by Nestor Soto

CMMC Level 2 Documentation: What You Actually Need

A practical guide to CMMC Level 2 System Security Plans, POA&Ms, evidence packages, and the current Phase I program status.

Small defense contractors and subcontractors face a daunting requirement: CMMC Level 2. The Cybersecurity Maturity Model Certification 2.0 framework requires 110 security controls aligned with NIST SP 800-171, supported by documentation and evidence for the applicable requirements.

You do not need an enterprise security team to start organizing the work. You do need accurate documentation that reflects the environment you actually operate and evidence that supports those statements.

This guide breaks down exactly what CMMC Level 2 documentation small defense contractors need, where to cut complexity, and how to build your documentation library without hiring a dozen consultants.

Need a starting point? Use the free Documentation Clarity Check to map what exists and what needs attention.

What Is CMMC Level 2?

CMMC 2.0 is the Department of Defense’s framework for protecting Controlled Unclassified Information (CUI) within the defense industrial base (DIB). Level 2 is the tier required for any contractor that handles CUI.

Level 2 aligns directly with the 110 security requirements in NIST SP 800-171 Rev. 2. The DoD’s official CMMC program information is available through the DoD CIO’s CMMC page.

As of August 2026, the department has suspended Phase II. Phase I remains in place: Level 2 uses an organization-led self-assessment every three years and an annual affirmation against the 110 NIST SP 800-171 Revision 2 requirements. Confirm current contract and program requirements on the official CMMC page before acting.

Small contractors have an advantage: simpler systems, fewer users, and less organizational baggage. The key is translating that simplicity into clear, concise documentation.

The Core CMMC Level 2 Documentation Requirements

A useful documentation library has four core categories. The exact materials depend on your system boundary, contract, and the way each applicable requirement is implemented.

1. System Security Plan (SSP)

The SSP is the crown jewel of CMMC documentation. It describes your system boundary, the CUI environment, and how you satisfy each of the 110 NIST 800-171 requirements.

Your SSP must include:

  • System boundary — what is in scope and what is not
  • Network diagram — with CUI flows clearly marked
  • Hardware and software inventory — every asset that touches CUI
  • System topology — how data moves between systems
  • Control mappings — how each of the 110 requirements is implemented
  • Roles and responsibilities — who owns security, IT, and compliance
  • Authorization boundary — signed by leadership

The SSP is not a one-and-done document. Update it whenever your system changes. Most small contractors maintain an SSP between 30 and 60 pages. Enterprise SSPs can run 200+ pages, but small contractors do not need that bloat.

If you are also building a SOC 2 documentation library, there is significant overlap between NIST 800-171 and the SOC 2 Security criteria. My SOC 2 Documentation Checklist breaks down how to reuse policies across frameworks.

2. Policies and Procedures

For every NIST 800-171 requirement that calls for a policy or procedure, you need a written document. That typically translates to 15–20 core policies.

  • Access Control Policy
  • Audit and Accountability Policy
  • Identification and Authentication Policy
  • Incident Response Policy
  • Media Protection Policy
  • Physical Protection Policy
  • Risk Assessment Policy
  • System and Communications Protection Policy
  • System and Information Integrity Policy
  • Configuration Management Policy
  • Contingency Planning Policy
  • Maintenance Policy
  • Personnel Security Policy
  • Security Assessment Policy

Organize policies around the NIST SP 800-171 requirement families, then map each statement to the specific Revision 2 requirement it supports. A policy does not replace implementation evidence.

3. Plan of Action and Milestones (POA&M)

Limited use of a POA&M may be permitted for Level 2, subject to the program rules. Not every requirement is eligible, so verify the current rule before relying on a remediation plan.

The POA&M tracks:

  • Deficiency description — what is missing or inadequate
  • NIST 800-171 reference — which requirement is affected
  • Date identified — when the gap was discovered
  • Remediation actions — specific steps to fix the gap
  • Milestone dates — when each step will be completed
  • Responsible party — who owns the remediation
  • Resources required — budget, tools, or personnel needed
  • Completion date — when the gap is closed

Under the current Phase I program information, permitted Level 2 POA&M items must be closed within 180 days. Track ownership, evidence, and completion dates, and verify the current rule on the official CMMC page.

