← All Insights
CMMCSP 800-171SPRSDoD

CMMC Level 2: What It Demands and How to Know Where You Stand

10 min readMay 2026Risk Posture Insights

If your organization touches Controlled Unclassified Information (CUI) as part of a Department of Defense contract, CMMC Level 2 is not optional. The requirement flows from prime contractors to subcontractors, and the mechanism for demonstrating compliance has real teeth: under DFARS 252.204-7012 and the CMMC final rule, contractors must post a self-assessed score in the Supplier Performance Risk System (SPRS), a number that's visible to contracting officers before award.

This post explains exactly what CMMC Level 2 requires, how the SPRS scoring formula works, and how to get a defensible number before an assessor, or a prime, asks for it.

What Is CUI and Why Does It Trigger CMMC?

Controlled Unclassified Information is information the government creates or possesses that requires safeguarding under law, regulation, or policy, but doesn't meet the threshold for classified designation. The categories are extensive: export-controlled technical data, law enforcement sensitive information, privacy data, proprietary business information related to DoD programs, and more. If your contract or Statement of Work references CUI, handles technical drawings or specifications for defense systems, or flows down the DFARS 252.204-7012 clause, you're in scope.

CMMC Level 2 aligns directly with NIST SP 800-171 Rev 2, which specifies 110 security requirements across 14 families. Level 2 means all 110 requirements, no exceptions, no partial credit for intent.

A note on versions: NIST finalized SP 800-171 Rev 3 in May 2024, but CMMC and the DoD Assessment Methodology are currently pegged to Rev 2. Until DoD updates the rule, a CMMC Level 2 assessment is scored against Rev 2's 110 requirements, so this article uses Rev 2 throughout. Expect a transition to Rev 3 in a future rulemaking.
Common misconception: "We're a small sub, the requirement doesn't apply to us." DFARS 252.204-7012 flows to all subcontractors that process, store, or transmit CUI, regardless of company size or tier. If the prime passes you CUI, you're in scope.

The Three CMMC Levels at a Glance

LevelNameScopeAssessment Type
L1 Foundational 15 requirements (FAR 52.204-21 FCI safeguarding) Annual self-assessment
L2 Advanced All 110 SP 800-171 Rev 2 requirements Triennial C3PAO or self-assessment (contract-dependent)
L3 Expert 110 + select SP 800-172 practices Government-led assessment

Level 2 is where the vast majority of DIB contractors land. The question isn't whether you need to achieve it, it's how far you currently are from it.

How the SPRS Score Is Calculated

The SPRS score uses the DoD Assessment Methodology v1.2.1, with precise rules:

The DoD methodology and DFARS don't define a "passing" SPRS score for self-assessment: 110 is perfect, and any lower number reflects open requirements. Buyers and primes apply their own expectations, and a higher score is more competitive, but specific cutoffs are industry convention rather than published standards. A negative score signals significant gaps. Whatever your number, it needs to be accurate: attestation of a falsely inflated SPRS score is False Claims Act exposure.

riskposture.tools/app/cmmc · SPRS Score Summary

SP 800-171 Rev 2 Self-Assessment · SPRS Score

82 SPRS Score
Met (97 reqs)88%
Partial (4 reqs)4%
Not Met (7 reqs)6%
N/A (2 reqs)2%
Highest-Weight Gaps (open POA&M items)
3.5.3, Multifactor Authentication−5 pts
3.1.2, Limit Access to Authorized Users & Processes−5 pts
3.13.11, FIPS-Validated Cryptography−3 pts (partial)

The 14 Requirement Families

SP 800-171 organizes its 110 requirements into 14 security families. Gaps aren't usually evenly distributed, most organizations cluster their weaknesses in a handful of families. Here's the full list with common pain points:

FamilyIDReqsCommon Pain Points
Access Control3.122Least privilege, remote access, external connections
Awareness & Training3.23Insider threat awareness, role-specific training records
Audit & Accountability3.39Log retention, review cadence, audit reduction tools
Configuration Management3.49Baseline configs, change control, least functionality
Identification & Authentication3.511MFA (3.5.3), password complexity, replay-resistant auth
Incident Response3.63IR capability, external reporting, incident tracking
Maintenance3.76Remote maintenance controls, equipment sanitization
Media Protection3.89CUI on removable media, sanitization, physical transport
Personnel Security3.92Screening, termination/transfer procedures
Physical Protection3.106Visitor control, monitoring access to CUI areas
Risk Assessment3.113Documented risk assessments, vulnerability scanning
Security Assessment3.124System Security Plan, POA&M, periodic assessment
System & Communications3.1316FIPS encryption (3.13.11), network segmentation, boundary protection
System & Info Integrity3.147Malicious code protection, security alerts, patching cadence

Self-Assessment vs. C3PAO Assessment

Under the CMMC final rule (32 CFR Part 170), whether you need a third-party assessment depends on the contract. DoD designates which Level 2 acquisitions require a Certified Third-Party Assessment Organization (C3PAO), typically those tied to more sensitive programs; the remainder allow self-assessment with an annual affirmation by a senior company official. In either case, your self-assessment score is your baseline and your attestation on record.

Practical guidance: Run your own self-assessment first, always. If you don't know your score before the C3PAO arrives, you're walking in blind. Self-assessment identifies gaps that can be remediated before the formal evaluation, reducing point deductions and, in some cases, moving an outcome from conditional to clean.

The System Security Plan Is a Gate

Requirement 3.12.4 mandates a System Security Plan covering all 110 requirements. The DoD Assessment Methodology states explicitly: if a contractor does not have a current SSP, their SPRS score is treated as zero. The SSP doesn't need to be elaborate, but it must document each requirement's implementation status and planned actions for any gaps.

The System Security Plan tool at Risk Posture Tools addresses this directly, with structured narratives for SP 800-53 controls that map to 800-171 requirements, and baseline tailoring built in.

Using the CMMC L2 Tool

The CMMC L2 tool walks all 110 SP 800-171 Rev 2 requirements with the official requirement statement and NIST discussion, the DoD Assessment Methodology point weight (5, 3, or 1), and a status selector for Met / Partial / Not Met / N/A. Your SPRS score updates in real time. Gaps automatically populate a POA&M that can be exported to CSV or carried into the POA&M Tracker.

Frequently asked questions

How is a CMMC Level 2 SPRS score calculated?

The SPRS score uses the DoD Assessment Methodology v1.2.1. You start at 110 and, for each unimplemented requirement, subtract its assigned point weight of 5, 3, or 1 point depending on criticality. The floor is −203, the worst case reached by deducting every requirement's point weight from 110. Two requirements allow partial credit: MFA (3.5.3) and FIPS-validated encryption (3.13.11).

What is a passing SPRS score for CMMC Level 2?

The DoD methodology and DFARS don't define a "passing" SPRS score for self-assessment. A score of 110 is perfect, and any lower number reflects open requirements. Buyers and primes apply their own expectations and a higher score is more competitive, but specific cutoffs are industry convention rather than published standards. A negative score signals significant gaps, and whatever your number, it needs to be accurate: attestation of a falsely inflated score is False Claims Act exposure.

Does CMMC Level 2 apply to small subcontractors?

Yes. It's a common misconception that a small sub is exempt. DFARS 252.204-7012 flows to all subcontractors that process, store, or transmit CUI, regardless of company size or tier. If the prime passes you CUI, you're in scope.

Do I need a System Security Plan for CMMC Level 2?

Yes. Requirement 3.12.4 mandates a System Security Plan covering all 110 requirements, and the DoD Assessment Methodology states that if a contractor does not have a current SSP, their SPRS score is treated as zero. The SSP doesn't need to be elaborate, but it must document each requirement's implementation status and planned actions for any gaps.

Related reading

References
  1. NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (2020). doi.org/10.6028/NIST.SP.800-171r2
  2. DoD Assessment Methodology v1.2.1, NIST SP 800-171 DoD Assessment Methodology (2020). acq.osd.mil
  3. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. acq.osd.mil
  4. 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program Final Rule (89 FR 83092, October 15, 2024). federalregister.gov

Know your SPRS score before the assessor does

Walk all 110 SP 800-171 requirements, compute your DoD score with official point weights, and generate your POA&M, in your browser, no account required.