CMMC Level 2 Documentation: What You Actually Need
A practical guide to CMMC Level 2 System Security Plans, POA&Ms, evidence packages, and the current Phase I program status.
A practical guide to CMMC Level 2 System Security Plans, POA&Ms, evidence packages, and the current Phase I program status.
Small defense contractors and subcontractors face a daunting requirement: CMMC Level 2. The Cybersecurity Maturity Model Certification 2.0 framework requires 110 security controls aligned with NIST SP 800-171, supported by documentation and evidence for the applicable requirements.
You do not need an enterprise security team to start organizing the work. You do need accurate documentation that reflects the environment you actually operate and evidence that supports those statements.
This guide breaks down exactly what CMMC Level 2 documentation small defense contractors need, where to cut complexity, and how to build your documentation library without hiring a dozen consultants.
Need a starting point? Use the free Documentation Clarity Check to map what exists and what needs attention.
CMMC 2.0 is the Department of Defense’s framework for protecting Controlled Unclassified Information (CUI) within the defense industrial base (DIB). Level 2 is the tier required for any contractor that handles CUI.
Level 2 aligns directly with the 110 security requirements in NIST SP 800-171 Rev. 2. The DoD’s official CMMC program information is available through the DoD CIO’s CMMC page.
As of August 2026, the department has suspended Phase II. Phase I remains in place: Level 2 uses an organization-led self-assessment every three years and an annual affirmation against the 110 NIST SP 800-171 Revision 2 requirements. Confirm current contract and program requirements on the official CMMC page before acting.
Small contractors have an advantage: simpler systems, fewer users, and less organizational baggage. The key is translating that simplicity into clear, concise documentation.
A useful documentation library has four core categories. The exact materials depend on your system boundary, contract, and the way each applicable requirement is implemented.
The SSP is the crown jewel of CMMC documentation. It describes your system boundary, the CUI environment, and how you satisfy each of the 110 NIST 800-171 requirements.
Your SSP must include:
The SSP is not a one-and-done document. Update it whenever your system changes. Most small contractors maintain an SSP between 30 and 60 pages. Enterprise SSPs can run 200+ pages, but small contractors do not need that bloat.
If you are also building a SOC 2 documentation library, there is significant overlap between NIST 800-171 and the SOC 2 Security criteria. My SOC 2 Documentation Checklist breaks down how to reuse policies across frameworks.
For every NIST 800-171 requirement that calls for a policy or procedure, you need a written document. That typically translates to 15–20 core policies.
Organize policies around the NIST SP 800-171 requirement families, then map each statement to the specific Revision 2 requirement it supports. A policy does not replace implementation evidence.
Limited use of a POA&M may be permitted for Level 2, subject to the program rules. Not every requirement is eligible, so verify the current rule before relying on a remediation plan.
The POA&M tracks:
Under the current Phase I program information, permitted Level 2 POA&M items must be closed within 180 days. Track ownership, evidence, and completion dates, and verify the current rule on the official CMMC page.
Policies and plans are promises. Evidence proves you keep them. For CMMC Level 2, you need artifacts like:
A common question is: “If I am already aligned with NIST 800-171, am I CMMC Level 2 ready?”
The answer: mostly, but not automatically.
CMMC Level 2 uses the same 110 Revision 2 requirements. Under the current Phase I status, Level 2 uses an organization-led self-assessment every three years and an annual affirmation. The department may change implementation after its review, so verify the current status before planning an assessment.
Key differences:
If you are starting from zero, download the official NIST SP 800-171 Rev. 2 document and use it as your control checklist. Map each requirement to your existing practices, identify gaps, and document everything.
Small defense contractors face limited IT staff, tight budgets, and systems that often evolved organically. These are common documentation mistakes to watch for:
1. Over-scoping the environment. Do not include your entire corporate network in the CUI boundary if only one segment handles CUI. A smaller, well-defined boundary is easier to document and assess.
2. Using enterprise templates blindly. A 50-person machine shop does not need the same policy depth as Lockheed Martin. Templates are starting points, not finished products. Adapt them to your size and risk profile.
3. Neglecting the POA&M. Some contractors treat the POA&M like a confession they want to hide. The opposite is true: a well-maintained POA&M shows maturity. Assessors prefer an honest POA&M to a facade of perfection.
4. Forgetting about subcontractors. If you share CUI with subcontractors, you need flow-down clauses and evidence that they also meet NIST 800-171. Document your due diligence.
5. Waiting until the last minute. Documentation takes time. Build a schedule from your actual scope, source readiness, review capacity, and current contract requirements.
You do not need a GRC platform to pass CMMC Level 2. Here is a realistic toolkit for small contractors:
| Tool | Purpose | Cost |
|---|---|---|
| Microsoft Word / Google Docs | Policies and SSP | Free–$12/mo |
| Microsoft Excel / Google Sheets | POA&M and asset inventory | Free–$12/mo |
| Draw.io / Lucidchart | Network diagrams | Free–$10/mo |
| Shared Drive (Google/OneDrive) | Evidence storage | Free–$6/mo/user |
| Vulnerability scanner (OpenVAS / Nessus Essentials) | Scanning and reports | Free–$3k/yr |
The most expensive part of CMMC is not software—it is labor. Someone has to write the documents, collect the evidence, and maintain the library. If your team lacks bandwidth, define the work carefully before engaging outside support.
Use the free browser-based check to map your existing documents, likely gaps, owners, and next review questions before choosing a template or drafting approach.
Use the free Documentation Clarity Check →
CMMC implementation is currently paused in Phase I, but the obligation to protect covered information remains. Confirm the current clause and assessment requirements for each contract.
GoGoSoto can support a defined SSP, POA&M, control-narrative, or evidence-index package under a qualified partner’s direction. Documentation support does not guarantee an assessment or contract outcome.
Schedule a free CMMC documentation consultation →
Nestor Soto provides founder-led documentation support grounded in systems thinking, clear writing, and factual review. Read more at gogosoto.com.