This CMMC Level 2 assessment guide walks the assessment from scope through submission, and it starts with the change that reshaped it: in July 2026 the Department of War suspended third-party CMMC assessment, which makes the Level 2 self-assessment the live requirement for most contractors handling Controlled Unclassified Information. The obligation to meet the standard did not go away. What changed is who confirms it, and for now that is you, attesting to your own score, which raises the stakes on getting the assessment right rather than lowering them.
Level 2 applies to organizations that process, store, or transmit CUI, and it is built on the 110 security requirements of NIST SP 800-171 Revision 2, measured across 320 assessment objectives. Whether you reach that standard through a self-assessment or, once third-party assessment resumes, through a certified assessor, the preparation is the same. This guide covers what Level 2 requires, how the assessment is scored and submitted, and what the suspension does and does not change.
What the CMMC Level 2 Assessment Requires Now
Level 2 requires implementing all 110 requirements of NIST SP 800-171 Revision 2 and being able to demonstrate each one against its assessment objectives. Those requirements span 14 families, from access control and identification and authentication through audit and accountability, configuration management, incident response, and system and communications protection. The standard is the same regardless of who assesses you against it.
The suspension changed the assessment path, not the standard. Under the July 2026 Department of War memo, program managers may currently require only CMMC Level 1 (Self) or Level 2 (Self), and the move to third-party Level 2 (C3PAO) and Level 3 (DIBCAC) assessment is paused while a review runs. The practical effect is that the self-assessment is the requirement you are accountable for today. For the full picture of what is paused and what stays in force, see the analysis of the CMMC Level 2 suspension.
Three things did not change, and they are the reason this assessment still matters. DFARS 252.204-7012 still obligates you to implement the 110 requirements. The 800-171 Rev 2 requirements themselves are unchanged. And a self-attestation you cannot support is a false statement to the government, which carries False Claims Act exposure. A self-assessment is not a lighter obligation than a third-party one; it is the same standard with your name on the attestation.
Scope the Assessment Before You Score It
The assessment measures the systems in your CMMC Assessment Scope, so defining that scope is the first move and the one that most affects cost and difficulty. Scope is the set of assets that will be assessed against the requirements, and it is driven by where CUI goes: everything that processes, stores, or transmits it, plus everything that protects those systems, is in. The tighter and better-documented the scope, the smaller the assessment.
Scoping is its own discipline, and the full method, including the five asset categories and how to draw a defensible boundary, is covered in the CMMC environment scoping guide. For the assessment, what matters is that scope is settled and documented before you score anything, because a score against the wrong scope is meaningless. If CUI is confined to part of your operation, isolating it in an enclave or segment keeps most of the business out of the assessment, and defining the CUI boundary is where that separation is made real.
Once scope is set, every in-scope asset needs a place in your asset inventory and your System Security Plan. The out-of-scope assets need a documented reason they cannot reach CUI. That inventory is the frame the rest of the assessment hangs on.
Run a Gap Assessment Against the 110 Requirements
Before you score for submission, assess yourself against the standard honestly to find what is missing. A gap assessment reviews your controls, documentation, and technical implementation against all 110 requirements and their 320 assessment objectives, using the same NIST SP 800-171A procedures an assessor would use. Working from the assessor’s own procedures means you are testing against the real criteria, not a simplified proxy.
A thorough gap assessment works through four kinds of review. It examines your policies, procedures, and System Security Plan against each requirement. It interviews the people who operate the controls to confirm they work as written. It evaluates the technical implementation, from configurations and segmentation to logging. And it maps each current control to its requirement to expose where coverage is missing or partial. The output is a ranked list of gaps that becomes your remediation plan.
The gap assessment is where most of the real work surfaces. Common shortfalls cluster in a few places: multi-factor authentication that is incomplete across privileged and non-privileged access, audit logging that does not capture enough, encryption that is not FIPS-validated, and documentation that describes a control the organization does not actually operate. Finding these before you attest is the entire point, because after you attest they become misstatements rather than open items.
