CMMC Level 2 Certification: Requirements, Process & Timeline

CMMC Level 2 certification specialist reviewing security controls in a security operations center

7 min read  ·  CMMC Compliance

Most DoD contractors will now need to achieve the new baseline of CMMC Level 2 certification to process Controlled Unclassified Information (CUI) in order to continue to work on DoD contracts.

With the CMMC Program rule in place, most DoD’s Defense Industrial Base will no longer be able to use a self-attestation. This Level 2 Guide provides details on the requirements of the Level 2 and how the assessment process was carried out and how long it usually takes to become certified.

The Baseline

What does CMMC Level 2 Certification mean?

There are three levels of Cybersecurity Maturity Model Certification (CMMC) framework. Basic Safeguarding of Federal Contract Information is covered in Level 1 (Foundational). Level 2 (Advanced) is based directly on NIST SP 800-171 and is applicable to all contractors working with CUI, regardless of whether they are storing, processing or transmitting CUI. Level 3 (Expert) introduces essentials from NIST SP 800-172 for the highest priority programs.

CMMC Level 2 certification helps you ensure that your organization has implemented all security requirements in NIST SP 800-171 Revision 2. That’s the largest change the program mandates: for most contracts that involve CUI, that verification is not a self-assessment by the contracting party, but rather, an independent, third-party assessment.

The Requirements

For CMMC Level 2 (L2), 110 Controls are required

The 110 CMMC Level 2 requirements are grouped under 14 control families which cover the life cycle of protecting sensitive data:

Network Traffic Managementmanaging the flow of network traffic so it isn’t a burden to the system’s core components and functions.
Identification & Authenticationmultifactor authentication and unique credentials.
Audit & AccountabilityLog, Track & Review the activities of the system.
Secure baselines and change controlConfiguration Management
Incident Response (IR)Discover, report and recover from incidents
System & Communications Protectionencryption, network boundary protection

Each Level 2 program is based on a pair of documents. Your system security plan (SSP) from your CMMC assesses how each control is applied throughout your environment. Gaps will be noted in your Plan of Action and Milestones (POA&M) and per the CMMC, only a few less weighted controls will remain on the POA&M at the time of assessment with 180 days to address the noted controls.

Checklist and dashboard representing the 110 NIST 800-171 controls for CMMC Level 2 certification

The 110 NIST SP 800-171 controls span 14 families

The Process

The steps of the CMMC Level 2 Certification Process

The certification process is a clearly-defined process. If you build your program based on these steps, the ultimate result will not be a scramble:

Set boundariesdefine where CUI is and where systems are on the assessment boundary.
Perform a gap analysisAssess where you are today (realistically) for each of the 110 controls and rate it in SPRS.
Remediateinstall missing controls, implement technical controls, and, of course, document the policy.
Documentcomplete your SSP and POA&M with evidence of each requirement.
Schedule your CMMC Assessmentuse a Certified Third-Party Assessment Organization to schedule your CMMC assessment.
Certify and maintainafter you pass, it will be certified for 3 years, and you will have to affirm continued compliance annually.

The most successful method for achieving a clean result is a good readiness review and gap analysis. The official control set is published in NIST SP 800-171 and information about the program is maintained on the DoD CMMC site.

C3PAO assessor reviewing evidence with a defense contractor during a CMMC Level 2 assessment

A C3PAO conducts the official CMMC Level 2 assessment

The Timeline

How much time does it take to get CMMC Level 2 Certification?

The timeline will vary according to the starting point, but most contractors could expect to take 6 to 12 months from start to pass. It may be faster for organisations that have already got an IT practice in place, and slower for those without any existing documentation or controls to implement; plan accordingly. Preparing early (preparing for CMMC compliance) is important as the two largest time consuming activities are remediation and evidence collection.

It is not a one-time process to get certified. As you’re required to maintain your controls and monitor continuously, make sure it is part of your plan from day one and that you submit the annual affirmation. Contractors that believe certification is the ultimate goal are in a rush to re-certify; contractors that have monitoring and documentation as a habit can breeze through re-certification with much less work and cost.

Team planning a CMMC Level 2 certification timeline on a project board

Mapping a realistic CMMC Level 2 certification timeline

Answers

Frequently Asked Questions

What is the meaning of CMMC Level 2?

It is an independent review to ensure that a contractor has the 110 controls specified in NIST SP 800-171 to protect CUI on DoD contracts.

Do all contractors need to have a third party assessment?

The majority of contracts that cover CUI mandate a C3PAO assessment every three years. Self-assessment may be offered for select programs, as outlined in each contract.

How do the two CMMC levels differ?

Level 1 is the basic level of protection for Federal Contract Information (FCI) and it requires 15 requirements and a self-assessment annually. Level 2 is meant for CUI, and includes all 110 of the NIST 800-171 controls and generally requires third party certification.

How much does it cost to get CMMC Level 2 certified?

The costs vary by the size of the environment and the current maturity and range from the readiness assessment costs, remediation costs, C3PAO assessment fee and maintenance costs.

Get CMMC Level 2 Certified with Confidence

From readiness review to your C3PAO assessment, Solvere One guides DoD contractors through every NIST SP 800-171 control on the path to CMMC Level 2 certification.

Solvere One – Compliance Services

Contact Info

Mon - Fri : 8:00am - 5:00pm
571-293-6267
Contact Us

Locations

Virginia Office
22365 Broderick Dr, Suite 100 Dulles, VA 20166

DC Office
601 Pennsylvania Ave, NW, South Building, Suite 900, Washington, DC 20004