The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · assessment and scoring

NIST 800-171 110 Controls List (Rev. 2): Every Requirement, What It Costs You, and Which Ones You Can Defer

Last updated:

Last verified: against current CMMC, eCFR, DFARS, NIST, DoD, and Cyber AB sources.

Last verified: August 14, 2026. DoD suspended CMMC Phase II on July 13, 2026 and is continuing Phase I self-assessment requirements. While the suspension remains in effect, only Level 1 (Self) and Level 2 (Self) CMMC status requirements may be newly designated. The 110 Level 2 requirements did not change. See the current DoD CMMC notice.

The Defense Compliance Report Editorial Team · Independent CMMC and DIB compliance research

Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.

The NIST 800-171 110 controls list is the set of 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families — and under 32 CFR 170.14(c)(3), those exact 110 requirements are CMMC Level 2. Under the current CMMC scoring method, 42 are fixed 5-point requirements, 14 are fixed 3-point requirements, 51 are 1-point requirements, two can deduct 3 or 5 points, and the system security plan is a gate rather than a weighted line item.

Here is the decision fact a plain control list does not show: 63 of the 110 cannot be placed on a Conditional Level 2 Plan of Action and Milestones under the current rule. One unmet 5-point requirement can end your Conditional path at a score of 105 — while a company at 88 with 22 eligible 1-point gaps may still have one.

We'll show you the arithmetic that proves it. First, the list.


Who this page is for — and who should leave

Use this page if… — Don't use this page as…
Use this page if…Don't use this page as…
You handle Controlled Unclassified Information (CUI) on DoD work and need the current Level 2 baselineProof that you comply — no list can do that
You're building or auditing a system security plan, self-assessment, CMMC score, or NIST DoD Assessment scoreA substitute for determining whether CUI is actually in your environment
You need to know what each gap actually costs before you build a remediation planA promise that any product, template, or provider makes a requirement “met”
You're sanity-checking a readiness quote against real scopeLegal, contractual, or compliance advice

If you only handle Federal Contract Information (FCI) and no CUI, this is the wrong list. Level 1 is a separate, smaller set — 15 basic safeguarding requirements at 48 CFR 52.204-21(b)(1)(i)–(xv), per 32 CFR 170.14(c)(2). Start with our Level 1 self-assessment checklist instead. You'll save yourself weeks.

The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining material regulatory claims with primary-source citations and mapping a contractor's required level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right path before they spend six figures.

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on the CMMC status required in your solicitation, contract, or flowdown; whether you handle FCI or CUI; your assessment type; your cloud and IT environment; and your contract timeline. A C3PAO is a CMMC Third-Party Assessment Organization, not a readiness consultant by definition and not a company that can promise you a certificate. Use our Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


What Is the NIST 800-171 110 Controls List?

The NIST 800-171 110 controls list is the complete set of security requirements in NIST SP 800-171 Revision 2 for protecting Controlled Unclassified Information on nonfederal systems, organized into 14 families. Under 32 CFR 170.14(c)(3), the CMMC Level 2 security requirements are identical to those in Revision 2. Behind the 110 requirements sit 320 individual assessment objectives from NIST SP 800-171A, and a requirement is scored MET only when every applicable objective is satisfied.

Three terms, defined once, because the vocabulary trips people up:

A security requirement is one of the 110 numbered items — 3.1.1, 3.4.7, 3.13.11. NIST calls them requirements. Most of the industry calls them controls. Same things. We'll use both, because you searched for one and the regulation uses the other.

An assessment objective is a single determination statement underneath a requirement. Requirement 3.1.1 has six. Requirement 3.4.7 has fifteen. Requirement 3.5.4 has one. The finding is per requirement; the evidence work is per objective.

SPRS is the Supplier Performance Risk System. But “the SPRS score” is not one universal record. Two different records can use the same 110-point arithmetic, and confusing them can leave you with the wrong submission for the clause in your contract.

SPRS is one system with two records you should not confuse

Record — Primary authority — What gets posted — What it proves
RecordPrimary authorityWhat gets postedWhat it proves
NIST SP 800-171 DoD Assessment summary recordDFARS 252.204-7019 and 252.204-7020Assessment standard/version, assessor, CAGE codes, assessment date and level, summary score, and expected date to reach 110A Basic, Medium, or High NIST SP 800-171 DoD Assessment record
CMMC Level 2 self-assessment record32 CFR 170.16, 170.22, and DFARS 252.204-7021CMMC level, status date, assessment scope, CAGE codes, score, POA&M status, CMMC UID, and the required affirmationConditional or Final Level 2 (Self) CMMC status for the assessed scope

The records can coexist. The NIST DoD Assessment record is tied to DFARS 252.204-7019/-7020. The CMMC record is tied to 32 CFR Part 170 and DFARS 252.204-7021 when the solicitation or contract requires a CMMC status. Same platform. Related arithmetic. Different record, different trigger, different evidence of eligibility.

The one number that decides whether you're on the right list

Before you spend a quarter building a program, confirm the version. Revision 2 has 110 requirements across 14 families. Revision 3 has 97 requirements across 17 families. They are not interchangeable, and picking wrong means rebuilding.

For current CMMC Level 2, it is Revision 2. 32 CFR 170.2 incorporates the February 2020 publication, including updates through January 28, 2021, and § 170.14(c)(3) makes Level 2 identical to it. That does not change because NIST published a newer document.

Your situation — The list you work from — Why
Your situationThe list you work fromWhy
CMMC Level 2 under current 32 CFR Part 170Revision 2 — 110 requirementsThe rule incorporates the February 2020 Rev. 2 version and makes Level 2 identical to it
DFARS 252.204-7012 safeguarding obligationThe NIST SP 800-171 version in effect when the solicitation was issued, unless the Contracting Officer authorizes otherwiseThat is the version rule written into DFARS 252.204-7012(b)(2)(i)
Your contract expressly names Revision 3Follow the written contract, then get it reviewedNever override express contract language with a general checklist
Internal planning for what comes nextTrack Rev. 3 separatelyUseful. Just do not blend it into a current CMMC Rev. 2 score
A non-DoD federal customerConfirm the actual clauseCMMC does not govern every federal agreement

Here's the uncomfortable part

NIST withdrew Revision 2. On May 14, 2024, NIST marked SP 800-171 Revision 2 as withdrawn and superseded by Revision 3. NIST marked SP 800-171A withdrawn the same day. Both NIST pages identify the PDFs as the normative source when derivative data files disagree.

So yes: the CMMC standard and assessment procedures DoD incorporated are archived documents on NIST's own website. That's genuinely strange, and if it has been nagging at you, you were not being paranoid.

