CMMC Level 2 and NIST SP 800-171: Protecting CUI the Right Way
by NOXMON Risk Team, Cybersecurity & Risk Management Experts
For defense contractors that handle Controlled Unclassified Information (CUI), CMMC Level 2 is the threshold that matters. Where Level 1 covers 17 basic practices mapped to the 15 safeguarding requirements in FAR 52.204-21 and applies to Federal Contract Information, Level 2 aligns to all 110 security requirements of NIST SP 800-171 and, for most contracts, requires a third-party assessment by a C3PAO every three years. The jump in rigor is substantial—and so is the business at stake.
NOXMON helps contractors clear that bar with the RISKMON platform.
Understanding the Scale and Structure of Level 2
The 110 security requirements in NIST SP 800-171 are organized across 14 domains, each addressing a distinct dimension of CUI protection:
| Domain | Focus Area |
|---|---|
| Access Control | Who can reach CUI and under what conditions |
| Awareness and Training | Whether personnel understand their security obligations |
| Audit and Accountability | Whether security events are captured and reviewable |
| Configuration Management | Whether systems are built and changed securely |
| Identification and Authentication | Whether identity claims can be verified |
| Incident Response | Whether security incidents can be detected and handled |
| Maintenance | Whether system upkeep is controlled and logged |
| Media Protection | Whether CUI on physical and digital media is protected |
| Personnel Security | Whether people with access are appropriately vetted |
| Physical Protection | Whether physical access to CUI systems is controlled |
| Risk Assessment | Whether threats and vulnerabilities are regularly evaluated |
| Security Assessment | Whether the security program itself is periodically reviewed |
| System and Communications Protection | Whether data in transit and at boundaries is protected |
| System and Information Integrity | Whether malicious activity and software flaws are detected |
Across these 14 domains, every requirement is weighted in the SPRS scoring model. A perfect implementation earns a score of 110. Failing to meet a single requirement deducts points based on its assigned weight—some requirements carry a five-point deduction, making them disproportionately important to address early. The assessor scores against that model, and a score that doesn't clear the threshold blocks certification.
What Separates Level 1 from Level 2
The distinction between Level 1 and Level 2 is more than a count of requirements. It reflects a fundamental difference in what's being protected, who assesses compliance, and what the program has to sustain over time.
Level 1 applies to Federal Contract Information—data related to contracts that is not intended for public release. The 17 practices that cover it map directly to the 15 basic safeguarding requirements in FAR 52.204-21. Compliance is verified by annual self-assessment and a senior official's affirmation submitted in SPRS. There is no third-party assessor, and the requirements address foundational hygiene: limiting access, establishing incident response, doing basic scanning.
Level 2 applies to CUI—information the government creates or possesses that requires protection under law, regulation, or government policy. The 110 NIST SP 800-171 requirements that cover it address a far broader and more technically demanding control set, and for most CUI contracts, an authorized C3PAO must independently verify the implementation on a three-year cycle. The annual affirmation by a senior official remains—but now it runs alongside a formal third-party certification rather than substituting for it.
Risk-Prioritized Implementation
The scale of 110 requirements makes implementation sequencing a strategic decision, not just a project management one. Attempting to implement all 110 requirements in parallel—without regard to their relative importance to risk or their SPRS weight—is the most common way CMMC programs slow to a crawl or stall entirely.
NOXMON uses RISKMON to map your CUI data flows, model the threats relevant to your environment, and rank the gaps by their combined contribution to residual risk and SPRS score impact. That prioritization produces a sequenced roadmap: the controls that remove the most exposure and most improve your score come first, which keeps momentum visible and measurable throughout the program.
This approach also tends to surface implementation dependencies that aren't obvious from a flat list. Multi-factor authentication, for instance, intersects with access control, identification and authentication, and remote access requirements simultaneously—implementing it early closes multiple gaps with one effort.
Top tip
Not all 110 requirements carry equal weight in the SPRS scoring model. RISKMON aligns risk-based prioritization with SPRS impact, so your remediation roadmap improves both your security posture and your score at the same time, rather than forcing you to choose between them.
Scoping CUI With Precision
A Level 2 assessment begins and ends with scope. Before any control is examined, the assessor validates the CUI boundary: which systems process, store, or transmit CUI; which provide security functions to those systems; and which have been correctly classified as out of scope. Over-scope forces you to secure and document systems that have no business touching CUI. Under-scope fails the assessment when the examiner finds CUI flowing through systems you didn't include.
NOXMON uses RISKMON to trace CUI from ingestion through processing to transmission and disposal. That tracing exercise typically reveals more in-scope systems than organizations expect—shared drives, email platforms, collaboration tools, and remote access paths all serve as potential CUI conduits. Identifying and either containing or excluding them before assessment is the work that makes the scope manageable.
Segmentation is the primary lever for scope reduction at Level 2, just as it is in other frameworks. Isolating the environment where CUI lives—through network controls, identity separation, and data-handling procedures—moves the rest of your infrastructure to lighter asset categories or out of scope entirely, reducing both the assessment burden and the ongoing operational cost of staying compliant.
Building Evidence That Survives Examination
The C3PAO assessment uses three methods—examine, interview, and test—for every control. Evidence must survive all three. A policy document that describes a control accurately but isn't reflected in system configurations, or a configuration that exists but isn't documented in the SSP, produces a finding under one of the methods even when the other two look clean.
NOXMON builds and maintains the evidence architecture inside RISKMON: SSP entries that describe actual system behavior rather than generic templates, supporting artifacts tied to specific controls, and a mapping layer that links each requirement to its implementation evidence. When the assessor asks "show me," the answer is immediate and complete.
- NIST SP 800-171 requirements assessed at Level 2
- 110
- Domains covering the full CUI protection surface
- 14
- C3PAO assessment cycle with annual affirmation
- 3yr
How NOXMON Helps
CMMC Level 2 is a demanding standard, but every requirement in NIST SP 800-171 is implementable—the difficulty is in doing it with the right sequence, the right evidence, and the right boundary definition. Organizations that try to manage this as a spreadsheet exercise, without a platform to track control state and a methodology to prioritize the gaps, tend to arrive at assessment with a lot of work done and still miss certification.
NOXMON's Cybersecurity Risk Assessment and Technology Risk Management services provide the structured program management that turns 110 requirements into an achievable roadmap. RISKMON tracks every control, maintains the SSP, and accumulates evidence continuously—so the program stays current rather than requiring a rebuild at assessment time. Our Virtual CISO service provides the ongoing compliance ownership that keeps the program running between the three-year cycles.
Related Reading
- Getting CMMC Scoping Right: CUI Asset Categorization That Holds Up — The assessment begins with scope validation. This guide covers how to categorize every asset accurately and build a CUI boundary the assessor will accept.
- Walking Into a C3PAO Assessment Ready: The NOXMON CMMC Playbook — Once your Level 2 program is built, this is what the third-party assessment process looks like—and how to walk in ready for all three assessment methods.
- CMMC Enclave Strategy: Defining and Defending Your CUI Boundary — Building a dedicated CUI enclave is the most effective way to reduce Level 2 scope and keep the compliance footprint manageable.
The Bottom Line
CMMC Level 2 is the standard that defends CUI and determines which defense contractors can bid on the contracts that matter most. The technical requirements are demanding, the assessment is rigorous, and the stakes are real. NOXMON combines deep defense-sector experience with the RISKMON platform to protect CUI, build a score that reflects genuine security, and walk organizations into a C3PAO assessment ready to certify.
Prepare for CMMC Level 2 with NOXMON and RISKMON.