-3.4.3 System Change Management | 1 | Track, review, approve or disapprove, and log changes to organizational systems. | Change tickets showing review, approval or rejection, and logging | |
| CM.L2-3.4.4 Security Impact Analysis | 1 | Analyze the security impact of changes prior to implementation. | Security impact analysis recorded on changes before they go live | |
| CM.L2-3.4.5 Access Restrictions for Change | 5 | Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. | Who may make changes, physically and logically, and how that is enforced | |
| CM.L2-3.4.6 Least Functionality | 5 | Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. | Baselines showing only essential capabilities are enabled | |
| CM.L2-3.4.7 Nonessential Functionality | 5 | Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. | List of allowed programs, ports, protocols and services, and scan results showing the rest are off | Scan |
| CM.L2-3.4.8 Application Execution Policy | 5 | Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. | Application allowlisting or blocklisting policy and the tool configuration that enforces it | |
| CM.L2-3.4.9 User-Installed Software | 1 | Control and monitor user-installed software. | Policy on user-installed software and monitoring of installs |
Identification and Authentication (IA): 11 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| IA.L2-3.5.1 Identification [CUI Data] | 5 | Identify system users, processes acting on behalf of users, and devices. | Unique identifiers for users, service accounts and devices, shown in a directory export | |
| IA.L2-3.5.2 Authentication [CUI Data] | 5 | Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. | Authentication methods for users, processes and devices, with the settings behind them | Test |
| IA.L2-3.5.3 Multifactor Authentication | 5 (3 if MFA covers only remote and privileged users) | Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. | MFA policy and enforcement settings for privileged and network access, with any exceptions listed | Test |
| IA.L2-3.5.4 Replay-Resistant Authentication | 1 | Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. | Authentication protocols in use and evidence that legacy protocols are disabled | |
| IA.L2-3.5.5 Identifier Reuse | 1 | Prevent reuse of identifiers for a defined period. | Policy and practice preventing reuse of identifiers for a defined period | |
| IA.L2-3.5.6 Identifier Handling | 1 | Disable identifiers after a defined period of inactivity. | Setting that disables inactive accounts, and proof it runs | |
| IA.L2-3.5.7 Password Complexity | 1 | Enforce a minimum password complexity and change of characters when new passwords are created. | Password policy settings for length, complexity and character change | |
| IA.L2-3.5.8 Password Reuse | 1 | Prohibit password reuse for a specified number of generations. | Password history setting | |
| IA.L2-3.5.9 Temporary Passwords | 1 | Allow temporary password use for system logons with an immediate change to a permanent password. | Setting that forces a change of temporary passwords at first logon | |
| IA.L2-3.5.10 Cryptographically-Protected Passwords | 5 | Store and transmit only cryptographically-protected passwords. | Evidence that passwords are stored hashed and sent only over encrypted channels | |
| IA.L2-3.5.11 Obscure Feedback | 1 | Obscure feedback of authentication information. | Screenshots showing password entry is masked |
Incident Response (IR): 3 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| IR.L2-3.6.1 Incident Handling | 5 | Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. | Incident response plan covering preparation, detection, analysis, containment, recovery and user response | |
| IR.L2-3.6.2 Incident Reporting | 5 | Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. | Incident tracking records and the procedure for reporting to DoD within 72 hours under DFARS 252.204-7012 | |
| IR.L2-3.6.3 Incident Response Testing | 1 | Test the organizational incident response capability. | Records of a tabletop or exercise that tested the incident response capability |
Maintenance (MA): 6 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| MA.L2-3.7.1 Perform Maintenance | 3 | Perform maintenance on organizational systems. | Maintenance schedule and completed maintenance records | |
| MA.L2-3.7.2 System Maintenance Control | 5 | Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance. | Approved maintenance tools, techniques and personnel | |
| MA.L2-3.7.3 Equipment Sanitization | 1 | Ensure equipment removed for off-site maintenance is sanitized of any CUI. | Sanitization records for equipment sent off-site for repair | |
| MA.L2-3.7.4 Media Inspection | 3 | Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. | Procedure and records for checking diagnostic media for malicious code before use | |
| MA.L2-3.7.5 Nonlocal Maintenance | 5 | Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. | MFA on remote maintenance sessions and settings that end them when work is done | |