Score the Assessment and Submit to SPRS
CMMC Level 2 self-assessment scoring uses the DoD Assessment Methodology, which starts every organization at a perfect score of 110 and subtracts points for each requirement not fully met. The deductions are weighted by security impact: the requirements that matter most carry a five-point deduction, others three, and the least-weighted one. A control with broad downstream effect, such as limiting system access to authorized users, costs more when it is missing than a narrow one, because its absence undermines other controls.
Partial Credit and Weighted Deductions
Some requirements allow partial credit rather than an all-or-nothing deduction, and two are worth calling out because they trip up scoring. Multi-factor authentication (3.5.3) can earn partial credit when it is implemented for some access types but not all. FIPS-validated cryptography (3.13.11) is scored on whether the cryptography protecting CUI is validated, not merely present. Because the weighting and partial-credit rules determine the number you attest to, the score has to be built from the official methodology rather than estimated, and the reasoning behind each deduction should be documented in case it is ever reviewed.
Submission and the POA&M Path
You submit the resulting score to the Supplier Performance Risk System, where it becomes the record of your Level 2 status. Not every gap has to be closed before you submit. A Plan of Action and Milestones can carry certain open items under a conditional status, with a 180-day window to close them, though some requirements cannot be deferred to a POA&M at all. What you cannot do is submit a score that overstates your implementation, because the score is an attestation and the gap between the number and reality is exactly what False Claims Act enforcement targets.
Self-Assessment Versus Third-Party Assessment
Level 2 has always had two assessment paths, and the suspension shifted which one is in front of you. The self-assessment path has you evaluate your own implementation, score it, and attest to it in SPRS. The third-party path, currently paused, has a Certified Third-Party Assessment Organization evaluate you against the same 320 objectives. The standard and the preparation are identical; the difference is who signs off.
The preparation does not change based on which path applies, and that is the strategic point during the suspension. An organization that has genuinely implemented the 110 requirements, documented them in a System Security Plan, maintained a POA&M where needed, and scored itself honestly is ready for either path. Treating the current self-assessment window as a reason to slow down is the trap, because when third-party assessment resumes the organizations that kept preparing will be ready and the ones that paused will be starting over against a queue.
Documentation the Assessment Depends On
Every assessment, self or third-party, runs on documentation, and thin documentation is the most common reason an otherwise secure organization struggles. The System Security Plan is the central artifact. It identifies the system and its boundary, describes how each of the 110 requirements is implemented, assigns responsibility for each control, and connects to your asset inventory, network diagram, and data flow documentation. An assessor’s first move is to read the SSP, so it has to match what the organization actually does.
The Plan of Action and Milestones is the second core document. It records each open gap, the fix, the owner, and the deadline, and under a conditional status those items carry a 180-day close-out clock. Beyond these two, you need the evidence that each control operates: policies and procedures, configuration records, training completion, and logs that show ongoing monitoring. The controls being real is necessary but not sufficient; the assessment tests whether you can prove they are real.
External Providers and the Cloud
If you use a cloud provider to handle CUI, that provider is part of your assessment picture. A Cloud Service Provider that processes, stores, or transmits CUI must meet FedRAMP Moderate equivalency, measured against the FedRAMP Moderate baseline. In current practice that equivalency is established through a third-party report from a 3PAO covering the Moderate baseline control set, delivered as a body of evidence, and the CMMC assessor checks that the equivalency exists as part of your assessment. The cloud’s FedRAMP Moderate equivalency is separate from your own 800-171 Rev 2 obligation on your own systems, and the two stack rather than substitute for each other. Using an authorized cloud does not transfer your responsibility; you still implement and evidence the controls that remain yours, documented in a Customer Responsibility Matrix inside your SSP.
Level 2 Maintenance After the Assessment
A Level 2 result runs on a three-year cycle with annual affirmations of continued compliance in between, and a significant architectural or boundary change to your scope can require a fresh assessment. The affirmation is not a formality: it is a renewed attestation, so it carries the same accuracy obligation as the original. Between affirmations, the work is keeping the SSP current as the environment changes, closing POA&M items on schedule, and re-scoping when CUI starts flowing somewhere new.
