About this Framework
CMMC 2.0 Level 2 aligns with NIST SP 800-171 and encompasses 110 practices across 17 security domains. Defense contractors processing, storing or transmitting Controlled Unclassified Information (CUI) must achieve CMMC Level 2 to bid on DoD contracts, typically requiring a C3PAO third-party assessment for contracts with significant CUI scope.
Key Control Domains
Access Control
Awareness & Training
Audit & Accountability
Configuration Management
Identification & Authentication
Incident Response
Maintenance
Media Protection
Personnel Security
Physical Protection
Risk Assessment
Security Assessment
System & Communications Protection
System & Information Integrity
Who Needs This?
- U.S. DoD prime contractors and subcontractors
- Defense Industrial Base suppliers handling CUI
- Aerospace, defense manufacturing and engineering firms
- IT and cybersecurity service providers to the DoD
Compliance Benefits
- Legal eligibility to bid on DoD contracts
- Competitive advantage in defence procurement
- Formal third-party validated cybersecurity maturity
- Aligned with NIST SP 800-171 federal standard
Official Reference
CMMC Official Program Site
https://dodcmmc.mil
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/cybersecurity-maturity-model-certification-cmmc-level-2