It also does not rewrite the rule. NIST publishes; DoD regulates and contracts. An incorporation by reference names a specific edition. Until DoD amends 32 CFR Part 170, Revision 2 and its 110 requirements remain the operative CMMC Level 2 baseline. Separately, DFARS 252.204-7012 applies the version in effect when the solicitation was issued unless the Contracting Officer authorizes otherwise.

That gap between “newest” and “operative” is exactly where contractors lose quarters of work. It is also why we date every regulatory fact on this page.


What are the 14 NIST 800-171 control families?

The 110 requirements are spread unevenly across 14 families. Access Control holds 22 requirements and 70 assessment objectives. Personnel Security holds 2 requirements and 4 objectives. Counting families tells you almost nothing about workload; counting objectives, point exposure, and deferral options tells you where your quarter goes.

This table is our own assembly. The requirement counts come from NIST SP 800-171 Rev. 2. We counted all 320 objective statements directly from the normative NIST SP 800-171A PDF. The point values come from 32 CFR 170.24(c)(2). The potential POA&M column is derived from 32 CFR 170.21(a)(2). It joins four source layers contractors normally have to reconcile themselves.

Family — Requirements — Assessment objectives — 5-point — 3-point — 3-or-5 — 1-point — Potentially POA&M-eligible
FamilyRequirementsAssessment objectives5-point3-point3-or-51-pointPotentially POA&M-eligible
3.1 Access Control22707201311
3.2 Awareness and Training3920011
3.3 Audit and Accountability92921066
3.4 Configuration Management94460033
3.5 Identification and Authentication112530177
3.6 Incident Response31420011
3.7 Maintenance61022022
3.8 Media Protection91523044
3.9 Personnel Security2411000
3.10 Physical Protection61620041
3.11 Risk Assessment3911011
3.12 Security Assessment41421000
3.13 System and Communications Protection1641511910
3.14 System and Information Integrity72052000
Total110320421425147

Security Assessment shows 4 requirements but only 3 carry point values — CA.L2-3.12.4, the system security plan requirement, is a gate rather than a weighted item. “Potentially POA&M-eligible” means the rule does not categorically bar the item; your score, findings, and 180-day closeout still control actual eligibility.

Four things this table tells you that a family list can't

Three families have zero potentially deferrable requirements. Personnel Security, Security Assessment, and System and Information Integrity are entirely pass/fail for Conditional Level 2 purposes. Every requirement in those three families must be MET at assessment.

Physical Protection is a trap. It looks flexible — four 1-point requirements out of six. But three of those four, 3.10.3, 3.10.4, and 3.10.5, are barred from a Conditional POA&M by name. Only 3.10.6, the alternate work site requirement, is potentially deferrable.

Configuration Management is a brutal 5-point cluster. Six of its nine requirements are fixed 5-pointers, and it carries 44 assessment objectives — the second-heaviest objective load behind Access Control. A CM gap list can lose 30 points across six lines before you count anything else.

The objective count inside a single requirement varies by 15×. CM.L2-3.4.7 — restricting nonessential programs, functions, ports, protocols, and services — has 15 assessment objectives, more than the entire Personnel Security family and Awareness and Training family combined. CM.L2-3.4.4 has one. Both live on the same “110 controls” list. They are not comparable units of evidence work.

We counted 23 requirements with one objective: 3.4.4, 3.5.4, 3.5.9, 3.5.11, 3.6.3, 3.7.1, 3.7.3, 3.7.4, 3.7.6, 3.8.2, 3.8.6, 3.8.7, 3.8.8, 3.8.9, 3.9.1, 3.10.4, 3.12.3, 3.13.4, 3.13.7, 3.13.11, 3.13.15, 3.13.16, 3.14.4.

We counted 13 requirements with six or more objectives: 3.1.1 (6), 3.1.20 (6), 3.3.1 (6), 3.3.8 (6), 3.4.1 (6), 3.4.5 (8), 3.4.7 (15), 3.6.1 (7), 3.6.2 (6), 3.12.4 (8), 3.13.1 (8), 3.13.2 (6), 3.14.1 (6).

Those counts come from a requirement-by-requirement parse of the normative NIST SP 800-171A PDF, not a family-total estimate.


The complete NIST 800-171 110 controls list

All 110 NIST SP 800-171 Revision 2 requirements are listed below by family, each with its CMMC Level 2 identifier, whether NIST designates it basic or derived, its point value under 32 CFR 170.24(c)(2), and whether 32 CFR 170.21(a)(2) leaves a possible Conditional POA&M path.

How to read the POA&M column: Yes means the requirement is worth 1 point and is not a named exclusion. No means the requirement is worth more than 1 point. No — named means the regulation bars it by name regardless of value. Conditional applies to exactly one requirement, explained below.

The descriptions below are our plain-language labels, not the official requirement text. The controlling text is NIST SP 800-171 Revision 2.

3.1 Access Control — 22 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
AC.L2-3.1.1Limit access to authorized users, processes, devicesBasic5No
AC.L2-3.1.2Limit access to permitted transactions and functionsBasic5No
AC.L2-3.1.3Control the flow of CUIDerived1Yes
AC.L2-3.1.4Separate duties of individualsDerived1Yes
AC.L2-3.1.5Employ least privilegeDerived3No
AC.L2-3.1.6Non-privileged accounts for nonsecurity functionsDerived1Yes
AC.L2-3.1.7Prevent and log non-privileged execution of privileged functionsDerived1Yes
AC.L2-3.1.8Limit unsuccessful logon attemptsDerived1Yes
AC.L2-3.1.9Privacy and security noticesDerived1Yes
AC.L2-3.1.10Session lock with pattern-hiding displayDerived1Yes
AC.L2-3.1.11Automatic session terminationDerived1Yes
AC.L2-3.1.12Monitor and control remote access sessionsDerived5No
AC.L2-3.1.13Cryptographic protection of remote accessDerived5No
AC.L2-3.1.14Route remote access through managed control pointsDerived1Yes
AC.L2-3.1.15Authorize remote privileged commands and access to security-relevant informationDerived1Yes
AC.L2-3.1.16Authorize wireless access before connectionDerived5No
AC.L2-3.1.17Protect wireless with authentication and encryptionDerived5No
AC.L2-3.1.18Control connection of mobile devicesDerived5No
AC.L2-3.1.19Encrypt CUI on mobile devicesDerived3No
AC.L2-3.1.20Verify and control connections to external systemsDerived1No — named
AC.L2-3.1.21Limit portable storage use on external systemsDerived1Yes
AC.L2-3.1.22Control CUI on publicly accessible systemsDerived1No — named

3.2 Awareness and Training — 3 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
AT.L2-3.2.1Security awareness for managers, admins, usersBasic5No
AT.L2-3.2.2Role-based training for security dutiesBasic5No
AT.L2-3.2.3Insider threat awareness trainingDerived1Yes

3.3 Audit and Accountability — 9 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
AU.L2-3.3.1Create and retain system audit logsBasic5No
AU.L2-3.3.2Trace user actions uniquely to individual usersBasic3No
AU.L2-3.3.3Review and update logged eventsDerived1Yes
AU.L2-3.3.4Alert on audit logging process failureDerived1Yes
AU.L2-3.3.5Correlate audit review, analysis, and reportingDerived5No
AU.L2-3.3.6Audit record reduction and report generationDerived1Yes
AU.L2-3.3.7Time stamps synchronized to an authoritative sourceDerived1Yes
AU.L2-3.3.8Protect audit information and logging toolsDerived1Yes
AU.L2-3.3.9Limit audit management to a privileged subsetDerived1Yes

3.4 Configuration Management — 9 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
CM.L2-3.4.1Baseline configurations and system inventoriesBasic5No
CM.L2-3.4.2Security configuration settingsBasic5No
CM.L2-3.4.3Track, review, approve, and log changesDerived1Yes
CM.L2-3.4.4Security impact analysis before changesDerived1Yes
CM.L2-3.4.5Access restrictions associated with changesDerived5No
CM.L2-3.4.6Least functionalityDerived5No
CM.L2-3.4.7Restrict nonessential programs, ports, protocols, servicesDerived5No
CM.L2-3.4.8Application allowlisting or denylistingDerived5No
CM.L2-3.4.9Control and monitor user-installed softwareDerived1Yes

3.5 Identification and Authentication — 11 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
IA.L2-3.5.1Identify users, processes, and devicesBasic5No
IA.L2-3.5.2Authenticate identities before granting accessBasic5No
IA.L2-3.5.3Multifactor authenticationDerived3 or 5No
IA.L2-3.5.4Replay-resistant authenticationDerived1Yes
IA.L2-3.5.5Prevent identifier reuseDerived1Yes
IA.L2-3.5.6Disable identifiers after inactivityDerived1Yes
IA.L2-3.5.7Password complexity and character changeDerived1Yes
IA.L2-3.5.8Prohibit password reuseDerived1Yes
IA.L2-3.5.9Temporary passwords changed immediatelyDerived1Yes
IA.L2-3.5.10Store and transmit only protected passwordsDerived5No
IA.L2-3.5.11Obscure authentication feedbackDerived1Yes

The CFR renders 3.5.1 and 3.5.2 as “IA-L2-” in its point-value list rather than “IA.L2-.” That is a typographical inconsistency in the regulation, not a different requirement.

3.6 Incident Response — 3 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
IR.L2-3.6.1Operational incident-handling capabilityBasic5No
IR.L2-3.6.2Track, document, and report incidentsBasic5No
IR.L2-3.6.3Test the incident response capabilityDerived1Yes

3.7 Maintenance — 6 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
MA.L2-3.7.1Perform maintenance on systemsBasic3No
MA.L2-3.7.2Control maintenance tools, techniques, and personnelBasic5No
MA.L2-3.7.3Sanitize equipment removed for off-site maintenanceDerived1Yes
MA.L2-3.7.4Check maintenance media for malicious codeDerived3No
MA.L2-3.7.5MFA and terminate nonlocal maintenance sessionsDerived5No
MA.L2-3.7.6Supervise maintenance by uncleared personnelDerived1Yes

3.8 Media Protection — 9 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
MP.L2-3.8.1Protect media containing CUIBasic3No
MP.L2-3.8.2Limit access to CUI on media to authorized usersBasic3No
MP.L2-3.8.3Sanitize or destroy media before disposal or reuseBasic5No
MP.L2-3.8.4Mark media with CUI markings and limitationsDerived1Yes
MP.L2-3.8.5Control and account for media during transportDerived1Yes
MP.L2-3.8.6Protect CUI on digital media during transportDerived1Yes
MP.L2-3.8.7Control the use of removable mediaDerived5No
MP.L2-3.8.8Prohibit portable storage with no identifiable ownerDerived3No
MP.L2-3.8.9Protect backup CUI at storage locationsDerived1Yes

3.9 Personnel Security — 2 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
PS.L2-3.9.1Screen individuals before authorizing accessBasic3No
PS.L2-3.9.2Protect CUI during and after personnel actionsBasic5No

3.10 Physical Protection — 6 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
PE.L2-3.10.1Limit physical access to systems and environmentsBasic5No
PE.L2-3.10.2Protect and monitor facilities and support infrastructureBasic5No
PE.L2-3.10.3Escort visitors and monitor visitor activityDerived1No — named
PE.L2-3.10.4Maintain audit logs of physical accessDerived1No — named
PE.L2-3.10.5Control and manage physical access devicesDerived1No — named
PE.L2-3.10.6Safeguarding at alternate work sitesDerived1Yes

3.11 Risk Assessment — 3 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
RA.L2-3.11.1Periodically assess riskBasic3No
RA.L2-3.11.2Scan for vulnerabilitiesDerived5No
RA.L2-3.11.3Remediate vulnerabilities per risk assessmentsDerived1Yes

3.12 Security Assessment — 4 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
CA.L2-3.12.1Periodically assess security controlsBasic5No
CA.L2-3.12.2Plans of action to correct deficienciesBasic3No
CA.L2-3.12.3Monitor security controls on an ongoing basisBasic5No
CA.L2-3.12.4System security planBasicGate — no point valueNo — named

3.13 System and Communications Protection — 16 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
SC.L2-3.13.1Monitor and protect communications at boundariesBasic5No
SC.L2-3.13.2Secure architecture, software development, and engineering principlesBasic5No
SC.L2-3.13.3Separate user functionality from system managementDerived1Yes
SC.L2-3.13.4Prevent unauthorized transfer via shared resourcesDerived1Yes
SC.L2-3.13.5Subnetworks for publicly accessible componentsDerived5No
SC.L2-3.13.6Deny network traffic by default, allow by exceptionDerived5No
SC.L2-3.13.7Prevent split tunnelingDerived1Yes
SC.L2-3.13.8Protect CUI during transmissionDerived3No
SC.L2-3.13.9Terminate connections after sessions or inactivityDerived1Yes
SC.L2-3.13.10Establish and manage cryptographic keysDerived1Yes
SC.L2-3.13.11FIPS-validated cryptography for CUIDerived3 or 5Conditional
SC.L2-3.13.12Block remote activation and indicate collaborative devices in useDerived1Yes
SC.L2-3.13.13Control and monitor mobile codeDerived1Yes
SC.L2-3.13.14Control and monitor VoIPDerived1Yes
SC.L2-3.13.15Protect authenticity of communications sessionsDerived5No
SC.L2-3.13.16Protect confidentiality of CUI at restDerived1Yes

3.14 System and Information Integrity — 7 requirements

ID — Plain-language label — Basic/Derived — Points — Potential POA&M
IDPlain-language labelBasic/DerivedPointsPotential POA&M
SI.L2-3.14.1Identify, report, and correct system flawsBasic5No
SI.L2-3.14.2Malicious code protectionBasic5No
SI.L2-3.14.3Monitor and act on security alerts and advisoriesBasic5No
SI.L2-3.14.4Update malicious code protection mechanismsDerived5No
SI.L2-3.14.5Periodic and real-time scansDerived3No
SI.L2-3.14.6Monitor systems and inbound/outbound trafficDerived5No
SI.L2-3.14.7Identify unauthorized use of systemsDerived3No

You have the list. Now turn it into an evidence-ready assessment.

Use our CMMC readiness checklist to work through contract requirements, scope, the SSP, objective-level evidence, scoring, POA&M gates, and the point where outside help becomes the cheaper decision.

→ Use the CMMC readiness checklist

For the determination statements beneath these rows, open all 320 NIST 800-171A assessment objectives.

Do not submit CUI, drawings, credentials, or contract details.


How many points is each NIST 800-171 control worth?

Under 32 CFR 170.24(c)(2), a CMMC Level 2 assessment starts at 110 and subtracts points for each requirement assessed NOT MET. The distribution is 42 fixed 5-point requirements, 14 fixed 3-point requirements, 51 1-point requirements, two that can deduct 3 or 5 depending on implementation, and one — the system security plan — that carries no point value. Because the deductions can exceed 110, the score range runs from 110 down to −203.

The three tiers, in the regulation's own logic

The point value tracks how badly the gap hurts the scored security posture. The CFR is unusually plain about it.

Five points goes to requirements where failure “could lead to significant exploitation of the network, or exfiltration of CUI.” Twenty-three basic and nineteen derived requirements are listed by ID.

Three points goes to requirements whose failure has “a specific and confined effect on the security of the network and its data.” Seven basic and seven derived requirements are listed by ID.

One point goes to the remaining derived requirements, whose failure has “a limited or indirect effect.” The CFR does not enumerate these by ID. It defines them as the residual, which is why the 1-point list has to be derived and checked.

The two requirements that give partial credit

The scoring methodology credits partial implementation in exactly two places, and both matter because they change the deduction without making the requirement MET.

Multifactor authentication (IA.L2-3.5.3). If MFA is implemented only for remote and privileged users, 3 points are deducted. If MFA is implemented for no users, 5 points are deducted. The 3-point state is still a NOT MET requirement worth more than 1 point, so it cannot sit on a Conditional Level 2 POA&M. Partial MFA recovers two score points; it does not preserve Conditional eligibility.

FIPS-validated encryption (SC.L2-3.13.11). If encryption is employed but the module is not FIPS-validated, 3 points are deducted. If encryption is not employed, 5 points are deducted. “We use AES-256” is not the same claim as “we use a FIPS-validated cryptographic module.” The validation, not the algorithm name, is what this requirement turns on. Unlike partial MFA, the 3-point encryption state is the rule's one explicit exception that may go on a Conditional POA&M.

That's it. Two requirements out of 110. Everywhere else, partial implementation receives no adjusted point value.

Why the system security plan is different

CA.L2-3.12.4 has no point value. Instead, § 170.24(c)(2)(i)(5) says an organization must have a current SSP in place at the time of assessment describing each information system in the CMMC Assessment Scope, and that the absence of an up-to-date SSP results in a finding that the assessment could not be completed because of incomplete information and noncompliance with DFARS 252.204-7012.

Read that again. Not a low score. Not a finding of NOT MET. The assessment cannot be completed. You can have all 109 other requirements implemented and still have no CMMC assessment result to post.

The arithmetic that proves the 1-point list

The CFR names the fixed 5-pointers and fixed 3-pointers but never enumerates the 1-pointers. So we derived them: take all 110, subtract the 42 fixed 5-point requirements, the 14 fixed 3-point requirements, the 2 partial-credit requirements, and the SSP gate. What remains is 51 requirements at 1 point each.

Then we checked it, because a residual you cannot reconcile is just a guess:

Tier — Count — Maximum deduction
TierCountMaximum deduction
Fixed 5-point requirements42210
Fixed 3-point requirements1442
Partial-credit requirements, at the full 5-point deduction210
1-point requirements5151
SSP gate (CA.L2-3.12.4)10
Total110313

110 − 313 = −203.

That is the published floor of the score range — also described in the Justice Department's March 2025 MORSECORP settlement as running from −203 to 110. The arithmetic reconciles exactly.

It also confirms why CA.L2-3.12.4 is a gate rather than a weighted row. If the SSP requirement carried even one point, the floor would be −204. It does not.

This 42/14/2/51/1 reconciliation is our derived cross-check for the per-requirement values in the table above. For implementation dollars rather than score deductions, see our CMMC Level 2 cost guide.


Which of the 110 controls can go on a POA&M?

Forty-seven of the 110 are potentially eligible for a Conditional Level 2 POA&M; 63 are not. Under 32 CFR 170.21(a)(2), Conditional Level 2 status requires a score of at least 88, generally permits only 1-point requirements on the POA&M, creates one narrow encryption exception, and bars six specific requirements by name. POA&M items must be closed and confirmed by a closeout assessment within 180 days or the Conditional status expires.

This section is about the CMMC Conditional-status POA&M in 32 CFR 170.21. It is not the same thing as every “plan of action” referenced elsewhere in NIST or DFARS.

The four conditions, in plain terms

  1. Your score divided by 110 must be at least 0.8. That's a score of 88 or better.
  2. Nothing worth more than 1 point may sit on the POA&M. The only exception is the encryption state below.
  3. SC.L2-3.13.11 gets a carve-out. CUI encryption may go on a POA&M only when encryption is employed but is not FIPS-validated — the 3-point state. If encryption is not employed, the 5-point state cannot be deferred.
  4. Six requirements are barred by name, regardless of point value.

