Serving Greater Portland & Southern Maine
Westbrook, Maine207-347-3500

CMMC Level 2 • Maine defense contractors

CMMC Level 2 readiness built around the environment you actually operate.

Atlantec helps defense contractors translate CMMC Level 2 and NIST SP 800-171 requirements into practical IT, cybersecurity, documentation and evidence work—without treating compliance as a separate technology universe.

Reviewed Aug. 31, 2026Technical review by Rob McDaniel, Certified CMMC Professional (CCP). Program requirements can change; contract terms and current government guidance control.
Current 2026 CMMC status: The Department of War suspended Phase II on July 13, 2026. CMMC remains paused in Phase I, and Phase I self-assessment requirements remain in place. The Department states that NIST SP 800-171 Rev. 2 compliance continues to be enforced through self-assessments and select government-led assessments. Organizations should evaluate the requirements in each solicitation and contract rather than relying on an old rollout timeline.

What CMMC Level 2 means right now

CMMC Level 2 is focused on the protection of Controlled Unclassified Information (CUI). The current model aligns Level 2 with the 110 security requirements in NIST SP 800-171 Revision 2. During the current Phase I pause, the Department describes Level 2 as requiring a self-assessment every three years with annual affirmation, subject to the requirements of the applicable procurement.

The important point for contractors is that the suspension of Phase II did not remove the underlying obligation to protect covered defense information. DFARS 252.204-7012 continues to apply NIST SP 800-171 to covered contractor information systems when required by contract.

110NIST SP 800-171 Rev. 2 security requirements associated with CMMC Level 2
3 yearsCurrent Level 2 self-assessment cycle described by the Department during Phase I
AnnualAffirmation requirement after the assessment

The readiness work starts with scope

A compliance project becomes much more expensive when every workstation, server, cloud service and user is casually treated as part of the CUI environment. The first technical question should be: where does CUI actually enter, live, move and leave?

That means identifying contracts and data types, interviewing the people who perform the work, mapping repositories and collaboration tools, reviewing remote access and considering any systems that provide security protection to the CUI environment. A carefully designed scope can reduce risk and assessment complexity without weakening the required safeguards.

CUI data flow

Identify how CUI is received, created, stored, transmitted, shared with subcontractors and ultimately retained or disposed of.

People and identities

Determine who needs access, how accounts are provisioned, how privileged access is controlled and how users authenticate.

Systems and boundaries

Define the endpoints, servers, networks, cloud services and security systems that are in scope or provide protection to the environment.

External dependencies

Review MSP tools, backup platforms, remote support, SaaS integrations, vendors and subcontractor interfaces that may affect CUI.

A practical CMMC Level 2 readiness sequence

Confirm contractual requirements and CUI scope

Start with the solicitation, contract clauses and actual data flow. Technical implementation should follow the requirement—not assumptions about what every defense contractor needs.

Assess the 110 NIST SP 800-171 Rev. 2 requirements

Evaluate both implementation and evidence. A control that exists but cannot be demonstrated consistently creates assessment risk.

Build or update the System Security Plan

The SSP should describe the real environment, system boundary, connections, responsible parties and how requirements are implemented.

Remediate technical and process gaps

Prioritize identity, endpoint security, logging, configuration, data protection, backup, access control and operational procedures according to risk and assessment impact.

Organize evidence and repeatable procedures

Policies alone are not enough. Prepare screenshots, configurations, logs, tickets, reports and repeatable operational evidence that support the assessment statements.

Prepare for the required assessment path

Current Phase I requirements emphasize self-assessments, while future or contract-specific requirements may change. Maintain readiness so a procurement change does not force a rushed technology project.

Where Atlantec fits

Atlantec works on the technology and operational side of readiness: system scoping, Microsoft cloud decisions, identity, endpoints, network security, monitoring, backup, configuration, documentation and evidence. For managed IT clients, many of those controls can become part of normal operations rather than a one-time compliance sprint.

  • CUI environment and technology scoping support
  • NIST SP 800-171 technical gap assessment and remediation planning
  • System Security Plan technical content and architecture documentation
  • Microsoft 365 and GCC High planning where appropriate
  • Endpoint, identity, MFA, privileged access, logging and security monitoring improvements
  • Backup, recovery and incident-readiness implementation
  • Evidence collection and operational procedure support
  • Coordination with the organization's compliance advisors and assessment organization
Important distinction: Atlantec provides readiness and implementation assistance. Atlantec is not a C3PAO and does not perform the independent certification assessment. The organization seeking assessment remains responsible for its representations, evidence and compliance decisions.

Build readiness as an operating model

The strongest CMMC programs do not depend on a spreadsheet that gets opened once a year. User onboarding, privileged access, patching, vulnerability remediation, backup testing, security monitoring, change management and evidence collection should operate continuously. That is also why managed IT and compliance readiness are closely related: the same operational discipline that makes an assessment easier usually makes the business more resilient.

Frequently asked questions

Questions buyers commonly ask.

Is CMMC Level 2 certification currently required for every contractor that handles CUI?

No. As of August 2026, the Department has suspended Phase II and says the program remains paused in Phase I. Current Phase I requirements emphasize Level 1 and Level 2 self-assessments. The applicable solicitation and contract determine what a specific organization must provide.

How many requirements are in CMMC Level 2?

CMMC Level 2 aligns with the 110 security requirements in NIST SP 800-171 Revision 2.

Does the Phase II suspension mean we can stop NIST 800-171 work?

No. The Department states that the suspension does not eliminate existing obligations to protect information under DFARS 252.204-7012, and current CMMC Phase I self-assessment requirements remain in effect.

Can Atlantec perform our CMMC certification assessment?

No. Atlantec provides readiness and implementation support. Independent CMMC certification assessments are performed by authorized assessment organizations when such an assessment is required.

Should we wait for CMMC reform before making security improvements?

Organizations should avoid spending blindly against assumptions, but core NIST SP 800-171 safeguards, contractual obligations and good cybersecurity operations remain relevant. A scoped, risk-based readiness plan can reduce future rush and rework.

Ready for IT to become easier to manage?

Tell us what is working, what is not, and what you need technology to do next.

Talk with Atlantec