Skip to content

CMMC · Cybersecurity & Cloud

CMMC Level 2 and NIST 800-171 Rev 3: CUI, SPRS, and what assessors sample

How defense contractors prepare for CMMC Level 2 — CUI scoping, SPRS scores, and the gap between a self-attestation spreadsheet and a C3PAO assessment.

6 min read

CMMC Level 2 is where defense contractors must show that protection of Controlled Unclassified Information is real, repeatable, and assessable. The work begins with CUI flows, not with a template SSP, because the assessment follows where CUI is created, received, stored, transmitted, and discussed.

Some Level 2 programs are eligible for self-assessment, while others require a C3PAO assessment. That distinction is not a convenience choice. It depends on contract requirements and DoD expectations, and self-attesting when third-party assessment is required can create procurement and credibility risk.

The checklist helps execute the work, but the guide frames the hard choices: enclave versus enterprise scope, how email and collaboration tools handle CUI, what cloud inheritance actually covers, and whether POA&Ms are realistic rather than permanent placeholders. For CMMC, evidence should be built around CUI handling rather than generic security maturity. Ask where CUI first enters, who recognizes it, how it is marked or classified, where it can be stored, which users can export it, and what collaboration paths are prohibited. Then test the uncomfortable workflows: email from primes, engineering drawings in chat, supplier sharing, help desk tickets, mobile access, and archived projects. A strong guide also explains inheritance limits in plain terms so executives do not assume a cloud authorization solves tenant operations. The organization needs a defensible story for every CUI path, every unmanaged exception, and every claim made in SPRS or to a prime contractor. A useful way to read the rest of this guide is to separate evidence from judgment. Evidence shows that an activity happened: a review, record, test, approval, training, scan, exercise, assessment, or decision. Judgment explains why the activity was scoped that way, why the risk treatment is proportionate, why an exception is acceptable, and what would cause the decision to change. The paired checklist should collect evidence and owners, while the guide should help teams avoid false certainty. For each topic, ask what a knowledgeable reviewer would challenge after seeing the first answer. They may ask whether the scope matches production, whether suppliers are included, whether recurring work is current, whether leadership approved trade-offs, and whether public or customer-facing claims match operations. That second layer is where preparation becomes credible. It also keeps teams from overclaiming, because a documented limitation with a plan is usually stronger than a broad statement no one can support.

What CMMC Level 2 actually is

CMMC Level 2 aligns with NIST SP 800-171 requirements for protecting CUI in nonfederal systems. It is not only an IT exercise. Contracts, engineering, program management, legal, procurement, and help desk workflows often touch CUI before anyone labels them security-relevant.

The System Security Plan should describe the real system boundary and implementation status. A polished template that does not match identity, email, endpoint, network, ticketing, and cloud architecture will unravel quickly in interviews and evidence sampling.

Cloud services deserve explicit treatment. Inheritance from FedRAMP authorized services can help, but it does not automatically satisfy every contractor responsibility. The shared responsibility matrix must identify what the provider covers, what the organization configures, and what remains outside the inherited environment.

Decisions the checklist will not make for you

A checklist can ask whether CUI is scoped; it cannot decide whether the business should isolate CUI in an enclave or bring the broader company into scope. That decision depends on collaboration needs, contract volume, cost, user friction, and the discipline required to prevent leakage.

It also cannot determine whether a C3PAO is required for a specific contract path. Procurement teams need to read flow-down clauses, solicitations, and customer expectations carefully, then align the assessment strategy with those commitments before making security claims.

The checklist cannot approve POA&M strategy. Some gaps may be allowable for limited periods; others may block certification or expose CUI immediately. Leadership needs to decide funding, sequencing, and risk acceptance with assessment consequences in view.

Where defense suppliers actually fail

CUI in email is the recurring collapse point. Teams build an enclave, then allow users to forward drawings, specs, or marked documents through unmanaged mailboxes, personal devices, or broad distribution lists. Once CUI leaves the controlled path, the boundary narrative stops working.

Self-attestation mistakes also appear late. A company assumes SPRS submission or a self-assessment is enough, then learns a C3PAO assessment is required for the opportunity it wants. That changes timeline, evidence quality, and executive sponsorship.

Cloud inheritance is often overstated. A FedRAMP authorized platform may cover facilities and platform controls, while the contractor still owns tenant configuration, MFA, device posture, audit logging, encryption choices, incident response, and user behavior. A missing inheritance matrix leaves everyone guessing.

How to use the paired checklist

Start the checklist with a CUI data-flow session. Include contracts, program teams, engineering, IT, security, and anyone who handles customer artifacts. Mark every system as in scope, connected, supporting, or excluded with a written rationale.

Use each checklist item to attach evidence to the SSP, not to create a second tracker. Screenshots, configurations, policies, training records, incident tests, access reviews, and cloud responsibility statements should all point back to the implementation description.

Before assessment, rehearse evidence sampling with real users. Ask how CUI arrives, where it is stored, how it is shared, and what they do when something looks wrong. CMMC interviews often reveal gaps that a document review misses.

What teams get wrong

A high SPRS score proves readiness.
SPRS is only one signal. Assessors will sample implementation, interviews, system boundaries, CUI handling, and whether the SSP reflects reality.
An enclave fixes CUI scope automatically.
An enclave works only if CUI stays inside it. Email, tickets, file shares, and endpoints must be designed and governed to prevent leakage.
FedRAMP cloud means the contractor inherits everything.
FedRAMP services can provide inherited controls, but tenant configuration, user access, monitoring, incident response, and data handling usually remain contractor responsibilities.

When the checklist is enough — and when it is not

  • Use the checklist to organize SSP evidence, CUI flows, implementation status, and remediation ownership.
  • Ask a C3PAO or qualified CMMC advisor when assessment type, scope, sampling expectations, or POA&M treatment is uncertain.
  • Ask counsel when DFARS clauses, flow-down duties, incident reporting, or bid representations are involved.
  • Treat this guide as practical orientation, not official DoD or NIST text; use current program rules and NIST publications for authoritative requirements.

Related checklists

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer