110 Requirements Explained

CMMC Level 2 Requirements

A complete breakdown of the 110 NIST SP 800-171 Revision 2 security requirements required for CMMC Level 2 certification β€” organized by the 14 CMMC domains.

What is CMMC Level 2?

CMMC Level 2 is designed for organizations that handle Controlled Unclassified Information (CUI) under DoD contracts. It requires full implementation of all 110 security requirements defined in NIST Special Publication 800-171 Revision 2.

Level 2 is the most common certification level for defense contractors. It has two assessment paths:

πŸ“‹

Self-Assessment

For contracts involving non-critical CUI. Annual self-assessment submitted to SPRS with senior official affirmation.

πŸ”

C3PAO Assessment

For contracts involving critical CUI programs. Independent third-party assessment every three years by an authorized C3PAO.

NIST SP 800-171 Security Requirement Domains

The 110 security requirements are organized into 14 domains. Each domain addresses a specific area of cybersecurity:

DomainRequirement AreaSecurity RequirementsFocus Area
ACAccess Control22Who can access systems and data
ATAwareness & Training3Security training for personnel
AUAudit & Accountability9Logging and monitoring activities
CMConfiguration Management9Secure system configurations
IAIdentification & Authentication11User identity verification
IRIncident Response3Handling security incidents
MAMaintenance6System maintenance practices
MPMedia Protection9Protecting digital and physical media
PEPhysical Protection6Physical access to facilities
PSPersonnel Security2Personnel screening and termination
RARisk Assessment3Identifying and managing risks
CASecurity Assessment4Evaluating control effectiveness
SCSystem & Communications Protection16Network and data transmission security
SISystem & Information Integrity7Detecting and correcting flaws

πŸ“Š SPRS Scoring

Each of the 110 security requirements carries point values. A perfect SPRS (Supplier Performance Risk System) score is 110. Organizations must submit their self-assessment score to SPRS before contract award. Missing requirements reduce your score based on their weighted impact.

Highest-Impact CMMC Domains

Access Control (22 Security Requirements)

The largest family covers system access policies, remote access, information flow enforcement, separation of duties, least privilege, and session management. Key requirements include:

System & Communications Protection (16 Security Requirements)

Covers network segmentation, encryption, boundary protection, and communications security:

Identification & Authentication (11 Security Requirements)

Ensures that all users and devices are properly identified before access is granted:

Required Documentation for Level 2

CMMC Level 2 assessment requires extensive documentation to demonstrate control implementation:

πŸ“„

System Security Plan (SSP)

Comprehensive document describing your system boundary, architecture, and how each of the 110 security requirements is implemented.

πŸ“

Plan of Action & Milestones

Tracks any unmet requirements with remediation plans, timelines, and responsible parties. Must be closed within 180 days.

πŸ“Š

Network Diagram

Visual representation of your CUI boundary, data flows, security controls placement, and interconnections.

πŸ“‹

Policies & Procedures

Written security policies covering each control family, with corresponding procedures for implementation and enforcement.

πŸ›‘οΈ Need help with specific Level 2 controls?

Ask ChatCMMC about any specific NIST SP 800-171 security requirement β€” get implementation guidance, assessment criteria, and evidence requirements instantly. Ask ChatCMMC β†’