If your organization touches Controlled Unclassified Information (CUI) as part of a Department of Defense contract, CMMC Level 2 is not optional. The requirement flows from prime contractors to subcontractors, and the mechanism for demonstrating compliance has real teeth: under DFARS 252.204-7012 and the CMMC final rule, contractors must post a self-assessed score in the Supplier Performance Risk System (SPRS), a number that's visible to contracting officers before award.
This post explains exactly what CMMC Level 2 requires, how the SPRS scoring formula works, and how to get a defensible number before an assessor, or a prime, asks for it.
What Is CUI and Why Does It Trigger CMMC?
Controlled Unclassified Information is information the government creates or possesses that requires safeguarding under law, regulation, or policy, but doesn't meet the threshold for classified designation. The categories are extensive: export-controlled technical data, law enforcement sensitive information, privacy data, proprietary business information related to DoD programs, and more. If your contract or Statement of Work references CUI, handles technical drawings or specifications for defense systems, or flows down the DFARS 252.204-7012 clause, you're in scope.
CMMC Level 2 aligns directly with NIST SP 800-171 Rev 2, which specifies 110 security requirements across 14 families. Level 2 means all 110 requirements, no exceptions, no partial credit for intent.
The Three CMMC Levels at a Glance
| Level | Name | Scope | Assessment Type |
|---|---|---|---|
| L1 | Foundational | 15 requirements (FAR 52.204-21 FCI safeguarding) | Annual self-assessment |
| L2 | Advanced | All 110 SP 800-171 Rev 2 requirements | Triennial C3PAO or self-assessment (contract-dependent) |
| L3 | Expert | 110 + select SP 800-172 practices | Government-led assessment |
Level 2 is where the vast majority of DIB contractors land. The question isn't whether you need to achieve it, it's how far you currently are from it.
How the SPRS Score Is Calculated
The SPRS score uses the DoD Assessment Methodology v1.2.1, with precise rules:
- Start at 110
- For each unimplemented requirement, subtract its assigned point weight
- Weights are 5, 3, or 1 points depending on criticality
- The floor is −203: starting from 110 and deducting every requirement's point weight (the 5/3/1 values summed across all 110 requirements) drives the worst case down to −203
- Two requirements allow partial credit: MFA (3.5.3, 5 pts full / 3 pts partial) and FIPS-validated encryption (3.13.11, 3 pts full / 1 pt partial). "Partial" is defined in the methodology (for 3.5.3, MFA is enforced for some account types but not all, such as privileged accounts but not non-privileged), not any partial effort
- If no current System Security Plan exists, the score is automatically treated as zero
The DoD methodology and DFARS don't define a "passing" SPRS score for self-assessment: 110 is perfect, and any lower number reflects open requirements. Buyers and primes apply their own expectations, and a higher score is more competitive, but specific cutoffs are industry convention rather than published standards. A negative score signals significant gaps. Whatever your number, it needs to be accurate: attestation of a falsely inflated SPRS score is False Claims Act exposure.
SP 800-171 Rev 2 Self-Assessment · SPRS Score
The 14 Requirement Families
SP 800-171 organizes its 110 requirements into 14 security families. Gaps aren't usually evenly distributed, most organizations cluster their weaknesses in a handful of families. Here's the full list with common pain points:
| Family | ID | Reqs | Common Pain Points |
|---|---|---|---|
| Access Control | 3.1 | 22 | Least privilege, remote access, external connections |
| Awareness & Training | 3.2 | 3 | Insider threat awareness, role-specific training records |
| Audit & Accountability | 3.3 | 9 | Log retention, review cadence, audit reduction tools |
| Configuration Management | 3.4 | 9 | Baseline configs, change control, least functionality |
| Identification & Authentication | 3.5 | 11 | MFA (3.5.3), password complexity, replay-resistant auth |
| Incident Response | 3.6 | 3 | IR capability, external reporting, incident tracking |
| Maintenance | 3.7 | 6 | Remote maintenance controls, equipment sanitization |
| Media Protection | 3.8 | 9 | CUI on removable media, sanitization, physical transport |
| Personnel Security | 3.9 | 2 | Screening, termination/transfer procedures |
| Physical Protection | 3.10 | 6 | Visitor control, monitoring access to CUI areas |
| Risk Assessment | 3.11 | 3 | Documented risk assessments, vulnerability scanning |
| Security Assessment | 3.12 | 4 | System Security Plan, POA&M, periodic assessment |
| System & Communications | 3.13 | 16 | FIPS encryption (3.13.11), network segmentation, boundary protection |
| System & Info Integrity | 3.14 | 7 | Malicious code protection, security alerts, patching cadence |
Self-Assessment vs. C3PAO Assessment
Under the CMMC final rule (32 CFR Part 170), whether you need a third-party assessment depends on the contract. DoD designates which Level 2 acquisitions require a Certified Third-Party Assessment Organization (C3PAO), typically those tied to more sensitive programs; the remainder allow self-assessment with an annual affirmation by a senior company official. In either case, your self-assessment score is your baseline and your attestation on record.