| MA.L2-3.7.6 Maintenance Personnel | 1 | Supervise the maintenance activities of maintenance personnel without required access authorization. | Supervision records for maintenance staff who lack access authorization |
Media Protection (MP): 9 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| MP.L2-3.8.1 Media Protection | 3 | Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. | Locked storage and handling rules for paper and digital CUI media | |
| MP.L2-3.8.2 Media Access | 3 | Limit access to CUI on system media to authorized users. | Access list for CUI media and the storage that holds it | |
| MP.L2-3.8.3 Media Disposal [CUI Data] | 5 | Sanitize or destroy system media containing CUI before disposal or release for reuse. | Sanitization or destruction records, such as certificates of destruction | |
| MP.L2-3.8.4 Media Markings | 1 | Mark media with necessary CUI markings and distribution limitations. | Examples of CUI-marked media and the marking procedure | |
| MP.L2-3.8.5 Media Accountability | 1 | Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas. | Transport logs and chain-of-custody records for CUI media | |
| MP.L2-3.8.6 Portable Storage Encryption | 1 | Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards. | Encryption settings for portable media carrying CUI outside controlled areas | |
| MP.L2-3.8.7 Removable Media | 5 | Control the use of removable media on system components. | Technical controls restricting removable media on system components | |
| MP.L2-3.8.8 Shared Media | 3 | Prohibit the use of portable storage devices when such devices have no identifiable owner. | Policy and controls blocking portable storage devices with no identifiable owner | |
| MP.L2-3.8.9 Protect Backups | 1 | Protect the confidentiality of backup CUI at storage locations. | Encryption and access controls for backups that hold CUI |
Personnel Security (PS): 2 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| PS.L2-3.9.1 Screen Individuals | 3 | Screen individuals prior to authorizing access to organizational systems containing CUI. | Screening records completed before access to CUI systems | |
| PS.L2-3.9.2 Personnel Actions | 5 | Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. | Offboarding and transfer checklists showing access removed and equipment returned |
Physical Protection (PE): 6 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| PE.L2-3.10.1 Limit Physical Access [CUI Data] | 5 | Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals. | Access lists for the facility, server rooms and equipment areas | |
| PE.L2-3.10.2 Monitor Facility | 5 | Protect and monitor the physical facility and support infrastructure for organizational systems. | Alarm, camera or guard monitoring records for the facility and support infrastructure | |
| PE.L2-3.10.3 Escort Visitors [CUI Data] | 1 | Escort visitors and monitor visitor activity. | Visitor escort policy and the practice an assessor can observe | |
| PE.L2-3.10.4 Physical Access Logs [CUI Data] | 1 | Maintain audit logs of physical access. | Visitor logs and badge access logs, retained | |
| PE.L2-3.10.5 Manage Physical Access [CUI Data] | 1 | Control and manage physical access devices. | Key and badge inventory and records of lock or combination changes | |
| PE.L2-3.10.6 Alternative Work Sites | 1 | Enforce safeguarding measures for CUI at alternate work sites. | Safeguards required for CUI at home and other alternate work sites |
Risk Assessment (RA): 3 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| RA.L2-3.11.1 Risk Assessments | 3 | Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. | A periodic risk assessment covering operations, assets and people, with its date | |
| RA.L2-3.11.2 Vulnerability Scan | 5 | Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. | Defined scan frequency, scan results for systems and applications, and scans run after new advisories | Scan |
| RA.L2-3.11.3 Vulnerability Remediation | 1 | Remediate vulnerabilities in accordance with risk assessments. | Remediation records ranked by risk, and rescans or retests showing the fixes held | Test + scan |
Security Assessment (CA): 4 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| CA.L2-3.12.1 Security Control Assessment | 5 | Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. | Defined assessment frequency and the assessment reports themselves | Test |
| CA.L2-3.12.2 Operational Plan of Action | 3 | Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. | Plans of action listing each deficiency, owner, milestone and progress | |
| CA.L2-3.12.3 Security Control Monitoring | 5 | Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. | The ongoing monitoring process and its recent outputs | |
| CA.L2-3.12.4 System Security Plan | No SSP, no assessment | Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. | A current SSP covering boundaries, environment, how each requirement is met, and connections |
