CMMC Level 2 Controls: 14 Families for SMBs
Updated:
September 28, 2026
CMMC Level 2 organizes 110 security requirements into 14 control families that help small and medium-sized businesses (SMBs) protect Controlled Unclassified Information (CUI). These families group related safeguards, including access control, incident response, and personnel security.
The Cybersecurity Maturity Model Certification (CMMC) program is in effect, with requirements entering defense contracts through phased implementation. SMB owners should check their solicitations, contracts, and subcontract requirements to confirm the required level and assessment type.
CMMC has three levels based on the information being protected and applicable program requirements. Level 1 addresses Federal Contract Information (FCI), Level 2 protects CUI, and Level 3 adds safeguards for designated programs requiring greater protection against advanced persistent threats.
Level 2 uses NIST SP 800-171 Revision 2, published by the National Institute of Standards and Technology (NIST). Its 14 families contain 110 individual requirements, so implementing one safeguard per family does not establish compliance.
This guide explains each Level 2 control family and the practical work SMB owners should plan, including assigning responsibilities, addressing security gaps, and collecting assessment evidence.
Understanding CMMC and NIST 800-171
The Cybersecurity Maturity Model Certification (CMMC) program verifies implementation of required cybersecurity safeguards, while NIST SP 800-171 defines requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. CMMC Level 2 incorporates NIST SP 800-171 Revision 2.
The following three sections explain CMMC, NIST SP 800-171, and the connection between them.
Explanation of CMMC
CMMC is a Department of Defense (DoD) program that assesses cybersecurity safeguards within contractor systems. Its three levels address different information protection needs across the defense supply chain.

- Goals: CMMC supports the protection of Federal Contract Information (FCI) and CUI. Assessments examine whether contractors implement the safeguards required for their applicable level.
- Levels: Level 1 covers 15 basic FAR safeguarding requirements for FCI. Level 2 incorporates 110 NIST SP 800-171 Revision 2 requirements for CUI. Level 3 adds 24 selected NIST SP 800-172 requirements to Level 2’s safeguards.
- Assessments: Level 1 uses self-assessments. The program includes both self-assessment and CMMC Third-Party Assessment Organization (C3PAO) assessment pathways for Level 2. Government assessors conduct Level 3 assessments. Applicable solicitation and contract requirements determine the required level and assessment type.
- Implementation: Contractors must demonstrate that applicable safeguards operate within the assessment scope. CMMC 2.0 removes the original model’s separate process maturity requirements.
Overview of NIST 800-171
NIST SP 800-171 is a National Institute of Standards and Technology publication addressing the confidentiality of CUI in nonfederal systems and organizations. Federal agencies use its requirements in contracts and other agreements with organizations handling CUI.
- Purpose: The publication specifies safeguards for CUI that organizations process, store, or transmit. Its scope includes components that provide security protection for those systems.
- Requirements: Revision 2 contains 110 security requirements across 14 families, including access control, incident response, and risk assessment. Reviewing implementation against these requirements supports a CMMC gap assessment.
- Objectives: The requirements support consistent CUI protection and help reduce unauthorized disclosure and data breaches. Implementation involves technical safeguards, operating procedures, and personnel responsibilities.
- Revision Selection: NIST publishes Revision 3 as the successor to Revision 2. The CMMC program regulation continues to specify Revision 2 for Level 2 assessments.
Integration of NIST 800-171 into CMMC Framework
The CMMC program rule incorporates NIST SP 800-171 Revision 2’s requirements directly into Level 2. Level 3 requires Final Level 2 (C3PAO) status for the relevant scope before the government assessment of its additional requirements.
Effective CMMC assessment preparation therefore combines implemented safeguards with supporting evidence, the applicable assessment, and required compliance affirmations.
Key CMMC Controls Derived from NIST 800-171
CMMC Level 2 uses the 14 security families in NIST SP 800-171 Revision 2, titled Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. These families organize 110 individual requirements into related security areas; they are not 14 individual controls.

14 CMMC Level 2 Control Families From NIST SP 800-171
CMMC Level 2 incorporates 110 security requirements organized into 14 families from NIST SP 800-171 Revision 2. These families cover the technical safeguards, operating procedures, and personnel responsibilities needed to protect Controlled Unclassified Information (CUI).

The following 14 control families explain their purpose and practical implementation priorities. These summaries support preparation but do not replace a requirement-by-requirement assessment.
1. Access Control
Access Control limits who can access systems, which activities they can perform, and how information moves between authorized users and systems. Its requirements address privileges, remote connections, wireless access, mobile devices, and publicly accessible systems.
Implementation priorities include:
- Assign permissions according to job responsibilities and apply least privilege to user and administrator accounts.
- Separate duties where necessary and use nonprivileged accounts for routine work.
- Control remote access, external connections, and portable storage use.
- Configure session locks and termination conditions, and prevent unauthorized public disclosure of CUI.
2. Awareness and Training
Awareness and Training prepares managers, administrators, and users to understand security risks and perform their assigned responsibilities. The family includes training on recognizing and reporting potential insider threats.
Implementation priorities include:
- Explain applicable security policies, CUI handling rules, and reporting procedures.
- Provide role-specific training for staff with security responsibilities.
- Teach personnel to recognize and report potential insider threat indicators.
- Retain training materials and completion records; use exercises to reinforce learning.
3. Audit and Accountability
Audit and Accountability requires records that support monitoring, investigation, and attribution of system activity to individual users. Organizations must protect audit information and maintain reliable logging capabilities.
Implementation priorities include:
- Define logged events and retention periods that support investigation and reporting needs.
- Review and correlate records for suspicious activity and respond to logging failures.
- Synchronize system clocks with an authoritative time source.
- Protect logs against unauthorized access, modification, and deletion, and restrict logging administration.
4. Configuration Management
Configuration Management establishes approved system configurations and controls changes to hardware, software, firmware, and documentation. It includes system inventories, secure settings, and restrictions on unnecessary functionality.
Implementation priorities include:
- Maintain current inventories and approved baseline configurations.
- Review the security impact of proposed changes before implementation.
- Approve, document, and monitor configuration changes.
- Disable unnecessary services, restrict software installation, and control which applications can execute.
5. Identification and Authentication
Identification and Authentication establishes and verifies the identities of users, processes, and devices before system access. It covers account identifiers, credentials, password requirements, and multifactor authentication (MFA).
Implementation priorities include:
- Assign and manage identifiers for authorized users, processes, and devices.
- Require MFA for local and network access to privileged accounts and network access to nonprivileged accounts.
- Enforce applicable password complexity, reuse, and temporary-password requirements.
- Protect stored and transmitted passwords cryptographically and disable identifiers after defined inactivity periods.
6. Incident Response
Incident Response requires an operational capability to prepare for, detect, analyze, contain, and recover from security incidents. Organizations must track incidents, report them to designated officials or authorities, and test their response capability.
Implementation priorities include:
- Document an incident response plan with defined roles and procedures.
- Establish reporting channels, escalation criteria, and applicable reporting deadlines.
- Record incident details, response actions, and recovery decisions.
- Test the response capability through exercises and correct weaknesses found during testing.
7. Maintenance
Maintenance controls protect systems and CUI during servicing, diagnostics, and repairs. The requirements address maintenance personnel, tools, diagnostic media, equipment removal, and remote maintenance connections.
Implementation priorities include:
- Authorize maintenance activities and supervise personnel who lack the required access authorization.
- Control maintenance tools and check diagnostic or test media for malicious code before use.
- Sanitize CUI from equipment before sending it for off-site maintenance.
- Require MFA for nonlocal maintenance through external networks and terminate connections when work ends.
8. Media Protection
Media Protection safeguards paper and digital media containing CUI throughout storage, use, transport, and disposal. It includes access restrictions, marking, accountability, and protection of backup information.
Implementation priorities include:
- Restrict media access and maintain secure storage for paper records and digital devices.
- Mark media with required CUI markings and distribution limitations.
- Protect and track media during transport, using encryption for digital CUI unless alternative physical safeguards provide protection.
- Sanitize or destroy media before disposal or reuse and prohibit portable storage devices without an identifiable owner.
9. Personnel Security
Personnel Security requires screening before individuals receive access to systems containing CUI. It requires continued protection of those systems during personnel transfers and terminations.
Implementation priorities include:
- Complete appropriate personnel screening before granting access.
- Coordinate access changes with human resources and responsible managers.
- Revoke or adjust accounts, credentials, keys, and access permissions when employment or responsibilities change.
- Document completed screening and offboarding actions.
10. Physical Protection
Physical Protection restricts access to systems, equipment, facilities, and supporting infrastructure. Its requirements cover visitors, physical access records, access devices, and CUI safeguards at alternate work sites.
Implementation priorities include:
- Limit entry to authorized individuals and protect equipment in controlled areas.
- Escort visitors, monitor their activity, and maintain physical access logs.
- Manage keys, badges, locks, and other access devices.
- Apply CUI safeguards at remote work locations and protect supporting infrastructure from unauthorized access or tampering.
11. Risk Assessment
Risk Assessment evaluates threats to operations, assets, and individuals associated with systems handling CUI. It includes vulnerability scanning and remediation based on assessed risk.
Implementation priorities include:
- Assess risks periodically across the systems and activities within scope.
- Scan systems and applications periodically and when newly reported vulnerabilities affect them.
- Prioritize remediation according to exposure, potential impact, and assessment findings.
- Record risks, corrective actions, responsible owners, and verification results.
12. Security Assessment
Security Assessment checks whether safeguards are correctly implemented and remain effective. It requires ongoing monitoring, corrective action plans, and a current System Security Plan (SSP).
Implementation priorities include:
- Assess security controls periodically and document their effectiveness.
- Develop and carry out plans to correct deficiencies.
- Monitor safeguards between assessments and investigate changes in effectiveness.
- Maintain an SSP describing system boundaries, operating environments, implementation, and connections to other systems.
Corrective action plans do not automatically qualify an organization for conditional CMMC status. Separate CMMC rules restrict which assessment deficiencies may remain open.
13. System and Communications Protection
System and Communications Protection safeguards system boundaries, communications, and CUI confidentiality. Its requirements cover network separation, secure architecture, cryptography, session connections, and information at rest.
Implementation priorities include:
- Monitor and protect external and key internal boundaries, with network traffic denied unless explicitly permitted.
- Separate publicly accessible components from internal networks and prevent prohibited split tunneling.
- Protect CUI during transmission and use FIPS-validated cryptography when cryptography protects CUI confidentiality.
- Manage cryptographic keys, protect CUI at rest, and terminate communication connections under defined conditions.
14. System and Information Integrity
System and Information Integrity addresses system flaws, malicious code, security alerts, attacks, and unauthorized system use. It requires timely corrective action and monitoring that can detect suspicious activity.
Implementation priorities include:
- Report and correct system flaws promptly, including applicable security updates.
- Deploy malicious code protection at appropriate locations and update it when new releases become available.
- Perform periodic system scans and real-time scans of externally sourced files.
- Review security alerts and monitor systems and network traffic for attacks or unauthorized use.
Implementing these families requires assigned responsibilities, working safeguards, and evidence that supports assessment findings. Review implementation as systems, personnel, and service arrangements change.
Related reading covers Drata and Vanta compliance platforms, PreVeil integration, and digital footprint protection.
Tools and Resources CMMC Controls Implementation
CMMC implementation requires security safeguards, documented responsibilities, and evidence that applicable requirements are met. Select tools based on your required CMMC level, assessment scope, and existing systems. Purchasing software does not establish compliance.
Tools and Resources for Effective Implementation
The following eight resources can support implementation and assessment preparation:
- CMMC Assessment Guides and Checklists: Use the official scoping and assessment guides for your required level. For Level 2, checklists should reflect the 110 requirements in NIST SP 800-171 Revision 2 and their assessment objectives. The NIST Cybersecurity Framework can support broader security planning but does not replace CMMC assessment criteria.
- Compliance Management Software: Use these platforms to assign control owners, organize evidence, track corrective actions, and schedule reviews. Check that collected evidence reflects actual implementation. A platform’s readiness score is not an official CMMC assessment result.
- Identity and Endpoint Management Tools: Manage user accounts, access permissions, device configurations, and malicious code protection. Configure authentication and access restrictions to satisfy applicable requirements, and promptly remove access that is no longer authorized.
- Security Information and Event Management Systems: SIEM tools can centralize logs and help staff investigate suspicious activity. Define relevant log sources, review responsibilities, retention periods, and access protections. CMMC does not mandate purchasing a particular SIEM product.
- Vulnerability Assessment Tools: Scan applicable systems for vulnerabilities, prioritize corrective work according to risk, and verify fixes through follow-up checks. Scanning supports security maintenance only when someone reviews the findings and takes action.
- Encryption and Key Management Solutions: Select encryption capabilities appropriate to the information and applicable requirements. For Level 2, cryptography used to protect CUI confidentiality must use FIPS-validated cryptographic modules. Verify the module’s validation and required configuration rather than relying on a vendor’s general encryption claims.
- Incident Response Management Tools: Track incidents, assign response tasks, preserve investigation records, and document recovery actions. Support these tools with defined reporting procedures, trained personnel, and exercises that test the response process.
- Qualified CMMC Implementation Support: A Cyber AB Registered Practitioner can assist with gap reviews and implementation planning for CMMC Level 1 and Level 2 requirements. Check the practitioner’s designation, relevant experience, and proposed deliverables. The RP designation alone does not authorize someone to conduct certification assessments.
Assign an owner to each implemented safeguard and retain evidence of its operation. Review tools and procedures when systems, service providers, or assessment scope change.
Conclusion: The Role of CMMC and NIST SP 800-171 in Defense Cybersecurity
CMMC and NIST SP 800-171 support the protection of sensitive information within the defense supply chain. NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems, while CMMC establishes assessment and affirmation requirements for verifying implementation. CMMC Level 2 uses the 110 requirements across 14 security families in NIST SP 800-171 Revision 2.
Defense contractors should confirm their contractual obligations, define their assessment scope, and address gaps in applicable safeguards.
Effective implementation requires working technical controls, documented procedures, trained personnel, and evidence that supports assessment findings.
Maintaining compliance requires continued attention to vulnerabilities, access permissions, system changes, and control effectiveness. These activities help contractors protect government information and maintain the cybersecurity status required for applicable contracts.
Bright Defense Provides CMMC Consulting and Advisory Services
Bright Defense helps small and medium-sized defense contractors prepare for CMMC assessments through gap reviews, remediation planning, documentation support, and ongoing compliance management.
Its advisory services help organizations turn applicable cybersecurity requirements into practical tasks with clear responsibilities.
Support includes the following four areas:
- Gap Assessment: Review existing safeguards and supporting evidence against the requirements of your applicable CMMC level.
- Remediation Planning: Prioritize deficiencies, assign responsibilities, and plan necessary changes to policies, technical controls, and employee training.
- Compliance Automation: Use platforms such as Drata to organize evidence, track corrective work, and monitor supported controls. Software supports assessment preparation but does not replace verification of implemented safeguards.
- Continuous Compliance: Review control performance, maintain documentation, and address changes that affect your cybersecurity program and assessment readiness.
Contact Bright Defense to discuss your CMMC requirements and develop a practical readiness plan.


