CMMC Level 2 for contractors handling CUI
Run your CMMC Level 2 program. Score it, prove it, and walk into your assessment ready.

- All 110 requirements, 320 objectivesIncluded
- The 14 policies, drafted and livingIncluded
- Your RP, year roundIncluded
- Your § 170.24 score, continuouslyIncluded
- Guided evidence capture, 40 kindsIncluded
- Assessment Ready PacketIncluded
110 requirements and 320 objectives, worked by your team in one workspace with a Registered Practitioner alongside you, without moving your data, without replacing your MSP or your enclave, and without a six figure consulting engagement.
Three different things. You need all three. We are the one you run yourself.
Holds the CUI
Your enclave
GCC High, a managed environment, your own tenant.
Assesses you
Your C3PAO
Independent by law, cannot remediate you.
Where the program runs
Custodia
Scope, assess, score, fix, prove, certify.
We do not become your cloud and we do not grade your homework. We run the program that gets you through both, and we work with whatever enclave and MSP you already have.
how it works
You get asked questions, in order, in plain English. A professional checks your answers. That is the whole job.
Nobody wants to self assess out of a spreadsheet. So we ask, you answer, the platform drafts what your answers imply, and your Registered Practitioner reviews it before it counts. One question at a time, across 7 steps.
It is not a document you buy. It is a program you run, and then someone checks it.

1. Scope your CUI
Map how controlled information enters, lives, gets worked on, and leaves. Categorize every asset, save the network diagram, and start a Customer Responsibility Matrix for every provider you rely on.

2. Assess the 110
Adopt the 14 policies, then resolve every requirement at the objective level with evidence behind each MET. Guided capture covers 40 kinds of proof, and connectors pull what they can automatically.

3. Score it and close the gaps
Your 32 CFR 170.24 score out of 110, a POA&M for what is still open, the 88 line for Conditional, 180 days to close, and the 6 that can never ride one.

4. Prove it, get assessed, file
Turn every readiness check green and sign your internal audit. Then your C3PAO walks the evidence in a read only seat, and the result gets filed.
Scope your CUI
Map how controlled information enters, lives, gets worked on, and leaves. Categorize every asset, save the network diagram, and start a Customer Responsibility Matrix for every provider you rely on.
Assess the 110
Adopt the 14 policies, then resolve every requirement at the objective level with evidence behind each MET. Guided capture covers 40 kinds of proof, and connectors pull what they can automatically.
Score it and close the gaps
Your 32 CFR 170.24 score out of 110, a POA&M for what is still open, the 88 line for Conditional, 180 days to close, and the 6 that can never ride one.
Prove it, get assessed, file
Turn every readiness check green and sign your internal audit. Then your C3PAO walks the evidence in a read only seat, and the result gets filed.
your score, 32 CFR 170.24
Start at 110. Every NOT MET requirement subtracts 1, 3, or 5 points by weight. At 88 or better, with every remaining gap eligible for a POA&M, you can file with Conditional status (32 CFR 170.21).
Example: Meridian Defense Systems, Inc.
the POA&M, closing
- AC.L2-3.1.3 Control CUI Flow
- AT.L2-3.2.3 Insider Threat Awareness
- AU.L2-3.3.3 Event Review
- CM.L2-3.4.3 System Change Management
180 days to close every POA&M item, or the status expires.
6 requirements can never ride a POA&M at all, the System Security Plan among them. Those are MET on assessment day or not at all.
You self assess first. You run your own internal audit first. Only then do you bring in an assessor.
That order is not our preference, it is how the program is designed to work, and the platform is built in that order.
worked by your team
Compliance stops being one person's problem. Invite your team and the work splits. Send the controls to whoever holds the passwords, let your IT person handle the evidence, and keep signing rights with the owner. Five roles, one workspace.
the rhythm
A cadence you can prove beats a screenshot you took last Tuesday.
Several Level 2 requirements ask you to define a frequency and then show you kept it, and one asks for continuous monitoring outright. So Custodia runs your program on a monthly rhythm and every month closes a packet. By the time your assessor arrives you are not assembling evidence, you are handing over a run of it.
each mark is one closed monthly packet
The monthly rhythm is how we do it. The regulation asks you to set your own cadence and keep it, and it never names a number.
Your evidence compounds instead of expiring.
the part nobody else gives you
Your assessor walks your evidence in your workspace, not in a shared drive.
Give your C3PAO a read only seat. They see every requirement, every objective, the evidence behind each one, and the guide line it answers. Findings get raised against the specific objective they belong to, and you resolve them in the same place, so nobody is reconciling a spreadsheet against an email thread.
- aauthorized users are identifiedMET
- bprocesses acting on behalf of authorized users are identifiedMET
- cdevices authorized to connect are identifiedMET
- aauthorized users are identifiedMET
- bprocesses acting on behalf of authorized users are identifiedMET
- cdevices authorized to connect are identifiedMET
no Charlie · no remediation hints · nothing they can change
They will still want to see some things live. Your tenant, your AWS account, your repos. That is what an assessment is. What we remove is the six weeks of hunting for documents before anyone gets to look at anything real.
why the Audit Room exists
Before an assessor evaluates a single control, they review your System Security Plan and your scope and decide whether you are ready at all. If you are not, that decision goes to your Affirming Official in writing and the assessment stops. The Audit Room exists so that conversation never happens: every readiness check green, your internal audit signed, before anyone books a date.
CMMC Assessment Process v2.0 § 1.22, Adverse Determination of Assessment Readiness. Read the source.
The Assessment Ready Packet
Everything an assessor could ask for, checked and packaged before they ask.
The public verified page
A live page at bidfedcmmc.com/verified/yourcompany for the primes who just need to check. Once you are certified it reads: CMMC Level 2 certified, renewal clocks tracked.
The payoff
The status is what unlocks the pipeline. Matching contracts land in your inbox every Monday.
the outside check
You think your security is fine.Everyone does, until someone qualified actually looks.
At Level 1 you answer 15 questions. At Level 2 you score yourself against 320 objectives across 110 requirements, and then a C3PAO checks your work in person. The gap between what a team believes it has implemented and what it can prove is where assessments fail, and it is not a gap anyone can see in their own program.
Your Registered Practitioner is the outside read before the outside read. They walk every requirement with you, they consult while you build, and they tell you which of your MET answers will not survive contact with an assessor. Included, every year, not just the first one.
“Under no circumstances shall the C3PAO, its Assessment Team, or any other affiliated personnel offer any advice, implementation assistance, or recommendations as to how the OSC can improve or enhance their preparedness for a replanned or rescheduled CMMC Level 2 certification assessment.”
Your assessor is not allowed to help you. That is not a criticism of them, it is what independence means. It is also why somebody qualified has to be on your side of the table long before they arrive.
You are not signing a form. You are signing a statement the government can prosecute.
A CMMC affirmation is made by a named senior official who can bind the company. A knowingly false one carries 18 U.S.C. § 1001 and False Claims Act exposure. That is the law today, on the self assessment path as much as any other.
Take the assessor out of the loop and that exposure does not go down, it concentrates. There is no third party left to catch the answer that was optimistic. Which is exactly why the person who signs should not also be the only person who checked.
That is the statute, not legal advice. Questions about your own exposure belong with your counsel.
one framework, all the way down
Every other framework helps you win the deal. This one decides whether you are allowed to bid.
SOC 2 and ISO 27001 get asked for by customers. CMMC is written into the contract clause, at DFARS 252.204-7021, Contractor Compliance with the CMMC Program, and DFARS 252.204-7025, Notice of CMMC Status. That is why we build one framework all the way down to its 320 objectives instead of thirty five frameworks an inch deep, and it is why a general purpose GRC platform and a CMMC platform are not the same purchase. Your contracts depend on this one.
Every other option leaves a hole somebody has to fill later.
| Do it yourself | Consultant or prep firm | Managed enclave or cloud | General GRC (Vanta, Drata) | Custodia | |
|---|---|---|---|---|---|
| Holds your CUI | You | No | Yes, that is the product | No | No, and we never will |
| Runs the program | You | While engaged | No | Partly | Yes |
| Scores you against § 170.24 | By hand | By hand | No | No | Yes, continuously |
| A CMMC professional on your account | No | While engaged | No | No | Yes, an RP, every year |
