Atom Cybersecurity — two practices, one standard
Reference • NIST SP 800-171 Rev 2 • CMMC Level 2

The 110 controls behind CMMC Level 2.

When your solicitation names Level 2, it is naming NIST SP 800-171. Level 2 protects Controlled Unclassified Information (CUI), and it requires implementing all 110 security requirements of NIST SP 800-171 (Rev 2), grouped into 14 control families. This page explains what those families cover, how they are assessed, and where the evidence lives.

What Level 2 requires

One standard, 110 requirements, 14 families.

NIST SP 800-171 is the federal standard for protecting CUI on the systems of a non-federal organization — a contractor. CMMC Level 2 does not invent new controls; it verifies that the 110 requirements of NIST SP 800-171 (Rev 2) are actually implemented. The 110 are organized into 14 families so they can be scoped, assigned, and assessed as coherent groups rather than a flat checklist.

The obligation is not new. DFARS 252.204-7012 has required contractors to implement NIST SP 800-171 for years. CMMC adds verification: at Level 2, for prioritized acquisitions involving CUI, an authorized C3PAO assesses your environment against these requirements rather than accepting a self-attestation.

  • 110 security requirements — every one is in scope for a Level 2 assessment; there is no partial family.
  • 14 control families — the organizing structure below, from Access Control to System & Information Integrity.
  • NIST SP 800-171 Rev 2 — the revision Level 2 currently measures against.
  • Weighted scoring — requirements carry point values in the SPRS methodology; the highest-weighted must be met outright.
Readiness posture

What a score against the 110 looks like.

A gap assessment turns "we think we're close" into a number: how many of the 110 requirements are met, and what the SPRS methodology makes of the gap. The dial below is an illustrative example.

92of 110 met

Illustrative example only — not a specific client's score. Your posture is established by a scoped gap assessment against all 110 requirements.

The reference

The 14 control families of NIST SP 800-171.

Each family is a group of related requirements. Together they cover who gets in, what they can do, how it is watched, and what happens when something goes wrong. This is the map an assessor works from — and the map Atom remediates against.

ACAccess Control
ATAwareness & Training
AUAudit & Accountability
CMConfiguration Management
IAIdentification & Authentication
IRIncident Response
MAMaintenance
MPMedia Protection
PSPersonnel Security
PEPhysical Protection
RARisk Assessment
CASecurity Assessment
SCSystem & Communications Protection
SISystem & Information Integrity
01

Access Control

Limits system access to authorized users, processes, and devices, and limits what each may do. Least privilege, session control, and control of CUI flow are the heart of it.

02

Awareness & Training

Ensures that users and administrators understand the security risks of their roles and are trained on the policies, procedures, and threats relevant to handling CUI.

03

Audit & Accountability

Creates, protects, and retains audit logs so activity can be traced to an individual, and provides the review and analysis needed to detect misuse and support investigation.

04

Configuration Management

Establishes and maintains baseline configurations and inventories, enforces secure settings, and controls changes so systems do not drift away from a known-good state.

05

Identification & Authentication

Uniquely identifies users and devices and proves those identities before granting access — including multifactor authentication and disciplined credential management.

06

Incident Response

Builds the capability to prepare for, detect, analyze, contain, and recover from incidents — and to report them, which ties directly to the 72-hour DIBNet obligation under 7012.

07

Maintenance

Governs how systems are maintained — controlling tools, remote maintenance sessions, and the personnel who perform it — so upkeep does not become an attack path.

08

Media Protection

Protects CUI on digital and physical media: marking, access, transport, and sanitization or destruction before media is reused or disposed of.

09

Personnel Security

Screens individuals before granting access to systems containing CUI and ensures that access is protected during and after personnel actions such as transfers and terminations.

10

Physical Protection

Limits physical access to systems, equipment, and operating environments to authorized individuals, and controls and monitors visitors and physical media.

11

Risk Assessment

Periodically assesses risk to operations and assets, scans for vulnerabilities, and remediates them — turning a static posture into one that responds to changing threats.

12

Security Assessment

Assesses controls periodically to confirm they work, produces and maintains the System Security Plan and POA&M, and monitors controls on an ongoing basis.

13

System & Communications Protection

Monitors and protects communications at system boundaries, separates functions, and applies encryption so CUI is protected in transit and at rest.

14

System & Information Integrity

Identifies and corrects flaws promptly, protects against malicious code, and monitors system security alerts — the day-to-day integrity of the environment.

How the 110 are assessed

A C3PAO, a three-year cycle, and two documents that carry the evidence.

For prioritized acquisitions that involve CUI, Level 2 is assessed by a Certified Third-Party Assessment Organization (C3PAO) rather than accepted as a self-assessment. A passing assessment is valid for a three-year cycle, with an annual affirmation recorded in SPRS in between. The assessor does not grade intentions — they test whether each of the 110 requirements is implemented and evidenced.

Two documents anchor that evidence. The System Security Plan (SSP) describes your environment and how each requirement is met. The Plan of Action & Milestones (POA&M) tracks the requirements not yet fully met, each with an owner and a target date. A limited set of lower-weighted requirements may be POA&M-eligible with a closeout window; the highest-weighted must be met outright.

How SPRS scoring weights the 110 →

  • C3PAO assessment — a third party, not Atom, issues the Level 2 certification.
  • Three-year validity — with annual affirmation in SPRS between assessments.
  • SSP — the authoritative description of how all 110 are implemented.
  • POA&M — the tracked, dated plan for anything not yet fully met.
  • Evidence over assertion — assessors test artifacts, not claims.
How Atom maps to the families

We operate the controls the 14 families demand.

Atom is not a C3PAO and does not issue the certification. We map our managed services to the 14 families, remediate the gaps, and generate the artifacts an assessor will accept — then keep the controls operating between assessments.

01

Identity & access

MFA, least privilege, conditional access, and joiner/mover/leaver processes cover Access Control and Identification & Authentication.

AC • IA

02

Detection & response

Our 24/7 SOC handles logging, monitoring, and incident handling — Audit & Accountability, Incident Response, and System & Information Integrity.

AU • IR • SI

03

Hardening & change

Baseline configuration, secure defaults, and controlled change management cover Configuration Management and Maintenance.

CM • MA

04

Data & boundary protection

Encryption in transit and at rest, boundary monitoring, and CUI media handling cover System & Communications Protection and Media Protection.

SC • MP

05

Governance & people

Awareness training, personnel security processes, and physical protection guidance cover AT, Personnel Security, and Physical Protection.

AT • PS • PE

06

Assessment & risk

Our vCISO authors the SSP and POA&M, runs vulnerability and risk assessments, and monitors controls — Risk Assessment and Security Assessment.

RA • CA

See the managed services behind each family →

Keep reading

Related reading.

CMMC 2.0, end to end

The levels, the phased rollout, and the readiness path — the full picture the 110 controls sit inside.

Read the CMMC 2.0 overview →

How SPRS scoring works

How the 110 requirements are weighted into a single SPRS score primes can see — and what a POA&M does to it.

Read: SPRS scoring explained →

Start with the facts

Know where you stand against all 110.

Request a readiness assessment. We’ll scope your CUI boundary, score you against every requirement in all 14 families, and hand you a prioritized, dated path to Level 2.

Request a Readiness Assessment