The six named exclusions

Straight from § 170.21(a)(2)(iii), using the regulation's titles:

ID — Title in the regulation — Points
IDTitle in the regulationPoints
AC.L2-3.1.20External Connections (CUI Data)1
AC.L2-3.1.22Control Public Information (CUI Data)1
CA.L2-3.12.4System Security PlanGate
PE.L2-3.10.3Escort Visitors (CUI Data)1
PE.L2-3.10.4Physical Access Logs (CUI Data)1
PE.L2-3.10.5Manage Physical Access (CUI Data)1

Five of these are 1-point requirements that would otherwise be potentially deferrable. The regulation removes them anyway. CA.L2-3.12.4 is the SSP gate and cannot be on a POA&M at all.

How we get to 47

  • 51 requirements worth 1 point
  • minus the 5 one-pointers barred by name
  • = 46 ordinarily eligible
  • plus SC.L2-3.13.11 in its encryption-employed-but-not-FIPS-validated state
  • = 47 potentially eligible, 63 ineligible

“Potentially eligible” is a screen, not a determination. It means the rule does not categorically bar the item. Actual Conditional status still depends on your score, the exact findings, the six named exclusions, the assessment record, the affirmation, and successful closeout within 180 days.

The 22-point budget

Because Conditional status requires at least 88, you can be down a maximum of 22 points at the assessment that creates the Conditional status. Every one of those points has to come from an eligible item. Twenty-two 1-point gaps is the theoretical maximum spread.

That budget is smaller than it sounds. Three families offer zero potentially deferrable requirements. Physical Protection offers exactly one. If your gaps cluster in System and Information Integrity or in Configuration Management's six fixed 5-point rows, your Conditional budget disappears before the score itself looks catastrophic.


Why you can score 105 out of 110 and still have no path forward

Every NOT MET requirement must have a POA&M in place under 32 CFR 170.24(c)(2)(i)(6), and 32 CFR 170.21(a)(2)(ii) bars requirements worth more than 1 point from the Conditional POA&M except for the narrow encryption state. Read together, those provisions mean a single unmet fixed 5-point requirement eliminates Conditional Level 2 status — regardless of how high the score is. A contractor at 105 with one fixed 5-point gap has no Conditional path, while a contractor at exactly 88 with 22 eligible 1-point gaps can pass this threshold-and-composition screen.

This is the finding that changes how you sequence remediation, so let's make it concrete.

Decision fact — Company A — Company B
Decision factCompany ACompany B
Requirements MET109 of 11088 of 110
The gapsOne: CM.L2-3.4.1, baseline configurationsTwenty-two, all 1-pointers, none named exclusions
Score10588
Score ÷ 1100.9550.800
Passes the 88 threshold?ComfortablyBarely
Can every gap go on the Conditional POA&M?No — the gap is worth 5 pointsPotentially — all are eligible 1-point gaps
Conditional Level 2 pathNot availableAvailable under this screen

Company A implemented more scored requirements and scores 17 points higher. Company B is the one that still has a Conditional path.

Every generic explainer tells you that you need 88. Almost none tell you that 88 is necessary but nowhere near sufficient — the composition of the gap list can matter more than the count.

What this means for how you sequence the work

Stop treating the fixed 5-pointers and fixed 3-pointers as ordinary backlog items. For Conditional purposes, they are gates.

The practical order:

  1. Confirm you have a current SSP. Without it, the assessment cannot be completed.
  2. Close every fixed 5-point gap. All 42 are non-deferrable for Conditional purposes.
  3. Close every fixed 3-point gap. All 14 are non-deferrable.
  4. Fully implement MFA. The 3-point partial state recovers score, but IA.L2-3.5.3 still cannot sit on the Conditional POA&M.
  5. For SC.L2-3.13.11, get encryption at least into the employed-but-not-FIPS-validated state if full FIPS validation is not complete. That is the only 3-point state the rule lets onto the Conditional POA&M.
  6. Then decide which eligible 1-pointers to defer, within the 22-point ceiling and 180-day closeout window.

If a readiness proposal sequences the work only by “easiest first” or “quickest wins,” ask how that sequence protects Conditional eligibility. A high score with the wrong gap is still a dead end.

Test the gap composition, not just the score.

Our CMMC Level 2 assessment guide walks through the scope, objective-level evidence, scoring, Conditional gates, and closeout path behind a defensible self-assessment.

→ Use the CMMC Level 2 assessment guide

Do not enter CUI or contract details into a public checklist or routing form.


What does “MET” actually require?

Under 32 CFR 170.24(b), each requirement receives one of three findings: MET, NOT MET, or Not Applicable. A requirement is MET only when all applicable assessment objectives are satisfied based on evidence that is in final form and not draft. The regulation names working papers, drafts, and unofficial or unapproved policies as unacceptable. A single unsatisfied applicable objective makes the requirement NOT MET.

The draft-evidence rule can kill a self-assessment before a technical gap does

Read § 170.24(b)(1) again: evidence must be in final form and not draft. Unacceptable forms explicitly include working papers, drafts, and unofficial or unapproved policies.

A company can write eleven security policies and still have eleven drafts if nobody with approval authority has approved them. Under the rule, those documents are not final evidence. The affected requirement is not “partially met.” It is NOT MET at its full deduction.

If your policy set has never been formally approved by someone empowered to approve it, that is not just documentation cleanup. It is a scoring problem across every requirement that depends on those policies.

Capability is not implementation

Here's the distinction that separates a real assessment from a vendor checklist.

“Microsoft 365 GCC High supports MFA enforcement” is a statement about a product.

“MFA is configured for the required privileged and non-privileged access paths, exceptions are documented and approved, the configuration was tested on this date, and here is the export” is a statement about your environment.

Only the second can support a MET finding. No product, platform, subscription tier, template, or provider makes a requirement MET on its own — the requirement is met by your implementation, operation, and final evidence.

When Not Applicable is legitimate

Per § 170.24(b)(3), a requirement or objective can be assessed N/A when it genuinely does not apply at the time of assessment, and an objective assessed N/A is treated the same as MET. The regulation supplies its own example: SC.L2-3.13.5 may be N/A if there are no publicly accessible systems inside the CMMC Assessment Scope.

N/A is a legitimate finding, not a loophole. Document the factual basis in the assessment record and in the SSP where it affects scope, architecture, or implementation. “We did not get to it” is not N/A. It is NOT MET.

Two more provisions matter. Enduring exceptions described with their mitigations in the SSP are assessed as MET. Temporary deficiencies addressed in operational plans of action that show review and progress may also be assessed as MET. Those operational plans are not the same thing as a Conditional CMMC POA&M under § 170.21; the rule uses similar words for different mechanisms.

If you hold a favorable DoD CIO adjudication under DFARS 252.204-7008 or 252.204-7012 that a requirement is inapplicable or that an alternative measure is equally effective, the adjudication must be included in the SSP to receive consideration.