| Your assessor gets a seat | No | No | No | No | Yes, read only |
| CMMC is the only framework they build for | n/a | Sometimes | No | No, one of 35+ | Yes |
| Year two and three | Start over | Re engage, re bill | Same bill, no program | Subscription plus a consultant anyway | Same subscription |
Platform, your team's seats, your assessor's seat, and your Registered Practitioner. That is save $15,400 a year versus paying monthly.
Prefer to pay monthly? $4,200 a month. It comes to $50,400 across the year and does not include the two free months.
CMMC Level 2 is an ongoing program, so the plan is annual.
Start the 30 day free trial. No credit card. Level 1 and Level 2 are both open, so sign up for the level your contracts call for.
Do you host our CUI?
Do you certify us?
We already have Vanta or Drata.
We are not sure we need Level 2.
sign up for the level you need
Level 1 and Level 2 are both open. Pick the one your contracts call for and start today, no call required.
reference
The full CMMC Level 2 reference guide
Plain English, primary sources cited. Not sure which level you need? Run the free check.
What CMMC Level 2 is, in one paragraph
CMMC Level 2 is how the Department of Defense verifies that a contractor protecting Controlled Unclassified Information (CUI) actually implements the safeguards its contracts have required for years. If a contract carries DFARS 252.204-7012, or the government sends you controlled technical drawings, export controlled specs, or technical data on a defense article, you are in Level 2 territory. The standard is NIST SP 800-171 Revision 2: 110 security requirements across 14 families, each judged at the objective level, scored out of 110, and recorded in SPRS under your CAGE code with an annual affirmation by a senior official.
Level 2 is not paperwork about security. It is a scored, evidence backed statement, with False Claims Act exposure behind it, that your business runs the 110 requirements today. That is exactly why contractors who file a defensible score early keep their contracts and pick up the work of competitors who cannot.
One point that gets muddled, so it is worth stating plainly. Self assessment and self attestation at Level 1 and Level 2 are law today. DFARS 252.204-7012 is unaffected. The NIST SP 800-171 Rev 2 baseline is unaffected. Self assessment requirements appear in solicitations today, government led assessments continue, and False Claims Act exposure for a knowingly false affirmation is unchanged. What is genuinely under review is the mechanism by which Level 2 gets certified by a third party, not whether the underlying obligation exists. If your contracts carry CUI, the work behind the 110 requirements applies to you either way.
The 110 requirements, in 14 plain-English families
Every requirement comes from NIST SP 800-171 r2. Here is the whole map, what each family actually asks of your business:
Assessors do not grade the families, they grade the 320 assessment objectives beneath them (NIST SP 800-171A). One unmet objective fails its whole requirement, which is why working at the objective level from day one is the only honest way to build.
The score, the 88 rule, and the POA&M clock
Scoring is arithmetic, defined in 32 CFR 170.24. Start at 110. Every NOT MET requirement subtracts 1, 3, or 5 points by weight. Missing multifactor authentication or FIPS validated encryption carries special deductions, and no System Security Plan means the assessment cannot be completed at all (CA.L2-3.12.4).
You do not need a perfect 110 to file. At 88 or better, with every remaining gap eligible for a Plan of Action and Milestones, you can file with Conditional status, then close every POA&M item within 180 daysor the status expires. Six requirements can never ride a POA&M, including the SSP itself and the physical access trio, and those must be MET on assessment day.
The two tracks use the same 110 requirements and they are not alternatives. Level 2 (Self) is a self assessment recorded in SPRS, and it is the precursor; Level 2 (C3PAO) is certification by an accredited third party, recorded in CMMC eMASS, where a contract demands it. Build one honest package and it serves both. A status is valid three years, with annual affirmations by your senior official.
How to get CMMC Level 2 filed, step by step
- 1Confirm CMMC Level 2 applies to you
Check your contracts for DFARS 252.204-7012 and look for information marked CUI, export controlled, or Distribution D. If you find either, Level 2 applies. If your contracts only involve FCI, start with Level 1 instead.
- 2Map your CUI
Document every flow of controlled information: what it is, where it comes from, which systems store, process, or transmit it, and where it leaves. This map drives everything that follows.
- 3Draw the assessment boundary
Categorize every asset under 32 CFR 170.19: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out of Scope. Determine FedRAMP status for every cloud vendor that touches CUI per DFARS 252.204-7012.
- 4Adopt the policies and stand up the registers
Adopt the written policies the documentation objectives call for, and start the trackers the operational objectives call for, so the paperwork objectives are satisfied by documents you actually run on.
- 5Work the 110 requirements at the objective level
Resolve each requirement the way an assessor scores it: every NIST SP 800-171A objective MET or Not Applicable, with evidence behind every MET. Adopted written policies satisfy the documentation objectives.
- 6Write the System Security Plan and score honestly
The SSP is mandatory, no SSP means the assessment cannot be completed (CA.L2-3.12.4). Run the official 32 CFR 170.24 scoring: 110 minus 1, 3, or 5 points per gap.
- 7POA&M what is eligible, fix what is not
At 88 or better with only POA&M eligible gaps you can file with Conditional status. POA&M items close within 180 days. Only 1 point gaps are POA&M eligible (except FIPS encryption, SC.L2-3.13.11, at 3 points), so the six never POA&M requirements and every other 3 and 5 point item must be MET first.
- 8Prove readiness, then record the self assessment and affirm
Turn every readiness check green and sign your internal audit before anyone books a date. Then record the assessment in SPRS under your CAGE code and have your Affirming Official, a senior company official, affirm. The status is valid three years with annual affirmations.
- 9Hold it year round, and certify when a contract demands it
Keep evidence fresh, close POA&Ms on schedule, review policies annually, and re-affirm every year. When a solicitation requires certification, give your C3PAO a read only seat and hand them the same assessment package.
What CMMC Level 2 really costs in 2026
Consultant readiness engagements run $35,000 to $150,000 over six months to a year, and the method leaves with the consultant. A full time compliance hire runs about $78,420 a year (Bureau of Labor Statistics), and one person cannot hold 320 objectives in their head. C3PAO assessment fees, when a contract requires certification, come on top of either path.
Custodia's CMMC Level 2 plan is $35,000 a year, or $4,200 a month. It covers the living Policy Center, the guided evidence capture, the Audit Room, your assessor's read only seat, contract opportunity matching, and a Registered Practitioner year round: your team runs the build on the platform so the method stays yours, and your RP advises, reviews the package before anything is filed, and keeps watching your posture after it is.