Blogs The Complete Guide to CMMC Level 2 and Its Requirements

The Complete Guide to CMMC Level 2 and Its Requirements

August 18, 2026

Preeya is a Content Marketing Specialist with expertise in crafting compelling stories about disruptive technologies across diverse industries. She is passionate about developing engaging, insightful content that empowers readers and decision-makers with the knowledge they need to drive innovation and success.

See All From This Author

If your organization handles Controlled Unclassified Information (CUI), CMMC Level 2 is likely the cybersecurity standard that will have the greatest impact on your business. For many defense contractors, achieving Level 2 isn't simply about passing an assessment. It's about demonstrating that sensitive engineering, manufacturing, and product information is protected throughout the product lifecycle.

While the framework centers on 110 security controls from NIST SP 800-171, many organizations discover the hardest part isn't understanding the controls. It's identifying where CUI exists, securing it across disconnected engineering systems, and producing the documentation needed to prove compliance.

Note: CMMC implementation guidance continues to evolve. While recent government action has paused certain Phase II third-party assessment requirements, contractors that handle CUI should continue to focus on NIST SP 800-171 alignment, documentation, and secure data management practices.

What is CMMC 2.0 Level 2 compliance?

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the Department of Defense's framework for verifying that contractors and subcontractors have the cybersecurity controls needed to protect sensitive information. As the level focused on protecting Controlled Unclassified Information (CUI), it is the certification most defense contractors and suppliers are expected to encounter.

CMMC Level 2 compliance requires organizations to implement 110 security controls drawn from NIST SP 800-171. These controls are designed to safeguard CUI, a category of sensitive but unclassified data that flows regularly through the Defense Industrial Base (DIB). Unlike Level 1, which focuses on basic cyber hygiene for Federal Contract Information (FCI), Level 2 demands a far more rigorous approach to documentation, implementation, and verification of security practices.

For many organizations, Level 2 represents the point where cybersecurity extends beyond IT infrastructure and into engineering operations. CUI often includes CAD models, technical drawings, software, requirements, system architectures, bills of material, manufacturing instructions, and test documentation. Protecting these engineering assets throughout their lifecycle is a core part of achieving compliance.

For defense contractors, understanding the certification requirements isn't optional. It's quickly becoming a prerequisite for winning and retaining DoD contracts.

Why is CMMC Level 2 important?

At its core, the certification model is designed to help protect sensitive defense information from growing cyber threats targeting the Defense Industrial Base. Defense contractors and their supply chains handle CUI ranging from technical drawings to logistics data, and every unsecured endpoint represents a potential vulnerability that adversaries can exploit.

Beyond national security, certification is becoming a business requirement for organizations that support the DoD. Contractors that fail to meet applicable cybersecurity requirements may face greater scrutiny, contract limitations, or future eligibility challenges as CMMC implementation evolves. As the DoD tightens its cybersecurity requirements across the supply chain, cybersecurity readiness has shifted from a competitive advantage to a baseline expectation.

CMMC Level 2 also helps standardize cybersecurity expectations across a contractor ecosystem with varying levels of cybersecurity maturity and resources. By establishing a uniform set of controls, the DoD can better assess and manage risk across its entire contractor base.

What is CMMC Level 2's role in protecting CUI?

Protecting CUI sits at the heart of the program. Contractors must demonstrate that they can identify, mark, store, transmit, and dispose of CUI according to strict security protocols. This isn't a one-time checklist exercise; it requires ongoing operational discipline across every team that touches sensitive data.

For manufacturers, CUI extends well beyond office documents. It often includes engineering models, source code, technical specifications, product structures, manufacturing processes, simulation results, and program documentation. Because this information moves across engineering, manufacturing, suppliers, and sustainment, organizations need consistent governance throughout the digital thread.

Who needs CMMC 2.0 Level 2 compliance?

Any organization within the Defense Industrial Base that handles CUI will likely need to meet the applicable certification requirements. This includes prime contractors, subcontractors, and suppliers at various tiers of the supply chain, regardless of company size.

Organizations commonly requiring Level 2 include aerospace manufacturers, defense electronics suppliers, missile and munitions manufacturers, shipbuilders, software developers, systems integrators, machine shops, engineering service providers, and sustainment organizations that handle CUI as part of DoD programs.

Compliance requirements extend throughout the aerospace and defense supply chain. If a prime contractor handles CUI and shares it with subcontractors, those subcontractors may also be required to meet the applicable certification requirements. This flow-down effect means even smaller suppliers should understand how cybersecurity obligations can impact their role in supporting defense programs.

How will CMMC 2.0 impact DoD contracts?

CMMC requirements are expected to continue shaping DoD contract language, but implementation timelines and assessment requirements are subject to change as the government reviews the program.