System and Communications Protection (SC): 16 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| SC.L2-3.13.1 Boundary Protection [CUI Data] | 5 | Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. | Diagram of external and key internal boundaries, firewall rules, and boundary monitoring | Test + scan |
| SC.L2-3.13.2 Security Engineering | 5 | Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. | Documented architecture and development practices that apply security principles | |
| SC.L2-3.13.3 Role Separation | 1 | Separate user functionality from system management functionality. | Separate interfaces and accounts for administration and everyday use | |
| SC.L2-3.13.4 Shared Resource Control | 1 | Prevent unauthorized and unintended information transfer via shared system resources. | Controls that stop information leaking through shared system resources | |
| SC.L2-3.13.5 Public-Access System Separation [CUI Data] | 5 | Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. | A separate subnet (DMZ) for public-facing systems and the rules around it | Test |
| SC.L2-3.13.6 Network Communication by Exception | 5 | Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). | Default-deny firewall rules with each exception documented | Test |
| SC.L2-3.13.7 Split Tunneling | 1 | Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). | VPN configuration that prevents split tunneling | Test |
| SC.L2-3.13.8 Data in Transit | 3 | Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. | TLS and VPN settings that protect CUI in transit | Scan |
| SC.L2-3.13.9 Connections Termination | 1 | Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. | Idle timeout settings for network sessions | |
| SC.L2-3.13.10 Key Management | 1 | Establish and manage cryptographic keys for cryptography employed in organizational systems. | Key management procedure and an inventory of keys and certificates | |
| SC.L2-3.13.11 CUI Encryption | 5 (3 if encryption is not FIPS-validated) | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. | FIPS 140 validation certificate numbers for the cryptographic modules that protect CUI | |
| SC.L2-3.13.12 Collaborative Device Control | 1 | Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device. | Settings that block remote activation of cameras and microphones and show when they are in use | |
| SC.L2-3.13.13 Mobile Code | 1 | Control and monitor the use of mobile code. | Policy and controls on mobile code such as macros and scripts | |
| SC.L2-3.13.14 Voice over Internet Protocol | 1 | Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. | VoIP inventory, configuration and monitoring | |
| SC.L2-3.13.15 Communications Authenticity | 5 | Protect the authenticity of communications sessions. | Controls that protect session authenticity, such as certificates and signing | |
| SC.L2-3.13.16 Data at Rest | 1 | Protect the confidentiality of CUI at rest. | Encryption or other protection for stored CUI |
System and Information Integrity (SI): 7 requirements
| Requirement | Points | What it requires | Evidence an assessor asks for | Test or scan |
|---|---|---|---|---|
| SI.L2-3.14.1 Flaw Remediation [CUI Data] | 5 | Identify, report, and correct system flaws in a timely manner. | Patch process, patch compliance reports and time-to-fix records | Test + scan |
| SI.L2-3.14.2 Malicious Code Protection [CUI Data] | 5 | Provide protection from malicious code at designated locations within organizational systems. | Endpoint protection coverage report for the designated locations | |
| SI.L2-3.14.3 Security Alerts & Advisories | 5 | Monitor system security alerts and advisories and take action in response. | Advisory sources monitored and records of action taken | |
| SI.L2-3.14.4 Update Malicious Code Protection [CUI Data] | 5 | Update malicious code protection mechanisms when new releases are available. | Automatic update settings for endpoint protection | |
| SI.L2-3.14.5 System & File Scanning [CUI Data] | 3 | Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed. | Scheduled scan settings and real-time scanning of downloaded or opened files | |
| SI.L2-3.14.6 Monitor Communications for Attacks | 5 | Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. | Inbound and outbound monitoring tools, their alerts, and who reviews them | Test |
| SI.L2-3.14.7 Identify Unauthorized Use | 3 | Identify unauthorized use of organizational systems. | A definition of authorized use and the monitoring that spots unauthorized use | Test |
Requirements a penetration test or validated scan can prove
Twenty-three of the 110 rows are flagged. They fall into five groups.
Security control assessment (CA.L2-3.12.1). The requirement is to assess, on a schedule, whether your controls work. A penetration test is that assessment, run against the live controls rather than the paperwork. It is also the requirement to point to when a prime asks why you test.
