palmiq Speak to an expert

CMMC Level 2 Compliance & C3PAO Readiness

Protect Controlled Unclassified Information. Score 110 on SPRS. Pass your C3PAO assessment.

What Is CMMC Level 2 Compliance?

Protect Controlled Unclassified Information. Score 110 on SPRS. Pass your C3PAO assessment. palmiq delivers end-to-end CMMC Level 2 readiness — CUI scoping, NIST 800-171 implementation across all 110 controls and 320 assessment objectives, SSP development, and full audit preparation.

CMMC Level 2 (Advanced) is the middle tier of the Department of Defense's Cybersecurity Maturity Model Certification program. It requires defense contractors and subcontractors to implement all 110 security controls from NIST SP 800-171 Revision 2 across 14 control families to protect Controlled Unclassified Information (CUI) — technical drawings, engineering data, manufacturing processes, export-controlled information, and any data marked with CUI designators under DFARS 252.204-7012. Unlike Level 1's pass/fail self-assessment, Level 2 uses a weighted scoring system with a maximum SPRS score of 110, and most contracts require a triennial assessment by a certified third-party organization (C3PAO). POA&Ms are permitted under specific conditions: score at least 80% and meet all essential controls for conditional certification, with 180 days to close remaining gaps.

CMMC Level 2 at a Glance

110
Security controls from NIST SP 800-171 Rev. 2 — also the maximum SPRS score
320
Assessment objectives from NIST 800-171A, each examined, interviewed, or tested
14
Control families, from Access Control through System & Information Integrity
3 years
Certification validity after a passed C3PAO assessment, with annual affirmations

Sound Familiar?

These are the problems defense contractors bring to palmiq when preparing for CMMC Level 2.

“Our SPRS Score Is Negative and We Don’t Know Where to Start.”

palmiq conducts a comprehensive gap analysis against all 110 controls and 320 assessment objectives, calculates your current SPRS score, and delivers a prioritized remediation plan that shows exactly which controls to address first for maximum score improvement.

“We Don’t Have an SSP, POA&M, or Any Documentation.”

Our team develops your complete System Security Plan, network diagrams, data flow maps, CUI asset inventory, POA&M with milestones and completion dates, and all supporting policies and procedures that C3PAO assessors expect to review.

“We Need Someone to Actually Implement the Controls.”

As a full-stack MSP, palmiq deploys and manages the technical controls: MFA, SIEM, EDR, encryption, network segmentation, FIPS-validated cryptography, audit logging, vulnerability scanning, and every other technical requirement across all 14 families.

“We’re Not Ready for a C3PAO Assessment.”

palmiq runs a full mock assessment using the same methodology C3PAOs use: examination, interview, and testing against every assessment objective. We identify and close every finding before you schedule your official assessment.

14 Control Families · 110 Controls · 320 Objectives

CMMC Level 2 requires implementation of every control across all 14 NIST 800-171 families. palmiq implements and manages them all.

  • Access Control

    22 Controls

  • Awareness & Training

    3 Controls

  • Audit & Accountability

    9 Controls

  • Configuration Mgmt

    9 Controls

  • Identification & Auth

    11 Controls

  • Incident Response

    3 Controls

  • Maintenance

    6 Controls

  • Media Protection

    9 Controls

  • Personnel Security

    2 Controls

  • Physical Protection

    6 Controls

  • Risk Assessment

    3 Controls

  • Security Assessment

    4 Controls

  • System & Comms Protection

    16 Controls

  • System & Info Integrity

    7 Controls

  • What palmiq’s CMMC Level 2 Services Include

    End-to-end compliance services from gap analysis through C3PAO certification and ongoing maintenance.

  1. CUI Scoping & Gap Analysis

    • Identify and classify CUI across contracts and data flows
    • Inventory all CUI assets, security protection assets, and specialized assets
    • Evaluate all 110 controls against 320 assessment objectives
    • Calculate current SPRS score with weighted point values
    • Deliver prioritized remediation roadmap by control family
  2. SSP, POA&M & Documentation

    • System Security Plan with system boundaries and architecture
    • Network diagrams and CUI data flow documentation
    • POA&M with milestones, responsible parties, and completion dates
    • CUI handling procedures, marking, and destruction policies
    • All 14-family security policies and operating procedures
    • Incident response plan aligned with DFARS 7012 72-hour reporting
  3. Technical Control Implementation

    • MFA for all privileged and network accounts (Entra ID, Duo, Okta)
    • SIEM deployment and centralized audit logging (Sentinel, Splunk)
    • EDR/XDR endpoint protection (CrowdStrike, SentinelOne)
    • FIPS 140-2 validated encryption for CUI at rest and in transit
    • Network segmentation and CUI enclave architecture
    • Vulnerability scanning, patch management, and baseline configs
    • Encrypted backup and disaster recovery (Acronis, Datto)
  4. Mock Assessment & C3PAO Preparation

    • Full mock assessment using C3PAO methodology (examine, interview, test)
    • Evidence package compilation for all 320 assessment objectives
    • Staff preparation and interview coaching
    • POA&M closeout and final remediation before scheduling
    • C3PAO coordination and assessment logistics support
    • SPRS score submission and annual affirmation process

Two Paths to CMMC Level 2 Compliance

Your contract determines the required assessment type. palmiq prepares you for both.

