Access Control
Limits system access to authorized users, processes, and devices, and limits what each may do. Least privilege, session control, and control of CUI flow are the heart of it.
When your solicitation names Level 2, it is naming NIST SP 800-171. Level 2 protects Controlled Unclassified Information (CUI), and it requires implementing all 110 security requirements of NIST SP 800-171 (Rev 2), grouped into 14 control families. This page explains what those families cover, how they are assessed, and where the evidence lives.
NIST SP 800-171 is the federal standard for protecting CUI on the systems of a non-federal organization — a contractor. CMMC Level 2 does not invent new controls; it verifies that the 110 requirements of NIST SP 800-171 (Rev 2) are actually implemented. The 110 are organized into 14 families so they can be scoped, assigned, and assessed as coherent groups rather than a flat checklist.
The obligation is not new. DFARS 252.204-7012 has required contractors to implement NIST SP 800-171 for years. CMMC adds verification: at Level 2, for prioritized acquisitions involving CUI, an authorized C3PAO assesses your environment against these requirements rather than accepting a self-attestation.
A gap assessment turns "we think we're close" into a number: how many of the 110 requirements are met, and what the SPRS methodology makes of the gap. The dial below is an illustrative example.
Illustrative example only — not a specific client's score. Your posture is established by a scoped gap assessment against all 110 requirements.
Each family is a group of related requirements. Together they cover who gets in, what they can do, how it is watched, and what happens when something goes wrong. This is the map an assessor works from — and the map Atom remediates against.
Limits system access to authorized users, processes, and devices, and limits what each may do. Least privilege, session control, and control of CUI flow are the heart of it.
Ensures that users and administrators understand the security risks of their roles and are trained on the policies, procedures, and threats relevant to handling CUI.
Creates, protects, and retains audit logs so activity can be traced to an individual, and provides the review and analysis needed to detect misuse and support investigation.
Establishes and maintains baseline configurations and inventories, enforces secure settings, and controls changes so systems do not drift away from a known-good state.
Uniquely identifies users and devices and proves those identities before granting access — including multifactor authentication and disciplined credential management.
Builds the capability to prepare for, detect, analyze, contain, and recover from incidents — and to report them, which ties directly to the 72-hour DIBNet obligation under 7012.
Governs how systems are maintained — controlling tools, remote maintenance sessions, and the personnel who perform it — so upkeep does not become an attack path.
Protects CUI on digital and physical media: marking, access, transport, and sanitization or destruction before media is reused or disposed of.
Screens individuals before granting access to systems containing CUI and ensures that access is protected during and after personnel actions such as transfers and terminations.
Limits physical access to systems, equipment, and operating environments to authorized individuals, and controls and monitors visitors and physical media.
Periodically assesses risk to operations and assets, scans for vulnerabilities, and remediates them — turning a static posture into one that responds to changing threats.
Assesses controls periodically to confirm they work, produces and maintains the System Security Plan and POA&M, and monitors controls on an ongoing basis.
Monitors and protects communications at system boundaries, separates functions, and applies encryption so CUI is protected in transit and at rest.
Identifies and corrects flaws promptly, protects against malicious code, and monitors system security alerts — the day-to-day integrity of the environment.
For prioritized acquisitions that involve CUI, Level 2 is assessed by a Certified Third-Party Assessment Organization (C3PAO) rather than accepted as a self-assessment. A passing assessment is valid for a three-year cycle, with an annual affirmation recorded in SPRS in between. The assessor does not grade intentions — they test whether each of the 110 requirements is implemented and evidenced.
Two documents anchor that evidence. The System Security Plan (SSP) describes your environment and how each requirement is met. The Plan of Action & Milestones (POA&M) tracks the requirements not yet fully met, each with an owner and a target date. A limited set of lower-weighted requirements may be POA&M-eligible with a closeout window; the highest-weighted must be met outright.
Atom is not a C3PAO and does not issue the certification. We map our managed services to the 14 families, remediate the gaps, and generate the artifacts an assessor will accept — then keep the controls operating between assessments.
MFA, least privilege, conditional access, and joiner/mover/leaver processes cover Access Control and Identification & Authentication.
AC • IA
Our 24/7 SOC handles logging, monitoring, and incident handling — Audit & Accountability, Incident Response, and System & Information Integrity.
AU • IR • SI
Baseline configuration, secure defaults, and controlled change management cover Configuration Management and Maintenance.
CM • MA
Encryption in transit and at rest, boundary monitoring, and CUI media handling cover System & Communications Protection and Media Protection.
SC • MP
Awareness training, personnel security processes, and physical protection guidance cover AT, Personnel Security, and Physical Protection.
AT • PS • PE
Our vCISO authors the SSP and POA&M, runs vulnerability and risk assessments, and monitors controls — Risk Assessment and Security Assessment.
RA • CA
The levels, the phased rollout, and the readiness path — the full picture the 110 controls sit inside.
How the 110 requirements are weighted into a single SPRS score primes can see — and what a POA&M does to it.
Request a readiness assessment. We’ll scope your CUI boundary, score you against every requirement in all 14 families, and hand you a prioritized, dated path to Level 2.
Request a Readiness Assessment →