GRCCopilot
Sign In
U.S. Department of Defense (DoD)

Cybersecurity Maturity Model Certification (CMMC) Level 2

Required DoD certification for defense contractors handling Controlled Unclassified Information

Start Assessment Create Free Account
38
Controls
114
Questions
Active
Status

About this Framework

CMMC 2.0 Level 2 aligns with NIST SP 800-171 and encompasses 110 practices across 17 security domains. Defense contractors processing, storing or transmitting Controlled Unclassified Information (CUI) must achieve CMMC Level 2 to bid on DoD contracts, typically requiring a C3PAO third-party assessment for contracts with significant CUI scope.

Key Control Domains

Access Control
Awareness & Training
Audit & Accountability
Configuration Management
Identification & Authentication
Incident Response
Maintenance
Media Protection
Personnel Security
Physical Protection
Risk Assessment
Security Assessment
System & Communications Protection
System & Information Integrity

Who Needs This?

  • U.S. DoD prime contractors and subcontractors
  • Defense Industrial Base suppliers handling CUI
  • Aerospace, defense manufacturing and engineering firms
  • IT and cybersecurity service providers to the DoD

Compliance Benefits

  • Legal eligibility to bid on DoD contracts
  • Competitive advantage in defence procurement
  • Formal third-party validated cybersecurity maturity
  • Aligned with NIST SP 800-171 federal standard

Official Reference

CMMC Official Program Site
https://dodcmmc.mil

Assessment Details

Issuer / AuthorityU.S. Department of Defense (DoD)
FrameworkCybersecurity Maturity Model Certification (CMMC) Level 2
Controls38
Questions114
StatusActive
Assessment Start10 May 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/cybersecurity-maturity-model-certification-cmmc-level-2

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.