![]()

Key Takeaways
- CMMC Level 2 requires full implementation of all 110 NIST SP 800-171 controls – there is no partial credit, and missing even one can derail certification.
- Access Control (AC) and System & Communications Protection (SC) are the largest and most technically demanding domains, with AC alone carrying 22 requirements.
- AC.L2-3.1.11 (session termination) is one of the most commonly misunderstood controls – it is fundamentally different from session locking and trips up organizations that conflate the two.
- Scoping your CUI environment and building an accurate System Security Plan (SSP) are hidden prerequisites that most contractors underestimate before remediation even begins.
- Delaying preparation can substantially multiply remediation costs and compress the timeline with your C3PAO assessor – starting now is the clearest competitive advantage available.
If your organization handles Controlled Unclassified Information (CUI) on behalf of the Department of Defense, CMMC Level 2 compliance is not optional – it is the price of doing business. Understanding which controls create the most friction, and why, can make the difference between a clean assessment and a costly Plan of Action & Milestones (POA&M). What follows is a direct look at where organizations consistently struggle and what it actually takes to close those gaps.
110 Controls, Zero Partial Credit
CMMC Level 2 maps directly to all 110 security requirements in NIST SP 800-171. Every single one must be fully implemented – not planned, not partially in place, not documented without evidence. Assessments are binary: a control either passes or it does not. That reality alone separates Level 2 from nearly every other compliance framework most contractors have encountered. There is no sliding scale, no credit for good intentions, and no grace period built into the assessment itself.
The one narrow exception is the path to Conditional Status: organizations that score at least 88 out of 110 may defer remaining gaps to a POA&M, with a hard 180-day clock to close them. Certain high-weighted controls cannot be deferred at all. That means gaps still have to be triaged carefully – some will disqualify a POA&M path entirely.
Why CMMC Level 2 Hits Differently Than Level 1
Level 1 vs. Level 2: A Structural Difference
CMMC Level 1 covers the foundational cyber hygiene practices outlined in FAR 52.204-21 – things like antivirus, basic access control, and physical protection. Most contractors handling Federal Contract Information (FCI) at Level 1 find the requirements manageable with existing IT resources. Level 2 is a different category of problem entirely. The jump to 110 requirements is not incremental; it is a structural transformation of how an organization manages, documents, and proves its security posture.
The Binary Pass/Fail Reality
Where other frameworks allow maturity ratings or tiered scoring, CMMC Level 2 assessments treat every control as a hard line. A firewall rule that is 90% configured is a failed control. A session termination policy that exists in writing but is not enforced in Group Policy is a failed control. This pass/fail structure is intentional – the DoD concern is real-world breach prevention, not paperwork compliance. Organizations that treat CMMC like an audit checklist rather than an operational security standard consistently fail assessments for exactly this reason.
The Hardest Controls to Actually Implement
Access Control (AC): 22 Requirements, Maximum Exposure
Access Control is the largest domain in CMMC Level 2 with 22 distinct requirements. It governs everything from least privilege and remote access enforcement to controlling the flow of CUI across internal and external systems. The breadth of AC is what makes it high-risk – a gap in one sub-requirement can expose an entire network segment. Common failure points include inadequate privileged access management, inconsistent enforcement of role-based access, and remote access configurations that do not meet the specificity CMMC demands.
AC.L2-3.1.11: Session Termination Is Not Session Locking
This is one of the most misunderstood controls in the entire framework. AC.L2-3.1.11 (derived from NIST SP 800-171 control 3.1.11) requires the automatic termination of user sessions after a defined period of inactivity or upon meeting a specific condition. It is entirely distinct from AC.L2-3.1.10, which only requires session locking – meaning the screen locks but the session stays alive in the background.
Why does the distinction matter? A locked session still holds active credentials, open connections, and potentially cached data. A terminated session closes all of that out. For environments handling CUI, an orphaned authenticated session represents a real attack surface. The remediation challenge is practical: in shared terminal environments or workflows with long-running background processes, configuring automatic logoff through Group Policy or equivalent tools without interrupting legitimate operations requires careful scoping and testing. Many organizations configure screen lock and mistakenly mark 3.1.11 as satisfied – it is not.
System & Communications Protection (SC): 16 High-Stakes Rules
The SC domain carries 16 requirements focused on network architecture, data-in-transit encryption, boundary protection, and denial-of-service resilience. Controls like SC.L2-3.13.8 (cryptographic protections for CUI during transmission) and SC.L2-3.13.5 (network segmentation between public and operational systems) are technically demanding and expensive to retrofit into legacy environments. Organizations that built their infrastructure before CUI handling was a concern often face the most remediation effort here, because SC controls frequently require architectural changes – not just configuration tweaks.