The case that shows what a wrong score costs

We rarely get a clean primary-source example of scoring failure. This one is on the record.

In March 2025, the Department of Justice announced that MORSECORP Inc. agreed to pay $4.6 million to resolve False Claims Act allegations involving Army and Air Force contracts. As part of the settlement, the company admitted, acknowledged, and accepted responsibility for a specific sequence of facts:

  • From January 2018 to February 2023, it had not fully implemented all the NIST SP 800-171 controls its contracts required.
  • From January 2018 to January 2021, it did not have a consolidated written SSP describing system boundaries, environments of operation, how requirements were implemented, and connections to other systems.
  • In January 2021 it submitted a score of 104 to DoD. DOJ described that as near the top of the possible −203-to-110 range.
  • In July 2022 a third-party consultant told the company its actual score was −142.
  • It did not correct the score in DoD's reporting system until June 2023 — three months after being served with a federal subpoena.

The whistleblower received $851,000 of the settlement.

DOJ also described the missing controls using language that tracks the current 5-point and 3-point scoring tiers: controls whose absence could lead to significant exploitation or exfiltration, and controls with a specific and confined security effect. That comparison is our synthesis of the DOJ release and § 170.24, not a DOJ statement that CMMC scoring caused the settlement.

A 246-point swing between a submitted score and the consultant's score is not a rounding error. It is what can happen when a spreadsheet says “yes” and objective-level evidence does not sit behind it. We are not claiming this outcome is typical. We are pointing out that false representations about contractual cybersecurity compliance can create False Claims Act exposure, and this mechanism is documented in a primary-source enforcement record.


Did the July 2026 CMMC Phase II suspension change the 110 controls?

No. The Federal Register CMMC acquisition rule took effect on November 10, 2025, so the original phase schedule ran Phase I from November 10, 2025 through November 9, 2026, with Phase II scheduled to begin November 10, 2026. On July 13, 2026, DoD suspended Phase II and directed a 60-day review. DoD's current CMMC page and the implementing memorandum say all Phase I self-assessment requirements remain in place.

The suspension did not amend NIST SP 800-171 Revision 2, the 110 Level 2 requirements, the scoring methodology in § 170.24, the Conditional POA&M rules in § 170.21, or separate obligations already imposed by DFARS 252.204-7012, -7019, or -7020.

What remains, what paused, and what did not disappear

Question — Current answer as of August 14, 2026
QuestionCurrent answer as of August 14, 2026
What CMMC statuses may be newly designated while Phase II is suspended?Level 1 (Self) and Level 2 (Self)
What new designations are paused?Level 2 (C3PAO) and Level 3 (DIBCAC) requirements in new solicitations
What happens to active solicitations or existing contracts carrying paused designations?The implementing memo directs amendments to affected active solicitations and modification of affected contracts before the next option exercise or through an administrative modification
Are CMMC waivers continuing?The implementing memo suspends the waiver process during the pause
Are C3PAOs, the CAICO, Registered Practitioner services, and voluntary certification gone?No. The Cyber AB said those program elements remain operational and voluntary C3PAO assessments remain available
Did government verification disappear?No. DoD said it will continue self-assessments and select government-led assessments
Do DFARS 252.204-7012/-7019/-7020 obligations disappear?No. Those are separate contractual safeguarding, NIST DoD Assessment, access, and SPRS-record obligations

The part that should get your attention

For a procurement designated Level 2 (Self), your own assessment record and affirmation are the immediate contract-eligibility gate. That does not mean nobody can check your work: 32 CFR 170.16 reserves DoD's right to conduct a DCMA DIBCAC assessment, and the suspension announcement expressly preserved select government-led assessments.

The dangerous sentence is not “an assessor will never look.” The dangerous sentence is “we scored ourselves, posted it, and affirmed it without objective-level evidence.” MORSECORP shows what a false cybersecurity representation can cost even outside a CMMC certification assessment.

DoD directed a 60-day CMMC review on July 13, 2026. That report was not yet due as of this page's August 14 verification date. We re-verify this section monthly and will date any change.


Do all 110 controls apply to your company?

The 110 requirements are the CMMC Level 2 baseline, but not every contractor is on the Level 2 path, and within a Level 2 assessment an individual requirement or objective may be Not Applicable when the facts support it. The required CMMC status and assessment type come from the solicitation, contract, or flowdown; DoD program managers and requiring activities select the status based on the information the contractor system will process, store, or transmit.

Your situation — Where to start — Why
Your situationWhere to startWhy
FCI only, no CUILevel 1 — 15 requirements48 CFR 52.204-21(b)(1)(i)–(xv), incorporated into CMMC by § 170.14(c)(2). No POA&M is permitted at Level 1
Solicitation, contract, or flowdown requires Level 2 for CUILevel 2 — these 110§ 170.14(c)(3)
Level 3 is namedLevel 2's 110 plus 24 selected requirements from NIST SP 800-172 February 2021The current rule still incorporates the February 2021 edition and requires a maximum Level 2 score before a Level 3 assessment can begin
No clear clause or unclear CUI flowScope and contract determination firstA checklist cannot decide what information enters the environment or what status the contract requires
Contract expressly names a different revisionFollow the written contract, then get it reviewedWritten contract language governs that obligation

Revision warning for Level 3: NIST withdrew the February 2021 edition of SP 800-172 in May 2026 and published Revision 3, but current 32 CFR 170.2 and § 170.14(c)(4) still name the February 2021 edition and its 24 selected CMMC Level 3 requirements. Do not silently replace the incorporated version with the newer publication.

Company size does not change the Level 2 list. A twelve-person machine shop and a 4,000-person prime face the same 110 requirements when the same Level 2 status applies. Size changes the assessment boundary, evidence volume, operating model, and cost. Scope reduction through a defensible CUI enclave can be the highest-leverage decision a small supplier makes — but it has to be made under the asset categories in § 170.19, before implementation starts.

Use our CMMC levels guide to confirm the differences among Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC). If the written requirement or CUI determination is still unclear, use a qualified CMMC practitioner and, where contract interpretation is involved, a qualified federal-contracts attorney.


Who in your company owns the 110?

No single department can own the full requirement set. The 110 requirements distribute across IT, security, HR, facilities, contracts, and executive leadership, and a defensible program assigns one accountable owner per requirement or family while naming the contributors who perform the work and hold the evidence.

This is our editorial framework, not a NIST- or DoD-prescribed assignment. Use it as a starting map, not an authority.

