110 Controls Explained

CMMC Level 2 Requirements

A complete breakdown of the 110 NIST SP 800-171 security controls required for CMMC Level 2 certification β€” organized by the 14 control families.

What is CMMC Level 2?

CMMC Level 2 (Advanced) is designed for organizations that handle Controlled Unclassified Information (CUI) under DoD contracts. It requires full implementation of all 110 security requirements defined in NIST Special Publication 800-171 Revision 2.

Level 2 is the most common certification level for defense contractors. It has two assessment paths:

πŸ“‹

Self-Assessment

For contracts involving non-critical CUI. Annual self-assessment submitted to SPRS with senior official affirmation.

πŸ”

C3PAO Assessment

For contracts involving critical CUI programs. Independent third-party assessment every three years by an authorized C3PAO.

NIST SP 800-171 Control Families

The 110 controls are organized into 14 families. Each family addresses a specific area of cybersecurity:

FamilyDomainControlsFocus Area
ACAccess Control22Who can access systems and data
ATAwareness & Training3Security training for personnel
AUAudit & Accountability9Logging and monitoring activities
CMConfiguration Management9Secure system configurations
IAIdentification & Authentication11User identity verification
IRIncident Response3Handling security incidents
MAMaintenance6System maintenance practices
MPMedia Protection9Protecting digital and physical media
PEPhysical Protection6Physical access to facilities
PSPersonnel Security2Personnel screening and termination
RARisk Assessment3Identifying and managing risks
CASecurity Assessment4Evaluating control effectiveness
SCSystem & Communications Protection16Network and data transmission security
SISystem & Information Integrity7Detecting and correcting flaws

πŸ“Š SPRS Scoring

Each of the 110 controls carries point values. A perfect SPRS (Supplier Performance Risk System) score is 110. Organizations must submit their self-assessment score to SPRS before contract award. Missing controls reduce your score based on their weighted impact.

Highest-Impact Control Families

Access Control (22 Controls)

The largest family covers system access policies, remote access, information flow enforcement, separation of duties, least privilege, and session management. Key requirements include:

System & Communications Protection (16 Controls)

Covers network segmentation, encryption, boundary protection, and communications security:

Identification & Authentication (11 Controls)

Ensures that all users and devices are properly identified before access is granted:

Required Documentation for Level 2

CMMC Level 2 assessment requires extensive documentation to demonstrate control implementation:

πŸ“„

System Security Plan (SSP)

Comprehensive document describing your system boundary, architecture, and how each of the 110 controls is implemented.

πŸ“

Plan of Action & Milestones

Tracks any unmet requirements with remediation plans, timelines, and responsible parties. Must be closed within 180 days.

πŸ“Š

Network Diagram

Visual representation of your CUI boundary, data flows, security controls placement, and interconnections.

πŸ“‹

Policies & Procedures

Written security policies covering each control family, with corresponding procedures for implementation and enforcement.

πŸ›‘οΈ Need help with specific Level 2 controls?

Ask ChatCMMC about any specific NIST SP 800-171 control β€” get implementation guidance, assessment criteria, and evidence requirements instantly. Ask ChatCMMC β†’