CMMC Level 2
Also known as: Level 2, CMMC L2
CMMC Level 2 is the middle CMMC certification tier, covering contractors who handle Controlled Unclassified Information (CUI). It requires implementing all 110 controls of NIST SP 800-171 and undergoing either a self-assessment or a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO) depending on the program's prioritization. DoD suspended CMMC Phase 2 on July 13, 2026, which paused the phased arrival of the C3PAO assessment requirement pending a program review, while the obligations that drive Level 2 in the first place, DFARS 252.204-7012 and NIST SP 800-171, are unaffected.
Related terms
- CMMC Level 1
CMMC Level 1 is the lowest of the three CMMC certification tiers, covering contractors who handle Federal Contract Information (FCI) but not CUI. It requires implementing the 15 safeguarding requirements in FAR 52.204-21(b)(1), an annual self-assessment, and an annual senior-official affirmation posted in SPRS.
- NIST SP 800-171
NIST SP 800-171 is the National Institute of Standards and Technology publication that defines 110 security controls for protecting Controlled Unclassified Information (CUI) on non-federal systems. It is the controls catalog used at CMMC Level 2, but is not used at Level 1, which is based on the 15 safeguarding requirements in FAR 52.204-21.
- CMMC Third-Party Assessment Organization
A CMMC Third-Party Assessment Organization (C3PAO) is an entity accredited by the Cyber AB to perform CMMC Level 2 assessments on behalf of DoD contractors. C3PAOs are not used at Level 1, Level 1 is exclusively self-assessed, and they are not used at Level 3, which is assessed by DIBCAC. The DoD suspension of CMMC Phase 2 on July 13, 2026 paused the rollout that would have required C3PAO assessments on covered contracts beginning November 10, 2026, and the memo cites severe shortages in third-party assessment capacity as one reason for the review.
- Controlled Unclassified Information
Controlled Unclassified Information (CUI) is unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. It is explicitly marked CUI by the originating agency and triggers NIST SP 800-171 protections, and at the contractual level, CMMC Level 2.
- CMMC Phase 2 Suspension
The CMMC Phase 2 suspension is the Department of Defense action of July 13, 2026 that halted Phase 2 of the CMMC rollout and opened a 60 day top to bottom review of the program, under a memo signed by DoD Chief Information Officer Kirsten Davies. Phase 2 would have required third-party C3PAO assessments across contracts involving sensitive but unclassified information starting November 10, 2026, so that date is no longer an operative deadline.
Read more in the Library
- CMMC Level 1 vs Level 2: Which One Do You Actually Need? (2026 Plain-English Guide)
Most small defense contractors are Level 1, not Level 2, but the wrong answer here costs you a year and tens of thousands of dollars. Here's the single question that decides it.
- CMMC vs NIST 800-171: The Difference Most Small Contractors Get Wrong (2026)
CMMC and NIST 800-171 are not the same thing. The difference decides whether your weekend is 5 days of paperwork or a $50K assessment.