Family cluster — Usually accountable — Usually contributing
Family clusterUsually accountableUsually contributing
Access Control, Identification & Authentication, System & Communications ProtectionSecurity or IT leadApplication owners, network engineering, HR for joiner/mover/leaver
Audit & Accountability, Configuration Management, System & Information IntegritySecurity operations or infrastructureSystem administrators, change approvers
Awareness & Training, Personnel SecurityHR or security governanceManagers, legal
Incident Response, Risk Assessment, Security AssessmentSecurity governanceExecutive leadership, legal, contracts
Maintenance, Media ProtectionIT operationsFacilities, third-party service vendors
Physical ProtectionFacilities or site operationsIT, HR, site leadership

The failure mode to avoid: handing all 110 to IT. That buries policy approval, training, physical security, personnel, contracting, and executive affirmation inside a technical backlog where no single owner has authority to finish them. Personnel Security has zero potentially deferrable requirements and it is not an IT function. Physical Protection has one potentially deferrable requirement out of six and it is not an IT function either.

One owner does not mean one implementer. Termination handling under PS.L2-3.9.2 can involve HR triggering the process, IT removing access, a manager confirming, and security validating — with one evidence record tying the chain together.

For a role-by-role hiring sequence, see who to hire first for NIST 800-171 implementation.


What to do once you have the list

Do not start at 3.1.1. Confirm the written requirement and the information type, define the assessment boundary, assign owners, work the assessment objectives rather than the requirement headlines, collect final evidence, score honestly, identify which SPRS record the clause requires, and document eligible gaps. Starting implementation before scoping can force expensive rework against the wrong assessment boundary.

1. Confirm the written requirement and the information type. What does the solicitation, contract, or flowdown require? Is FCI or CUI actually entering the environment? Does DFARS 252.204-7012 apply? Is DFARS 252.204-7021 present with a CMMC level and assessment type? This question can prevent a six-figure program built against the wrong obligation.

2. Map the CUI data flow and classify the assets. Under 32 CFR 170.19, Level 2 scoping distinguishes CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. A system does not become out of scope merely because it does not store CUI; a Security Protection Asset can still be assessed because it protects the CUI environment.

3. Freeze the version for each obligation. Current CMMC Level 2 uses Rev. 2. A DFARS 252.204-7012 obligation uses the NIST SP 800-171 version in effect when the solicitation was issued unless the Contracting Officer authorized otherwise. Track Rev. 3 separately; never blend it into a current Rev. 2 score.

4. Assign an accountable owner to every requirement. Anything without a name attached does not get finished. Run a “no owner” filter before you run anything else.

5. Work the objectives, not the headlines. All 320. A requirement with fifteen objectives is not one task. This is where self-assessments quietly inflate.

6. Attach and retain final evidence. Approved, current, in scope, with a test date and a named custodian. Draft policies do not count. For a Level 2 self-assessment, 32 CFR 170.16(c)(4) requires the artifacts used as evidence to be retained for six years from the CMMC Status Date.

7. Score honestly, then check the composition. Do not stop at “are we at 88?” Ask what each gap is worth, whether any gap is a named exclusion, whether MFA is only partial, and whether SC.L2-3.13.11 is in the 3-point or 5-point state.

8. Post the right record and maintain the right cadence. A DFARS 252.204-7019/-7020 NIST DoD Assessment record is not a substitute for a CMMC Level 2 self-assessment record when DFARS 252.204-7021 requires CMMC status. CMMC Level 2 (Self) requires the assessment on a three-year cycle and an affirmation at the assessment and annually thereafter, subject to the rule and the clause.

Somewhere around step 4 or 5, most teams reach the honest question: can we execute this in-house? That is not a failure. Scoping, SSP authoring, technical implementation, evidence operations, and formal assessment are different disciplines. Use our CMMC provider categories guide before comparing proposals that solve different problems.

What a C3PAO can — and cannot — promise

A C3PAO performs a formal Level 2 certification assessment. The Cyber AB CMMC Assessment Process v2.0 does not create a simplistic rule that every prior interaction automatically disqualifies a C3PAO. It requires the C3PAO to manage impartiality, identify and disclose conflicts of interest, document mitigation, and refuse to proceed when a conflict cannot be sufficiently mitigated.

It also prohibits a C3PAO from offering guarantees or promises about the assessment result and prohibits incentives or bonus payments contingent on a Certificate of CMMC Status.

Before hiring one, verify the organization's current authorized or accredited status in the Cyber AB Marketplace. A Marketplace listing establishes good standing and eligibility to conduct an assessment; it is not an endorsement. The CAP says the Cyber AB, CAICO, and DoD do not recommend or facilitate introductions to a C3PAO.

Need help deciding what type of CMMC provider you need?

Tell us your required level, scope, environment, and timeline, and we'll route you to the provider category that fits the work before you compare quotes.

→ Find my CMMC path

Already know the category and scope? Request comparable CMMC quotes.

Find My CMMC Path routes to a provider category, not a named provider. It is not a score, a certification decision, or compliance advice. Do not submit CUI, drawings, technical data, credentials, or sensitive contract details.


What we actually verified

This page was produced by The Defense Compliance Report Editorial Team from primary sources. Here is precisely what we checked and when.

Read in full at eCFR on August 14, 2026 — Title 32 was current as of August 13, 2026 and last amended July 24, 2026:

  • 32 CFR 170.14 — the Level 1, Level 2, and Level 3 requirement sets, including the 24 selected Level 3 requirements from NIST SP 800-172 February 2021
  • 32 CFR 170.16 and 170.22 — Level 2 self-assessment inputs, three-year assessment cycle, CMMC status, and annual affirmation
  • 32 CFR 170.19 — Level 2 asset categories and scoping rules
  • 32 CFR 170.21 — the 88 threshold, six named exclusions, the SC.L2-3.13.11 exception, and 180-day closeout
  • 32 CFR 170.24 — findings, point values, partial-credit states, the SSP gate, N/A treatment, and the requirement-level scoring method

Cross-checked the controlling rule history in the Federal Register:

Cross-checked at Acquisition.gov on August 14, 2026:

  • DFARS 252.204-7012 — the safeguarding baseline and its version-at-solicitation language
  • DFARS 252.204-7019 and 252.204-7020 — NIST SP 800-171 DoD Assessment summary records in SPRS and government access for Medium or High assessments
  • DFARS 252.204-7021 — required CMMC status, CMMC UID, self-assessment posting, flowdown, and annual affirmation

Counted directly from the normative NIST PDFs on August 14, 2026: all 110 NIST SP 800-171 Rev. 2 requirements, their basic/derived designations, and all 320 NIST SP 800-171A assessment objectives. We also checked NIST's withdrawal notices and normative-source notes for SP 800-171 Rev. 2 and SP 800-171A.

