Last verified: August 14, 2026. DoD suspended CMMC Phase II on July 13, 2026 and is continuing Phase I self-assessment requirements. While the suspension remains in effect, only Level 1 (Self) and Level 2 (Self) CMMC status requirements may be newly designated. The 110 Level 2 requirements did not change. See the current DoD CMMC notice.
The Defense Compliance Report Editorial Team · Independent CMMC and DIB compliance research
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.
The NIST 800-171 110 controls list is the set of 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families — and under 32 CFR 170.14(c)(3), those exact 110 requirements are CMMC Level 2. Under the current CMMC scoring method, 42 are fixed 5-point requirements, 14 are fixed 3-point requirements, 51 are 1-point requirements, two can deduct 3 or 5 points, and the system security plan is a gate rather than a weighted line item.
Here is the decision fact a plain control list does not show: 63 of the 110 cannot be placed on a Conditional Level 2 Plan of Action and Milestones under the current rule. One unmet 5-point requirement can end your Conditional path at a score of 105 — while a company at 88 with 22 eligible 1-point gaps may still have one.
We'll show you the arithmetic that proves it. First, the list.
Who this page is for — and who should leave
| Use this page if… | Don't use this page as… |
|---|---|
| You handle Controlled Unclassified Information (CUI) on DoD work and need the current Level 2 baseline | Proof that you comply — no list can do that |
| You're building or auditing a system security plan, self-assessment, CMMC score, or NIST DoD Assessment score | A substitute for determining whether CUI is actually in your environment |
| You need to know what each gap actually costs before you build a remediation plan | A promise that any product, template, or provider makes a requirement “met” |
| You're sanity-checking a readiness quote against real scope | Legal, contractual, or compliance advice |
If you only handle Federal Contract Information (FCI) and no CUI, this is the wrong list. Level 1 is a separate, smaller set — 15 basic safeguarding requirements at 48 CFR 52.204-21(b)(1)(i)–(xv), per 32 CFR 170.14(c)(2). Start with our Level 1 self-assessment checklist instead. You'll save yourself weeks.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining material regulatory claims with primary-source citations and mapping a contractor's required level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right path before they spend six figures.
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on the CMMC status required in your solicitation, contract, or flowdown; whether you handle FCI or CUI; your assessment type; your cloud and IT environment; and your contract timeline. A C3PAO is a CMMC Third-Party Assessment Organization, not a readiness consultant by definition and not a company that can promise you a certificate. Use our Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
What Is the NIST 800-171 110 Controls List?
The NIST 800-171 110 controls list is the complete set of security requirements in NIST SP 800-171 Revision 2 for protecting Controlled Unclassified Information on nonfederal systems, organized into 14 families. Under 32 CFR 170.14(c)(3), the CMMC Level 2 security requirements are identical to those in Revision 2. Behind the 110 requirements sit 320 individual assessment objectives from NIST SP 800-171A, and a requirement is scored MET only when every applicable objective is satisfied.
Three terms, defined once, because the vocabulary trips people up:
A security requirement is one of the 110 numbered items — 3.1.1, 3.4.7, 3.13.11. NIST calls them requirements. Most of the industry calls them controls. Same things. We'll use both, because you searched for one and the regulation uses the other.
An assessment objective is a single determination statement underneath a requirement. Requirement 3.1.1 has six. Requirement 3.4.7 has fifteen. Requirement 3.5.4 has one. The finding is per requirement; the evidence work is per objective.
SPRS is the Supplier Performance Risk System. But “the SPRS score” is not one universal record. Two different records can use the same 110-point arithmetic, and confusing them can leave you with the wrong submission for the clause in your contract.
SPRS is one system with two records you should not confuse
| Record | Primary authority | What gets posted | What it proves |
|---|---|---|---|
| NIST SP 800-171 DoD Assessment summary record | DFARS 252.204-7019 and 252.204-7020 | Assessment standard/version, assessor, CAGE codes, assessment date and level, summary score, and expected date to reach 110 | A Basic, Medium, or High NIST SP 800-171 DoD Assessment record |
| CMMC Level 2 self-assessment record | 32 CFR 170.16, 170.22, and DFARS 252.204-7021 | CMMC level, status date, assessment scope, CAGE codes, score, POA&M status, CMMC UID, and the required affirmation | Conditional or Final Level 2 (Self) CMMC status for the assessed scope |
The records can coexist. The NIST DoD Assessment record is tied to DFARS 252.204-7019/-7020. The CMMC record is tied to 32 CFR Part 170 and DFARS 252.204-7021 when the solicitation or contract requires a CMMC status. Same platform. Related arithmetic. Different record, different trigger, different evidence of eligibility.
The one number that decides whether you're on the right list
Before you spend a quarter building a program, confirm the version. Revision 2 has 110 requirements across 14 families. Revision 3 has 97 requirements across 17 families. They are not interchangeable, and picking wrong means rebuilding.
For current CMMC Level 2, it is Revision 2. 32 CFR 170.2 incorporates the February 2020 publication, including updates through January 28, 2021, and § 170.14(c)(3) makes Level 2 identical to it. That does not change because NIST published a newer document.
| Your situation | The list you work from | Why |
|---|---|---|
| CMMC Level 2 under current 32 CFR Part 170 | Revision 2 — 110 requirements | The rule incorporates the February 2020 Rev. 2 version and makes Level 2 identical to it |
| DFARS 252.204-7012 safeguarding obligation | The NIST SP 800-171 version in effect when the solicitation was issued, unless the Contracting Officer authorizes otherwise | That is the version rule written into DFARS 252.204-7012(b)(2)(i) |
| Your contract expressly names Revision 3 | Follow the written contract, then get it reviewed | Never override express contract language with a general checklist |
| Internal planning for what comes next | Track Rev. 3 separately | Useful. Just do not blend it into a current CMMC Rev. 2 score |
| A non-DoD federal customer | Confirm the actual clause | CMMC does not govern every federal agreement |
Here's the uncomfortable part
NIST withdrew Revision 2. On May 14, 2024, NIST marked SP 800-171 Revision 2 as withdrawn and superseded by Revision 3. NIST marked SP 800-171A withdrawn the same day. Both NIST pages identify the PDFs as the normative source when derivative data files disagree.
So yes: the CMMC standard and assessment procedures DoD incorporated are archived documents on NIST's own website. That's genuinely strange, and if it has been nagging at you, you were not being paranoid.
It also does not rewrite the rule. NIST publishes; DoD regulates and contracts. An incorporation by reference names a specific edition. Until DoD amends 32 CFR Part 170, Revision 2 and its 110 requirements remain the operative CMMC Level 2 baseline. Separately, DFARS 252.204-7012 applies the version in effect when the solicitation was issued unless the Contracting Officer authorizes otherwise.
That gap between “newest” and “operative” is exactly where contractors lose quarters of work. It is also why we date every regulatory fact on this page.
What are the 14 NIST 800-171 control families?