Aspect Level 2 Self-Assessment Level 2 C3PAO Assessment (most contracts)
When it applies Lower-risk CUI where the DoD permits self-assessment Critical programs and high-value CUI requiring independent verification
Cadence Triennial self-assessment against 110 controls Triennial assessment by an accredited C3PAO
Reporting Scored assessment submitted to SPRS Results posted to eMASS by the assessor
Affirmation Annual senior-official affirmation Annual senior-official affirmation
POA&Ms Allowed with 80% minimum score, self-managed closeout in 180 days Conditional certification at 80% + essential controls, C3PAO-verified closeout in 180 days
Validity Rolling self-assessment cycle 3-year certification validity
  • From Gap Analysis to C3PAO Certification

    A proven process built from years of guiding defense contractors through NIST 800-171 and CMMC compliance.

  • CUI Identification & Scoping

    We trace where CUI enters, moves through, and leaves your environment, then define the assessment boundary — the single decision that most affects cost and effort.

  • Gap Analysis & SPRS Scoring

    Every control is evaluated against its 800-171A objectives, your weighted SPRS score is calculated, and remediation is sequenced by score impact.

  • SSP Development & Documentation

    palmiq writes the System Security Plan, network and data-flow diagrams, POA&M, and the family-by-family policies assessors examine first.

  • Technical Control Implementation

    Our engineers deploy the controls the documentation claims: MFA, SIEM, EDR, FIPS-validated encryption, segmentation, logging, and backup.

  • Mock Assessment & Remediation

    A full dry run using C3PAO methodology — examine, interview, test — with every finding closed before the real assessment is scheduled.

  • C3PAO Assessment & Ongoing Compliance

    We coordinate the official assessment, support your team through it, and then keep the environment compliant through annual affirmations and continuous monitoring.

Your CMMC Level 2 Partner from Assessment to Certification

  • Assess + Implement + Operate

    We don’t just write documentation — we deploy and manage every technical control as part of your ongoing managed services. One partner, end to end.

  • Government & DIB Expertise

    Based in Ashburn, Virginia with deep experience serving defense contractors, government agencies, and regulated industries. We understand CUI, DFARS, and CMMC inside and out.

  • GCC High & Sentinel

    Expert deployment of Microsoft 365 GCC/GCC High, Entra ID, Sentinel SIEM, Defender for Endpoint, and Intune for CMMC-compliant environments.

  • FIPS Backup & DR

    Enterprise-grade encrypted backup and disaster recovery that satisfies media protection, system integrity, and availability controls across all 14 families.

  • Certified Small Business

    Certified women-owned small business serving the defense supply chain. No long-term contracts required. Built for the DIB.

  • English & Spanish

    Full service delivery in English and Spanish, supporting defense contractors and subcontractors across the Americas.

  • Related Compliance Frameworks

    One control set can serve several obligations. These sibling programs share assessments, policies, and technical controls with CMMC Level 2:

NIST 800-171 Gap Assessment

The control set behind Level 2 — start here if you need a score before you need a certificate.

CMMC Level 1

For contracts handling only Federal Contract Information — 15 practices, annual self-assessment.

CMMC Level 3

For the most critical programs — 24 additional NIST 800-172 controls assessed by DIBCAC.

Microsoft GCC High

The cloud platform most Level 2 environments standardize on for CUI and ITAR data.

ISO 27001

For contractors selling internationally — Annex A maps extensively onto the 800-171 families.

SOC 2 Type II

For contractors with commercial enterprise clients — reuse the same evidence across both programs.

Common questions

What is CMMC Level 2?

CMMC Level 2 applies to contractors that store, process or transmit Controlled Unclassified Information, and requires all 110 NIST SP 800-171 controls measured across 320 assessment objectives.

Do I need a C3PAO assessment for Level 2?

Most Level 2 contracts require a triennial assessment by an accredited C3PAO, while a limited subset permit an annual self-assessment instead. The contract language determines which applies to you.

What SPRS score do I need?

110 is the maximum score, representing full implementation of all 110 controls. Many contractors begin with a negative score, because unimplemented controls carry weighted deductions — that is normal before remediation, not a disqualifier.

What is an SSP and do I have to have one?

A System Security Plan documents how each of the 110 controls is implemented across your environment, and it is required. Assessors examine it first, so gaps or vagueness in the SSP tend to surface as findings.

What is a POA&M?

A Plan of Action and Milestones records controls that are not yet fully implemented and the dated plan to close them. Some may be permitted at assessment time depending on the control, but they must be closed within the allowed window.

Don't let a low SPRS score cost you your next contract

CMMC Level 2 enforcement is live. palmiq gives you a clear, managed path from gap analysis to a perfect SPRS score and C3PAO certification.