What Is CMMC Level 2 Compliance?
Protect Controlled Unclassified Information. Score 110 on SPRS. Pass your C3PAO assessment. palmiq delivers end-to-end CMMC Level 2 readiness — CUI scoping, NIST 800-171 implementation across all 110 controls and 320 assessment objectives, SSP development, and full audit preparation.
CMMC Level 2 (Advanced) is the middle tier of the Department of Defense's Cybersecurity Maturity Model Certification program. It requires defense contractors and subcontractors to implement all 110 security controls from NIST SP 800-171 Revision 2 across 14 control families to protect Controlled Unclassified Information (CUI) — technical drawings, engineering data, manufacturing processes, export-controlled information, and any data marked with CUI designators under DFARS 252.204-7012. Unlike Level 1's pass/fail self-assessment, Level 2 uses a weighted scoring system with a maximum SPRS score of 110, and most contracts require a triennial assessment by a certified third-party organization (C3PAO). POA&Ms are permitted under specific conditions: score at least 80% and meet all essential controls for conditional certification, with 180 days to close remaining gaps.
CMMC Level 2 at a Glance
- 110
- Security controls from NIST SP 800-171 Rev. 2 — also the maximum SPRS score
- 320
- Assessment objectives from NIST 800-171A, each examined, interviewed, or tested
- 14
- Control families, from Access Control through System & Information Integrity
- 3 years
- Certification validity after a passed C3PAO assessment, with annual affirmations
Sound Familiar?
These are the problems defense contractors bring to palmiq when preparing for CMMC Level 2.
“Our SPRS Score Is Negative and We Don’t Know Where to Start.”
palmiq conducts a comprehensive gap analysis against all 110 controls and 320 assessment objectives, calculates your current SPRS score, and delivers a prioritized remediation plan that shows exactly which controls to address first for maximum score improvement.
“We Don’t Have an SSP, POA&M, or Any Documentation.”
Our team develops your complete System Security Plan, network diagrams, data flow maps, CUI asset inventory, POA&M with milestones and completion dates, and all supporting policies and procedures that C3PAO assessors expect to review.
“We Need Someone to Actually Implement the Controls.”
As a full-stack MSP, palmiq deploys and manages the technical controls: MFA, SIEM, EDR, encryption, network segmentation, FIPS-validated cryptography, audit logging, vulnerability scanning, and every other technical requirement across all 14 families.
“We’re Not Ready for a C3PAO Assessment.”
palmiq runs a full mock assessment using the same methodology C3PAOs use: examination, interview, and testing against every assessment objective. We identify and close every finding before you schedule your official assessment.
14 Control Families · 110 Controls · 320 Objectives
CMMC Level 2 requires implementation of every control across all 14 NIST 800-171 families. palmiq implements and manages them all.
-
Access Control
22 Controls
-
Awareness & Training
3 Controls
-
Audit & Accountability
9 Controls
-
Configuration Mgmt
9 Controls
-
Identification & Auth
11 Controls
-
Incident Response
3 Controls
-
Maintenance
6 Controls
-
Media Protection
9 Controls
-
Personnel Security
2 Controls
-
Physical Protection
6 Controls
-
Risk Assessment
3 Controls
-
Security Assessment
4 Controls
-
System & Comms Protection
16 Controls
-
System & Info Integrity
7 Controls
-
What palmiq’s CMMC Level 2 Services Include
End-to-end compliance services from gap analysis through C3PAO certification and ongoing maintenance.
-
CUI Scoping & Gap Analysis
- Identify and classify CUI across contracts and data flows
- Inventory all CUI assets, security protection assets, and specialized assets
- Evaluate all 110 controls against 320 assessment objectives
- Calculate current SPRS score with weighted point values
- Deliver prioritized remediation roadmap by control family
-
SSP, POA&M & Documentation
- System Security Plan with system boundaries and architecture
- Network diagrams and CUI data flow documentation
- POA&M with milestones, responsible parties, and completion dates
- CUI handling procedures, marking, and destruction policies
- All 14-family security policies and operating procedures
- Incident response plan aligned with DFARS 7012 72-hour reporting
-
Technical Control Implementation
- MFA for all privileged and network accounts (Entra ID, Duo, Okta)
- SIEM deployment and centralized audit logging (Sentinel, Splunk)
- EDR/XDR endpoint protection (CrowdStrike, SentinelOne)
- FIPS 140-2 validated encryption for CUI at rest and in transit
- Network segmentation and CUI enclave architecture
- Vulnerability scanning, patch management, and baseline configs
- Encrypted backup and disaster recovery (Acronis, Datto)
-
Mock Assessment & C3PAO Preparation
- Full mock assessment using C3PAO methodology (examine, interview, test)
- Evidence package compilation for all 320 assessment objectives
- Staff preparation and interview coaching
- POA&M closeout and final remediation before scheduling
- C3PAO coordination and assessment logistics support
- SPRS score submission and annual affirmation process
Two Paths to CMMC Level 2 Compliance
Your contract determines the required assessment type. palmiq prepares you for both.
