How it works Pricing Guides FAQ Trust Login Start free

CMMC Level 2 Requirements for Small Business

CMMC Level 2 requires implementation of all 110 security controls from NIST SP 800-171 Revision 2. It applies to DoD contractors and subcontractors that handle Controlled Unclassified Information (CUI) when the solicitation includes DFARS 252.204-7021. The controls span 14 security families covering access control, incident response, system integrity, and more. DoD's regulatory impact analysis for 32 CFR Part 170 estimated costs of $20,000 to $100,000 for small businesses; see the cost section below.

Where CMMC Stands Today

CMMC Phase 1 has been in effect since November 10, 2025. Contracts that include DFARS 252.204-7021 require a CMMC Level 1 or Level 2 self-assessment recorded in SPRS with an annual affirmation. In July 2026 the DoD CIO suspended the advancement to Phase 2 and placed later phases on hold pending a CMMC Reform Task Force review; third-party (C3PAO) and Level 3 requirements are not being added to new solicitations during the suspension. The underlying rules (32 CFR Part 170 and DFARS 252.204-7021) remain in place.

Source: dowcio.war.gov/CMMC (memos dated July 13, 2026) and 32 CFR Part 170. Current as of 2026-09-02.

What Is Controlled Unclassified Information (CUI)?

CUI is government-created or government-owned information that requires safeguarding but is not classified. Examples include technical drawings, engineering data, test results, contract performance reports, personnel records, and export-controlled information. CUI is identified by markings on documents or by the CUI Registry maintained by the National Archives (ISOO).

If your DoD contract includes DFARS clause 252.204-7012, you are handling CUI and will need to meet CMMC Level 2 when the solicitation also includes DFARS 252.204-7021. DFARS 252.204-7012 remains in force and, under DoD Class Deviation 2024-O0013, requires NIST SP 800-171 Revision 2. CMMC formalizes the verification process that was previously based on self-attestation alone.

The key distinction from CMMC Level 1 is scope. Level 1 covers Federal Contract Information (FCI) with 15 basic requirements and allows annual self-assessment. Level 2 covers CUI with 110 controls and, where the solicitation designates it, assessment by a CMMC Third-Party Assessment Organization (C3PAO). During the July 2026 suspension, C3PAO assessments are not being added to new solicitations.

What Are the 14 Control Families in NIST 800-171?

The 110 controls in NIST SP 800-171 (and by extension CMMC Level 2) are organized into 14 families. Each family addresses a distinct area of information security:

Access Control (AC)
22 controls
Awareness & Training (AT)
3 controls
Audit & Accountability (AU)
9 controls
Configuration Management (CM)
9 controls
Identification & Auth (IA)
11 controls
Incident Response (IR)
3 controls
Maintenance (MA)
6 controls
Media Protection (MP)
9 controls
Personnel Security (PS)
2 controls
Physical Protection (PE)
6 controls
Risk Assessment (RA)
3 controls
Security Assessment (CA)
4 controls
System & Comm Protection (SC)
16 controls
System & Info Integrity (SI)
7 controls

Access Control is the largest family with 22 controls, covering areas like least privilege, session management, remote access, and wireless restrictions. Small businesses often find this family, along with Audit and Accountability, to be the most challenging to implement fully.

What Does the Assessment Process Look Like?

CMMC Level 2 assessments come in two forms, depending on the sensitivity of the CUI involved:

  • Self-Assessment: For contracts involving less critical CUI, you conduct your own assessment against all 110 controls and submit results to the Supplier Performance Risk System (SPRS). You must achieve a score of 110 (all controls met) or document a Plan of Action and Milestones (POA&M) for any gaps.
  • C3PAO Assessment: For contracts involving prioritized CUI, a Certified Third-Party Assessment Organization (C3PAO) conducts an on-site evaluation. The C3PAO reviews your System Security Plan (SSP), interviews staff, examines evidence, and tests controls. Assessment length depends on scope.

