CMMC 2.0: tracing software engineering practice to a specific control, not a narrative

Standard & Framework · CMMC 2.0

CMMC 2.0 Level 2 requires 110 practices mapped to NIST SP 800-171, and your system security plan must name an evidence artifact for each one, because the SPRS score is a mechanical deduction for every unmet practice.

What does CMMC 2.0 Level 2 require of software engineering practice?

CMMC 2.0 Level 2 requires 110 practices mapped to NIST SP 800-171. Your system security plan must name an evidence artifact for each one, because the SPRS score deducts points for every unmet practice.

CMMC 2.0 Level 2 is assessed by a C3PAO for critical programs and self-assessed (feeding an SPRS score) otherwise. "We follow good security practices" isn't a CMMC answer.

Three levels, one underlying requirement: name the evidence

LevelScopeAssessment
Level 1 — Foundational17 practices, basic safeguarding of FCIAnnual self-assessment
Level 2 — Advanced110 practices, aligned to NIST SP 800-171, protecting CUISelf-assessment or C3PAO third-party assessment, depending on program criticality
Level 3 — ExpertLevel 2 plus a subset of NIST SP 800-172 enhanced practicesGovernment-led assessment

SPRS scoring is arithmetic, not judgment

For GovCon contractors, the Supplier Performance Risk System (SPRS) score starts at 110 and subtracts a fixed point value for each NIST SP 800-171 practice left open in the POA&M — some practices are worth more points than others. That means the highest-leverage remediation work is whichever unmet practice has the largest point value, not whichever is easiest to fix or alphabetically first — a software engineering team scoping a remediation sprint should sort by point value, not effort.

Practice-to-evidence traceability, worked

PracticeEvidence artifact (not a narrative)
AC.L2-3.1.1 — Limit system access to authorized usersIAM policy export + access-review log with timestamps
AU.L2-3.3.1 — Create and retain system audit logsAppend-only audit-log schema + retention configuration (see this cluster's observability practice for the schema pattern)
CM.L2-3.4.1 — Establish baseline configurationsInfrastructure-as-code repository + config-drift detection output

Engineering reference only. Not formal regulatory counsel. Consult the current CMMC model documentation and your C3PAO for a specific assessment.

Artifact: cmmc-practice-evidence-ledger-template.md

Generated client-side; no server round-trip, no account required.

# CMMC Practice-to-Evidence Ledger (template, v1.0.0)

One row per CMMC Level 2 practice (aligned to NIST SP 800-171). Engineering
reference template only.

| Practice ID | Practice (short) | Implementation evidence | SPRS score contribution | Status |
|---|---|---|---|---|
| AC.L2-3.1.1 | Limit system access to authorized users | IAM policy + access review log | | Met / Partially met / Not met |
| AU.L2-3.3.1 | Create and retain system audit logs | Append-only audit-log schema + retention config | | |
| CM.L2-3.4.1 | Establish baseline configurations | IaC repository + config-drift detection | | |
| IR.L2-3.6.1 | Establish an incident-response capability | IR plan + tested runbook | | |
| SC.L2-3.13.1 | Monitor and control communications at boundaries | Firewall/segmentation config + logs | | |

## Notes
- SPRS (Supplier Performance Risk System) scoring is 110 minus a weighted
  deduction per unmet practice -- unmet practices with the largest point
  values should be prioritized first, not addressed alphabetically.
- Evidence column should point to an artifact (config file, log query,
  policy document with a version/date), never a narrative claim.

Download cmmc-practice-evidence-ledger-template.md

Provenance & review state

Last reviewed
Sources
  • NIST SP 800-171 Rev. 2 — National Institute of Standards and Technology
  • CMMC 2.0 Model Overview — U.S. Department of Defense
Ingested from

Sign in or sign up

Enter your work email to receive a temporary sign-in link.

By continuing, you agree to our Terms of Service and Privacy Policy.