| Aspect | Level 2 Self-Assessment | Level 2 C3PAO Assessment (most contracts) |
|---|---|---|
| When it applies | Lower-risk CUI where the DoD permits self-assessment | Critical programs and high-value CUI requiring independent verification |
| Cadence | Triennial self-assessment against 110 controls | Triennial assessment by an accredited C3PAO |
| Reporting | Scored assessment submitted to SPRS | Results posted to eMASS by the assessor |
| Affirmation | Annual senior-official affirmation | Annual senior-official affirmation |
| POA&Ms | Allowed with 80% minimum score, self-managed closeout in 180 days | Conditional certification at 80% + essential controls, C3PAO-verified closeout in 180 days |
| Validity | Rolling self-assessment cycle | 3-year certification validity |
-
From Gap Analysis to C3PAO Certification
A proven process built from years of guiding defense contractors through NIST 800-171 and CMMC compliance.
-
CUI Identification & Scoping
We trace where CUI enters, moves through, and leaves your environment, then define the assessment boundary — the single decision that most affects cost and effort.
-
Gap Analysis & SPRS Scoring
Every control is evaluated against its 800-171A objectives, your weighted SPRS score is calculated, and remediation is sequenced by score impact.
-
SSP Development & Documentation
palmiq writes the System Security Plan, network and data-flow diagrams, POA&M, and the family-by-family policies assessors examine first.
-
Technical Control Implementation
Our engineers deploy the controls the documentation claims: MFA, SIEM, EDR, FIPS-validated encryption, segmentation, logging, and backup.
-
Mock Assessment & Remediation
A full dry run using C3PAO methodology — examine, interview, test — with every finding closed before the real assessment is scheduled.
-
C3PAO Assessment & Ongoing Compliance
We coordinate the official assessment, support your team through it, and then keep the environment compliant through annual affirmations and continuous monitoring.
Your CMMC Level 2 Partner from Assessment to Certification
-
Assess + Implement + Operate
We don’t just write documentation — we deploy and manage every technical control as part of your ongoing managed services. One partner, end to end.
-
Government & DIB Expertise
Based in Ashburn, Virginia with deep experience serving defense contractors, government agencies, and regulated industries. We understand CUI, DFARS, and CMMC inside and out.
-
GCC High & Sentinel
Expert deployment of Microsoft 365 GCC/GCC High, Entra ID, Sentinel SIEM, Defender for Endpoint, and Intune for CMMC-compliant environments.
-
FIPS Backup & DR
Enterprise-grade encrypted backup and disaster recovery that satisfies media protection, system integrity, and availability controls across all 14 families.
-
Certified Small Business
Certified women-owned small business serving the defense supply chain. No long-term contracts required. Built for the DIB.
-
English & Spanish
Full service delivery in English and Spanish, supporting defense contractors and subcontractors across the Americas.
-
Related Compliance Frameworks
One control set can serve several obligations. These sibling programs share assessments, policies, and technical controls with CMMC Level 2:
NIST 800-171 Gap Assessment
The control set behind Level 2 — start here if you need a score before you need a certificate.
CMMC Level 1
For contracts handling only Federal Contract Information — 15 practices, annual self-assessment.
CMMC Level 3
For the most critical programs — 24 additional NIST 800-172 controls assessed by DIBCAC.
Microsoft GCC High
The cloud platform most Level 2 environments standardize on for CUI and ITAR data.
ISO 27001
For contractors selling internationally — Annex A maps extensively onto the 800-171 families.
SOC 2 Type II
For contractors with commercial enterprise clients — reuse the same evidence across both programs.