Core Level 2 Requirements
The 110 Level 2 requirements are derived from NIST SP 800-171 Revision 2 and cover 14 security requirement families. They address areas such as access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
- Access control: restrict system access to authorized users, processes, and devices.
- Identification and authentication: establish appropriate user and device authentication mechanisms.
- Audit and accountability: create and protect records that support traceability of system activity.
- Configuration management: maintain controlled configurations and manage system changes.
- Incident response: establish procedures for detecting, reporting, analyzing, and responding to cybersecurity incidents.
- System and communications protection: safeguard CUI while it is processed, stored, or transmitted.
Level 2 Assessment and Scoring
Under the current Phase I framework, a Level 2 self-assessment is conducted every three years, with an annual affirmation of compliance. Assessment results are entered into the Supplier Performance Risk System (SPRS). The Department states that the Level 2 self-assessment covers all 110 NIST SP 800-171 Revision 2 requirements. :contentReference[oaicite:1]{index=1}
The established assessment methodology assigns points to requirements based on their assessment scoring structure. The Federal Register rule explains that an assessment satisfying all 110 requirements produces a score of 110. The framework also provides for limited use of Plans of Action and Milestones (POA&Ms), subject to specified conditions and a 180-day closeout period. :contentReference[oaicite:2]{index=2}
For example, if an organization has an assessment score of 88 out of 110, the numerical percentage is calculated as 88 ÷ 110 × 100 = 80%. The applicable CMMC rules should then be reviewed to determine whether the organization satisfies the conditions for the relevant CMMC status.
Level 2 Requirements for Finance Systems
Finance systems may fall within the CMMC environment when they process, store, or transmit CUI or connect to systems within the applicable assessment scope. This makes access management, audit records, system interfaces, configuration controls, and data protection relevant to accounting and procurement workflows.
Invoice-processing environments can also involve structured financial data that requires controlled handling. Matching Fields Configurability illustrates how field-level invoice matching can use defined rules and tolerances to support consistent transaction validation. Similarly, 100 Accurate Extraction addresses automated checking of invoice fields and purchase-order data to support dependable invoice processing.
Where financial systems exchange data with tax engines or other applications, Integration With Tax Dictionaries can apply jurisdiction-specific tax rules at the invoice line-item level. Identification And Reporting Of Tax Mismatch can identify tax discrepancies for review, while Higher Tax Compliance supports accurate invoice matching and audit-ready journal entries.
Procurement, ERP, and Tax Controls
CMMC Level 2 controls can intersect with procurement when CUI is present in requisitions, supplier records, contracts, or purchasing systems. A controlled purchase order workflow can help organizations establish authorization, approval, and recordkeeping practices within the broader information-security environment.
When an ERP is part of the assessed environment, teams should map integrations, users, data flows, and system responsibilities to the applicable CMMC boundary. How Many Levels Does a Typical ERP System Include? provides context on how ERP layers can work together when organizations extend finance workflows around an enterprise system.
Tax controls remain a separate financial obligation but may intersect with protected financial data. Teams should document applicable jurisdiction rules, exemptions, nexus considerations, and audit evidence when validating use tax or other transaction-level tax treatments. sales tax validation can likewise help identify incorrect rates, exemptions, and overcharges before financial records are finalized.
Documentation and Evidence
Meeting Level 2 requirements requires evidence showing how controls operate in the actual environment. Organizations should maintain current system boundaries, policies, procedures, configurations, access records, incident documentation, assessment evidence, and remediation records.
Financial information exchanged electronically should also follow applicable transaction and recordkeeping rules. E Invoice Requirements provide a useful reference point for understanding electronic invoicing obligations within broader finance workflows, while Disclosure Requirements address information that organizations may need to provide under applicable reporting or regulatory frameworks.
For analytics and compliance reporting, Reporting Requirements help organizations distinguish required reporting information from internal management data. Keeping these records organized supports evidence retrieval during assessments and strengthens coordination among security, finance, compliance, and contract teams.
Practical Implementation Approach
A practical Level 2 program begins by identifying where CUI resides and determining which people, devices, applications, services, and facilities are included in the assessment scope. The organization can then map the 110 requirements to responsible owners and identify the evidence needed to demonstrate implementation.
- Define and document the CUI environment and assessment boundary.
- Map each applicable requirement to a responsible control owner.
- Collect evidence that demonstrates actual control implementation.
- Track remediation activities and applicable POA&M items.
- Review controls continuously and maintain annual affirmation readiness.
Because CMMC implementation requirements can change, organizations should verify current contract clauses and official CMMC guidance when planning an assessment. The Department's current guidance confirms that Phase II has been suspended while Phase I self-assessment requirements remain active. :contentReference[oaicite:3]{index=3}
Summary
CMMC Level 2 Requirements consist of 110 NIST SP 800-171 Revision 2 security requirements covering access, authentication, auditing, configuration, incident response, data protection, and other cybersecurity areas. Current Level 2 self-assessment requirements call for assessment every three years and annual affirmation, with results entered into SPRS. For organizations whose finance and ERP environments fall within scope, disciplined access controls, evidence management, transaction controls, and documented system boundaries can support both cybersecurity and financial governance objectives.