The System Security Plan Is a Gate
Requirement 3.12.4 mandates a System Security Plan covering all 110 requirements. The DoD Assessment Methodology states explicitly: if a contractor does not have a current SSP, their SPRS score is treated as zero. The SSP doesn't need to be elaborate, but it must document each requirement's implementation status and planned actions for any gaps.
The System Security Plan tool at Risk Posture Tools addresses this directly, with structured narratives for SP 800-53 controls that map to 800-171 requirements, and baseline tailoring built in.
Using the CMMC L2 Tool
The CMMC L2 tool walks all 110 SP 800-171 Rev 2 requirements with the official requirement statement and NIST discussion, the DoD Assessment Methodology point weight (5, 3, or 1), and a status selector for Met / Partial / Not Met / N/A. Your SPRS score updates in real time. Gaps automatically populate a POA&M that can be exported to CSV or carried into the POA&M Tracker.
Frequently asked questions
How is a CMMC Level 2 SPRS score calculated?
The SPRS score uses the DoD Assessment Methodology v1.2.1. You start at 110 and, for each unimplemented requirement, subtract its assigned point weight of 5, 3, or 1 point depending on criticality. The floor is −203, the worst case reached by deducting every requirement's point weight from 110. Two requirements allow partial credit: MFA (3.5.3) and FIPS-validated encryption (3.13.11).
What is a passing SPRS score for CMMC Level 2?
The DoD methodology and DFARS don't define a "passing" SPRS score for self-assessment. A score of 110 is perfect, and any lower number reflects open requirements. Buyers and primes apply their own expectations and a higher score is more competitive, but specific cutoffs are industry convention rather than published standards. A negative score signals significant gaps, and whatever your number, it needs to be accurate: attestation of a falsely inflated score is False Claims Act exposure.
Does CMMC Level 2 apply to small subcontractors?
Yes. It's a common misconception that a small sub is exempt. DFARS 252.204-7012 flows to all subcontractors that process, store, or transmit CUI, regardless of company size or tier. If the prime passes you CUI, you're in scope.
Do I need a System Security Plan for CMMC Level 2?
Yes. Requirement 3.12.4 mandates a System Security Plan covering all 110 requirements, and the DoD Assessment Methodology states that if a contractor does not have a current SSP, their SPRS score is treated as zero. The SSP doesn't need to be elaborate, but it must document each requirement's implementation status and planned actions for any gaps.
Related reading
- POA&M Template: The Fields That Matter (and a Free Tracker)
- SP 800-53 Control Tailoring: A Daunting Task Made Systematic
- RMF Simplified: How the Seven Steps Bring Clarity to System Authorization
- the free CMMC Level 2 SPRS calculator
References
- NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (2020). doi.org/10.6028/NIST.SP.800-171r2
- DoD Assessment Methodology v1.2.1, NIST SP 800-171 DoD Assessment Methodology (2020). acq.osd.mil
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. acq.osd.mil
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program Final Rule (89 FR 83092, October 15, 2024). federalregister.gov