CMMC 2.0 Level 2 for Defense Manufacturers: What Level 2 Actually Requires

Published May 11, 2026

If your manufacturing firm supplies the Department of Defense and you handle Controlled Unclassified Information (CUI, the category of sensitive but unclassified data that the federal government needs to protect), you are on the path to CMMC 2.0 Level 2 certification whether you have started preparing or not. The program began phased rollout in late 2025 after the final rule went into effect, and contractual flow-down to subcontractors is now arriving on real contracts.

For small and mid-size manufacturers, the CMMC conversation often starts with a prime contractor asking, “Where are you on CMMC?” The honest answer from many suppliers is some version of “we are figuring it out.” That is not a sustainable answer anymore.

This post walks through what Level 2 actually requires so you can evaluate where your firm stands and what gaps you need to close before assessment.

The Problem: CMMC Is Bigger Than Most People Expect

CMMC (Cybersecurity Maturity Model Certification) 2.0 at Level 2 requires implementation of the 110 security controls in NIST Special Publication 800-171 Revision 2, plus 10 objective assessment processes. For companies handling Critical National Security Information at Level 3, requirements include additional controls from NIST SP 800-172.

For most defense suppliers that do not handle the highest-sensitivity data, Level 2 is the bar. It is a significant bar. The 110 controls span every area of information security:

  • Access control
  • Awareness and training
  • Audit and accountability
  • Configuration management
  • Identification and authentication
  • Incident response
  • Maintenance
  • Media protection
  • Personnel security
  • Physical protection
  • Risk assessment
  • Security assessment
  • System and communications protection
  • System and information integrity

Each control has specific implementation requirements, and each must be documented in a System Security Plan (SSP) and, where gaps exist, a Plan of Action and Milestones (POA&M, a tracked plan for closing specific control gaps over time). For Level 2 with CUI, a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) verifies implementation.

Why It Matters to You Specifically

For a manufacturing firm with defense exposure, CMMC readiness affects four specific areas of the business:

Contract Eligibility

Primes are flowing down CMMC requirements to subcontractors. Suppliers who cannot demonstrate progress risk losing their position on existing contracts at renewal and being ineligible for new ones. This is happening now, not at some future date.

Assessment Timing

Level 2 third-party assessments take months to schedule and weeks to execute. The pipeline of available C3PAO firms is limited relative to the number of defense suppliers needing assessment. A firm that starts preparation 12 months before a required assessment is ahead of schedule. A firm that starts 3 months before is behind schedule.

Cost of Remediation

Bringing a typical mid-size manufacturer into full NIST SP 800-171 compliance generally costs somewhere between several tens of thousands and several hundred thousand dollars, depending on the starting point. The cost scales with how many gaps exist and how much of the work is done by internal staff versus external providers. Budget planning at least a year ahead of assessment is prudent.

Business Continuity

CMMC assessment failures have real contract implications. A manufacturer that attests to compliance and then fails an assessment faces both commercial and potential False Claims Act exposure. This is not a risk to take casually.

What Level 2 Actually Looks Like in Practice

The 110 controls cluster into several thematic areas. What does each look like in a small manufacturing environment?

Identity, Authentication, and Access Control

Every user has a unique account. Multi-factor authentication (MFA) is required for all accounts that access CUI, including remote access, privileged accounts, and local administrative access. Sessions are locked after periods of inactivity. Account lifecycles (provisioning and deprovisioning) are managed. Administrative privileges are restricted to people whose job requires them.

Configuration Management

Systems have documented baseline configurations. Changes to those baselines go through a change management process. Unauthorized software is prevented from running. Removable media is restricted. This is often where smaller manufacturers struggle, because “we just install what we need” is not acceptable documentation.

System and Information Integrity

Antivirus or endpoint protection is deployed on all systems handling CUI. Critical security patches are applied in defined timeframes. Monitoring of security events is in place. Suspicious activity triggers response.

Media Protection

CUI on portable media (thumb drives, external hard drives, laptops) is encrypted. Media is tracked. Media is disposed of securely when no longer needed. Printed CUI is handled with physical controls.

Audit and Accountability

Security-relevant events are logged. Logs are protected from tampering. Logs are reviewed, with specific attention to anomalies. For most Level 2 environments, this means implementing a SIEM (Security Information and Event Management) tool or using a managed security service.

Incident Response

An incident response plan exists. Personnel are trained. Incidents involving CUI are reported to the DoD through the DIBNet reporting portal within 72 hours. Incident response is tested.

Awareness and Training

Users receive role-appropriate security training. Training is repeated annually. Training records are maintained. Phishing simulation or similar ongoing awareness activity is common.

Physical Protection

Facility access is controlled. Visitors are escorted in areas containing CUI. Physical access logs are maintained. Workstations displaying CUI are positioned to prevent unauthorized viewing.

Risk Assessment

Regular vulnerability scanning is performed. Risks to CUI are assessed and documented. Risk responses (mitigate, accept, transfer) are tracked.

Documentation

Every control has to be documented in the System Security Plan. For controls that are not fully implemented, a Plan of Action and Milestones describes the remediation plan. Policies and procedures supporting the controls exist in writing.

Where Smaller Manufacturers Typically Get Stuck

Several recurring patterns slow down preparation for smaller defense suppliers:

CUI Scope Is Too Broad

Firms that do not clearly identify where CUI lives in their environment end up scoping the entire IT estate as CUI-handling, which makes compliance much harder and more expensive. A better approach is to consolidate CUI into a defined enclave (a specific set of systems, often cloud-based, that are in CMMC scope), leaving the rest of the environment out of scope.

Microsoft GCC High, AWS GovCloud, and specialized CMMC-enabled cloud platforms are common enclave choices. Using them correctly narrows the compliance surface dramatically.

Documentation Is Underestimated

“Doing” the controls is half the work. Documenting them is the other half. System Security Plans for Level 2 typically run 100 to 200+ pages. Firms that skip documentation and focus only on implementation fail assessments.

Ongoing Operations Are Not Planned

CMMC is not a one-time project. Continuous monitoring, regular vulnerability scanning, log review, patch management, and annual training are all ongoing operational obligations. Firms that pass assessment without a plan for sustaining the controls fall out of compliance quickly.

Cost Surprise

CMMC Level 2 readiness involves tooling (endpoint protection, SIEM, MDM, MFA), potentially cloud migration to CMMC-enabled platforms, security services, policy work, and assessment fees. The total cost surprises firms that only budget for “a consultant.”

Practical Takeaways

  1. Identify where CUI lives in your environment. Emails, file shares, engineering drawings, quality documents, and customer portals are common locations. Scope the CMMC boundary accordingly.
  2. Consider an enclave approach. Moving CUI into a specifically-scoped environment (often a GCC High tenant) reduces the overall compliance burden significantly.
  3. Inventory the 110 controls against your current state. A gap analysis against NIST SP 800-171 is the starting point for any CMMC program.
  4. Budget realistically. Plan for both one-time costs (tooling, migration, assessment) and ongoing costs (managed services, annual training, continuous monitoring).
  5. Start early. The assessment bottleneck is real. Firms that start 12 to 18 months before their required assessment date have the best outcomes.

CMMC is not going away. Defense suppliers who engage with it proactively come out with improved security, preserved revenue, and a defensible position. Suppliers who treat it as a problem to solve at the last minute face difficult tradeoffs under time pressure.

If you want a conversation about assessing your firm’s CMMC readiness or planning a path to Level 2, the HVR Cloud team supports defense manufacturers through this process regularly. Get in touch and we can walk through your specific environment.