What's CMMC compliance, and what does Level 2 require?
CMMC is a set of compliance regulations the DoD uses to assess how well defense contractors detect, prevent, and address cybersecurity threats. The DoD's Supplier Performance Risk System (SPRS) stores your self-assessment scores and CMMC assessment results for the three CMMC levels. Most contractors strive for Level 2.
Note: Level 3 requires highly advanced cybersecurity techniques, so it's out of reach for most organizations.
CMMC Level 1 requirements
CMMC Level 1 is the most basic compliance level. It means you can handle low-risk Federal Contract Information (FCI), such as administrative records or non-sensitive financial information.
To qualify, you complete a self-assessment against 15 basic safeguarding requirements from FAR 52.204-21 and submit your results in SPRS each year.
CMMC Level 2 requirements and where organizations typically fall short
CMMC Level 2 means you can bid for projects involving controlled unclassified information (CUI). This includes technical military data and security vulnerabilities.
Level 2 CMMC is far more thorough than Level 1. It requires you and your subcontractors to implement 110 different security controls. The National Institute of Standards and Technology (NIST) sets these regulations in its NIST SP 800-171 guidelines.
You can still gain limited access to some DoD contracts even if you don't score a perfect 110, but the majority of jobs require full compliance.
The most common reason companies fall short is their lack of a dedicated security operations center (SOC) that provides continuous monitoring, log management, and formal strategy documents. Examples of these documents are a System Security Plan (SSP) or a Plan of Action and Milestones (PoA&M).
A managed solution, like Huntress, fills those gaps without adding to your head count or complicating your cybersecurity setup.