Vulnerability scanning and remediation (RA.L2-3.11.2, RA.L2-3.11.3, SI.L2-3.14.1). Scans must run at a defined frequency on systems and applications, and again when new vulnerabilities are announced. The Assessment Guide says every in-scope asset must be scanned, including laptops that rarely connect to the network. For custom software it adds that analysis “may require a penetration tester to properly test and validate findings.” Validated scans, plus rescans after the fixes, cover the scanning and remediation rows.
Boundaries and segmentation (SC.L2-3.13.1, SC.L2-3.13.5, SC.L2-3.13.6, SC.L2-3.13.7, AC.L2-3.1.3). An external test proves what the internet can reach. An internal test from a foothold in the corporate network proves whether the CUI enclave boundary holds, whether traffic is denied by default, whether VPN clients can split-tunnel, and whether CUI can flow where it should not.
Access, authentication and detection (AC.L2-3.1.1, AC.L2-3.1.2, AC.L2-3.1.5, AC.L2-3.1.7, AC.L2-3.1.12, IA.L2-3.5.2, IA.L2-3.5.3, AU.L2-3.3.1, SI.L2-3.14.6, SI.L2-3.14.7). Testing shows whether access is limited to authorized users and functions, whether a standard user can gain admin rights, whether MFA is enforced where the requirement says it must be, and whether your logging and monitoring caught the test.
Configuration and encryption (CM.L2-3.4.2, CM.L2-3.4.7, AC.L2-3.1.13, SC.L2-3.13.8). An authenticated scan compares settings to your hardening standard, finds ports and services that should be off, and flags weak or missing encryption on remote access and data in transit. A scan cannot prove FIPS validation for SC.L2-3.13.11. That row needs the certificate numbers for your cryptographic modules.
Two more families can be checked on site, although their rows ask mainly for records. For wireless access (AC.L2-3.1.16, AC.L2-3.1.17), wireless penetration testing shows whether enterprise authentication and encryption hold. For physical protection (the PE family), a physical penetration test shows whether badge and visitor controls stop an outsider.
Our NIST SP 800-171 penetration testing guide explains how a test evidences each of these practices and how the findings feed the SSP and the POA&M.
SPRS scoring and the POA&M rules
The score starts at 110. Each NOT MET requirement subtracts its value of 5, 3 or 1 point. Forty-four requirements are worth 5 points, 14 are worth 3, and 51 are worth 1. The SSP requirement (CA.L2-3.12.4) carries no points, because without a current SSP the assessment cannot be completed. If every requirement were NOT MET, the score would be -203.
Two requirements allow partial credit:
- IA.L2-3.5.3 Multifactor Authentication: 3 points off if MFA covers only remote and privileged users, 5 if it covers none.
- SC.L2-3.13.11 CUI Encryption: 3 points off if encryption is used but is not FIPS-validated, 5 if there is no encryption.
A POA&M lets you reach Conditional status with some gaps still open. The limits come from 32 CFR 170.21:
| Rule | Detail |
|---|---|
| Minimum score | At least 88, which is 80% of 110 |
| Gaps that may stay open | 1-point requirements only, plus SC.L2-3.13.11 when encryption is used but not FIPS-validated |
| Never on a POA&M | AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5, and every 3-point or 5-point requirement |
| Deadline | Close every item and confirm it in a closeout assessment within 180 days of the Conditional status date, or the status expires |
In practice, every requirement worth 3 or 5 points must be MET on assessment day. The one exception is SC.L2-3.13.11 when encryption is in place but not FIPS-validated. Those requirements include MFA, vulnerability scanning, security control assessment and boundary protection. Those are the rows to test first, early enough to fix what the test finds.
Keep two plans apart. The operational plan of action under CA.L2-3.12.2 is an everyday management tool. The Assessment Guide and 32 CFR 170.24 both say temporary deficiencies handled properly in operational plans of action, and enduring exceptions described in the SSP, are assessed as MET. The assessment POA&M is the limited list of open gaps allowed at Conditional status.
Self-assessment or C3PAO, and where the rollout stands
Level 2 has two routes:
- Level 2 (Self). You score yourself, post the result in SPRS, and a senior official affirms it at the time of the assessment and every year after. You repeat it every three years. POA&M items must be closed, and the closeout posted to SPRS, within 180 days (32 CFR 170.16).
- Level 2 (C3PAO). A Certified Third-Party Assessment Organization checks every requirement against your evidence. Most contracts involving CUI were set to require this route.