For many contractors, cybersecurity readiness will remain an important factor in pursuing DoD opportunities. Organizations that understand their gaps, document controls, and improve CUI protection will be better positioned as requirements evolve.

The DoD has also signaled that compliance will be verified more rigorously than under the original CMMC framework. Self-attestation still plays a role for some requirements, but Level 2 may involve self-assessment or third-party assessment depending on contract requirements and future implementation guidance.

What are the CMMC 2.0 Level 2 requirements?

CMMC Level 2 requirements are built around 110 security controls organized into 14 security domains. Together, these domains address both the technical and operational practices required to protect CUI. The domains include:

  • Access control (AC) – Restricting system access to authorized users
  • Awareness training (AT) – Ensuring staff understand security responsibilities
  • Audit and accountability (AU) – Tracking system activity and maintaining logs
  • Configuration management (CM) – Controlling changes to system configurations
  • Identification and authentication (IA) – Verifying user and device identities
  • Incident response (IR) – Establishing procedures for detecting and responding to breaches
  • Maintenance (MA) – Managing system maintenance securely
  • Media protection (MP) – Safeguarding physical and digital media containing CUI
  • Personnel security (PS) – Screening and managing personnel with access to sensitive data
  • Physical protection (PE) – Securing facilities and hardware
  • Risk assessment (RA) – Identifying and evaluating potential vulnerabilities
  • Security assessment (CA) – Regularly evaluating security control effectiveness
  • System and communications protection (SC) – Protecting data in transit and at rest
  • System and information integrity (SI) – Detecting and correcting system flaws

Meeting these requirements demands more than technical implementation. Organizations must also maintain detailed documentation demonstrating how each control is applied, monitored, and updated over time. This documentation becomes the backbone of the assessment process, whether through self-assessment or third-party evaluation.

What's the difference between the three CMMC levels?

CMMC 2.0 simplified the original five-level model into three certification tiers based on the sensitivity of the information being handled and the security controls required to protect it.

Eligibility and types of data

Level 1 applies to organizations handling only Federal Contract Information and requires basic safeguarding practices. Level 2 applies to organizations handling CUI and requires the full 110 controls from NIST SP 800-171. Level 3 applies to organizations handling the most sensitive CUI associated with critical DoD programs and adds additional controls from NIST SP 800-172.

Cybersecurity requirements

Level 1 requires 17 basic safeguarding practices. Level 2 requires all 110 NIST SP 800-171 controls. Level 3 builds on Level 2 with an additional set of enhanced controls designed to defend against advanced persistent threats.

Assessment types

Level 1 relies on annual self-assessment. Level 2 may require self-assessment or third-party assessment by a Certified Third-Party Assessment Organization (C3PAO), depending on contract requirements, information sensitivity, and current implementation guidance. Level 3 requires assessment conducted by the government.

Option for conditional compliance

Organizations pursuing Level 2 certification may qualify for conditional compliance status if they have outstanding Plans of Action and Milestones (POA&Ms) for a limited subset of controls. This provides a pathway for organizations that are actively working toward full compliance but haven't yet closed every gap.

Challenges in achieving CMMC Level 2 compliance

Achieving CMMC Level 2 requires far more than implementing cybersecurity controls. Organizations must understand where Controlled Unclassified Information (CUI) exists, protect it across increasingly complex engineering and manufacturing environments, and continuously demonstrate that security controls remain effective. For many defense contractors, the operational challenges—not the technical requirements—become the greatest obstacle to certification.

Identifying where CUI exists

Many organizations underestimate how widely CUI is distributed across the business. Beyond documents and email, sensitive information often resides in CAD models, technical drawings, software, requirements, bills of material, manufacturing work instructions, simulation data, and test results. Identifying every location where CUI is created, stored, or shared is often the first major challenge in preparing for CMMC Level 2.

Securing engineering data across disconnected systems

Engineering data rarely lives in a single application. Product information moves between CAD, PLM, requirements management, software development, manufacturing, quality, and supplier systems throughout the product lifecycle. Maintaining consistent access controls, traceability, and governance across these disconnected environments can be difficult without a connected digital engineering strategy.

Managing secure collaboration across the supply chain

Defense programs depend on close collaboration between prime contractors, subcontractors, suppliers, and engineering partners. Organizations must securely share CUI while maintaining visibility into who has access, what information has changed, and whether security policies are consistently enforced across internal and external teams.

Producing assessment-ready documentation

Implementing security controls is only part of the process. Organizations must also demonstrate how those controls are implemented, monitored, and maintained through documentation such as System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, procedures, and supporting evidence. Maintaining accurate documentation as systems evolve often becomes one of the most resource-intensive aspects of certification.

Maintaining compliance over time

CMMC Level 2 is not a one-time project. Engineering environments, supplier relationships, software, and manufacturing processes change continuously. Organizations need repeatable governance processes that help ensure security controls remain effective, documentation stays current, and sensitive engineering information remains protected as products and programs evolve.

