← Back to Resources
DCG Blog

CMMC Level 2 Requirements for Mid-Size Contractors

A laptop and checklist on a workbench in a precision manufacturing workshop.

CMMC Level 2 is not aimed at defense giants with security operations centers and a compliance department down the hall. It is aimed squarely at the mid-size manufacturer, the small engineering firm, the machine shop with forty employees and one overworked IT person, that happens to touch Controlled Unclassified Information somewhere in its supply chain. If that describes your company, this post is written for you specifically, not for a hypothetical prime contractor ten times your size.

That distinction matters because most of what gets written about CMMC Level 2 online assumes resources your company probably doesn’t have. Let’s set that aside and talk about what the requirement actually is, for the contractor actually facing it.

Who CMMC Level 2 Actually Applies To

If your company handles Controlled Unclassified Information (CUI) anywhere in a Department of Defense contract or subcontract, and that CUI touches your systems even briefly, Level 2 is not optional. It is the default certification tier for that population, period.

This is where the mid-size DIB contractor gets caught. Too large to hide from a prime’s flow-down requirements, too small to have a dedicated security team, and too new to CMMC to know that “we’ll figure it out when the contract requires it” is not a plan. Level 2 assumes a mature security program already exists, and building a CMMC program from scratch is exactly the position most mid-size contractors start in.

The 110 security requirements in NIST SP 800-171 are the baseline every CMMC Level 2 certification is built on. Nobody gets exempted from them for being mid-size. The requirement does not scale down with headcount.

Being in scope for Level 2 does not mean every system in the building has to meet every requirement. It means the systems that actually touch CUI do, and drawing that boundary correctly is one of the first decisions a mid-size contractor has to get right.

Getting it wrong in either direction costs money. Scope it too narrow and an assessor finds CUI outside the boundary you claimed. Scope it too broad and you are building and maintaining security controls for systems that never needed them in the first place.

What “Requirements” Actually Means at Level 2

Contractors searching for CMMC level 2 requirements usually want a checklist. What they get instead is layered. CMMC Level 2 currently takes the 110 security requirements in NIST SP 800-171 Rev. 2, breaks them into 320 assessment objectives in NIST SP 800-171A, and has those objectives verified during a formal assessment by a Certified Third-Party Assessment Organization, or C3PAO.

That is not bureaucratic padding. A requirement like “limit information system access” means nothing to an assessor until it is broken into specific, testable pieces: who has access, how it is granted, how it is revoked, and how it is logged. A C3PAO assessment tests those pieces individually, not the requirement as a general statement of intent.

CMMC Level 2 currently follows NIST SP 800-171 Rev. 2, which organizes its 110 security requirements into fourteen families: access control, incident response, media protection, and eleven more. NIST SP 800-171 Rev. 3 expands that structure to seventeen families, but Rev. 3 has not yet been incorporated into the CMMC Level 2 assessment standard. Contractors researching CMMC Level 2 certification often discover this structure (and the distinction between the two revisions) the hard way, mid-assessment, instead of ahead of it.

Rev. 3 was approved and published by NIST in 2024, but DoD’s process to adopt it into CMMC is still underway. Until that rulemaking is complete, Rev. 2 remains the standard against which CMMC Level 2 contractors are assessed.

What Changes Under NIST SP 800-171 Rev. 3

Contractors preparing for CMMC today are still assessed against Rev. 2, but they should understand where the underlying NIST standard is headed. NIST SP 800-171 Rev. 3 organizes its security requirements into seventeen families: access control, awareness and training, assessment, authorization and monitoring, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical and environmental protection, planning, risk assessment, system and services acquisition, system and communications protection, system and information integrity, and supply chain risk management.

Rev. 3 adds three families that did not exist as separate families in Rev. 2: planning, system and services acquisition, and supply chain risk management. It also restructures and renames portions of the earlier framework.

Most mid-size contractors already have partial coverage across many of these areas, usually without realizing it. A password policy touches identification and authentication. A locked server room touches physical and environmental protection. A process for evaluating a cloud provider may touch both system and services acquisition and supply chain risk management.

The gap is rarely zero. It is usually incomplete, undocumented, or unverified, which is a different problem than starting from nothing, and a more common one.

Why All of It Comes Back to Protecting CUI

Every one of those 320 objectives exists to answer one question: is the CUI in this environment actually protected, not described as protected on paper. The whole point is to protect Controlled Unclassified Information (CUI), and every requirement traces back to that, not to compliance for its own sake.

A contractor who treats CUI protection as a subset of the broader compliance program has the relationship backwards. Compliance is the evidence that CUI protection is real. It is not the goal itself.

Getting this backwards is how contractors end up with a technically compliant environment that still leaks. A firewall rule satisfies an objective. It does not, by itself, guarantee the CUI behind it stays where it belongs.

Consider a shared drive that stores CUI mixed in with ordinary business files, never sorted apart. Every user with drive access technically has access to CUI, whether their job requires it or not.

That is not a hypothetical. It is one of the most common findings in early gap assessments, and it usually surprises the people who assumed their existing IT setup already handled it.

Level 2 and What It Actually Means for Contract Award

For a defense contractor pursuing new work, CMMC Level 2 compliance is no longer a future requirement. More solicitations now require CMMC Level 2 certification before award, not a plan to get one someday.

The Department of Defense built CMMC because the prior system, self-attestation, was not producing verified security across the defense industrial base. A prime cannot flow CUI down its supply chain to a subcontractor it cannot verify. Level 2 certification is how that verification happens at scale, one contractor at a time.

That flow-down obligation reaches further down the supply chain every year. A prime is not going to gamble its own certification status on a subcontractor’s promise, and if the flow-down clause requires Level 2, it requires Level 2 regardless of how far removed a company feels from the primary contract.

For a mid-size company without in-house security staff to build and run that program day to day, Midwatch, DCG’s CMMC-as-a-Service offering, exists for exactly this gap: ongoing operational support for a compliance program that has to run continuously, not just at renewal.

CMMC Is a Program, Not a Project

The single most common mistake we see in mid-size contractors approaching Level 2 for the first time is treating it as a project with an end date instead of a program that runs continuously.

CMMC is a program. It is not a project. A System Security Plan (SSP) gets written once, but the environment it describes changes constantly, new employees, new systems, new vendors, and the SSP has to keep pace or the certification it supports stops matching reality. We cover what actually has to be in that document in detail elsewhere.

Contractors who understand this from day one build toward CMMC requirements as an operating discipline. Contractors who treat it as a project spend the recertification cycle rebuilding what they let go stale.

CMMC Level 2 requirements are not designed to be impossible for a mid-size contractor to meet. They are designed to be impossible to fake. Know which category your company actually falls into, build toward the real requirement instead of a simplified version of it, and the certification takes care of itself.

← All posts
Ready to Talk?

The First Conversation Is Free.
And It Will Tell You the Truth.

If this raised a question about your specific situation, the next step is a conversation with DCG. We will tell you honestly what we see before we tell you anything about our services.

Book a Free Consultation