The 110 requirements are spread unevenly across 14 families. Access Control holds 22 requirements and 70 assessment objectives. Personnel Security holds 2 requirements and 4 objectives. Counting families tells you almost nothing about workload; counting objectives, point exposure, and deferral options tells you where your quarter goes.
This table is our own assembly. The requirement counts come from NIST SP 800-171 Rev. 2. We counted all 320 objective statements directly from the normative NIST SP 800-171A PDF. The point values come from 32 CFR 170.24(c)(2). The potential POA&M column is derived from 32 CFR 170.21(a)(2). It joins four source layers contractors normally have to reconcile themselves.
| Family | Requirements | Assessment objectives | 5-point | 3-point | 3-or-5 | 1-point | Potentially POA&M-eligible |
|---|---|---|---|---|---|---|---|
| 3.1 Access Control | 22 | 70 | 7 | 2 | 0 | 13 | 11 |
| 3.2 Awareness and Training | 3 | 9 | 2 | 0 | 0 | 1 | 1 |
| 3.3 Audit and Accountability | 9 | 29 | 2 | 1 | 0 | 6 | 6 |
| 3.4 Configuration Management | 9 | 44 | 6 | 0 | 0 | 3 | 3 |
| 3.5 Identification and Authentication | 11 | 25 | 3 | 0 | 1 | 7 | 7 |
| 3.6 Incident Response | 3 | 14 | 2 | 0 | 0 | 1 | 1 |
| 3.7 Maintenance | 6 | 10 | 2 | 2 | 0 | 2 | 2 |
| 3.8 Media Protection | 9 | 15 | 2 | 3 | 0 | 4 | 4 |
| 3.9 Personnel Security | 2 | 4 | 1 | 1 | 0 | 0 | 0 |
| 3.10 Physical Protection | 6 | 16 | 2 | 0 | 0 | 4 | 1 |
| 3.11 Risk Assessment | 3 | 9 | 1 | 1 | 0 | 1 | 1 |
| 3.12 Security Assessment | 4 | 14 | 2 | 1 | 0 | 0 | 0 |
| 3.13 System and Communications Protection | 16 | 41 | 5 | 1 | 1 | 9 | 10 |
| 3.14 System and Information Integrity | 7 | 20 | 5 | 2 | 0 | 0 | 0 |
| Total | 110 | 320 | 42 | 14 | 2 | 51 | 47 |
Security Assessment shows 4 requirements but only 3 carry point values — CA.L2-3.12.4, the system security plan requirement, is a gate rather than a weighted item. “Potentially POA&M-eligible” means the rule does not categorically bar the item; your score, findings, and 180-day closeout still control actual eligibility.
Four things this table tells you that a family list can't
Three families have zero potentially deferrable requirements. Personnel Security, Security Assessment, and System and Information Integrity are entirely pass/fail for Conditional Level 2 purposes. Every requirement in those three families must be MET at assessment.
Physical Protection is a trap. It looks flexible — four 1-point requirements out of six. But three of those four, 3.10.3, 3.10.4, and 3.10.5, are barred from a Conditional POA&M by name. Only 3.10.6, the alternate work site requirement, is potentially deferrable.
Configuration Management is a brutal 5-point cluster. Six of its nine requirements are fixed 5-pointers, and it carries 44 assessment objectives — the second-heaviest objective load behind Access Control. A CM gap list can lose 30 points across six lines before you count anything else.
The objective count inside a single requirement varies by 15×. CM.L2-3.4.7 — restricting nonessential programs, functions, ports, protocols, and services — has 15 assessment objectives, more than the entire Personnel Security family and Awareness and Training family combined. CM.L2-3.4.4 has one. Both live on the same “110 controls” list. They are not comparable units of evidence work.
We counted 23 requirements with one objective: 3.4.4, 3.5.4, 3.5.9, 3.5.11, 3.6.3, 3.7.1, 3.7.3, 3.7.4, 3.7.6, 3.8.2, 3.8.6, 3.8.7, 3.8.8, 3.8.9, 3.9.1, 3.10.4, 3.12.3, 3.13.4, 3.13.7, 3.13.11, 3.13.15, 3.13.16, 3.14.4.
We counted 13 requirements with six or more objectives: 3.1.1 (6), 3.1.20 (6), 3.3.1 (6), 3.3.8 (6), 3.4.1 (6), 3.4.5 (8), 3.4.7 (15), 3.6.1 (7), 3.6.2 (6), 3.12.4 (8), 3.13.1 (8), 3.13.2 (6), 3.14.1 (6).
Those counts come from a requirement-by-requirement parse of the normative NIST SP 800-171A PDF, not a family-total estimate.
The complete NIST 800-171 110 controls list
All 110 NIST SP 800-171 Revision 2 requirements are listed below by family, each with its CMMC Level 2 identifier, whether NIST designates it basic or derived, its point value under 32 CFR 170.24(c)(2), and whether 32 CFR 170.21(a)(2) leaves a possible Conditional POA&M path.
How to read the POA&M column: Yes means the requirement is worth 1 point and is not a named exclusion. No means the requirement is worth more than 1 point. No — named means the regulation bars it by name regardless of value. Conditional applies to exactly one requirement, explained below.
The descriptions below are our plain-language labels, not the official requirement text. The controlling text is NIST SP 800-171 Revision 2.
