Contact us

CMMC Level 2 and NIST SP 800-171: Protecting CUI the Right Way

by NOXMON Risk Team, Cybersecurity & Risk Management Experts

For defense contractors that handle Controlled Unclassified Information (CUI), CMMC Level 2 is the threshold that matters. Where Level 1 covers 17 basic practices mapped to the 15 safeguarding requirements in FAR 52.204-21 and applies to Federal Contract Information, Level 2 aligns to all 110 security requirements of NIST SP 800-171 and, for most contracts, requires a third-party assessment by a C3PAO every three years. The jump in rigor is substantial—and so is the business at stake.

NOXMON helps contractors clear that bar with the RISKMON platform.

Understanding the Scale and Structure of Level 2

The 110 security requirements in NIST SP 800-171 are organized across 14 domains, each addressing a distinct dimension of CUI protection:

DomainFocus Area
Access ControlWho can reach CUI and under what conditions
Awareness and TrainingWhether personnel understand their security obligations
Audit and AccountabilityWhether security events are captured and reviewable
Configuration ManagementWhether systems are built and changed securely
Identification and AuthenticationWhether identity claims can be verified
Incident ResponseWhether security incidents can be detected and handled
MaintenanceWhether system upkeep is controlled and logged
Media ProtectionWhether CUI on physical and digital media is protected
Personnel SecurityWhether people with access are appropriately vetted
Physical ProtectionWhether physical access to CUI systems is controlled
Risk AssessmentWhether threats and vulnerabilities are regularly evaluated
Security AssessmentWhether the security program itself is periodically reviewed
System and Communications ProtectionWhether data in transit and at boundaries is protected
System and Information IntegrityWhether malicious activity and software flaws are detected

Across these 14 domains, every requirement is weighted in the SPRS scoring model. A perfect implementation earns a score of 110. Failing to meet a single requirement deducts points based on its assigned weight—some requirements carry a five-point deduction, making them disproportionately important to address early. The assessor scores against that model, and a score that doesn't clear the threshold blocks certification.

What Separates Level 1 from Level 2

The distinction between Level 1 and Level 2 is more than a count of requirements. It reflects a fundamental difference in what's being protected, who assesses compliance, and what the program has to sustain over time.

Level 1 applies to Federal Contract Information—data related to contracts that is not intended for public release. The 17 practices that cover it map directly to the 15 basic safeguarding requirements in FAR 52.204-21. Compliance is verified by annual self-assessment and a senior official's affirmation submitted in SPRS. There is no third-party assessor, and the requirements address foundational hygiene: limiting access, establishing incident response, doing basic scanning.

Level 2 applies to CUI—information the government creates or possesses that requires protection under law, regulation, or government policy. The 110 NIST SP 800-171 requirements that cover it address a far broader and more technically demanding control set, and for most CUI contracts, an authorized C3PAO must independently verify the implementation on a three-year cycle. The annual affirmation by a senior official remains—but now it runs alongside a formal third-party certification rather than substituting for it.

Risk-Prioritized Implementation

The scale of 110 requirements makes implementation sequencing a strategic decision, not just a project management one. Attempting to implement all 110 requirements in parallel—without regard to their relative importance to risk or their SPRS weight—is the most common way CMMC programs slow to a crawl or stall entirely.

NOXMON uses RISKMON to map your CUI data flows, model the threats relevant to your environment, and rank the gaps by their combined contribution to residual risk and SPRS score impact. That prioritization produces a sequenced roadmap: the controls that remove the most exposure and most improve your score come first, which keeps momentum visible and measurable throughout the program.

This approach also tends to surface implementation dependencies that aren't obvious from a flat list. Multi-factor authentication, for instance, intersects with access control, identification and authentication, and remote access requirements simultaneously—implementing it early closes multiple gaps with one effort.

Top tip

Not all 110 requirements carry equal weight in the SPRS scoring model. RISKMON aligns risk-based prioritization with SPRS impact, so your remediation roadmap improves both your security posture and your score at the same time, rather than forcing you to choose between them.

Scoping CUI With Precision

A Level 2 assessment begins and ends with scope. Before any control is examined, the assessor validates the CUI boundary: which systems process, store, or transmit CUI; which provide security functions to those systems; and which have been correctly classified as out of scope. Over-scope forces you to secure and document systems that have no business touching CUI. Under-scope fails the assessment when the examiner finds CUI flowing through systems you didn't include.

NOXMON uses RISKMON to trace CUI from ingestion through processing to transmission and disposal. That tracing exercise typically reveals more in-scope systems than organizations expect—shared drives, email platforms, collaboration tools, and remote access paths all serve as potential CUI conduits. Identifying and either containing or excluding them before assessment is the work that makes the scope manageable.

Segmentation is the primary lever for scope reduction at Level 2, just as it is in other frameworks. Isolating the environment where CUI lives—through network controls, identity separation, and data-handling procedures—moves the rest of your infrastructure to lighter asset categories or out of scope entirely, reducing both the assessment burden and the ongoing operational cost of staying compliant.

Building Evidence That Survives Examination

The C3PAO assessment uses three methods—examine, interview, and test—for every control. Evidence must survive all three. A policy document that describes a control accurately but isn't reflected in system configurations, or a configuration that exists but isn't documented in the SSP, produces a finding under one of the methods even when the other two look clean.

NOXMON builds and maintains the evidence architecture inside RISKMON: SSP entries that describe actual system behavior rather than generic templates, supporting artifacts tied to specific controls, and a mapping layer that links each requirement to its implementation evidence. When the assessor asks "show me," the answer is immediate and complete.

NIST SP 800-171 requirements assessed at Level 2
110
Domains covering the full CUI protection surface
14
C3PAO assessment cycle with annual affirmation
3yr

How NOXMON Helps

CMMC Level 2 is a demanding standard, but every requirement in NIST SP 800-171 is implementable—the difficulty is in doing it with the right sequence, the right evidence, and the right boundary definition. Organizations that try to manage this as a spreadsheet exercise, without a platform to track control state and a methodology to prioritize the gaps, tend to arrive at assessment with a lot of work done and still miss certification.

NOXMON's Cybersecurity Risk Assessment and Technology Risk Management services provide the structured program management that turns 110 requirements into an achievable roadmap. RISKMON tracks every control, maintains the SSP, and accumulates evidence continuously—so the program stays current rather than requiring a rebuild at assessment time. Our Virtual CISO service provides the ongoing compliance ownership that keeps the program running between the three-year cycles.

Related Reading

The Bottom Line

CMMC Level 2 is the standard that defends CUI and determines which defense contractors can bid on the contracts that matter most. The technical requirements are demanding, the assessment is rigorous, and the stakes are real. NOXMON combines deep defense-sector experience with the RISKMON platform to protect CUI, build a score that reflects genuine security, and walk organizations into a C3PAO assessment ready to certify.

Prepare for CMMC Level 2 with NOXMON and RISKMON.

More articles

The Third Parties in Your Code: Software Supply Chain Risk and the SBOM

Every application you build or buy is assembled from third-party components you never assessed. A practical look at software supply chain risk, SBOMs, and governing the dependencies inside your software.

Read more

Deepfakes and AI-Powered Social Engineering: Defending Against Attacks That Sound Like Your CFO

Generative AI has made voice cloning, deepfake video, and flawless phishing cheap and scalable. Why awareness training alone is no longer enough, and what process-level defenses actually stop these attacks.

Read more

Tell us about your project

Our offices

  • Houghton
    Houghton, MI 49931
    (212) 913-9184
    info@noxmon.com
  • New York City
    New York, NY 10011
    (212) 913-9184
    info@noxmon.com