Elevate helps defense contractors run the Level 2 assessment honestly, from scoping and gap assessment through an SPRS score that will hold up to scrutiny. To pressure-test your readiness before you attest, book a readiness call with an Elevate advisor.
Conclusion
The CMMC Level 2 assessment did not get easier when third-party assessment paused; it got closer, because the self-assessment is now the live requirement and the attestation is yours. The path runs the same way it always has: settle and document your scope, assess honestly against all 110 requirements, score with the official methodology, submit to SPRS, and carry any deferrable gaps on a POA&M you actually close. What makes the difference is treating the self-assessment as the serious obligation it is rather than a lighter alternative.
Organizations that keep preparing through the suspension will be ready whichever path applies when the review concludes. The standard is fixed, the documentation is knowable, and the score is defensible when it is built from reality. To confirm your Level 2 readiness before you put your name on the attestation, book a readiness call with an Elevate advisor.
Key Takeaways
The CMMC Level 2 assessment is now, for most contractors, a self-assessment, and the standard behind it is unchanged.
- The self-assessment is the live requirement: third-party Level 2 and Level 3 assessment is paused, so the obligation you are accountable for today is your own attested score.
- The standard did not move: DFARS 252.204-7012, the 110 NIST 800-171 Rev 2 requirements, and False Claims Act exposure on a false attestation all remain in force.
- Scope before you score: the assessment measures your CMMC Assessment Scope, so a documented, defensible boundary is the prerequisite to a meaningful score.
- Score from the official methodology: the 110-point DoD Assessment Methodology uses weighted deductions and partial credit, so the number you attest to must be built from the real rules, not estimated.
- Documentation decides the outcome: a System Security Plan that matches reality and evidence that each control operates are what an assessment actually tests.
FAQs
Q1. What is a CMMC Level 2 assessment? A CMMC Level 2 assessment measures an organization that handles Controlled Unclassified Information against all 110 requirements of NIST SP 800-171 Revision 2, across 320 assessment objectives. It can be a self-assessment, where you evaluate and attest to your own implementation in the Supplier Performance Risk System, or a third-party assessment by a certified organization. As of the July 2026 suspension of third-party assessment, the self-assessment is the live path for most contractors.
Q2. Is CMMC Level 2 still required after the suspension? Yes. The July 2026 Department of War memo paused third-party assessment, but it did not remove the underlying obligation. DFARS 252.204-7012 still requires implementing the 110 NIST SP 800-171 requirements, and contractors must still complete and attest to a Level 2 self-assessment. A false self-attestation carries False Claims Act exposure, so the requirement is unchanged in substance even though third-party verification is paused.
Q3. How is a CMMC Level 2 self-assessment scored? Scoring uses the DoD Assessment Methodology, which starts at a perfect 110 and subtracts weighted points for each requirement not fully met, five points for the highest-impact requirements down to one for the lowest. A few requirements, including multi-factor authentication and FIPS-validated cryptography, allow partial credit. The resulting score is submitted to the Supplier Performance Risk System and functions as your attestation, so it must be built from the official methodology rather than estimated.
Q4. What documentation does a CMMC Level 2 assessment require? The central document is the System Security Plan, which describes how each of the 110 requirements is implemented, defines the system boundary, and connects to your asset inventory, network diagram, and data flow documentation. You also need a Plan of Action and Milestones for any open gaps, with a 180-day close-out window under conditional status, plus the evidence that each control operates, such as policies, configuration records, training records, and logs.
Q5. Can I use a cloud provider for CUI under CMMC Level 2? Yes, but a Cloud Service Provider that handles CUI must meet FedRAMP Moderate equivalency, measured against the FedRAMP Moderate baseline and established through a 3PAO report and body of evidence. The CMMC assessment checks that this equivalency exists, and it is separate from your own 800-171 Rev 2 obligation on your own systems, so the two stack. Using an authorized cloud does not transfer your responsibility, and you document the split in a Customer Responsibility Matrix within your System Security Plan.