CMMC Level 2 requirements: all 110 NIST 800-171 practices by domain
Level 2 means all 110 security requirements of NIST SP 800-171 Revision 2, grouped into 14 families. What each family asks for, how the requirements are weighted, and where to read every one of them in plain language.
Key takeaways
- Level 2 is all 110 requirements of NIST SP 800-171 Revision 2, organized into 14 families.
- Requirements are not equal: 44 carry five points in the DoD scoring methodology, 14 carry three, 51 carry one, and the system security plan is not scored at all.
- Revision 3 changes the numbering, the families and the wording, but it is not what a contract requires today.
- Every requirement has its own plain-language page in our free guide, linked from each family below.
At a glance
110 security requirements. 14 families. Assessed every three years with annual affirmations. Under the Phase 2 rollout, assessed by a C3PAO; during the suspension, by self-assessment affirmed in SPRS.
Bedrock CMMC carries all 110 requirements with their NIST SP 800-171A objectives. For each one you record status per objective, attach evidence, and generate the system security plan, so you always know where you stand. See a live package.
The 14 domains
Each heading links to the family in our guide, where every requirement has a page with the plain version, the verbatim text, the assessment objectives and the weight.
Access Control (AC): 22 requirements
Who and what may use your systems, what each may do once inside, how CUI is allowed to move, and how remote, wireless and mobile access are controlled. Four of the 22 are also Level 1 practices.
- Limit system access to authorized users, processes and devices
- Limit access to the transactions and functions each user is permitted to execute
- Control the flow of CUI in accordance with approved authorizations
- Separate duties, apply least privilege, and use non-privileged accounts for ordinary work
- Monitor and control remote, wireless and mobile access
Awareness and Training (AT): 3 requirements
People know the risks, people with security duties are trained for them, and staff can recognise insider threat.
Audit and Accountability (AU): 9 requirements
Logs good enough to reconstruct what happened, tied to named users, protected from tampering, and actually reviewed.
- Create and retain audit logs; trace actions to individual users
- Review, analyse, correlate and protect audit records; alert on logging failure
Configuration Management (CM): 9 requirements
Know what you run, keep it in a known state, change it deliberately, and strip out what is not needed.
- Baselines and inventories; change control with security impact analysis
- Least functionality; restrictions on user-installed software
Identification and Authentication (IA): 11 requirements
Unique identities for users and devices, multi-factor authentication, authenticator management, password rules and replay resistance.
Incident Response (IR): 3 requirements
A capability, not a document: detect, contain, recover and report; track incidents; test the capability.
Maintenance (MA): 6 requirements
Who performs maintenance, with what tools, what leaves the building and comes back, and how remote sessions are controlled.
Media Protection (MP): 9 requirements
Media that carry CUI: protected, marked, controlled in transit, sanitised or destroyed, with removable media and backups handled.
Physical Protection (PE): 6 requirements
Who can walk up to the systems, how visitors are escorted and logged, how access devices are controlled, and alternate work sites.
Personnel Security (PS): 2 requirements
Screen people before they get access; protect CUI when they leave or move.
Risk Assessment (RA): 3 requirements
Assess risk on a schedule, scan for vulnerabilities, and fix what the scans find.
Security Assessment (CA): 4 requirements
Periodic self-assessment, the plan of action, continuous monitoring, and the system security plan itself.
System and Communications Protection (SC): 16 requirements
Boundary protection, network separation, session protection and cryptography, including FIPS-validated cryptography for CUI.
System and Information Integrity (SI): 7 requirements
Patching, malware protection, monitoring for attacks, and acting on advisories. Four of the seven are Level 1 practices.
How the 110 are weighted
The DoD Assessment Methodology assigns each requirement a weight. Your SPRS score starts at 110 and subtracts the weight of every requirement not met, down to a floor of minus 203.
| Weight | Requirements | What it means |
|---|---|---|
| 5 points | 44 | The requirements with the largest effect on posture. None may be placed on a POA&M at assessment. |
| 3 points | 14 | Important requirements; most may not be deferred to a POA&M either. |
| 1 point | 51 | Supporting requirements; typically POA&M-eligible. |
| Not scored | 1 | The system security plan (3.12.4). No points, but without it an assessment cannot proceed. |
Two requirements carry a partial-credit rule: multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) deduct three points instead of five in one specific case each. The weight of every requirement is shown on its page in the guide.
What about Revision 3?
NIST published Revision 3 of SP 800-171 in 2024. It has 97 requirements in 17 families, introduces organization-defined parameters, and renumbers everything. It is not what a contract requires: a standing DoD class deviation keeps DFARS 252.204-7012 contracts on Revision 2, and the Department has said any move would come through rulemaking. Preparation is sensible; renumbering your program is premature. The guide shows every requirement's Rev. 2 and Rev. 3 wording side by side.
Questions people ask
How many controls are in CMMC Level 2?
All 110 security requirements of NIST SP 800-171 Revision 2, in 14 families ranging from Access Control with 22 requirements to Personnel Security with two.
Which domains are hardest?
Most organizations find System and Communications Protection and Audit and Accountability the hardest: the first needs encryption and network separation, the second needs logging that is complete, protected and actually reviewed. Configuration Management is close behind because baselines have to be written down.
Can I get Level 2 with a POA&M?
A limited number of requirements may be open on a POA&M at assessment for a conditional result, with 180 days to close them. Five-point requirements may not be deferred, and most three-point ones may not either. The POA&M guide covers the rules.
Does Revision 3 apply to me?
Not for defense contracts today. Revision 2 remains the assessed baseline under a standing class deviation. Civilian agency contracts may point at Revision 3 once the proposed FAR CUI rule is final.
Keep the proof, not just the plan.
Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.