110 Rev. 2 requirements
CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. The current CMMC rule scores Level 2 against those requirements; Revision 3 exists, but it is not the Level 2 CMMC baseline today.
If your solicitation or contract requires CMMC Level 2 (Self), your organization assesses the 110 NIST SP 800-171 Revision 2 security requirements, submits the required result in SPRS, and maintains the status with annual affirmation. Cyberneza helps define scope, evaluate implementation, remediate gaps, build the SSP and supporting evidence, and prepare the submission information. Your organization performs the self-assessment, submits the result, and makes the required affirmation.
The Department suspended CMMC Phase II requirements on July 13, 2026. Its current CMMC guidance says the program is paused in Phase 1 and may require Level 1 (Self) or Level 2 (Self). For Level 2 Self, the assessment is conducted by the Organization Seeking Assessment every three years, the results are entered in SPRS, and an affirmation is required after the assessment and annually thereafter.
CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. The current CMMC rule scores Level 2 against those requirements; Revision 3 exists, but it is not the Level 2 CMMC baseline today.
32 CFR 170.16 requires the organization to conduct the Level 2 Self assessment and submit its results to SPRS every three years to maintain Level 2 (Self) status.
An affirming official submits an affirmation after the assessment and annually thereafter. If the annual affirmation is not maintained, the assessment status lapses.
Under the CMMC scoring rule, a requirement is MET when all applicable assessment objectives are satisfied based on evidence. Draft or unofficial evidence does not qualify as final evidence.
Level 2 can reach Conditional status only under the rule's POA&M conditions. Eligible items must be closed through the required closeout assessment within 180 days. Requirements that are not POA&M-eligible must be satisfied for the applicable status.
Current DFARS procedures require contracting officers to check SPRS for a current CMMC status at the level required by the solicitation for the contractor information systems identified by CMMC UID.
Cyberneza provides readiness, implementation and documentation support. We do not make the government-facing representation for you and we do not issue CMMC certifications.
CMMC Level 2 scope is broader than only devices that directly hold CUI, but it is not automatically every computer in the company. The rule includes CUI Assets and relevant Security Protection Assets and defines treatment for Contractor Risk Managed Assets, Specialized Assets, external service providers and Out-of-Scope Assets. The architecture therefore matters before major licensing or migration decisions.
Where the business workflow allows it, a secure CUI enclave can confine CUI to a smaller set of users, systems and workflows instead of allowing it to spread through ordinary commercial email and file sharing. That can reduce the assessment footprint and may reduce implementation and operating cost. It does not automatically make every surrounding system out of scope; the actual boundary still has to satisfy 32 CFR 170.19.
PreVeil is one enclave option. PreVeil states that its service is FedRAMP Moderate Equivalent and uses AES-256-GCM cryptography in a FIPS 140-3 validated module. It is designed to run alongside existing Microsoft 365 or Google Workspace workflows, allowing general business work to remain on the existing platform while CUI is handled in the protected enclave. Cyberneza is a PreVeil referral partner and can scope, deploy and document that architecture.
Review the solicitation, contract and prime flow-down and identify the required CMMC level and assessment type.
Trace where CUI enters, is stored, is processed, is transmitted and leaves the environment before broad technology purchases.
Remediate gaps, build the SSP from the operating environment, and collect final evidence as the requirements are performed.
Conduct the Level 2 Self assessment, submit the result in SPRS, complete the required affirmation and maintain the assessed environment between assessment cycles.
Send us the applicable contract clauses, the systems and services that handle CUI, and the security controls already in place. Cyberneza can define the preliminary boundary, assess the 110 requirements, identify remediation work, and organize the SSP and evidence required for your self-assessment.
This page is written against current Department CMMC implementation guidance, 32 CFR Part 170, DFARS Subpart 204.75 and NIST SP 800-171 Revision 2. Product-specific statements are attributed to the product publisher in the page text; contractual and regulatory requirements are grounded in the government sources below.