3.1 Access Control — 22 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| AC.L2-3.1.1 | Limit access to authorized users, processes, devices | Basic | 5 | No |
| AC.L2-3.1.2 | Limit access to permitted transactions and functions | Basic | 5 | No |
| AC.L2-3.1.3 | Control the flow of CUI | Derived | 1 | Yes |
| AC.L2-3.1.4 | Separate duties of individuals | Derived | 1 | Yes |
| AC.L2-3.1.5 | Employ least privilege | Derived | 3 | No |
| AC.L2-3.1.6 | Non-privileged accounts for nonsecurity functions | Derived | 1 | Yes |
| AC.L2-3.1.7 | Prevent and log non-privileged execution of privileged functions | Derived | 1 | Yes |
| AC.L2-3.1.8 | Limit unsuccessful logon attempts | Derived | 1 | Yes |
| AC.L2-3.1.9 | Privacy and security notices | Derived | 1 | Yes |
| AC.L2-3.1.10 | Session lock with pattern-hiding display | Derived | 1 | Yes |
| AC.L2-3.1.11 | Automatic session termination | Derived | 1 | Yes |
| AC.L2-3.1.12 | Monitor and control remote access sessions | Derived | 5 | No |
| AC.L2-3.1.13 | Cryptographic protection of remote access | Derived | 5 | No |
| AC.L2-3.1.14 | Route remote access through managed control points | Derived | 1 | Yes |
| AC.L2-3.1.15 | Authorize remote privileged commands and access to security-relevant information | Derived | 1 | Yes |
| AC.L2-3.1.16 | Authorize wireless access before connection | Derived | 5 | No |
| AC.L2-3.1.17 | Protect wireless with authentication and encryption | Derived | 5 | No |
| AC.L2-3.1.18 | Control connection of mobile devices | Derived | 5 | No |
| AC.L2-3.1.19 | Encrypt CUI on mobile devices | Derived | 3 | No |
| AC.L2-3.1.20 | Verify and control connections to external systems | Derived | 1 | No — named |
| AC.L2-3.1.21 | Limit portable storage use on external systems | Derived | 1 | Yes |
| AC.L2-3.1.22 | Control CUI on publicly accessible systems | Derived | 1 | No — named |
3.2 Awareness and Training — 3 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| AT.L2-3.2.1 | Security awareness for managers, admins, users | Basic | 5 | No |
| AT.L2-3.2.2 | Role-based training for security duties | Basic | 5 | No |
| AT.L2-3.2.3 | Insider threat awareness training | Derived | 1 | Yes |
3.3 Audit and Accountability — 9 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| AU.L2-3.3.1 | Create and retain system audit logs | Basic | 5 | No |
| AU.L2-3.3.2 | Trace user actions uniquely to individual users | Basic | 3 | No |
| AU.L2-3.3.3 | Review and update logged events | Derived | 1 | Yes |
| AU.L2-3.3.4 | Alert on audit logging process failure | Derived | 1 | Yes |
| AU.L2-3.3.5 | Correlate audit review, analysis, and reporting | Derived | 5 | No |
| AU.L2-3.3.6 | Audit record reduction and report generation | Derived | 1 | Yes |
| AU.L2-3.3.7 | Time stamps synchronized to an authoritative source | Derived | 1 | Yes |
| AU.L2-3.3.8 | Protect audit information and logging tools | Derived | 1 | Yes |
| AU.L2-3.3.9 | Limit audit management to a privileged subset | Derived | 1 | Yes |
3.4 Configuration Management — 9 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| CM.L2-3.4.1 | Baseline configurations and system inventories | Basic | 5 | No |
| CM.L2-3.4.2 | Security configuration settings | Basic | 5 | No |
| CM.L2-3.4.3 | Track, review, approve, and log changes | Derived | 1 | Yes |
| CM.L2-3.4.4 | Security impact analysis before changes | Derived | 1 | Yes |
| CM.L2-3.4.5 | Access restrictions associated with changes | Derived | 5 | No |
| CM.L2-3.4.6 | Least functionality | Derived | 5 | No |
| CM.L2-3.4.7 | Restrict nonessential programs, ports, protocols, services | Derived | 5 | No |
| CM.L2-3.4.8 | Application allowlisting or denylisting | Derived | 5 | No |
| CM.L2-3.4.9 | Control and monitor user-installed software | Derived | 1 | Yes |
3.5 Identification and Authentication — 11 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| IA.L2-3.5.1 | Identify users, processes, and devices | Basic | 5 | No |
| IA.L2-3.5.2 | Authenticate identities before granting access | Basic | 5 | No |
| IA.L2-3.5.3 | Multifactor authentication | Derived | 3 or 5 | No |
| IA.L2-3.5.4 | Replay-resistant authentication | Derived | 1 | Yes |
| IA.L2-3.5.5 | Prevent identifier reuse | Derived | 1 | Yes |
| IA.L2-3.5.6 | Disable identifiers after inactivity | Derived | 1 | Yes |
| IA.L2-3.5.7 | Password complexity and character change | Derived | 1 | Yes |
| IA.L2-3.5.8 | Prohibit password reuse | Derived | 1 | Yes |
| IA.L2-3.5.9 | Temporary passwords changed immediately | Derived | 1 | Yes |
| IA.L2-3.5.10 | Store and transmit only protected passwords | Derived | 5 | No |
| IA.L2-3.5.11 | Obscure authentication feedback | Derived | 1 | Yes |
The CFR renders 3.5.1 and 3.5.2 as “IA-L2-” in its point-value list rather than “IA.L2-.” That is a typographical inconsistency in the regulation, not a different requirement.
3.6 Incident Response — 3 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| IR.L2-3.6.1 | Operational incident-handling capability | Basic | 5 | No |
| IR.L2-3.6.2 | Track, document, and report incidents | Basic | 5 | No |
| IR.L2-3.6.3 | Test the incident response capability | Derived | 1 | Yes |
3.7 Maintenance — 6 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| MA.L2-3.7.1 | Perform maintenance on systems | Basic | 3 | No |
| MA.L2-3.7.2 | Control maintenance tools, techniques, and personnel | Basic | 5 | No |
| MA.L2-3.7.3 | Sanitize equipment removed for off-site maintenance | Derived | 1 | Yes |
| MA.L2-3.7.4 | Check maintenance media for malicious code | Derived | 3 | No |
| MA.L2-3.7.5 | MFA and terminate nonlocal maintenance sessions | Derived | 5 | No |
| MA.L2-3.7.6 | Supervise maintenance by uncleared personnel | Derived | 1 | Yes |
3.8 Media Protection — 9 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| MP.L2-3.8.1 | Protect media containing CUI | Basic | 3 | No |
| MP.L2-3.8.2 | Limit access to CUI on media to authorized users | Basic | 3 | No |
| MP.L2-3.8.3 | Sanitize or destroy media before disposal or reuse | Basic | 5 | No |
| MP.L2-3.8.4 | Mark media with CUI markings and limitations | Derived | 1 | Yes |
| MP.L2-3.8.5 | Control and account for media during transport | Derived | 1 | Yes |
| MP.L2-3.8.6 | Protect CUI on digital media during transport | Derived | 1 | Yes |
| MP.L2-3.8.7 | Control the use of removable media | Derived | 5 | No |
| MP.L2-3.8.8 | Prohibit portable storage with no identifiable owner | Derived | 3 | No |
| MP.L2-3.8.9 | Protect backup CUI at storage locations | Derived | 1 | Yes |
3.9 Personnel Security — 2 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| PS.L2-3.9.1 | Screen individuals before authorizing access | Basic | 3 | No |
| PS.L2-3.9.2 | Protect CUI during and after personnel actions | Basic | 5 | No |
3.10 Physical Protection — 6 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| PE.L2-3.10.1 | Limit physical access to systems and environments | Basic | 5 | No |
| PE.L2-3.10.2 | Protect and monitor facilities and support infrastructure | Basic | 5 | No |
| PE.L2-3.10.3 | Escort visitors and monitor visitor activity | Derived | 1 | No — named |
| PE.L2-3.10.4 | Maintain audit logs of physical access | Derived | 1 | No — named |
| PE.L2-3.10.5 | Control and manage physical access devices | Derived | 1 | No — named |
| PE.L2-3.10.6 | Safeguarding at alternate work sites | Derived | 1 | Yes |
3.11 Risk Assessment — 3 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| RA.L2-3.11.1 | Periodically assess risk | Basic | 3 | No |
