Share This

NeoSystems Corporation

CMMC 2.0 Level 2: Advanced

Level 2, also known as the Advanced level, is required of companies that handle Controlled Unclassified Information (CUI) and establishes a higher level of cybersecurity. Level 2 establishes a minimum-security threshold for organizations that store, process, or transmit CUIs.

Get Level 2 Compliant

Level 2 consists of a total of 110 cybersecurity controls that incorporate the controls in Level 1. These controls, drawn from National Institute of Standards and Technology (NIST) Special Publication 800-171, are organized into 14 domains:  

  • Access Control (AC) – Management of who has access to systems and sensitive information.
  • Asset Management (AM) – Inventory and protection of information system assets.
  • Audit and Accountability (AU) – Ensuring the ability to audit and track events and actions in the system.
  • Awareness and Training (AT) – Providing cybersecurity training to ensure users are aware of their security responsibilities.
  • Configuration Management (CM) – Maintaining security settings and ensuring only approved changes are made.
  • Identification and Authentication (IA) – Controlling access to systems by verifying user identities.
  • Incident Response (IR) – Planning and managing how to respond to security incidents.
  • Maintenance (MA) – Safeguarding maintenance activities to ensure system integrity.
  • Media Protection (MP) – Protection of media (hard drives, USBs, etc.) containing sensitive information.
  • Personnel Security (PS) – Ensuring personnel handling sensitive data are properly vetted and trained.
  • Physical Protection (PE) – Protecting physical access to systems and sensitive data.
  • Recovery (RE) – Ensuring data is backed up and can be restored in the event of a breach or failure.
  • Risk Management (RM) – Identifying, assessing, and managing risks to the organization.
  • Security Assessment (CA) – Continuous monitoring and evaluating security processes to ensure compliance and effectiveness.

Unlike Level 1, Level 2 requires a triennial formal assessment by an independent CMMC third-party assessment organization (C3PAO) plus annual self-assessments in years 2 and 3. This assessment verifies conformance with the 110 controls and is required to obtain and maintain certification. Contractors are required to submit the results through the Department of Defense’s Supplier Performance Risk System (SPRS). This submission must include an attestation from a senior company official that affirms the accuracy and completeness of the assessment.

Get Level 2 Compliant


Want to learn more? Understanding CMMC starts with comprehending the terminology and phrases inherent in any conversation related to it. Request our free eBook – The Alphabet Soup Of CMMC – to learn the most common terms and acronyms related to CMMC, and gain insights into strategies for becoming certification ready.

Request Your Copy

Software & Industry Partners