← Custodia

CMMC Level 2 for contractors handling CUI

Run your CMMC Level 2 program. Score it, prove it, and walk into your assessment ready.

bidfedcmmc.com
The Custodia Level 2 workspace: the 110 requirements worked at the objective level, your score, and the Audit Room
Everything includedYour team, your officer, your assessor's seat
  • All 110 requirements, 320 objectivesIncluded
  • The 14 policies, drafted and livingIncluded
  • Your RP, year roundIncluded
  • Your § 170.24 score, continuouslyIncluded
  • Guided evidence capture, 40 kindsIncluded
  • Assessment Ready PacketIncluded

110 requirements and 320 objectives, worked by your team in one workspace with a Registered Practitioner alongside you, without moving your data, without replacing your MSP or your enclave, and without a six figure consulting engagement.

One placeScope, assess, score, fix, prove, certify
One professionalAn RP checks your work before your assessor does
One seat for your assessorThey walk your evidence in here
30 days free No credit card An RP is assigned and reaches out We never touch your CUI

Jump to the reference guide

110 / 320
requirements and objectives, NIST SP 800-171 Rev 2
88
the score that makes you Conditional under 32 CFR 170.21
“In order to be considered for award”
DFARS 252.204-7019(b). Your assessment has to be current and posted before you can win the work
$35,000/yr
platform, your team, and your RP. Or $4,200/mo

Three different things. You need all three. We are the one you run yourself.

Holds the CUI

Your enclave

GCC High, a managed environment, your own tenant.

Assesses you

Your C3PAO

Independent by law, cannot remediate you.

Where the program runs

Custodia

Scope, assess, score, fix, prove, certify.

We do not become your cloud and we do not grade your homework. We run the program that gets you through both, and we work with whatever enclave and MSP you already have.

how it works

You get asked questions, in order, in plain English. A professional checks your answers. That is the whole job.

Nobody wants to self assess out of a spreadsheet. So we ask, you answer, the platform drafts what your answers imply, and your Registered Practitioner reviews it before it counts. One question at a time, across 7 steps.

It is not a document you buy. It is a program you run, and then someone checks it.

Mapping CUI flows and drawing the assessment boundary in the Level 2 workspace

1. Scope your CUI

Map how controlled information enters, lives, gets worked on, and leaves. Categorize every asset, save the network diagram, and start a Customer Responsibility Matrix for every provider you rely on.

1 · Your business2 · Find your CUI3 · Build your enclave
Working the 110 requirements at the objective level with evidence attached

2. Assess the 110

Adopt the 14 policies, then resolve every requirement at the objective level with evidence behind each MET. Guided capture covers 40 kinds of proof, and connectors pull what they can automatically.

4 · Policies and registers5 · Self assessment
The Level 2 score out of 110 with the POA&M beneath it

3. Score it and close the gaps

Your 32 CFR 170.24 score out of 110, a POA&M for what is still open, the 88 line for Conditional, 180 days to close, and the 6 that can never ride one.

5 · Self assessmentthe finale of the self assessment
The Audit Room readiness verdict and the assessment ready packet

4. Prove it, get assessed, file

Turn every readiness check green and sign your internal audit. Then your C3PAO walks the evidence in a read only seat, and the result gets filed.

6 · Attest and file7 · Certification

your score, 32 CFR 170.24

0of 110
Conditional at 88

Start at 110. Every NOT MET requirement subtracts 1, 3, or 5 points by weight. At 88 or better, with every remaining gap eligible for a POA&M, you can file with Conditional status (32 CFR 170.21).

Example: Meridian Defense Systems, Inc.

the POA&M, closing

  • AC.L2-3.1.3 Control CUI Flow
  • AT.L2-3.2.3 Insider Threat Awareness
  • AU.L2-3.3.3 Event Review
  • CM.L2-3.4.3 System Change Management

180 days to close every POA&M item, or the status expires.

