CMMC Level 2 Self-Assessment Guide for North Carolina Contractors
A practical, evidence-focused guide for primes and subcontractors that handle CUI
For North Carolina defense contractors, a CMMC Level 2 self-assessment is more than a cybersecurity checklist. It is a documented evaluation of whether the systems, people, facilities, and service providers within a defined assessment scope satisfy the 110 security requirements in NIST Special Publication 800-171 Revision 2. When a solicitation or contract requires CMMC Level 2 (Self), the contractor must achieve the required status and submit the applicable information and affirmation in the Supplier Performance Risk System (SPRS).
That makes preparation a business issue as well as an IT issue. A weak scope can pull unnecessary systems into the assessment. A policy that exists only on paper may fail when the team cannot demonstrate how it operates. A score entered without defensible evidence can expose senior leadership to avoidable risk when an authorized official affirms continuing compliance.
This guide explains how to approach a CMMC self-assessment methodically, what evidence to assemble, how scoring and Plans of Action and Milestones (POA&Ms) work, and when to bring in outside help before a contract deadline.
What CMMC Level 2 Means
CMMC Level 2 applies to the protection of Controlled Unclassified Information (CUI) in nonfederal systems. CUI is unclassified information that the government creates or possesses, or that an organization creates or possesses for or on behalf of the government, and that requires safeguarding or dissemination controls under law, regulation, or government-wide policy.
Under 32 CFR Part 170, the CMMC Level 2 security baseline is the 110 requirements in NIST SP 800-171 Revision 2. Although NIST has published Revision 3 of SP 800-171, the current CMMC regulation incorporates Revision 2. A contractor should not quietly substitute Revision 3 when calculating its CMMC Level 2 result. It can plan for newer NIST guidance separately, but its CMMC assessment should follow the version and assessment method incorporated by the rule and required by the contract.
Level 2 has two assessment paths:
- Level 2 (Self): The organization assesses its own environment and submits the result in SPRS.
- Level 2 (C3PAO): An authorized or accredited CMMC Third-Party Assessment Organization conducts the certification assessment.
The solicitation or contract determines the required CMMC status. Processing CUI does not give a contractor the freedom to choose self-assessment when the procurement requires a C3PAO assessment. Conversely, a readiness consultant or managed service provider cannot issue a CMMC certificate unless it is acting through the authorized CMMC ecosystem in the role permitted by the rule.
Why This Matters in North Carolina
North Carolina’s defense economy includes manufacturers, engineering firms, technology companies, research organizations, construction businesses, and specialized suppliers supporting prime contractors and military installations. The Economic Development Partnership of North Carolina reports eight military installations and $8.5 billion in federal DoD contracts awarded in the state in 2025. Research Triangle Park also connects Raleigh, Cary, and Durham businesses to a broader aerospace, technology, and federal-contractor ecosystem.
A company does not need to manufacture a weapons system to encounter CUI. Engineering drawings, technical specifications, controlled research data, maintenance information, software, and contract performance records can all create handling obligations when they meet the applicable CUI definition and contract terms. Subcontractors must also pay close attention to flowdowns from prime contractors.
The immediate question is therefore not, “Are we a large defense company?” It is, “What information will we receive or create under this contract, where will it move, and what CMMC status does the contract require?”
Before You Start: Confirm the Requirement
Do not launch a full Level 2 project based only on a customer email or a general reference to “CMMC compliant.” Begin with the contractual record.
Review the solicitation, contract, task order, option, and relevant flowdowns for:
- The required CMMC level and assessment type.
- DFARS clauses, especially 252.204-7012, 252.204-7020, and 252.204-7021 when included.
- Whether the company will process, store, or transmit CUI.
- Which locations, business units, systems, and subcontractors will support performance.
- The date by which the required status must be current.
The current DFARS CMMC clause requires contractors to maintain the stated CMMC status for covered systems used in performance, provide applicable CMMC unique identifiers, maintain annual affirmations, and flow appropriate requirements to subcontractors that will handle FCI or CUI. Your contracting officer, prime contractor, or qualified counsel can clarify ambiguous contractual obligations; your IT provider should not unilaterally interpret unclear contract language.
An Eight-Step CMMC Level 2 Self-Assessment Process
1. Name an Executive Owner and Assessment Team
CMMC compliance crosses operations, HR, facilities, legal or contracts, and IT. Assign an executive sponsor with authority to resolve conflicts and fund remediation. Identify the senior-level Affirming Official who will ultimately attest to continuing compliance in SPRS. That person should understand what the assessment covers, how the conclusions were reached, and what open work remains.
Build a working team that includes the system owner, security lead, administrators, HR or personnel security, facilities, contract management, and representatives for external service providers. Define who collects evidence, who tests configurations, who approves policies, and who maintains the final record.
2. Trace CUI Before Drawing the Boundary
Scope is the foundation of a defensible CMMC self-assessment. Interview contract owners and users to trace CUI from receipt or creation through use, sharing, storage, backup, archiving, and disposal. Include email, collaboration platforms, file transfers, endpoints, removable media, print workflows, shop-floor or lab systems, remote work, and support tools.
For each flow, record:
- The CUI category and contractual source.
- Who can access it and for what purpose.
- The devices, applications, networks, and facilities it touches.
- Any cloud, managed service, backup, security, or other external provider involved.
- Where copies, logs, exports, temporary files, and backups may persist.
Do not assume that labeling a folder “CUI” contains the boundary. If CUI travels through ordinary corporate email, endpoints, identity systems, or backup infrastructure, those dependencies may become relevant to the scope.
3. Categorize Assets and Document the Scope
The Level 2 scoping rule identifies asset categories including CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets. Classification affects what must be documented and how an asset is assessed.
At minimum, produce an asset inventory, a network diagram, and an SSP that agree with one another. The inventory should identify owners, locations, functions, operating systems or platforms, and the applicable asset category. The diagram should show trust boundaries, CUI flows, remote connections, cloud services, security tools, and links to other networks.
Containment can reduce cost and complexity when it is designed around real workflows. A dedicated CUI enclave may be appropriate for some small and midsize contractors, but only if users can complete contract work without bypassing it. Scoping decisions should be documented and technically enforced, not based on intention alone.
4. Build or Refresh the System Security Plan
The System Security Plan (SSP) is the central narrative of the assessed environment. It should describe the boundary, operational environment, how each applicable requirement is implemented, and the relationships with other systems. It must reflect the environment that exists, not the environment planned for next quarter.
For each NIST 800-171 requirement, identify:
- The responsible owner.
- The policy or procedure that directs the activity.
- The technical or administrative implementation.
- The assets and users to which it applies.
- The evidence that proves it operates as described.
- Any shared responsibility with a cloud or external service provider.
An SSP is not a substitute for implementation. It is the map that lets an assessor connect requirements to real controls and evidence. An absent SSP is also one of the deficiencies that cannot be placed on a CMMC Level 2 POA&M for Conditional status.
5. Assess Every Objective Using Examine, Interview, and Test
Use the June 2018 NIST SP 800-171A procedures and the official CMMC Level 2 Assessment Guide. A requirement may contain multiple assessment objectives, and all applicable objectives must be satisfied for the requirement to be MET. One screenshot rarely proves an entire requirement.
Collect evidence in three complementary ways:
- Examine: Review policies, procedures, diagrams, configurations, tickets, logs, training records, access reviews, incident records, and vendor documentation.
- Interview: Ask personnel to explain what they do, when they do it, and how exceptions are handled.
- Test: Observe configurations or processes operating, such as disabling an account, restoring a backup, enforcing multifactor authentication, generating an audit log, or blocking unauthorized removable media.
Evidence should be current, attributable to the scoped environment, and easy to reproduce. Create an evidence index that maps each artifact to the relevant requirement and objective. Record the artifact owner, collection date, source system, and sensitivity. Protect the evidence repository because it may reveal security architecture, weaknesses, and administrative details.
6. Score Honestly and Separate Gaps From Proof Problems
The maximum Level 2 score is 110. When a requirement is NOT MET, the methodology subtracts one, three, or five points depending on the requirement. Because deductions can exceed the maximum, a score can be negative.
A requirement should not be marked MET because a product has been purchased, a policy template exists, or a remediation ticket is open. The implementation must satisfy every applicable assessment objective. “We do this, but cannot show it” is an evidence gap that still needs resolution before a defensible MET finding.
Maintain a findings register with four useful categories:
- Implemented and supported by sufficient evidence.
- Implemented but evidence is incomplete or inconsistent.
- Partially implemented.
- Not implemented.
This distinction prevents teams from buying more technology when the real issue is documentation, ownership, or repeatable execution. It also exposes controls that look complete at the tenant level but are not applied to every in-scope user, device, location, or service.
7. Use POA&Ms Only Where the Rule Allows Them
A POA&M is a time-limited remediation mechanism, not permission to defer foundational controls. Conditional Level 2 status is available only when the assessment score is at least 80% of 110, which is 88, and the open requirements meet the restrictions in 32 CFR 170.21.
In general, requirements worth more than one point cannot be placed on the CMMC POA&M, with a narrow exception for CUI encryption when encryption is used but is not FIPS-validated. Six additional requirements are specifically prohibited from a POA&M: controls concerning external connections, public release of CUI, the SSP, visitor escort, physical access logs, and management of physical access.
All permitted POA&M items must be remediated and verified in a closeout assessment within 180 days of the Conditional status date. Missing that window causes the Conditional status to expire. Build each action item with an owner, technical task, required evidence, dependency, budget, and completion date that leaves time for verification before day 180.
8. Submit to SPRS and Maintain the Status
The self-assessment result must be submitted in SPRS for the applicable assessment scope. The submission includes identifying and scope information, the assessment date, score, and POA&M status, as applicable. Confirm current PIEE/SPRS roles and submission instructions before the deadline rather than waiting until the technical work is complete.
An Affirming Official must submit an affirmation after the assessment, after achieving Final status, after a POA&M closeout assessment when applicable, and annually following the Final status date. A Final Level 2 (Self) status is generally current for three years under the contract clause, provided required annual affirmations remain current and there has been no relevant change that undermines compliance.
Treat the result as a point-in-time status supported by continuous operations. Preserve the assessment record, monitor control performance, update the SSP and inventory when the environment changes, review external providers, track staff transitions, and test incident response. Before adding a new cloud service, opening another facility, or changing identity or backup platforms, assess the effect on the CUI boundary and evidence set.
Common Self-Assessment Mistakes
Starting With the 110 Requirements Instead of the Data Flow
Without a defensible boundary, teams may assess too much, miss a CUI pathway, or apply evidence from the wrong environment. Start with the contract and CUI flow, then determine the asset scope.
Treating Policies as Proof of Operation
A policy may say access is reviewed quarterly, but an assessor will expect records showing that reviews occurred and exceptions were resolved. Match written requirements to configurations, records, interviews, and tests.
Ignoring Cloud and External Provider Responsibilities
Cloud providers, managed service providers, security platforms, and backup vendors can affect the assessment. For cloud services that process, store, or transmit CUI, the rule addresses FedRAMP Moderate authorization or equivalency and requires customer responsibilities to be documented in the SSP. Contracts, service descriptions, and customer responsibility matrices should align with the technical implementation.
Assuming a High SPRS Score Equals CMMC Readiness
A historical NIST 800-171 Basic Assessment and a CMMC Level 2 self-assessment are related, but teams should verify the current scope, assessment objectives, evidence, scoring rules, and affirmation obligations. A number in SPRS is not a substitute for an evidence-backed assessment record.
Waiting Until the Bid Deadline
Identity changes, network segmentation, FIPS-validated encryption, logging, incident response, and vendor transitions can take months. Starting early gives the business options. Starting late forces rushed scope decisions and brittle evidence.
CMMC Level 2 Readiness Checklist
Before leadership approves submission, confirm that the organization can answer yes to each question:
- Does the contract record clearly identify the required CMMC level and assessment type?
- Have we identified the CUI categories and traced every approved CUI workflow?
- Do the asset inventory, network diagram, SSP, and actual environment match?
- Have all 110 NIST SP 800-171 Revision 2 requirements been assessed at the objective level?
- Can each MET conclusion be supported through appropriate examination, interview, or testing?
- Are cloud and external provider responsibilities documented and verified?
- Is the score calculated under the current CMMC scoring methodology?
- Do any POA&M items satisfy every eligibility restriction and fit inside the 180-day closeout window?
- Has the Affirming Official reviewed the scope, findings, score, and ongoing obligations?
- Are the team, account access, and records ready for the SPRS submission and annual affirmation cycle?
If any answer is uncertain, the next step is not to guess. It is to validate the gap, assign an owner, and create evidence that can withstand review.
When a CMMC Gap Assessment Helps
An independent readiness review is useful when your team is unsure about the CUI boundary, has inherited an old SSP or SPRS score, relies heavily on cloud and external providers, or faces a near-term solicitation. A gap assessment should connect technical controls, documentation, operations, and evidence. Its output should give leadership a prioritized remediation plan rather than another generic checklist.
Computerbilities can help North Carolina contractors evaluate their current environment against CMMC Level 2 readiness needs, identify technical and documentation gaps, and organize remediation around the systems that support contract performance. Computerbilities does not determine the CMMC level in your contract or replace an authorized C3PAO when a certification assessment is required.
Book a CMMC gap assessment to map your CUI environment, test the strength of your evidence, and build a practical remediation roadmap before a bid, option, or customer deadline.
Frequently Asked Questions
Is every CMMC Level 2 assessment a self-assessment?
No. Level 2 includes a self-assessment path and a C3PAO certification-assessment path. The solicitation or contract states which status is required. DoD may require Level 2 (C3PAO) instead of Level 2 (Self) for an applicable procurement.
How many requirements are in a CMMC Level 2 self-assessment?
CMMC Level 2 uses 110 security requirements from NIST SP 800-171 Revision 2. Each requirement can include multiple assessment objectives that must be evaluated using the applicable NIST SP 800-171A procedures and CMMC guidance.
What score is needed for Conditional Level 2 (Self) status?
The score must be at least 80% of the 110 Level 2 requirements, or 88, and every open item must be eligible for a POA&M. A score of 88 alone does not make the organization eligible if a prohibited or higher-value requirement remains open.
How long do we have to close a CMMC Level 2 POA&M?
Permitted POA&M items must be remediated and verified through a closeout assessment within 180 days of the Conditional status date. If closeout is not completed in time, the Conditional status expires.
How often is a CMMC Level 2 self-assessment required?
Final Level 2 (Self) status is generally valid for three years, while the Affirming Official must affirm continuing compliance in SPRS annually. Contract terms, material changes, or a government assessment may affect the practical timing, so contractors should monitor both the rule and their specific awards.
Did the 2026 Phase II suspension cancel CMMC self-assessments?
No. The July 13, 2026 DoD announcement says the transition to Phase II and future implementation milestones were suspended for review, but it also says Phase I self-assessment requirements remain in place. Review current contract language and official updates because the program is under active review.
Can Computerbilities certify our company for CMMC Level 2?
A Level 2 certification assessment must be conducted by an authorized or accredited C3PAO. Computerbilities can support readiness, scoping, technical remediation, documentation, and evidence preparation, but readiness support is not a CMMC certificate.