4. Evidence and Artifacts

Policies and plans are promises. Evidence proves you keep them. For CMMC Level 2, you need artifacts like:

  • User access lists and quarterly access reviews
  • System configuration baselines and hardening checklists
  • Vulnerability scan results (monthly or quarterly)
  • Security awareness training records
  • Incident response logs and after-action reports
  • Backup and restoration test results
  • Multi-factor authentication (MFA) enrollment records
  • Encryption verification for data at rest and in transit
  • Visitor logs and physical access records
  • Change management tickets and approval chains

NIST SP 800-171 and CMMC 2.0 Mapping

A common question is: “If I am already aligned with NIST 800-171, am I CMMC Level 2 ready?”

The answer: mostly, but not automatically.

CMMC Level 2 uses the same 110 Revision 2 requirements. Under the current Phase I status, Level 2 uses an organization-led self-assessment every three years and an annual affirmation. The department may change implementation after its review, so verify the current status before planning an assessment.

Key differences:

  • CMMC requires objective evidence for every control, not just self-attestation
  • CMMC assessments include interviews with personnel; your team needs to know the policies
  • CMMC has scoring based on the number of deficiencies; some findings carry heavier weight
  • CMMC requires a current POA&M with realistic timelines

If you are starting from zero, download the official NIST SP 800-171 Rev. 2 document and use it as your control checklist. Map each requirement to your existing practices, identify gaps, and document everything.

Common Mistakes Small Contractors Make

Small defense contractors face limited IT staff, tight budgets, and systems that often evolved organically. These are common documentation mistakes to watch for:

1. Over-scoping the environment. Do not include your entire corporate network in the CUI boundary if only one segment handles CUI. A smaller, well-defined boundary is easier to document and assess.

2. Using enterprise templates blindly. A 50-person machine shop does not need the same policy depth as Lockheed Martin. Templates are starting points, not finished products. Adapt them to your size and risk profile.

3. Neglecting the POA&M. Some contractors treat the POA&M like a confession they want to hide. The opposite is true: a well-maintained POA&M shows maturity. Assessors prefer an honest POA&M to a facade of perfection.

4. Forgetting about subcontractors. If you share CUI with subcontractors, you need flow-down clauses and evidence that they also meet NIST 800-171. Document your due diligence.

5. Waiting until the last minute. Documentation takes time. Build a schedule from your actual scope, source readiness, review capacity, and current contract requirements.

Building Your Documentation on a Budget

You do not need a GRC platform to pass CMMC Level 2. Here is a realistic toolkit for small contractors:

Tool Purpose Cost
Microsoft Word / Google Docs Policies and SSP Free–$12/mo
Microsoft Excel / Google Sheets POA&M and asset inventory Free–$12/mo
Draw.io / Lucidchart Network diagrams Free–$10/mo
Shared Drive (Google/OneDrive) Evidence storage Free–$6/mo/user
Vulnerability scanner (OpenVAS / Nessus Essentials) Scanning and reports Free–$3k/yr

The most expensive part of CMMC is not software—it is labor. Someone has to write the documents, collect the evidence, and maintain the library. If your team lacks bandwidth, define the work carefully before engaging outside support.

Start with the Documentation Clarity Check

Use the free browser-based check to map your existing documents, likely gaps, owners, and next review questions before choosing a template or drafting approach.

Use the free Documentation Clarity Check →

Let’s Get You Assessment-Ready

CMMC implementation is currently paused in Phase I, but the obligation to protect covered information remains. Confirm the current clause and assessment requirements for each contract.

GoGoSoto can support a defined SSP, POA&M, control-narrative, or evidence-index package under a qualified partner’s direction. Documentation support does not guarantee an assessment or contract outcome.

Schedule a free CMMC documentation consultation →


Nestor Soto provides founder-led documentation support grounded in systems thinking, clear writing, and factual review. Read more at gogosoto.com.