6 requirements can never ride a POA&M at all, the System Security Plan among them. Those are MET on assessment day or not at all.

You self assess first. You run your own internal audit first. Only then do you bring in an assessor.

That order is not our preference, it is how the program is designed to work, and the platform is built in that order.

worked by your team

Compliance stops being one person's problem. Invite your team and the work splits. Send the controls to whoever holds the passwords, let your IT person handle the evidence, and keep signing rights with the owner. Five roles, one workspace.

OwnerManagerSigning OfficialControls workerAuditor (read only)
And one more seat: your C3PAO gets read only access. No Charlie, no remediation hints, no ability to change anything. Assessor independence is built into the product, not promised in a sentence.

the rhythm

A cadence you can prove beats a screenshot you took last Tuesday.

Several Level 2 requirements ask you to define a frequency and then show you kept it, and one asks for continuous monitoring outright. So Custodia runs your program on a monthly rhythm and every month closes a packet. By the time your assessor arrives you are not assembling evidence, you are handing over a run of it.

Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec

each mark is one closed monthly packet

The monthly rhythm is how we do it. The regulation asks you to set your own cadence and keep it, and it never names a number.

Your evidence compounds instead of expiring.

the part nobody else gives you

Your assessor walks your evidence in your workspace, not in a shared drive.

Give your C3PAO a read only seat. They see every requirement, every objective, the evidence behind each one, and the guide line it answers. Findings get raised against the specific objective they belong to, and you resolve them in the same place, so nobody is reconciling a spreadsheet against an email thread.

AC.L2-3.1.1You, owner
  • aauthorized users are identifiedMET
  • bprocesses acting on behalf of authorized users are identifiedMET
  • cdevices authorized to connect are identifiedMET
Save answerAttach evidenceAsk Charlie
AC.L2-3.1.1Your C3PAO
  • aauthorized users are identifiedMET
  • bprocesses acting on behalf of authorized users are identifiedMET
  • cdevices authorized to connect are identifiedMET
Save answerAttach evidence
read only

no Charlie · no remediation hints · nothing they can change

They will still want to see some things live. Your tenant, your AWS account, your repos. That is what an assessment is. What we remove is the six weeks of hunting for documents before anyone gets to look at anything real.

why the Audit Room exists

Before an assessor evaluates a single control, they review your System Security Plan and your scope and decide whether you are ready at all. If you are not, that decision goes to your Affirming Official in writing and the assessment stops. The Audit Room exists so that conversation never happens: every readiness check green, your internal audit signed, before anyone books a date.

CMMC Assessment Process v2.0 § 1.22, Adverse Determination of Assessment Readiness. Read the source.

01

The Assessment Ready Packet

Everything an assessor could ask for, checked and packaged before they ask.

02

The public verified page

A live page at bidfedcmmc.com/verified/yourcompany for the primes who just need to check. Once you are certified it reads: CMMC Level 2 certified, renewal clocks tracked.

03

The payoff

The status is what unlocks the pipeline. Matching contracts land in your inbox every Monday.

the outside check

You think your security is fine.Everyone does, until someone qualified actually looks.

At Level 1 you answer 15 questions. At Level 2 you score yourself against 320 objectives across 110 requirements, and then a C3PAO checks your work in person. The gap between what a team believes it has implemented and what it can prove is where assessments fail, and it is not a gap anyone can see in their own program.

Your Registered Practitioner is the outside read before the outside read. They walk every requirement with you, they consult while you build, and they tell you which of your MET answers will not survive contact with an assessor. Included, every year, not just the first one.

“Under no circumstances shall the C3PAO, its Assessment Team, or any other affiliated personnel offer any advice, implementation assistance, or recommendations as to how the OSC can improve or enhance their preparedness for a replanned or rescheduled CMMC Level 2 certification assessment.”
CMMC Assessment Process v2.0, § 1.23

Your assessor is not allowed to help you. That is not a criticism of them, it is what independence means. It is also why somebody qualified has to be on your side of the table long before they arrive.

