CMMC Level 2 is where the defense industrial base does its heavy lifting: all 110 security requirements of NIST SP 800-171 Rev 2, applied to every system in scope for CUI, and verified for most contractors by a triennial C3PAO assessment. What defeats people is rarely a single control — it is the volume, and not knowing what order to tackle it in. This checklist breaks the journey into seven ordered steps, so you always know what comes next and what "done" looks like at each stage.
If you handle CUI, or DFARS 252.204-7012 appears in your contracts, plan for Level 2. Most contracts will require a triennial C3PAO certification assessment; a small subset are designated for self-assessment instead — also conducted every three years, with annual affirmations in SPRS either way. Timing matters too: under the CMMC rollout, Phase 2 begins November 10, 2026, when applicable new solicitations start requiring C3PAO certification as a condition of award. If CUI work is in your pipeline, the clock is already running.
Map where CUI enters, moves, and rests, and categorize assets per the CMMC scoping guidance. This is the decision point with the biggest cost impact of the entire program: bring your whole enterprise into scope, or consolidate CUI into a CMMC secure enclave so far fewer systems carry the 110 requirements.
The SSP documents your boundary, network and data-flow diagrams, asset inventory, and an implementation statement for each of the 110 requirements. It is not optional paperwork: under the DoD assessment methodology, an assessment cannot be completed without an SSP at all. We cover the full anatomy in our SSP guide.
The requirements span 14 families — access control, audit and accountability, configuration management, identification and authentication, incident response, and ten more. Sequence the work by DoD point weight: the 5-point items, multifactor authentication and FIPS-validated encryption among them, carry the largest score deductions and the longest deployment timelines. Start them first.
Policies alone are not proof. Collect configurations, logs, records, and screenshots mapped to each requirement and assessment objective — there are 320 objectives behind the 110 requirements. Assessors sample three ways: artifacts, interviews, and demonstrations. If your evidence exists only in someone's head, it does not exist.
Apply the DoD assessment methodology — scores run from -203 to +110 — and submit through PIEE, recording the score, date, scope, SSP name, and your projected full-implementation date. Our SPRS guide walks the scoring and submission mechanics in detail.
Level 2 permits a limited POA&M: broadly, only 1-point items qualify (with narrow exceptions, and six requirements that can never be on one), your score must reach at least 88 of 110, and everything on the list must close within 180 days. The rules are unforgiving enough that the best strategy is simple — arrive on assessment day with few open items, or none. The details are in our POA&M explainer.
Run a mock assessment or a formal CMMC readiness assessment, rehearse evidence walkthroughs and staff interviews, and handle logistics early: C3PAO calendars are booked months out, so schedule before you are perfect, not after. Assemble your assessment team and agree on how artifacts will be delivered.
Essendis takes contractors through every step on this list — readiness, remediation, enclave build, and assessment preparation — with advisory and engineering under one roof. It is the approach behind our client RPS Defense's perfect 110/110 Level 2 assessment with A-LIGN (C3PAO), achieved with no POA&M. Explore our CMMC Level 2 compliance services, or Connect with an expert to find out which step you are actually on.