The timeline, as set out on our CMMC Level 2 page: 32 CFR Part 170 took effect on December 16, 2024. The DFARS rule that puts CMMC clauses into contracts took effect on November 10, 2025 and started a phased rollout. Phase 2, which would make C3PAO certification a condition of award for most Level 2 contracts, was due on November 10, 2026.
On July 13, 2026 the Department paused Phase 2 and the later phases and started a 60-day review (WilmerHale). Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev. 2 and SPRS posting stay in effect. The review’s report was due on September 11, 2026 and had not been made public by late September (Inside Government Contracts). Confirm the current phase with your contracting officer. A self-assessment done now is the same work a C3PAO will check later.
Using the Level 2 Assessment Guide
The CMMC Assessment Guide for Level 2 (version 2.13, September 2024) is the assessor’s reference for every row in this checklist. For each requirement it gives:
- the assessment objectives from NIST SP 800-171A, lettered [a], [b] and so on;
- what an assessor may examine, who they may interview, and what they may test;
- a plain-language discussion and a short example;
- assessment considerations, which read like the assessor’s own questions.
Work through the objectives for the 58 requirements worth 3 or 5 points first. The guide explains that interviews tell the assessor what staff believe is true, documents show the policies and procedures, and testing shows what has actually been done. It adds that most objectives will require testing.
Enclave scoping: the biggest cost lever
Many contractors, including the manufacturers and construction and engineering firms in the defense supply chain, keep CMMC affordable by scoping it to an enclave: a segmented environment where CUI lives, so the 110 requirements apply to a few dozen systems instead of the whole company. That works only if the segmentation is real. How to test the enclave boundary, and what assessors look for, is covered on our CMMC Level 2 penetration testing page.
Download the checklist
The spreadsheet has all 110 rows with the official requirement text, the number of assessment objectives, the point value, POA&M eligibility, the evidence list and the test or scan flag. It adds Status, Partial credit, Points deducted, Evidence location, Owner, Target date and Notes columns. A Summary sheet calculates your score as you mark rows and checks it against the 88-point and POA&M rules.
Download the CMMC Level 2 checklist (XLSX)
Testing evidence at a fixed price
Two tests scoped to the CUI environment cover most of the flagged rows: an external network penetration test from $4,200 and an internal network penetration test from $6,000. Validated vulnerability scanning for RA.L2-3.11.2 is $1,500 per scan for up to 250 devices, with a free re-scan of what you fix.
Every price is fixed in writing before work starts. Every penetration test includes a free retest, so the report shows the gaps closed. Each finding names the requirement it touches, ready for your SSP, your POA&M or your assessor. See CMMC Level 2 penetration testing for the full scope, or scope your test and get the price in writing.
Frequently asked questions
How many requirements are in CMMC Level 2? 110, in 14 families, identical to NIST SP 800-171 Rev. 2. They break down into 320 assessment objectives.
Does CMMC Level 2 use NIST SP 800-171 Revision 3? No. The CMMC rule ties Level 2 to Revision 2, and that is what assessors check today.
Can we be certified with gaps still open? Yes, as Conditional status, if the score is at least 88 and every open gap is allowed on a POA&M. That means a 1-point requirement that is not on the excluded list, or SC.L2-3.13.11 when encryption is used but not FIPS-validated. The gaps must be closed within 180 days.
Does CMMC Level 2 require a penetration test? Not by name. CA.L2-3.12.1 requires you to assess whether your controls work, and RA.L2-3.11.2 and RA.L2-3.11.3 require scanning and remediation. A penetration test and validated scans are the most direct evidence for those rows. Our compliance frameworks guide compares CMMC with the frameworks that name testing outright.
What is the difference between this checklist and a System Security Plan? The checklist tracks status, owners and evidence. The SSP is a required document (CA.L2-3.12.4) that describes your boundary, your environment and how each requirement is met. Without a current SSP there is no assessment.
Do we still need to do this while Phase 2 is paused? Yes. DFARS 252.204-7012 still requires the NIST SP 800-171 controls, self-assessments are still required, and primes are still asking suppliers for Level 2 evidence.
Can Invadel run our CMMC assessment? No. We are not a C3PAO and we do not write SSPs. We run the penetration tests and validated scans that give your assessor objective evidence, and we keep that work independent of your assessment.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →