Nationwide CMMC & NIST 800-171 implementation for the Defense Industrial Base

CMMC Level 2 Compliance

Level 2 is where CMMC gets expensive and where most contractors stall. 110 controls, a real assessment, and a scoping decision at the start that determines everything downstream.

Find out what Level 2 actually costs for your environment

The honest answer depends on scoping. Our free gap assessment gives you a real SPRS baseline and a scoped remediation range — not a brochure number.

Not sure? That's the most common answer — and it's the first thing we work out with you.

No cost. No obligation. NDA available on request.

We respond within 1 business hour · We are not a C3PAO and do not perform certification assessments

Level 1
achieved for an industrial robotics manufacturer
Defense
software built for defense contractors
Federal
law-enforcement task force under active support
Regulated
HIPAA, IRS WISP & FTC Safeguards work

The short answer

CMMC Level 2 applies to contractors handling Controlled Unclassified Information. It requires implementing all 110 security controls in NIST SP 800-171 across 14 control families. Most Level 2 contracts require a triennial assessment by an authorized C3PAO, with annual affirmations in between; a limited subset qualifies for self-assessment. Limited POA&Ms are permitted for certain lower-weighted controls and must be closed within 180 days to convert a conditional certification into a final one.

Scoping is the decision that sets your budget

Before a single control gets implemented, you have to decide where CUI is allowed to live. Contractors who let CUI spread across their entire corporate network end up applying 110 controls to every laptop, server, and SaaS app they own. Contractors who build a defined enclave apply them to a much smaller boundary.

The enclave approach is usually dramatically cheaper and faster, but it only works if your business processes can actually be restructured to keep CUI inside it. That is an operational question as much as a technical one, and it is the first thing we work through.

  • Full-boundary: every system in scope. Simplest to explain, most expensive to build and maintain.
  • Enclave: a hardened, segmented environment where all CUI is created, stored, and processed.
  • Hybrid: enclave for CUI workloads plus tightly controlled interfaces to corporate IT.

The 110 controls and your SPRS score

NIST SP 800-171 organizes 110 controls across 14 families — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

The DoD Assessment Methodology converts your implementation status into a score submitted to SPRS. It starts at 110 and subtracts weighted points for every unimplemented control — 5, 3, or 1 point depending on severity. A contractor who has done nothing scores -203. Primes increasingly check SPRS scores before awarding subcontracts, which means your score is a commercial asset, not just a compliance artifact.

GCC High, enclaves, and the licensing question

Most Level 2 conversations arrive at Microsoft licensing quickly. GCC High is the common answer for CUI in Microsoft 365, but it is not the only answer and it is not automatically required — what matters is that your environment meets the control requirements, including FedRAMP-equivalent handling for cloud services storing CUI and, where ITAR applies, US-person access restrictions.

We work through the actual requirement rather than defaulting to the most expensive SKU. Sometimes GCC High is right. Sometimes a purpose-built enclave is cheaper and cleaner.

Where we fit — and where we do not

We do the implementation: scoping, remediation engineering, System Security Plan, POA&M, evidence packages, and the ongoing managed services that keep controls in place between assessments.

We do not perform your assessment. Under CMMC independence rules, an authorized C3PAO cannot assess an environment it built, so you need a separate implementation partner regardless. We will make C3PAO introductions when your environment is ready.

We do the work. We don't grade it.

Smith Network Solutions is not a C3PAO and not a registered RPO. We are the engineering and managed-services partner that closes your gaps, writes your System Security Plan, and gets your SPRS score where it needs to be. Your assessment is performed by an independent, authorized C3PAO — and that separation is deliberate. Under CMMC independence rules your assessor cannot remediate what they assess, so you need an implementation partner either way. We are that partner, and we will introduce you to C3PAOs when you are ready.

Find out what Level 2 actually costs for your environment

The honest answer depends on scoping. Our free gap assessment gives you a real SPRS baseline and a scoped remediation range — not a brochure number.

Nationwide remote delivery · Response within 1 business hour

CMMC Level 2 FAQs

Do we need a C3PAO assessment or can we self-assess?

It depends on what your contract requires. Most Level 2 contracts require a triennial assessment by an authorized C3PAO. A limited subset of Level 2 contracts permit annual self-assessment. Your contracting officer and your contract clauses determine which applies — do not assume.

How do POA&Ms work at Level 2?

Limited POA&Ms are permitted, but not for everything. Controls weighted at 5 points, and certain specific controls, must be fully implemented at assessment time. Eligible POA&M items must be closed within 180 days, at which point a conditional certification becomes final. Miss the window and the certification lapses.

How long does Level 2 realistically take?

For a contractor starting from a typical commercial IT baseline, plan on six to twelve months before you are assessment-ready, depending heavily on scoping. Enclave builds move faster than full-boundary programs. Anyone promising Level 2 in eight weeks is selling you documentation, not compliance.

Are you a C3PAO? Can you certify us?

No. We are not a C3PAO and we are not a registered RPO. We are the implementation partner that gets your environment and documentation ready, and we are transparent about that. Your certification comes from an independent authorized C3PAO — which is a requirement, not a limitation, since assessors are barred from certifying work they performed.

What does Level 2 cost?

Implementation varies widely with scope, headcount, and how much of your existing environment can be reused. Licensing and the C3PAO assessment fee are separate line items. We give you a scoped range after the gap assessment rather than a number before we have seen your environment.