| RA.L2-3.11.2 | Scan for vulnerabilities | Derived | 5 | No |
| RA.L2-3.11.3 | Remediate vulnerabilities per risk assessments | Derived | 1 | Yes |
3.12 Security Assessment — 4 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| CA.L2-3.12.1 | Periodically assess security controls | Basic | 5 | No |
| CA.L2-3.12.2 | Plans of action to correct deficiencies | Basic | 3 | No |
| CA.L2-3.12.3 | Monitor security controls on an ongoing basis | Basic | 5 | No |
| CA.L2-3.12.4 | System security plan | Basic | Gate — no point value | No — named |
3.13 System and Communications Protection — 16 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| SC.L2-3.13.1 | Monitor and protect communications at boundaries | Basic | 5 | No |
| SC.L2-3.13.2 | Secure architecture, software development, and engineering principles | Basic | 5 | No |
| SC.L2-3.13.3 | Separate user functionality from system management | Derived | 1 | Yes |
| SC.L2-3.13.4 | Prevent unauthorized transfer via shared resources | Derived | 1 | Yes |
| SC.L2-3.13.5 | Subnetworks for publicly accessible components | Derived | 5 | No |
| SC.L2-3.13.6 | Deny network traffic by default, allow by exception | Derived | 5 | No |
| SC.L2-3.13.7 | Prevent split tunneling | Derived | 1 | Yes |
| SC.L2-3.13.8 | Protect CUI during transmission | Derived | 3 | No |
| SC.L2-3.13.9 | Terminate connections after sessions or inactivity | Derived | 1 | Yes |
| SC.L2-3.13.10 | Establish and manage cryptographic keys | Derived | 1 | Yes |
| SC.L2-3.13.11 | FIPS-validated cryptography for CUI | Derived | 3 or 5 | Conditional |
| SC.L2-3.13.12 | Block remote activation and indicate collaborative devices in use | Derived | 1 | Yes |
| SC.L2-3.13.13 | Control and monitor mobile code | Derived | 1 | Yes |
| SC.L2-3.13.14 | Control and monitor VoIP | Derived | 1 | Yes |
| SC.L2-3.13.15 | Protect authenticity of communications sessions | Derived | 5 | No |
| SC.L2-3.13.16 | Protect confidentiality of CUI at rest | Derived | 1 | Yes |
3.14 System and Information Integrity — 7 requirements
| ID | Plain-language label | Basic/Derived | Points | Potential POA&M |
|---|---|---|---|---|
| SI.L2-3.14.1 | Identify, report, and correct system flaws | Basic | 5 | No |
| SI.L2-3.14.2 | Malicious code protection | Basic | 5 | No |
| SI.L2-3.14.3 | Monitor and act on security alerts and advisories | Basic | 5 | No |
| SI.L2-3.14.4 | Update malicious code protection mechanisms | Derived | 5 | No |
| SI.L2-3.14.5 | Periodic and real-time scans | Derived | 3 | No |
| SI.L2-3.14.6 | Monitor systems and inbound/outbound traffic | Derived | 5 | No |
| SI.L2-3.14.7 | Identify unauthorized use of systems | Derived | 3 | No |
You have the list. Now turn it into an evidence-ready assessment.
Use our CMMC readiness checklist to work through contract requirements, scope, the SSP, objective-level evidence, scoring, POA&M gates, and the point where outside help becomes the cheaper decision.
→ Use the CMMC readiness checklist
For the determination statements beneath these rows, open all 320 NIST 800-171A assessment objectives.
Do not submit CUI, drawings, credentials, or contract details.
How many points is each NIST 800-171 control worth?
Under 32 CFR 170.24(c)(2), a CMMC Level 2 assessment starts at 110 and subtracts points for each requirement assessed NOT MET. The distribution is 42 fixed 5-point requirements, 14 fixed 3-point requirements, 51 1-point requirements, two that can deduct 3 or 5 depending on implementation, and one — the system security plan — that carries no point value. Because the deductions can exceed 110, the score range runs from 110 down to −203.
The three tiers, in the regulation's own logic
The point value tracks how badly the gap hurts the scored security posture. The CFR is unusually plain about it.
Five points goes to requirements where failure “could lead to significant exploitation of the network, or exfiltration of CUI.” Twenty-three basic and nineteen derived requirements are listed by ID.
Three points goes to requirements whose failure has “a specific and confined effect on the security of the network and its data.” Seven basic and seven derived requirements are listed by ID.
One point goes to the remaining derived requirements, whose failure has “a limited or indirect effect.” The CFR does not enumerate these by ID. It defines them as the residual, which is why the 1-point list has to be derived and checked.
The two requirements that give partial credit
The scoring methodology credits partial implementation in exactly two places, and both matter because they change the deduction without making the requirement MET.
Multifactor authentication (IA.L2-3.5.3). If MFA is implemented only for remote and privileged users, 3 points are deducted. If MFA is implemented for no users, 5 points are deducted. The 3-point state is still a NOT MET requirement worth more than 1 point, so it cannot sit on a Conditional Level 2 POA&M. Partial MFA recovers two score points; it does not preserve Conditional eligibility.
FIPS-validated encryption (SC.L2-3.13.11). If encryption is employed but the module is not FIPS-validated, 3 points are deducted. If encryption is not employed, 5 points are deducted. “We use AES-256” is not the same claim as “we use a FIPS-validated cryptographic module.” The validation, not the algorithm name, is what this requirement turns on. Unlike partial MFA, the 3-point encryption state is the rule's one explicit exception that may go on a Conditional POA&M.
That's it. Two requirements out of 110. Everywhere else, partial implementation receives no adjusted point value.
Why the system security plan is different
CA.L2-3.12.4 has no point value. Instead, § 170.24(c)(2)(i)(5) says an organization must have a current SSP in place at the time of assessment describing each information system in the CMMC Assessment Scope, and that the absence of an up-to-date SSP results in a finding that the assessment could not be completed because of incomplete information and noncompliance with DFARS 252.204-7012.
Read that again. Not a low score. Not a finding of NOT MET. The assessment cannot be completed. You can have all 109 other requirements implemented and still have no CMMC assessment result to post.
The arithmetic that proves the 1-point list
The CFR names the fixed 5-pointers and fixed 3-pointers but never enumerates the 1-pointers. So we derived them: take all 110, subtract the 42 fixed 5-point requirements, the 14 fixed 3-point requirements, the 2 partial-credit requirements, and the SSP gate. What remains is 51 requirements at 1 point each.
Then we checked it, because a residual you cannot reconcile is just a guess:
| Tier | Count | Maximum deduction |
|---|---|---|
| Fixed 5-point requirements | 42 | 210 |
| Fixed 3-point requirements | 14 | 42 |
| Partial-credit requirements, at the full 5-point deduction | 2 | 10 |
| 1-point requirements | 51 | 51 |
| SSP gate (CA.L2-3.12.4) | 1 | 0 |
| Total | 110 | 313 |
110 − 313 = −203.
That is the published floor of the score range — also described in the Justice Department's March 2025 MORSECORP settlement as running from −203 to 110. The arithmetic reconciles exactly.
It also confirms why CA.L2-3.12.4 is a gate rather than a weighted row. If the SSP requirement carried even one point, the floor would be −204. It does not.
This 42/14/2/51/1 reconciliation is our derived cross-check for the per-requirement values in the table above. For implementation dollars rather than score deductions, see our CMMC Level 2 cost guide.
Which of the 110 controls can go on a POA&M?
Forty-seven of the 110 are potentially eligible for a Conditional Level 2 POA&M; 63 are not. Under 32 CFR 170.21(a)(2), Conditional Level 2 status requires a score of at least 88, generally permits only 1-point requirements on the POA&M, creates one narrow encryption exception, and bars six specific requirements by name. POA&M items must be closed and confirmed by a closeout assessment within 180 days or the Conditional status expires.
This section is about the CMMC Conditional-status POA&M in 32 CFR 170.21. It is not the same thing as every “plan of action” referenced elsewhere in NIST or DFARS.
The four conditions, in plain terms
- Your score divided by 110 must be at least 0.8. That's a score of 88 or better.
- Nothing worth more than 1 point may sit on the POA&M. The only exception is the encryption state below.
- SC.L2-3.13.11 gets a carve-out. CUI encryption may go on a POA&M only when encryption is employed but is not FIPS-validated — the 3-point state. If encryption is not employed, the 5-point state cannot be deferred.
- Six requirements are barred by name, regardless of point value.
The six named exclusions
Straight from § 170.21(a)(2)(iii), using the regulation's titles:
| ID | Title in the regulation | Points |
|---|---|---|
| AC.L2-3.1.20 | External Connections (CUI Data) | 1 |
| AC.L2-3.1.22 | Control Public Information (CUI Data) | 1 |
| CA.L2-3.12.4 | System Security Plan | Gate |
| PE.L2-3.10.3 | Escort Visitors (CUI Data) | 1 |
| PE.L2-3.10.4 | Physical Access Logs (CUI Data) | 1 |
| PE.L2-3.10.5 | Manage Physical Access (CUI Data) | 1 |
Five of these are 1-point requirements that would otherwise be potentially deferrable. The regulation removes them anyway. CA.L2-3.12.4 is the SSP gate and cannot be on a POA&M at all.
How we get to 47
- 51 requirements worth 1 point
- minus the 5 one-pointers barred by name
- = 46 ordinarily eligible
- plus SC.L2-3.13.11 in its encryption-employed-but-not-FIPS-validated state
- = 47 potentially eligible, 63 ineligible
“Potentially eligible” is a screen, not a determination. It means the rule does not categorically bar the item. Actual Conditional status still depends on your score, the exact findings, the six named exclusions, the assessment record, the affirmation, and successful closeout within 180 days.
The 22-point budget
Because Conditional status requires at least 88, you can be down a maximum of 22 points at the assessment that creates the Conditional status. Every one of those points has to come from an eligible item. Twenty-two 1-point gaps is the theoretical maximum spread.
That budget is smaller than it sounds. Three families offer zero potentially deferrable requirements. Physical Protection offers exactly one. If your gaps cluster in System and Information Integrity or in Configuration Management's six fixed 5-point rows, your Conditional budget disappears before the score itself looks catastrophic.
Why you can score 105 out of 110 and still have no path forward
Every NOT MET requirement must have a POA&M in place under 32 CFR 170.24(c)(2)(i)(6), and 32 CFR 170.21(a)(2)(ii) bars requirements worth more than 1 point from the Conditional POA&M except for the narrow encryption state. Read together, those provisions mean a single unmet fixed 5-point requirement eliminates Conditional Level 2 status — regardless of how high the score is. A contractor at 105 with one fixed 5-point gap has no Conditional path, while a contractor at exactly 88 with 22 eligible 1-point gaps can pass this threshold-and-composition screen.
This is the finding that changes how you sequence remediation, so let's make it concrete.
| Decision fact | Company A | Company B |
|---|---|---|
| Requirements MET | 109 of 110 | 88 of 110 |
| The gaps | One: CM.L2-3.4.1, baseline configurations | Twenty-two, all 1-pointers, none named exclusions |
| Score | 105 | 88 |
| Score ÷ 110 | 0.955 | 0.800 |
| Passes the 88 threshold? | Comfortably | Barely |
| Can every gap go on the Conditional POA&M? | No — the gap is worth 5 points | Potentially — all are eligible 1-point gaps |
| Conditional Level 2 path | Not available | Available under this screen |
Company A implemented more scored requirements and scores 17 points higher. Company B is the one that still has a Conditional path.
Every generic explainer tells you that you need 88. Almost none tell you that 88 is necessary but nowhere near sufficient — the composition of the gap list can matter more than the count.
What this means for how you sequence the work
Stop treating the fixed 5-pointers and fixed 3-pointers as ordinary backlog items. For Conditional purposes, they are gates.
The practical order:
- Confirm you have a current SSP. Without it, the assessment cannot be completed.
- Close every fixed 5-point gap. All 42 are non-deferrable for Conditional purposes.
- Close every fixed 3-point gap. All 14 are non-deferrable.
- Fully implement MFA. The 3-point partial state recovers score, but IA.L2-3.5.3 still cannot sit on the Conditional POA&M.
- For SC.L2-3.13.11, get encryption at least into the employed-but-not-FIPS-validated state if full FIPS validation is not complete. That is the only 3-point state the rule lets onto the Conditional POA&M.
- Then decide which eligible 1-pointers to defer, within the 22-point ceiling and 180-day closeout window.
If a readiness proposal sequences the work only by “easiest first” or “quickest wins,” ask how that sequence protects Conditional eligibility. A high score with the wrong gap is still a dead end.
Test the gap composition, not just the score.
Our CMMC Level 2 assessment guide walks through the scope, objective-level evidence, scoring, Conditional gates, and closeout path behind a defensible self-assessment.
→ Use the CMMC Level 2 assessment guide
Do not enter CUI or contract details into a public checklist or routing form.
What does “MET” actually require?
Under 32 CFR 170.24(b), each requirement receives one of three findings: MET, NOT MET, or Not Applicable. A requirement is MET only when all applicable assessment objectives are satisfied based on evidence that is in final form and not draft. The regulation names working papers, drafts, and unofficial or unapproved policies as unacceptable. A single unsatisfied applicable objective makes the requirement NOT MET.
The draft-evidence rule can kill a self-assessment before a technical gap does
Read § 170.24(b)(1) again: evidence must be in final form and not draft. Unacceptable forms explicitly include working papers, drafts, and unofficial or unapproved policies.
A company can write eleven security policies and still have eleven drafts if nobody with approval authority has approved them. Under the rule, those documents are not final evidence. The affected requirement is not “partially met.” It is NOT MET at its full deduction.
If your policy set has never been formally approved by someone empowered to approve it, that is not just documentation cleanup. It is a scoring problem across every requirement that depends on those policies.
Capability is not implementation
Here's the distinction that separates a real assessment from a vendor checklist.
“Microsoft 365 GCC High supports MFA enforcement” is a statement about a product.
“MFA is configured for the required privileged and non-privileged access paths, exceptions are documented and approved, the configuration was tested on this date, and here is the export” is a statement about your environment.
Only the second can support a MET finding. No product, platform, subscription tier, template, or provider makes a requirement MET on its own — the requirement is met by your implementation, operation, and final evidence.
When Not Applicable is legitimate
Per § 170.24(b)(3), a requirement or objective can be assessed N/A when it genuinely does not apply at the time of assessment, and an objective assessed N/A is treated the same as MET. The regulation supplies its own example: SC.L2-3.13.5 may be N/A if there are no publicly accessible systems inside the CMMC Assessment Scope.
N/A is a legitimate finding, not a loophole. Document the factual basis in the assessment record and in the SSP where it affects scope, architecture, or implementation. “We did not get to it” is not N/A. It is NOT MET.
Two more provisions matter. Enduring exceptions described with their mitigations in the SSP are assessed as MET. Temporary deficiencies addressed in operational plans of action that show review and progress may also be assessed as MET. Those operational plans are not the same thing as a Conditional CMMC POA&M under § 170.21; the rule uses similar words for different mechanisms.
If you hold a favorable DoD CIO adjudication under DFARS 252.204-7008 or 252.204-7012 that a requirement is inapplicable or that an alternative measure is equally effective, the adjudication must be included in the SSP to receive consideration.
The case that shows what a wrong score costs
We rarely get a clean primary-source example of scoring failure. This one is on the record.
In March 2025, the Department of Justice announced that MORSECORP Inc. agreed to pay $4.6 million to resolve False Claims Act allegations involving Army and Air Force contracts. As part of the settlement, the company admitted, acknowledged, and accepted responsibility for a specific sequence of facts:
- From January 2018 to February 2023, it had not fully implemented all the NIST SP 800-171 controls its contracts required.
- From January 2018 to January 2021, it did not have a consolidated written SSP describing system boundaries, environments of operation, how requirements were implemented, and connections to other systems.
- In January 2021 it submitted a score of 104 to DoD. DOJ described that as near the top of the possible −203-to-110 range.
- In July 2022 a third-party consultant told the company its actual score was −142.
- It did not correct the score in DoD's reporting system until June 2023 — three months after being served with a federal subpoena.
The whistleblower received $851,000 of the settlement.
DOJ also described the missing controls using language that tracks the current 5-point and 3-point scoring tiers: controls whose absence could lead to significant exploitation or exfiltration, and controls with a specific and confined security effect. That comparison is our synthesis of the DOJ release and § 170.24, not a DOJ statement that CMMC scoring caused the settlement.
A 246-point swing between a submitted score and the consultant's score is not a rounding error. It is what can happen when a spreadsheet says “yes” and objective-level evidence does not sit behind it. We are not claiming this outcome is typical. We are pointing out that false representations about contractual cybersecurity compliance can create False Claims Act exposure, and this mechanism is documented in a primary-source enforcement record.
Did the July 2026 CMMC Phase II suspension change the 110 controls?
No. The Federal Register CMMC acquisition rule took effect on November 10, 2025, so the original phase schedule ran Phase I from November 10, 2025 through November 9, 2026, with Phase II scheduled to begin November 10, 2026. On July 13, 2026, DoD suspended Phase II and directed a 60-day review. DoD's current CMMC page and the implementing memorandum say all Phase I self-assessment requirements remain in place.
The suspension did not amend NIST SP 800-171 Revision 2, the 110 Level 2 requirements, the scoring methodology in § 170.24, the Conditional POA&M rules in § 170.21, or separate obligations already imposed by DFARS 252.204-7012, -7019, or -7020.
What remains, what paused, and what did not disappear
| Question | Current answer as of August 14, 2026 |
|---|---|
| What CMMC statuses may be newly designated while Phase II is suspended? | Level 1 (Self) and Level 2 (Self) |
| What new designations are paused? | Level 2 (C3PAO) and Level 3 (DIBCAC) requirements in new solicitations |
| What happens to active solicitations or existing contracts carrying paused designations? | The implementing memo directs amendments to affected active solicitations and modification of affected contracts before the next option exercise or through an administrative modification |
| Are CMMC waivers continuing? | The implementing memo suspends the waiver process during the pause |
| Are C3PAOs, the CAICO, Registered Practitioner services, and voluntary certification gone? | No. The Cyber AB said those program elements remain operational and voluntary C3PAO assessments remain available |
| Did government verification disappear? | No. DoD said it will continue self-assessments and select government-led assessments |
| Do DFARS 252.204-7012/-7019/-7020 obligations disappear? | No. Those are separate contractual safeguarding, NIST DoD Assessment, access, and SPRS-record obligations |
The part that should get your attention
For a procurement designated Level 2 (Self), your own assessment record and affirmation are the immediate contract-eligibility gate. That does not mean nobody can check your work: 32 CFR 170.16 reserves DoD's right to conduct a DCMA DIBCAC assessment, and the suspension announcement expressly preserved select government-led assessments.
The dangerous sentence is not “an assessor will never look.” The dangerous sentence is “we scored ourselves, posted it, and affirmed it without objective-level evidence.” MORSECORP shows what a false cybersecurity representation can cost even outside a CMMC certification assessment.
DoD directed a 60-day CMMC review on July 13, 2026. That report was not yet due as of this page's August 14 verification date. We re-verify this section monthly and will date any change.
Do all 110 controls apply to your company?
The 110 requirements are the CMMC Level 2 baseline, but not every contractor is on the Level 2 path, and within a Level 2 assessment an individual requirement or objective may be Not Applicable when the facts support it. The required CMMC status and assessment type come from the solicitation, contract, or flowdown; DoD program managers and requiring activities select the status based on the information the contractor system will process, store, or transmit.
| Your situation | Where to start | Why |
|---|---|---|
| FCI only, no CUI | Level 1 — 15 requirements | 48 CFR 52.204-21(b)(1)(i)–(xv), incorporated into CMMC by § 170.14(c)(2). No POA&M is permitted at Level 1 |
| Solicitation, contract, or flowdown requires Level 2 for CUI | Level 2 — these 110 | § 170.14(c)(3) |
| Level 3 is named | Level 2's 110 plus 24 selected requirements from NIST SP 800-172 February 2021 | The current rule still incorporates the February 2021 edition and requires a maximum Level 2 score before a Level 3 assessment can begin |
| No clear clause or unclear CUI flow | Scope and contract determination first | A checklist cannot decide what information enters the environment or what status the contract requires |
| Contract expressly names a different revision | Follow the written contract, then get it reviewed | Written contract language governs that obligation |
Revision warning for Level 3: NIST withdrew the February 2021 edition of SP 800-172 in May 2026 and published Revision 3, but current 32 CFR 170.2 and § 170.14(c)(4) still name the February 2021 edition and its 24 selected CMMC Level 3 requirements. Do not silently replace the incorporated version with the newer publication.
Company size does not change the Level 2 list. A twelve-person machine shop and a 4,000-person prime face the same 110 requirements when the same Level 2 status applies. Size changes the assessment boundary, evidence volume, operating model, and cost. Scope reduction through a defensible CUI enclave can be the highest-leverage decision a small supplier makes — but it has to be made under the asset categories in § 170.19, before implementation starts.
Use our CMMC levels guide to confirm the differences among Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC). If the written requirement or CUI determination is still unclear, use a qualified CMMC practitioner and, where contract interpretation is involved, a qualified federal-contracts attorney.
Who in your company owns the 110?
No single department can own the full requirement set. The 110 requirements distribute across IT, security, HR, facilities, contracts, and executive leadership, and a defensible program assigns one accountable owner per requirement or family while naming the contributors who perform the work and hold the evidence.
This is our editorial framework, not a NIST- or DoD-prescribed assignment. Use it as a starting map, not an authority.
| Family cluster | Usually accountable | Usually contributing |
|---|---|---|
| Access Control, Identification & Authentication, System & Communications Protection | Security or IT lead | Application owners, network engineering, HR for joiner/mover/leaver |
| Audit & Accountability, Configuration Management, System & Information Integrity | Security operations or infrastructure | System administrators, change approvers |
| Awareness & Training, Personnel Security | HR or security governance | Managers, legal |
| Incident Response, Risk Assessment, Security Assessment | Security governance | Executive leadership, legal, contracts |
| Maintenance, Media Protection | IT operations | Facilities, third-party service vendors |
| Physical Protection | Facilities or site operations | IT, HR, site leadership |
The failure mode to avoid: handing all 110 to IT. That buries policy approval, training, physical security, personnel, contracting, and executive affirmation inside a technical backlog where no single owner has authority to finish them. Personnel Security has zero potentially deferrable requirements and it is not an IT function. Physical Protection has one potentially deferrable requirement out of six and it is not an IT function either.
One owner does not mean one implementer. Termination handling under PS.L2-3.9.2 can involve HR triggering the process, IT removing access, a manager confirming, and security validating — with one evidence record tying the chain together.
For a role-by-role hiring sequence, see who to hire first for NIST 800-171 implementation.
What to do once you have the list
Do not start at 3.1.1. Confirm the written requirement and the information type, define the assessment boundary, assign owners, work the assessment objectives rather than the requirement headlines, collect final evidence, score honestly, identify which SPRS record the clause requires, and document eligible gaps. Starting implementation before scoping can force expensive rework against the wrong assessment boundary.
1. Confirm the written requirement and the information type. What does the solicitation, contract, or flowdown require? Is FCI or CUI actually entering the environment? Does DFARS 252.204-7012 apply? Is DFARS 252.204-7021 present with a CMMC level and assessment type? This question can prevent a six-figure program built against the wrong obligation.
2. Map the CUI data flow and classify the assets. Under 32 CFR 170.19, Level 2 scoping distinguishes CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. A system does not become out of scope merely because it does not store CUI; a Security Protection Asset can still be assessed because it protects the CUI environment.
3. Freeze the version for each obligation. Current CMMC Level 2 uses Rev. 2. A DFARS 252.204-7012 obligation uses the NIST SP 800-171 version in effect when the solicitation was issued unless the Contracting Officer authorized otherwise. Track Rev. 3 separately; never blend it into a current Rev. 2 score.
4. Assign an accountable owner to every requirement. Anything without a name attached does not get finished. Run a “no owner” filter before you run anything else.
5. Work the objectives, not the headlines. All 320. A requirement with fifteen objectives is not one task. This is where self-assessments quietly inflate.
6. Attach and retain final evidence. Approved, current, in scope, with a test date and a named custodian. Draft policies do not count. For a Level 2 self-assessment, 32 CFR 170.16(c)(4) requires the artifacts used as evidence to be retained for six years from the CMMC Status Date.
7. Score honestly, then check the composition. Do not stop at “are we at 88?” Ask what each gap is worth, whether any gap is a named exclusion, whether MFA is only partial, and whether SC.L2-3.13.11 is in the 3-point or 5-point state.
8. Post the right record and maintain the right cadence. A DFARS 252.204-7019/-7020 NIST DoD Assessment record is not a substitute for a CMMC Level 2 self-assessment record when DFARS 252.204-7021 requires CMMC status. CMMC Level 2 (Self) requires the assessment on a three-year cycle and an affirmation at the assessment and annually thereafter, subject to the rule and the clause.
Somewhere around step 4 or 5, most teams reach the honest question: can we execute this in-house? That is not a failure. Scoping, SSP authoring, technical implementation, evidence operations, and formal assessment are different disciplines. Use our CMMC provider categories guide before comparing proposals that solve different problems.
What a C3PAO can — and cannot — promise
A C3PAO performs a formal Level 2 certification assessment. The Cyber AB CMMC Assessment Process v2.0 does not create a simplistic rule that every prior interaction automatically disqualifies a C3PAO. It requires the C3PAO to manage impartiality, identify and disclose conflicts of interest, document mitigation, and refuse to proceed when a conflict cannot be sufficiently mitigated.
It also prohibits a C3PAO from offering guarantees or promises about the assessment result and prohibits incentives or bonus payments contingent on a Certificate of CMMC Status.
Before hiring one, verify the organization's current authorized or accredited status in the Cyber AB Marketplace. A Marketplace listing establishes good standing and eligibility to conduct an assessment; it is not an endorsement. The CAP says the Cyber AB, CAICO, and DoD do not recommend or facilitate introductions to a C3PAO.
Need help deciding what type of CMMC provider you need?
Tell us your required level, scope, environment, and timeline, and we'll route you to the provider category that fits the work before you compare quotes.
Already know the category and scope? Request comparable CMMC quotes.
Find My CMMC Path routes to a provider category, not a named provider. It is not a score, a certification decision, or compliance advice. Do not submit CUI, drawings, technical data, credentials, or sensitive contract details.
What we actually verified
This page was produced by The Defense Compliance Report Editorial Team from primary sources. Here is precisely what we checked and when.
Read in full at eCFR on August 14, 2026 — Title 32 was current as of August 13, 2026 and last amended July 24, 2026:
- 32 CFR 170.14 — the Level 1, Level 2, and Level 3 requirement sets, including the 24 selected Level 3 requirements from NIST SP 800-172 February 2021
- 32 CFR 170.16 and 170.22 — Level 2 self-assessment inputs, three-year assessment cycle, CMMC status, and annual affirmation
- 32 CFR 170.19 — Level 2 asset categories and scoping rules
- 32 CFR 170.21 — the 88 threshold, six named exclusions, the SC.L2-3.13.11 exception, and 180-day closeout
- 32 CFR 170.24 — findings, point values, partial-credit states, the SSP gate, N/A treatment, and the requirement-level scoring method
Cross-checked the controlling rule history in the Federal Register:
- 32 CFR Part 170 CMMC Program final rule — published October 15, 2024 and effective December 16, 2024
- DFARS CMMC acquisition final rule — published September 10, 2025 and effective November 10, 2025
Cross-checked at Acquisition.gov on August 14, 2026:
- DFARS 252.204-7012 — the safeguarding baseline and its version-at-solicitation language
- DFARS 252.204-7019 and 252.204-7020 — NIST SP 800-171 DoD Assessment summary records in SPRS and government access for Medium or High assessments
- DFARS 252.204-7021 — required CMMC status, CMMC UID, self-assessment posting, flowdown, and annual affirmation
Counted directly from the normative NIST PDFs on August 14, 2026: all 110 NIST SP 800-171 Rev. 2 requirements, their basic/derived designations, and all 320 NIST SP 800-171A assessment objectives. We also checked NIST's withdrawal notices and normative-source notes for SP 800-171 Rev. 2 and SP 800-171A.
Computed and reconciled: the 51 one-point requirements, the 313-point maximum deduction, the −203 floor, the 46 ordinary POA&M-eligible one-pointers, and the 47/63 split after adding the narrow SC.L2-3.13.11 exception.
Checked against current program materials: DoD's current CMMC notice, the July 13, 2026 implementing memorandum, the Cyber AB's July 15 statement, and the Cyber AB CMMC Assessment Process v2.0 provisions on Marketplace status, impartiality, conflicts, guarantees, and contingent incentives.
Confirmed at Justice.gov: the MORSECORP settlement amount, dates, 104 submitted score, −142 consultant finding, June 2023 correction, $851,000 relator share, and DOJ's description of the possible score range.
What is editorial judgment, not regulation: the remediation sequence, ownership map, family-level workload commentary, Company A/Company B illustration, and our synthesis that any fixed 5-point or 3-point NOT MET requirement forecloses Conditional Level 2. That last conclusion is derived from § 170.24(c)(2)(i)(6) and § 170.21(a)(2)(ii), which are linked above so you can check the reasoning.
Read our methodology and editorial standards. Found an error? Use our corrections policy and send the requirement ID, primary source, and proposed correction. Material corrections are logged with the date.
This is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a qualified CMMC practitioner and, where contract interpretation is involved, a qualified federal-contracts attorney. The written requirement and your actual information flow govern — not a checklist.
Frequently asked questions
How many controls are in NIST 800-171? There are 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families. Revision 3 has 97 requirements across 17 families, but current 32 CFR Part 170 incorporates Revision 2 for CMMC Level 2.
Are NIST 800-171 controls the same as CMMC Level 2 requirements? Yes. 32 CFR 170.14(c)(3) states that the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 Revision 2.
Is it 110 controls or 97? For current CMMC Level 2, 110. The 97 figure comes from Revision 3. Building only to Revision 3 does not replace the Revision 2 baseline incorporated into the current CMMC rule.
NIST withdrew Revision 2 — is it still the CMMC baseline? Yes. NIST withdrew the publication on May 14, 2024, but 32 CFR Part 170 incorporates the February 2020 Revision 2 edition, including updates through January 28, 2021. NIST's withdrawal did not amend the CFR.
Does DFARS 252.204-7012 always mean Revision 2? Not automatically. The clause applies the NIST SP 800-171 version in effect when the solicitation was issued unless the Contracting Officer authorizes otherwise. Read the solicitation and contract instead of assuming the CMMC incorporation rule answers every 7012 version question.
How many assessment objectives are behind the 110 requirements? 320. We counted 23 requirements with one objective and 13 with six or more. CM.L2-3.4.7 has the maximum, at 15.
How many points is each control worth? The fixed values are 1, 3, or 5 under 32 CFR 170.24(c)(2). Forty-two requirements are fixed at 5 points, 14 are fixed at 3, and 51 are worth 1. IA.L2-3.5.3 and SC.L2-3.13.11 can deduct 3 or 5. CA.L2-3.12.4 is an SSP gate with no point value.
What is the lowest possible score? −203. The maximum is 110, and the maximum possible deduction is 313.
What score do I need for Conditional Level 2? At least 88, because the score divided by 110 must be at least 0.8. The threshold alone is not enough; the composition of the NOT MET requirements must also satisfy the POA&M restrictions.
How many of the 110 can go on a Conditional Level 2 POA&M? 47 potentially; 63 cannot. The 47 are 46 eligible 1-point requirements plus SC.L2-3.13.11 in the encryption-employed-but-not-FIPS-validated state.
Which controls can never go on that POA&M? Any fixed 3-point or 5-point requirement, IA.L2-3.5.3 in either NOT MET state, SC.L2-3.13.11 when encryption is not employed, and the six requirements named at § 170.21(a)(2)(iii): AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5.
How long do I have to close a CMMC POA&M? 180 days from the Conditional CMMC Status Date. If the closeout assessment is not successfully completed in that window, the Conditional status for the information system expires.
What happens if I do not have a system security plan? Under § 170.24(c)(2)(i)(5), the assessment cannot be completed because of incomplete information and noncompliance with DFARS 252.204-7012. It is not merely a point deduction.
Does a Not Applicable finding hurt the score? No. An assessment objective marked N/A is equivalent to MET. The factual basis should be documented, especially where it affects scope, architecture, or the SSP.
Can a draft policy count as evidence? No. Section 170.24(b)(1) requires evidence to be final, not draft, and expressly identifies working papers, drafts, and unofficial or unapproved policies as unacceptable.
Can one unmet objective make the whole requirement NOT MET? Yes. A requirement is NOT MET when one or more applicable objectives is not satisfied.
How long must Level 2 self-assessment evidence be retained? Six years from the CMMC Status Date. 32 CFR 170.16(c)(4) applies that retention period to the artifacts used as assessment evidence.
Is the CMMC Level 2 self-assessment record the same as the DFARS 252.204-7019/-7020 NIST DoD Assessment record? No. Both are in SPRS and can use the same 110-point range, but they are separate records with different authorities, fields, statuses, and contract triggers.
Do the 110 still apply after the July 2026 Phase II suspension? Yes. The suspension paused Phase II designations; it did not change the Level 2 requirements or scoring method. Phase I self-assessment requirements remain in place.
Do I need a C3PAO right now? Not for a Level 2 (Self) requirement. New Level 2 (C3PAO) and Level 3 (DIBCAC) designations are paused while Phase II is suspended, though voluntary C3PAO assessments remain available and select government-led assessments continue.
Can a C3PAO guarantee certification? No. The Cyber AB CAP prohibits guarantees or promises about the result and prohibits incentives or bonus payments contingent on issuance of a CMMC certificate.
Does compliance software make these requirements MET? No. Software can help document, track, and evidence implementation. The requirement is met by your environment's implementation and operation, supported by final evidence.
Is this list enough to submit an SPRS record? No. You must apply the requirements to a defined scope, assess the applicable objectives, connect findings to a current SSP and final evidence, calculate the score honestly, and submit the record required by the actual clause. A NIST DoD Assessment record and a CMMC self-assessment record are not interchangeable.
Does current CMMC Level 3 use NIST SP 800-172 Revision 3? No. NIST published a newer SP 800-172, but current 32 CFR Part 170 still incorporates the February 2021 edition and selects 24 requirements from it for CMMC Level 3.
Need help deciding what type of CMMC provider you need? Tell us your required level, scope, environment, and timeline, and we'll route you to source-checked provider categories.
Do not submit CUI, drawings, technical data, credentials, or contract documents.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice.