CMMC Level 2 Self
For organizations whose contract requires the active Phase 1 Level 2 Self path: 110 requirements, scope, evidence, SPRS, POA&M rules, and annual affirmation.
Cyberneza helps defense contractors determine the applicable CMMC requirement, define the CUI boundary, implement NIST SP 800-171 Revision 2, build the SSP and supporting evidence, prepare SPRS submissions, and minimize unnecessary scope before major platform decisions are made.
Cyberneza translates the applicable requirements into security architecture, control designs, remediation plans, implementation procedures, configuration guidance, and validation criteria. Your technical team executes approved production changes through its established change-management process.
The Department suspended the Phase II rollout of mandatory Level 2 C3PAO requirements on July 13, 2026. Current Department guidance says the program is paused in Phase 1, where procurements may require Level 1 (Self) or Level 2 (Self). NIST SP 800-171 Revision 2 obligations under applicable DFARS clauses remain in force.
Level 1 Self: annual self-assessment and annual affirmation against the 15 FAR 52.204-21 safeguarding requirements. No POA&M.
Level 2 Self: self-assessment every three years against the 110 NIST SP 800-171 Revision 2 security requirements, with annual affirmation and limited POA&M use under the CMMC rule.
For organizations whose contract requires the active Phase 1 Level 2 Self path: 110 requirements, scope, evidence, SPRS, POA&M rules, and annual affirmation.
Understand the 110 NIST SP 800-171 Rev. 2 requirements and how scope, implementation, evidence and recurring practices fit together.
Identify the cost drivers before buying a government-oriented platform or licensing the entire company. Scope and architecture can materially affect implementation and operating costs.
A practical approach for small defense contractors that need experienced CMMC support without maintaining a full internal compliance team.
Determine what the procurement documents require before selecting the target CMMC level or assessment type.
Trace information flows and define a defensible boundary using the CMMC asset categories and applicable DFARS obligations.
Evaluate the environment against the 110 Rev. 2 security requirements and remediate technical, administrative and operational gaps.
Build documentation that matches the operating environment and evidence that demonstrates implemented and recurring security requirements.
Calculate a supportable NIST SP 800-171 DoD Basic Assessment score where applicable and prepare the information your organization is responsible for submitting.
Establish and maintain logging, monitoring, endpoint security, identity protection, incident response and awareness practices that continue after the readiness project.
CMMC Level 2 scoping includes CUI Assets and relevant Security Protection Assets and has defined treatment for Contractor Risk Managed Assets, Specialized Assets, external service providers and Out-of-Scope Assets. The boundary requires analysis; it is neither automatically the entire company nor only the systems that directly store CUI.
Where business workflows permit, a secure CUI enclave can confine protected email and file sharing to a smaller set of users and systems. That can reduce unnecessary implementation and operating cost because fewer assets may require CMMC-specific treatment.
PreVeil is one enclave option. PreVeil publishes FedRAMP Moderate Equivalency and FIPS 140-3-validated AES-256-GCM cryptography information and is designed to run alongside Microsoft 365 or Google Workspace. Cyberneza is a PreVeil referral partner and can scope, deploy and document the enclave.
No enclave product makes an organization CMMC compliant by itself. The actual scope still has to satisfy 32 CFR 170.19, and the remaining NIST SP 800-171 requirements still have to be implemented and evidenced.
Level 1 may be the relevant CMMC path. It is an annual self-assessment against the 15 FAR 52.204-21 safeguarding requirements with annual affirmation and no POA&M.
Level 2 applies to CUI protection. Under current Phase 1 implementation, Level 2 Self may be required. Confirm the assessment type in your procurement documents rather than assuming C3PAO certification.
Cyberneza's founder is a Cyber AB CMMC Registered Practitioner with decades of DoD, federal contracting and enterprise cybersecurity experience. Cyberneza provides readiness, implementation and advisory support. We do not perform CMMC certification assessments or issue certifications. When a C3PAO assessment is appropriate, the C3PAO remains independent.
Send us the relevant contract or flow-down clauses, where FCI or CUI is received, stored and transmitted, and the systems you use today. Cyberneza can identify the applicable CMMC level and assessment type, define the preliminary boundary, and outline the implementation, documentation and evidence work required.