CMMC Level 2 and NIST SP 800-171 assessments for consultants
Updated
CMMC Level 2 asks defense contractors that handle Controlled Unclassified Information (CUI) to implement the 110 security requirements of NIST SP 800-171 Rev. 2. Each requirement breaks down into assessment objectives from NIST SP 800-171A, 320 in total, and an assessor checks every one of them. A readiness assessment answers three questions for the contractor: which requirements are met today, what the resulting score is, and whether the gaps are small enough for conditional status.
The CMMC levels at a glance
| Level | Requirements | Assessment |
|---|---|---|
| Level 1 | 15 basic safeguarding requirements for Federal Contract Information | Annual self-assessment and affirmation |
| Level 2 | 110 requirements of NIST SP 800-171 Rev. 2 | Self-assessment or certification by an authorized C3PAO every three years, as the contract specifies, with an annual affirmation |
| Level 3 | Level 2 plus 24 requirements from NIST SP 800-172 | Assessment by the Department of Defense (DIBCAC) |
Assess at the objective level
A requirement is met only when every one of its assessment objectives is met or not applicable. Requirement 3.1.1, for example, has six objectives covering who is authorized, which processes act for them and which devices may connect, and whether access is limited to each. One missing objective makes the requirement not met and takes its full weight off the score. Record a result and the supporting evidence for each objective, not only for the requirement.
Calculate the SPRS score
The score starts at 110 and loses the weight of every requirement that is not met:
- 5 points for requirements whose absence most directly exposes CUI, such as multifactor authentication and audit logging.
- 3 points for requirements with a moderate effect, plus the partial credit cases: multifactor authentication only for remote and privileged users (3.5.3), and encryption that is not FIPS-validated (3.13.11).
- 1 point for the remaining requirements.
A contractor with no system security plan cannot score at all, because 3.12.4 is a prerequisite for the assessment.
Check eligibility for conditional status
A contractor can reach conditional Level 2 status with open items when all of the following hold:
- The score is at least 88 of 110.
- Every requirement on the plan of action and milestones is worth 1 point, except 3.13.11, which may be on it at 3 points.
- None of 3.1.20, 3.1.22, 3.12.4, 3.10.3, 3.10.4 or 3.10.5 is on the plan.
Open items must be closed and confirmed by a closeout assessment within 180 days, or the conditional status expires. A useful readiness report shows the current score, the score after planned fixes, and which gaps block conditional status outright.
Evidence that holds up
Assessors examine documents, interview people and test mechanisms. Prepare evidence for each method: the system security plan and policies, records showing practices operate over time (access reviews, audit log reviews, incident tickets), and configuration exports or screenshots that show technical settings. Define the CUI boundary first. Most disputed findings come from assets that were left out of scope or included without the right protections.
How Control+s runs a CMMC assessment
- Each uploaded file is mapped to the relevant requirements and to every other framework in the assessment, such as CPCSC or ISO 27001.
- Each requirement’s assessment objectives are answered as met, not met or not applicable, with a reason. Objectives the evidence does not address stay open, and your answers are kept when evidence is re-analyzed.
- The project calculates the SPRS score from 32 CFR 170.24, including partial credit, and shows whether the open items allow conditional status. Incomplete requirements count as not met, so the score never flatters the contractor.
- Each requirement also receives a 0 to 5 maturity score with cited rationale, for the remediation roadmap.
- Share a scoped view with the contractor, or invite their auditor to review.
Frequently asked questions
How is the CMMC Level 2 SPRS score calculated?
Start at 110, one point per NIST SP 800-171 Rev. 2 requirement, and subtract the weight of each requirement that is not met. Weights are 5, 3 or 1 points. Two requirements allow partial credit, multifactor authentication implemented only for remote and privileged users (3.5.3) and encryption that is not FIPS-validated (3.13.11), which subtract 3 points instead of 5. A requirement is met only when all of its assessment objectives are met or not applicable.
What score is needed for conditional CMMC Level 2 status?
The score divided by 110 must be at least 0.8, which is 88 points. Only 1-point requirements, plus 3.13.11 at 3 points, can be on the plan of action and milestones, and six requirements can never be on it, 3.1.20, 3.1.22, 3.12.4, 3.10.3, 3.10.4 and 3.10.5. Every item on the plan must be closed and verified within 180 days.
When do CMMC Level 2 certification assessments become a contract requirement?
The rule phases CMMC in over four phases. Phase 1 started on November 10, 2025, with self-assessment requirements. Phase 2 starts one year later, on November 10, 2026, when the Department of Defense intends to require Level 2 certification assessments by an authorized C3PAO for applicable contracts.
Can a consultant or RPO certify a contractor?
No. Level 2 certification assessments are performed by an authorized C3PAO, and Level 3 assessments by DIBCAC. Consultants and Registered Provider Organizations prepare contractors by scoping the environment, assessing each requirement against evidence, scoring it and planning remediation.
How does CMMC relate to Canada's CPCSC?
CPCSC is built on ITSP.10.171, which the Canadian Centre for Cyber Security describes as a Canadian version of NIST SP 800-171 with no substantial technical changes. Suppliers to both countries can reuse most evidence, but each program has its own levels, assessors and contract rules.
Sources
- Federal Register: Cybersecurity Maturity Model Certification (CMMC) Program final rule, 32 CFR part 170 (October 15, 2024)
- U.S. Department of Defense: CMMC program
- NIST: SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST: SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information