How is CMMC 2.0 related to DFARS?

CMMC 2.0 and the Defense Federal Acquisition Regulation Supplement (DFARS) are closely connected but serve different purposes. Understanding how CMMC aligns with broader defense cybersecurity requirements can help contractors navigate compliance obligations more effectively. DFARS clause 252.204-7012 has long required contractors to implement NIST SP 800-171 controls and report cyber incidents involving CUI. CMMC 2.0 essentially formalizes and verifies compliance with those existing DFARS obligations.

Organizations should think of DFARS, NIST SP 800-171, FedRAMP, and CMMC as interconnected requirements rather than separate compliance initiatives. Together they establish expectations for protecting sensitive government information throughout the defense supply chain.

In other words, CMMC 2.0 doesn't introduce entirely new cybersecurity standards. It creates a verification mechanism for standards that many contractors were already supposed to be meeting under DFARS. For contractors who have been self-attesting compliance with DFARS for years without formal validation, certification represents the point where those claims are independently validated.

When does CMMC 2.0 Level 2 take effect?

CMMC 2.0 implementation remains phased, but the government has suspended the Phase II transition that would have expanded mandatory third-party assessment requirements. During this period, contractors should continue monitoring official guidance and maintaining the cybersecurity practices required to protect CUI.

While implementation is phased, many organizations will need significant time to assess gaps, document controls, and prepare for assessment. Given the time required to implement controls, close documentation gaps, and complete assessments, organizations that wait until requirements are finalized in a specific contract may still face compressed timelines for documenting controls, closing gaps, and demonstrating readiness.

Rather than waiting for a contract to require certification, organizations should use this period to strengthen engineering data governance, identify CUI, mature documentation practices, and close security gaps that often take months to remediate.

How should organizations prepare for a CMMC Level 2 assessment?

Preparing for CMMC Level 2 requires a structured approach to understanding requirements, documenting controls, and strengthening CUI protection.

Organizations should start with a gap assessment to understand where their current cybersecurity posture stands against the 110 required controls. As part of that review, many contractors also evaluate the security and compliance posture of the cloud environments used to store and manage sensitive information.

From there, organizations need to develop or update their System Security Plan (SSP), which documents how each control is implemented. Alongside the SSP, a Plan of Action and Milestones (POA&M) tracks remaining gaps and the timeline for closing them.

Once plans and documentation are established, organizations can focus on closing identified gaps and operationalizing controls across systems, processes, and teams. This phase often takes the longest, particularly for organizations without mature cybersecurity programs already in place.

Finally, organizations should conduct an internal readiness review before submitting self-assessment results or pursuing any future third-party assessment required by contract. This review helps identify any remaining weaknesses before they show up in a formal assessment.

How can PTC help companies prepare for CMMC Level certification?

Achieving CMMC Level 2 isn't simply about implementing cybersecurity controls or completing documentation. Organizations must also protect Controlled Unclassified Information (CUI) wherever it exists across the product lifecycle—from requirements and engineering through manufacturing, supplier collaboration, testing, and sustainment.

For many defense contractors, some of the most valuable CUI resides within engineering systems. CAD models, technical drawings, software, system architectures, product structures, manufacturing work instructions, and other engineering artifacts are shared across teams and suppliers every day. Maintaining visibility, access control, traceability, and governance over this information is often one of the most complex aspects of preparing for CMMC.

PTC helps defense contractors establish secure digital engineering environments that improve control over sensitive product information while supporting collaboration across the Defense Industrial Base. By connecting engineering data throughout the digital thread, organizations can better understand where sensitive information resides, control who has access to it, maintain complete change histories, and support the documentation needed for cybersecurity and compliance initiatives.

Solutions such as Windchill+ running on PTC's FedRAMP Authorized cloud infrastructure provide a secure environment for managing engineering and product data while enabling organizations to collaborate across distributed teams and suppliers. Combined with capabilities for requirements management, software lifecycle management, model-based systems engineering, and product lifecycle management, PTC helps organizations strengthen governance over the engineering data that is central to CMMC Level 2 readiness.

While no technology platform alone can achieve CMMC certification, establishing secure processes for managing engineering information can play an important role in protecting CUI, reducing compliance risk, and preparing organizations for future assessments.

Topics Regulatory Compliance
Up Next

Prepare your engineering data for CMMC

Learn how secure product lifecycle management can help protect engineering data, improve traceability, and support your organization's CMMC readiness. Discover More
Preeya Dave

Preeya is a Content Marketing Specialist with expertise in crafting compelling stories about disruptive technologies across diverse industries. She is passionate about developing engaging, insightful content that empowers readers and decision-makers with the knowledge they need to drive innovation and success.

Continue Reading