Computed and reconciled: the 51 one-point requirements, the 313-point maximum deduction, the −203 floor, the 46 ordinary POA&M-eligible one-pointers, and the 47/63 split after adding the narrow SC.L2-3.13.11 exception.

Checked against current program materials: DoD's current CMMC notice, the July 13, 2026 implementing memorandum, the Cyber AB's July 15 statement, and the Cyber AB CMMC Assessment Process v2.0 provisions on Marketplace status, impartiality, conflicts, guarantees, and contingent incentives.

Confirmed at Justice.gov: the MORSECORP settlement amount, dates, 104 submitted score, −142 consultant finding, June 2023 correction, $851,000 relator share, and DOJ's description of the possible score range.

What is editorial judgment, not regulation: the remediation sequence, ownership map, family-level workload commentary, Company A/Company B illustration, and our synthesis that any fixed 5-point or 3-point NOT MET requirement forecloses Conditional Level 2. That last conclusion is derived from § 170.24(c)(2)(i)(6) and § 170.21(a)(2)(ii), which are linked above so you can check the reasoning.

Read our methodology and editorial standards. Found an error? Use our corrections policy and send the requirement ID, primary source, and proposed correction. Material corrections are logged with the date.

This is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a qualified CMMC practitioner and, where contract interpretation is involved, a qualified federal-contracts attorney. The written requirement and your actual information flow govern — not a checklist.


Frequently asked questions

How many controls are in NIST 800-171? There are 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families. Revision 3 has 97 requirements across 17 families, but current 32 CFR Part 170 incorporates Revision 2 for CMMC Level 2.

Are NIST 800-171 controls the same as CMMC Level 2 requirements? Yes. 32 CFR 170.14(c)(3) states that the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 Revision 2.

Is it 110 controls or 97? For current CMMC Level 2, 110. The 97 figure comes from Revision 3. Building only to Revision 3 does not replace the Revision 2 baseline incorporated into the current CMMC rule.

NIST withdrew Revision 2 — is it still the CMMC baseline? Yes. NIST withdrew the publication on May 14, 2024, but 32 CFR Part 170 incorporates the February 2020 Revision 2 edition, including updates through January 28, 2021. NIST's withdrawal did not amend the CFR.

Does DFARS 252.204-7012 always mean Revision 2? Not automatically. The clause applies the NIST SP 800-171 version in effect when the solicitation was issued unless the Contracting Officer authorizes otherwise. Read the solicitation and contract instead of assuming the CMMC incorporation rule answers every 7012 version question.

How many assessment objectives are behind the 110 requirements? 320. We counted 23 requirements with one objective and 13 with six or more. CM.L2-3.4.7 has the maximum, at 15.

How many points is each control worth? The fixed values are 1, 3, or 5 under 32 CFR 170.24(c)(2). Forty-two requirements are fixed at 5 points, 14 are fixed at 3, and 51 are worth 1. IA.L2-3.5.3 and SC.L2-3.13.11 can deduct 3 or 5. CA.L2-3.12.4 is an SSP gate with no point value.

What is the lowest possible score? −203. The maximum is 110, and the maximum possible deduction is 313.

What score do I need for Conditional Level 2? At least 88, because the score divided by 110 must be at least 0.8. The threshold alone is not enough; the composition of the NOT MET requirements must also satisfy the POA&M restrictions.

How many of the 110 can go on a Conditional Level 2 POA&M? 47 potentially; 63 cannot. The 47 are 46 eligible 1-point requirements plus SC.L2-3.13.11 in the encryption-employed-but-not-FIPS-validated state.

Which controls can never go on that POA&M? Any fixed 3-point or 5-point requirement, IA.L2-3.5.3 in either NOT MET state, SC.L2-3.13.11 when encryption is not employed, and the six requirements named at § 170.21(a)(2)(iii): AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5.

How long do I have to close a CMMC POA&M? 180 days from the Conditional CMMC Status Date. If the closeout assessment is not successfully completed in that window, the Conditional status for the information system expires.

What happens if I do not have a system security plan? Under § 170.24(c)(2)(i)(5), the assessment cannot be completed because of incomplete information and noncompliance with DFARS 252.204-7012. It is not merely a point deduction.

Does a Not Applicable finding hurt the score? No. An assessment objective marked N/A is equivalent to MET. The factual basis should be documented, especially where it affects scope, architecture, or the SSP.

Can a draft policy count as evidence? No. Section 170.24(b)(1) requires evidence to be final, not draft, and expressly identifies working papers, drafts, and unofficial or unapproved policies as unacceptable.

Can one unmet objective make the whole requirement NOT MET? Yes. A requirement is NOT MET when one or more applicable objectives is not satisfied.

How long must Level 2 self-assessment evidence be retained? Six years from the CMMC Status Date. 32 CFR 170.16(c)(4) applies that retention period to the artifacts used as assessment evidence.

Is the CMMC Level 2 self-assessment record the same as the DFARS 252.204-7019/-7020 NIST DoD Assessment record? No. Both are in SPRS and can use the same 110-point range, but they are separate records with different authorities, fields, statuses, and contract triggers.

Do the 110 still apply after the July 2026 Phase II suspension? Yes. The suspension paused Phase II designations; it did not change the Level 2 requirements or scoring method. Phase I self-assessment requirements remain in place.

Do I need a C3PAO right now? Not for a Level 2 (Self) requirement. New Level 2 (C3PAO) and Level 3 (DIBCAC) designations are paused while Phase II is suspended, though voluntary C3PAO assessments remain available and select government-led assessments continue.

Can a C3PAO guarantee certification? No. The Cyber AB CAP prohibits guarantees or promises about the result and prohibits incentives or bonus payments contingent on issuance of a CMMC certificate.

Does compliance software make these requirements MET? No. Software can help document, track, and evidence implementation. The requirement is met by your environment's implementation and operation, supported by final evidence.

Is this list enough to submit an SPRS record? No. You must apply the requirements to a defined scope, assess the applicable objectives, connect findings to a current SSP and final evidence, calculate the score honestly, and submit the record required by the actual clause. A NIST DoD Assessment record and a CMMC self-assessment record are not interchangeable.

Does current CMMC Level 3 use NIST SP 800-172 Revision 3? No. NIST published a newer SP 800-172, but current 32 CFR Part 170 still incorporates the February 2021 edition and selects 24 requirements from it for CMMC Level 3.


Need help deciding what type of CMMC provider you need? Tell us your required level, scope, environment, and timeline, and we'll route you to source-checked provider categories.

→ Find My CMMC Path

Do not submit CUI, drawings, technical data, credentials, or contract documents.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.

The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice.