Top 10 CMMC Level 2 Requirements You Must Meet in 2025

Top 10 CMMC Level 2 Requirement

If you’re a contractor or subcontractor who does business with the U.S. Department of Defense (DoD), the year 2025 looks like a turning point. Why? Because the Cybersecurity Maturity Model Certification (CMMC) 2.0 standard is now fully implemented. And if you deal with Controlled Unclassified Information (CUI), compliance with CMMC Level 2 is no longer optional.

 

But what is Level 2, exactly? And how do you prepare to meet the standards before they impact your contracts? Here in this blog, we’re going to highlight the top 10 CMMC Level 2 requirements you need to meet in 2025 to remain compliant, competitive, and secure.

What is CMMC Level 2?

CMMC Level 2 is the mid-level of the CMMC 2.0 model. It’s tailored specifically for contractors that work with Controlled Unclassified Information (CUI). Whereas Level 1 addresses foundational cyber hygiene, Level 2 takes it a step further by mapping closely to NIST SP 800-171, a collection of 110 security controls designed to protect sensitive information.

 

Beginning in 2025, contractors handling CUI will need to either undergo a triennial third-party evaluation or, in certain situations, an annual self-evaluation, depending on the sensitivity of information to be handled.

Top 10 CMMC Level 2 Requirements You Need to Comply With in 2025

Access Control (AC): Restrict System Access

Controlling access to your systems is a building block. You must ensure that organizational systems and data can be accessed only by authorized users, processes, and devices. This means you should put in place role-based access and utilize multi-factor authentication (MFA).

 

Continuously review and update user permissions to avoid privilege creep.

Audit and Accountability (AU): Monitor and Log Activity

Auditing and logging are not IT jargon—they are requirements. You are required to implement audit logs for system events, user activity, and security incidents. These should be protected, stored securely, and reviewed regularly.

 

Effective auditing can detect malicious activity early and assist forensic investigations in the case of a breach.

Incident Response (IR): Prepare Incase of a Breach

You are required to possess and maintain an incident response plan with preparation, detection, containment, eradication, and recovery steps. Having the plan is not sufficient—you should periodically test it and train personnel on how to implement it.

 

If you do this once something has happened, it’s too late.

Identification and Authentication (IA): Authenticate User Identities

Every device, process, or user attempting to get into your systems needs to be uniquely identified and authenticated. This involves strong, one-time-only credentials and implementing MFA at every access point.

 

Utilize a password manager and implement complex password policies to minimize risk.

System & Communications Protection (SC): Protect Data in Transit

Savings data as it moves around your network is a must. CMMC Level 2 requirements use encryption and secure methods (like TLS) for data in transit. And also, separate sensitive communications and scan for unauthorized access.

 

If your data is interceptable, it’s already breached.

Configuration Management (CM): Secure System Settings

Misconfigured devices are a hacker’s dream world. CMMC demands that you possess and sustain secure configurations for both software and hardware. Turn off unused ports, reset default values, and stay current.

 

Create a configuration baseline and have compliance checks automated.

Media Protection (MP): Manage Physical and Digital Media

CMMC Level 2 also requires you to safeguard information on removable media and devices such as external hard drives, USB drives, and laptops, including disposal, storage, and encryption.

 

Shredding isn’t limited to paper. Use certified data destruction products on digital media too.

Physical Protection (PE): Secure Your Facility

Cybersecurity isn’t just digital. You also have to physically secure your infrastructure. This involves limiting access to buildings, rooms, and devices where CUI is stored or processed.

 

Think about using video monitoring and visitor logs to encourage accountability.

Personnel Security (PS): Vet Your People

Verify that people with access to CUI are secure and properly screened. Conduct background checks and use formal onboarding/offboarding processes to avoid insider threats.

 

Human error and insider threats continue to be the number-one causes of breaches.

Risk Assessment (RA): Know Your Threats

You can’t defend the unknown. Conduct regular risk assessments to identify, analyze, and mitigate possible cybersecurity threats. Document your findings and adjust your security posture based on evolving threats.

 

Use models like NIST or ISO to organize your risk assessments.

Final Thoughts

Time is running out. As of 2025, adherence to CMMC Level 2 will no longer be a “nice to have” but an absolute requirement for doing business with the DoD. The requirements may appear overwhelming, but they exist to protect national security and your business from debilitating cyber attacks. Have a read on the Top 10 Compliance Management Tools in 2025

 

If you have not, start conducting a gap analysis against NIST SP 800-171, create your System Security Plan (SSP), and prepare for the assessment process—a third-party audit or self-assessment.

 

Share the Post: