What CMMC Level 2 means right now
CMMC Level 2 is focused on the protection of Controlled Unclassified Information (CUI). The current model aligns Level 2 with the 110 security requirements in NIST SP 800-171 Revision 2. During the current Phase I pause, the Department describes Level 2 as requiring a self-assessment every three years with annual affirmation, subject to the requirements of the applicable procurement.
The important point for contractors is that the suspension of Phase II did not remove the underlying obligation to protect covered defense information. DFARS 252.204-7012 continues to apply NIST SP 800-171 to covered contractor information systems when required by contract.
The readiness work starts with scope
A compliance project becomes much more expensive when every workstation, server, cloud service and user is casually treated as part of the CUI environment. The first technical question should be: where does CUI actually enter, live, move and leave?
That means identifying contracts and data types, interviewing the people who perform the work, mapping repositories and collaboration tools, reviewing remote access and considering any systems that provide security protection to the CUI environment. A carefully designed scope can reduce risk and assessment complexity without weakening the required safeguards.
CUI data flow
Identify how CUI is received, created, stored, transmitted, shared with subcontractors and ultimately retained or disposed of.
People and identities
Determine who needs access, how accounts are provisioned, how privileged access is controlled and how users authenticate.
Systems and boundaries
Define the endpoints, servers, networks, cloud services and security systems that are in scope or provide protection to the environment.
External dependencies
Review MSP tools, backup platforms, remote support, SaaS integrations, vendors and subcontractor interfaces that may affect CUI.
A practical CMMC Level 2 readiness sequence
Start with the solicitation, contract clauses and actual data flow. Technical implementation should follow the requirement—not assumptions about what every defense contractor needs.
Evaluate both implementation and evidence. A control that exists but cannot be demonstrated consistently creates assessment risk.
The SSP should describe the real environment, system boundary, connections, responsible parties and how requirements are implemented.
Prioritize identity, endpoint security, logging, configuration, data protection, backup, access control and operational procedures according to risk and assessment impact.
Policies alone are not enough. Prepare screenshots, configurations, logs, tickets, reports and repeatable operational evidence that support the assessment statements.
Current Phase I requirements emphasize self-assessments, while future or contract-specific requirements may change. Maintain readiness so a procurement change does not force a rushed technology project.
Where Atlantec fits
Atlantec works on the technology and operational side of readiness: system scoping, Microsoft cloud decisions, identity, endpoints, network security, monitoring, backup, configuration, documentation and evidence. For managed IT clients, many of those controls can become part of normal operations rather than a one-time compliance sprint.
- CUI environment and technology scoping support
- NIST SP 800-171 technical gap assessment and remediation planning
- System Security Plan technical content and architecture documentation
- Microsoft 365 and GCC High planning where appropriate
- Endpoint, identity, MFA, privileged access, logging and security monitoring improvements
- Backup, recovery and incident-readiness implementation
- Evidence collection and operational procedure support
- Coordination with the organization's compliance advisors and assessment organization
Build readiness as an operating model
The strongest CMMC programs do not depend on a spreadsheet that gets opened once a year. User onboarding, privileged access, patching, vulnerability remediation, backup testing, security monitoring, change management and evidence collection should operate continuously. That is also why managed IT and compliance readiness are closely related: the same operational discipline that makes an assessment easier usually makes the business more resilient.