The scoring methodology assigns 1 point per control for a maximum of 110. You may receive a conditional certification with a POA&M if certain controls are not fully implemented, but POA&M items must be closed within 180 days. Some controls are weighted more heavily and cannot be on a POA&M.

RFI Hawk's CMMC Tracker helps you self-assess against all 110 controls, generate your SSP documentation, and track POA&M items with remediation deadlines, so you can prepare for formal assessment with confidence.

How Much Does CMMC Level 2 Cost for a Small Business?

Cost estimates for CMMC Level 2 vary widely based on your current security posture, company size, and IT environment complexity. The DoD's regulatory impact analysis estimated costs of $20,000 to $100,000 for small businesses (source: CMMC Program final rule, 32 CFR Part 170). Illustrative ranges reported by contractors follow; your costs depend on scope:

  • C3PAO Assessment Fee: $30,000 to $60,000 for small organizations (varies by assessor and scope)
  • Technology Implementation: $5,000 to $30,000 for multi-factor authentication, encryption, SIEM, endpoint detection
  • Consulting and Gap Assessment: $5,000 to $20,000 for initial readiness evaluation and remediation planning
  • Ongoing Compliance: $10,000 to $25,000 annually for monitoring tools, training, and documentation maintenance

Companies that already have a mature NIST 800-171 implementation will spend significantly less. The biggest cost driver for most small businesses is moving from partial compliance to full implementation of all 110 controls, particularly in the Access Control and Audit families.

What Is a POA&M and How Does It Work Under CMMC?

A Plan of Action and Milestones (POA&M) documents security controls that are not yet fully implemented, along with specific remediation steps and target completion dates. Under CMMC Level 2, you may receive a conditional certification with open POA&M items, but several important rules apply:

  • All POA&M items must be closed within 180 days of the assessment
  • Certain high-priority controls cannot be placed on a POA&M and must be fully implemented at assessment time
  • You must achieve a minimum score (not all controls can be deferred)
  • A follow-up assessment verifies POA&M closure

The POA&M is not a way to avoid compliance. It is a structured remediation plan for controls that are in progress. Assessors and contracting officers will evaluate the credibility of your POA&M milestones. Realistic timelines and demonstrated progress are essential.

Related Resources

CMMC Compliance Guide (Overview) Authority to Operate (ATO) Guide Security Clearance Guide

Frequently Asked Questions

How much does CMMC certification cost?

CMMC Level 2 certification costs for small businesses range from $20,000 to $100,000, according to the DoD regulatory impact analysis. This includes the C3PAO assessment fee ($30,000 to $60,000), technology implementation costs, consulting fees, and ongoing compliance maintenance. Companies with existing NIST 800-171 implementations will spend less on remediation.

Do subcontractors need CMMC?

Yes. Subcontractors that handle CUI must achieve the same CMMC level specified in the prime contract. If the prime requires Level 2, any subcontractor processing, storing, or transmitting CUI must also hold Level 2. Subcontractors handling only Federal Contract Information (FCI) may need only Level 1 self-assessment. Prime contractors must verify subcontractor compliance.

When is CMMC required?

CMMC Phase 1 has been in effect since November 10, 2025. Contracts that include DFARS 252.204-7021 require a CMMC Level 1 or Level 2 self-assessment recorded in SPRS with an annual affirmation. In July 2026 the DoD CIO suspended the advancement to Phase 2 and placed later phases on hold pending a CMMC Reform Task Force review; third-party (C3PAO) and Level 3 requirements are not being added to new solicitations during the suspension. The underlying rules (32 CFR Part 170 and DFARS 252.204-7021) remain in place. Contractors should start preparing now; many small contractors report a year or more of preparation. Current as of 2026-09-02.

Start a CMMC self-assessment

RFI Hawk is a federal contracting research, decision-support, compliance-readiness, and proposal-production platform. This page is general information, not legal advice. Requirements change; confirm controlling text at the official source cited. Current as of 2026-09-02.