You are not signing a form. You are signing a statement the government can prosecute.

A CMMC affirmation is made by a named senior official who can bind the company. A knowingly false one carries 18 U.S.C. § 1001 and False Claims Act exposure. That is the law today, on the self assessment path as much as any other.

Take the assessor out of the loop and that exposure does not go down, it concentrates. There is no third party left to catch the answer that was optimistic. Which is exactly why the person who signs should not also be the only person who checked.

That is the statute, not legal advice. Questions about your own exposure belong with your counsel.

Registered Practitioner, the Cyber AB credential for advising contractors on CMMC
Master's degree minimum on every officer
MSISPM, Carnegie Mellon
Included on every plan, every year, not just the first one

one framework, all the way down

Every other framework helps you win the deal. This one decides whether you are allowed to bid.

SOC 2 and ISO 27001 get asked for by customers. CMMC is written into the contract clause, at DFARS 252.204-7021, Contractor Compliance with the CMMC Program, and DFARS 252.204-7025, Notice of CMMC Status. That is why we build one framework all the way down to its 320 objectives instead of thirty five frameworks an inch deep, and it is why a general purpose GRC platform and a CMMC platform are not the same purchase. Your contracts depend on this one.

Every other option leaves a hole somebody has to fill later.

Do it yourselfConsultant or prep firmManaged enclave or cloudGeneral GRC (Vanta, Drata)Custodia
Holds your CUIYouNoYes, that is the productNoNo, and we never will
Runs the programYouWhile engagedNoPartlyYes
Scores you against § 170.24By handBy handNoNoYes, continuously
A CMMC professional on your accountNoWhile engagedNoNoYes, an RP, every year
Your assessor gets a seatNoNoNoNoYes, read only
CMMC is the only framework they build forn/aSometimesNoNo, one of 35+Yes
Year two and threeStart overRe engage, re billSame bill, no programSubscription plus a consultant anywaySame subscription
$0a year

Platform, your team's seats, your assessor's seat, and your Registered Practitioner. That is save $15,400 a year versus paying monthly.

Prefer to pay monthly? $4,200 a month. It comes to $50,400 across the year and does not include the two free months.

CMMC Level 2 is an ongoing program, so the plan is annual.

Start the 30 day free trial. No credit card. Level 1 and Level 2 are both open, so sign up for the level your contracts call for.

Do you host our CUI?
Do you certify us?
We already have Vanta or Drata.
We are not sure we need Level 2.

sign up for the level you need

Level 1 and Level 2 are both open. Pick the one your contracts call for and start today, no call required.

30 days free No credit card An RP is assigned and reaches out We never touch your CUI

reference

The full CMMC Level 2 reference guide

Plain English, primary sources cited. Not sure which level you need? Run the free check.

110
Requirements (NIST SP 800-171 r2)
320
Assessment objectives (800-171A)
88
Minimum score for Conditional status
180
Days to close every POA&M item

What CMMC Level 2 is, in one paragraph

CMMC Level 2 is how the Department of Defense verifies that a contractor protecting Controlled Unclassified Information (CUI) actually implements the safeguards its contracts have required for years. If a contract carries DFARS 252.204-7012, or the government sends you controlled technical drawings, export controlled specs, or technical data on a defense article, you are in Level 2 territory. The standard is NIST SP 800-171 Revision 2: 110 security requirements across 14 families, each judged at the objective level, scored out of 110, and recorded in SPRS under your CAGE code with an annual affirmation by a senior official.

Level 2 is not paperwork about security. It is a scored, evidence backed statement, with False Claims Act exposure behind it, that your business runs the 110 requirements today. That is exactly why contractors who file a defensible score early keep their contracts and pick up the work of competitors who cannot.

