Learn
What is CMMC? FAR 52.204-21 explained Your environment SPRS submission How it works Pricing FAQ Log in Get started

This page is about CMMC Level 2.

The 110 controls below come from NIST SP 800-171 — the framework underlying CMMC Level 2. If you handle Federal Contract Information (FCI) but no Controlled Unclassified Information (CUI), you don't need this — your obligations come from FAR 52.204-21's 17 practices, not these 110 controls. See the L1 vs L2 explainer if you're not sure which applies to you.

110 controls
Note: These plain-English summaries are written to give a working sense of each control. They do not replace the official NIST SP 800-171 Rev 3 text, which remains the authoritative source for assessment. If a summary feels wrong or unclear, email us — we update this regularly.

Ready to find out where you actually stand?

Take the guided readiness interview. Walk away with a score, a gap list, and a draft of the documents CMMC requires.

Get your readiness report