top of page

Axiotrop Blog

The Jump to Level 2 & Transitioning from 15 to 110 Controls  

Transitioning from CMMC Level 1 to Level 2 is a monumental shift that requires moving from 15 basic safeguarding requirements to 110 rigorous security controls. While Level 1 focuses on protecting Federal Contract Information (FCI), Level 2 is specifically designed to safeguard Controlled Unclassified Information (CUI), which requires a much higher level of protection.  

Level 2 is cumulative, meaning you cannot achieve certification without also demonstrating mastery of all Level 1 practices alongside the additional advanced requirements. This transition is not just about "more controls"; it is a complete overhaul of how your organization handles sensitive data, aligning your internal culture with the standards of NIST SP 800-171 Rev 2.  


The jump in complexity is most visible in the documentation and technical rigor required for Level 2:  

  • The 100-Page Reality: While Level 1 documentation is minimal, Level 2 requires a formal System Security Plan (SSP) that frequently exceeds 100 pages to detail how your organization meets every requirement.  

  • 320 Objectives: Beyond the 110 controls, assessors will evaluate your organization against 320 individual assessment objectives across 14 security domains.  

  • Technical Rigor: Technical complexity scales exponentially with the mandatory implementation of multifactor authentication (MFA) for all system access and the use of FIPS-validated cryptography to protect CUI at rest and in transit.  

  • Audit Accountability: Level 2 necessitates sophisticated audit and accountability measures, including the creation, protection, and analysis of detailed system logs to track the actions of every unique user.  


Perhaps the most significant change is the shift from self-attestation to independent verification. For most contractors handling defense-related CUI, a third-party assessment conducted by an accredited C3PAO is now mandatory every three years.  


To even qualify for a "Conditional" passing status, your organization must achieve a minimum Supplier Performance Risk System (SPRS) score of 88 out of 110, and certain critical controls can never be left to a Plan of Action and Milestones (POA&M). Failing to bridge this gap correctly is no longer just a regulatory hurdle; it is a threat to your business continuity and your ability to remain in the defense industrial base.  


At AXIOTROP, we understand that Level 2 is a strategic investment in your organization’s future. We are here to help you navigate this technical and administrative mountain, turning your "Not Met" gaps into a verified "MET" status that protects both the warfighter and your bottom line.  


 

About AXIOTROP, LLC:        

AXIOTROP's mission is to make CMMC compliance accessible, attainable, and sustainable for small and medium-sized businesses in the Defense Industrial Base (DIB) so they remain competitive and positioned to win government contracts. As a C3PAO, we can support DIB contractors during their preparation or their assessments. 


We simplify the path to certification by working closely with businesses to right-size their CMMC program to their specific scope and contract requirements, resulting in successful assessments, expanded contracting opportunities, and a stronger security posture 

Comments


bottom of page