One point that gets muddled, so it is worth stating plainly. Self assessment and self attestation at Level 1 and Level 2 are law today. DFARS 252.204-7012 is unaffected. The NIST SP 800-171 Rev 2 baseline is unaffected. Self assessment requirements appear in solicitations today, government led assessments continue, and False Claims Act exposure for a knowingly false affirmation is unchanged. What is genuinely under review is the mechanism by which Level 2 gets certified by a third party, not whether the underlying obligation exists. If your contracts carry CUI, the work behind the 110 requirements applies to you either way.

The 110 requirements, in 14 plain-English families

Every requirement comes from NIST SP 800-171 r2. Here is the whole map, what each family actually asks of your business:

AC
Access Control · 22
Who can get in, and what they can touch
AT
Awareness & Training · 3
Your people know the risks
AU
Audit & Accountability · 9
Logs that prove what happened
CM
Configuration Management · 9
Systems set up on purpose, and kept that way
IA
Identification & Authentication · 11
Everyone proves who they are
IR
Incident Response · 3
A plan for when things go wrong
MA
Maintenance · 6
Fixing systems without opening holes
MP
Media Protection · 9
Drives and paper handled safely
PS
Personnel Security · 2
Screening before access, offboarding after
PE
Physical Protection · 6
Locks, escorts, and visitor logs
RA
Risk Assessment · 3
Knowing your weaknesses first
CA
Security Assessment · 4
Checking your own work, in writing
SC
System & Communications Protection · 16
The network boundary, encryption, separation
SI
System & Information Integrity · 7
Patching, malware protection, monitoring

Assessors do not grade the families, they grade the 320 assessment objectives beneath them (NIST SP 800-171A). One unmet objective fails its whole requirement, which is why working at the objective level from day one is the only honest way to build.

The score, the 88 rule, and the POA&M clock

Scoring is arithmetic, defined in 32 CFR 170.24. Start at 110. Every NOT MET requirement subtracts 1, 3, or 5 points by weight. Missing multifactor authentication or FIPS validated encryption carries special deductions, and no System Security Plan means the assessment cannot be completed at all (CA.L2-3.12.4).

You do not need a perfect 110 to file. At 88 or better, with every remaining gap eligible for a Plan of Action and Milestones, you can file with Conditional status, then close every POA&M item within 180 daysor the status expires. Six requirements can never ride a POA&M, including the SSP itself and the physical access trio, and those must be MET on assessment day.

The two tracks use the same 110 requirements and they are not alternatives. Level 2 (Self) is a self assessment recorded in SPRS, and it is the precursor; Level 2 (C3PAO) is certification by an accredited third party, recorded in CMMC eMASS, where a contract demands it. Build one honest package and it serves both. A status is valid three years, with annual affirmations by your senior official.

How to get CMMC Level 2 filed, step by step

  1. 1
    Confirm CMMC Level 2 applies to you

    Check your contracts for DFARS 252.204-7012 and look for information marked CUI, export controlled, or Distribution D. If you find either, Level 2 applies. If your contracts only involve FCI, start with Level 1 instead.

  2. 2
    Map your CUI

    Document every flow of controlled information: what it is, where it comes from, which systems store, process, or transmit it, and where it leaves. This map drives everything that follows.

  3. 3
    Draw the assessment boundary

    Categorize every asset under 32 CFR 170.19: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out of Scope. Determine FedRAMP status for every cloud vendor that touches CUI per DFARS 252.204-7012.

  4. 4
    Adopt the policies and stand up the registers

    Adopt the written policies the documentation objectives call for, and start the trackers the operational objectives call for, so the paperwork objectives are satisfied by documents you actually run on.

  5. 5
    Work the 110 requirements at the objective level

    Resolve each requirement the way an assessor scores it: every NIST SP 800-171A objective MET or Not Applicable, with evidence behind every MET. Adopted written policies satisfy the documentation objectives.

  6. 6
    Write the System Security Plan and score honestly

    The SSP is mandatory, no SSP means the assessment cannot be completed (CA.L2-3.12.4). Run the official 32 CFR 170.24 scoring: 110 minus 1, 3, or 5 points per gap.

  7. 7
    POA&M what is eligible, fix what is not

    At 88 or better with only POA&M eligible gaps you can file with Conditional status. POA&M items close within 180 days. Only 1 point gaps are POA&M eligible (except FIPS encryption, SC.L2-3.13.11, at 3 points), so the six never POA&M requirements and every other 3 and 5 point item must be MET first.

  8. 8
    Prove readiness, then record the self assessment and affirm

    Turn every readiness check green and sign your internal audit before anyone books a date. Then record the assessment in SPRS under your CAGE code and have your Affirming Official, a senior company official, affirm. The status is valid three years with annual affirmations.

  9. 9
    Hold it year round, and certify when a contract demands it

    Keep evidence fresh, close POA&Ms on schedule, review policies annually, and re-affirm every year. When a solicitation requires certification, give your C3PAO a read only seat and hand them the same assessment package.

What CMMC Level 2 really costs in 2026

Consultant readiness engagements run $35,000 to $150,000 over six months to a year, and the method leaves with the consultant. A full time compliance hire runs about $78,420 a year (Bureau of Labor Statistics), and one person cannot hold 320 objectives in their head. C3PAO assessment fees, when a contract requires certification, come on top of either path.

Custodia's CMMC Level 2 plan is $35,000 a year, or $4,200 a month. It covers the living Policy Center, the guided evidence capture, the Audit Room, your assessor's read only seat, contract opportunity matching, and a Registered Practitioner year round: your team runs the build on the platform so the method stays yours, and your RP advises, reviews the package before anything is filed, and keeps watching your posture after it is.