Documentation Gaps That Sink Assessments
The SSP Problem Most Contractors Overlook
A recurring theme in failed CMMC assessments is the gap between what is written and what is actually running. The System Security Plan (SSP) is the foundational document that maps every control to its implementation – and it must be accurate, current, and verifiable by an assessor looking at real evidence, not just stated intent.
Documentation development – including the SSP, policies, procedures, and supporting evidence – is estimated to cost between $12,000 and $70,000 depending on organizational size and existing documentation maturity. That is before any technical remediation begins. The SSP is the lens through which a C3PAO assessor evaluates every other control. An incomplete or inaccurate SSP is one of the fastest ways to fail an assessment even when the technical controls are properly implemented.
Scoping and CUI Identification: The Hidden Starting Point
Before any control can be implemented, an organization has to know exactly where CUI lives. This sounds straightforward – it is not. CUI can exist in email threads, shared drives, portable media, engineering drawings, procurement data, and contractor communications. Defining the boundary of the CMMC assessment scope, identifying every system that touches CUI, and securing management buy-in on that scope are consistently cited as top challenges for small and medium-sized businesses in the Defense Industrial Base.
Scoping errors are expensive in both directions. Too narrow a scope and an assessor will flag systems that should have been included. Too broad a scope and the remediation cost balloons unnecessarily. Getting this right at the start – with a rigorous CUI identification exercise and a defensible asset inventory – is the prerequisite that makes every downstream control implementable and assessable.
What CMMC Level 2 Compliance Actually Costs
SMB vs. Enterprise: The Wide Cost Range
Total investment for CMMC Level 2 compliance typically ranges from $50,000 to $200,000+ for small to mid-sized contractors. Larger defense primes or organizations with complex multi-site environments can exceed $2,000,000 when accounting for infrastructure upgrades, tooling, personnel, documentation, and third-party assessment fees. The variance depends heavily on the current security baseline, the size of the CUI environment, and how much technical debt the organization is carrying.
Why Delaying Multiplies the Price
Waiting is not a neutral decision. Organizations that delay CMMC preparation face substantially higher remediation costs than those who start early – a product of compressed timelines, limited assessor availability, and the elevated cost of emergency remediation work. With DoD contract requirements rolling out across the supply chain, the window to prepare on a reasonable timeline is narrowing. Every month of delay is a month of compressed options and inflated costs.
How Stealth-ISS Closes the Gaps Faster
CMMC-in-a-Box: A-La-Carte, Not One-Size-Fits-All
No two contractors start from the same place. A manufacturer with a mature IT environment has completely different gaps than a small engineering firm running shared workstations. CMMC-in-a-Box, offered through Stealth-ISS Group, is built around that reality – delivering customized bundles of gap assessment, remediation, policy development, and managed security services scoped specifically to what an organization actually needs, rather than forcing every client through an identical engagement model. That distinction matters when budget is finite and the gap list is long.
The approach addresses the hardest parts of the compliance process – from SSP development and CUI scoping to technical controls like MFA, email encryption, continuous monitoring, and CMMC Enclave implementation for organizations that need a segmented CUI environment. The emphasis is on building a compliance-ready operational posture, not just producing documentation.
CCAs and CCPs on Your Team
Having access to Certified CMMC Assessors (CCAs) and Certified CMMC Practitioners (CCPs) during preparation – rather than only at formal assessment – is a significant advantage. Remediation decisions informed by the same methodology an assessor will apply reduce the risk of building out controls that satisfy intent but miss specific evidence requirements. Stealth-ISS leadership includes personnel with deep, early-stage training in CMMC requirements, methodology, and scoping – institutional knowledge that translates directly into faster, more targeted gap closure.
Start Remediation Now Before the 180-Day Clock Runs Out
The 180-day POA&M window sounds generous – until it is already running. Organizations that enter an assessment underprepared, earn Conditional Status, and then race to close remaining gaps in six months routinely discover that the hardest controls to implement are also the ones that were deferred. AC.L2-3.1.11, SC domain requirements, SSP accuracy, and CUI scoping do not get easier under time pressure. They get more expensive and more disruptive.
The clearest path through CMMC Level 2 is preparation that starts well before the assessment date – with a realistic gap analysis, a defensible scope, accurate documentation, and technical controls that are configured, tested, and evidenced. That is not a one-time project; it is an operational shift. The organizations that treat it as such are the ones that pass.
For DoD contractors ready to build a defensible, audit-ready CMMC program, Stealth-ISS Group provides the cybersecurity expertise and certified CMMC professionals to close gaps efficiently and keep DIB organizations competitive for the contracts ahead.
Stealth-ISS
610 E Zack St. Suite 110-4165
Tampa
FL
33602
United States