CMMC Level 2, the honest answers

What is CMMC Level 2?+
CMMC Level 2 is the tier of the Department of Defense's Cybersecurity Maturity Model Certification program for contractors that handle Controlled Unclassified Information (CUI). It requires implementation of all 110 security requirements from NIST SP 800-171 Revision 2, assessed against 320 assessment objectives from NIST SP 800-171A, scored out of 110 under 32 CFR 170.24, and recorded in the Supplier Performance Risk System (SPRS) with an annual senior official affirmation.
Who needs CMMC Level 2?+
Any organization whose DoD contracts flow down DFARS 252.204-7012, or that receives, creates, or handles Controlled Unclassified Information: controlled technical drawings, export controlled specs, technical data on defense articles, research deliverables marked CUI. If your contracts only involve Federal Contract Information (FCI) and never CUI, CMMC Level 1 covers you instead.
How many requirements are in CMMC Level 2?+
110 security requirements, straight from NIST SP 800-171 Revision 2, spread across 14 families. Assessors evaluate them against 320 assessment objectives from NIST SP 800-171A: every objective under a requirement must be MET or Not Applicable, or the whole requirement is NOT MET.
Is self assessment an alternative to a C3PAO assessment?+
No, it is the precursor. You self assess against the same 110 requirements, you run your own internal audit, and only then do you bring in an assessor. The regulation does recognize Level 2 (Self) as a terminal CMMC Status where the solicitation allows it, and Level 2 (C3PAO) as certification by an accredited third party where the contract demands it, but the work underneath is one package built in one order. A status is valid for three years with annual affirmations either way.
Where does a CMMC Level 2 result get filed, SPRS or eMASS?+
It depends which track produced it. Level 1, Level 2 (Self), and every annual affirmation are entered in the Supplier Performance Risk System (SPRS), reached through PIEE. Level 2 (C3PAO) certification assessments and Level 3 certifications are recorded in CMMC eMASS by the assessing organization. The Affirming Official is a senior company official who can bind the company, and a knowingly false affirmation carries 18 U.S.C. 1001 and False Claims Act exposure.
What is the CMMC Level 2 score and the 88 rule?+
Scoring starts at 110 and subtracts 1, 3, or 5 points for every NOT MET requirement per 32 CFR 170.24. Missing multifactor authentication or FIPS validated encryption carries special 3 or 5 point deductions, and having no System Security Plan means the assessment cannot be completed at all. You can achieve Conditional status at 88 or better only if every remaining gap is eligible for a Plan of Action and Milestones (POA&M), and POA&M items must close within 180 days or the status expires.
What can never go on a CMMC Level 2 POA&M?+
Six requirements can never ride a POA&M: 3.1.20 (external connections), 3.1.22 (public content control), 3.12.4 (the System Security Plan itself), and 3.10.3, 3.10.4, 3.10.5 (visitor escort, physical access logs, physical access devices). Those must be MET on assessment day. Beyond them, only 1 point requirements can go on a POA&M at all, so every 3 and 5 point requirement must be MET, with one exception: FIPS validated encryption (SC.L2-3.13.11, 3 points) when encryption is employed but not FIPS validated.
Does CMMC require a certain number of months of evidence?+
No. Nothing in the CMMC Assessment Process or 32 CFR 170 sets a duration or an evidence history requirement, and any vendor telling you that six months of anything is required to certify is wrong. What does create an over time obligation is the defined frequency pattern in NIST SP 800-171: requirements such as RA.L2-3.11.1, RA.L2-3.11.2, CA.L2-3.12.1 and CA.L2-3.12.4 each ask you to define a frequency and then show you performed at it, and CA.L2-3.12.3 asks for continuous monitoring outright. The organization picks the cadence and is then held to it. A screenshot taken the week of the assessment cannot prove a cadence, which is why Custodia runs the program on a monthly rhythm. That rhythm is our method, not a regulatory requirement.
What does CMMC Level 2 cost in 2026?+
Consultant readiness engagements typically run $35,000 to $150,000 and take six months to a year, before any C3PAO assessment fees. A full time compliance hire runs about $78,420 a year per the Bureau of Labor Statistics. Custodia's CMMC Level 2 plan is $35,000 a year, or $4,200 a month: the platform walks all 110 requirements with you, your assessor gets a read only seat, and a Registered Practitioner is on your account year round, reviewing the package before anything is filed. 30 day free trial, no credit card.
What's the difference between CMMC Level 1 and Level 2?+
Level 1 protects Federal Contract Information with 15 FAR 52.204-21 safeguarding requirements, self attested annually, binary MET or NOT MET with no score. Level 2 protects Controlled Unclassified Information with all 110 NIST SP 800-171 requirements, a numeric score out of 110, POA&M rules, and a self assessment that precedes third party certification. Contractors handling CUI almost always handle FCI too, and the 110 already include the 15 Level 1 safeguards; the standalone Level 1 filing is its own package.
What happens if I misrepresent my CMMC Level 2 posture in SPRS?+
A false SPRS score or affirmation is a federal false statement under 18 U.S.C. 1001 and actionable under the False Claims Act (31 U.S.C. 3729). The Department of Justice's Civil Cyber Fraud Initiative has settled multiple cases against contractors for overstated NIST 800-171 postures. The senior official who affirms is personally exposed, which is why an honest, evidence backed score matters more than a high one. Questions about your own exposure belong with your counsel.
Free · Every Monday

Get the federal bids a small business can win, in your inbox.

The Monday Bid Digest: brand-new SAM.gov solicitations matched to your NAICS, pre-filtered to Level 1 fit, with the CMMC gate called out on every one. Two minutes, no spam.

Get the Monday Bid Digest
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements, no signup, no card. If you like what you see, the 30 day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

30 day free trial · No credit card required · $550/mo with a Custodia Officer included ($5,000/yr on annual, save $1,600 a year)

Stuck on CMMC? Ask Charlie, or book an officer.