CMMC 2.0: tracing software engineering practice to a specific control, not a narrative
Standard & Framework · CMMC 2.0
CMMC 2.0 Level 2 requires 110 practices mapped to NIST SP 800-171, and your system security plan must name an evidence artifact for each one, because the SPRS score is a mechanical deduction for every unmet practice.
What does CMMC 2.0 Level 2 require of software engineering practice?
CMMC 2.0 Level 2 requires 110 practices mapped to NIST SP 800-171. Your system security plan must name an evidence artifact for each one, because the SPRS score deducts points for every unmet practice.
CMMC 2.0 Level 2 is assessed by a C3PAO for critical programs and self-assessed (feeding an SPRS score) otherwise. "We follow good security practices" isn't a CMMC answer.
Three levels, one underlying requirement: name the evidence
| Level | Scope | Assessment |
|---|---|---|
| Level 1 — Foundational | 17 practices, basic safeguarding of FCI | Annual self-assessment |
| Level 2 — Advanced | 110 practices, aligned to NIST SP 800-171, protecting CUI | Self-assessment or C3PAO third-party assessment, depending on program criticality |
| Level 3 — Expert | Level 2 plus a subset of NIST SP 800-172 enhanced practices | Government-led assessment |
SPRS scoring is arithmetic, not judgment
For GovCon contractors, the Supplier Performance Risk System (SPRS) score starts at 110 and subtracts a fixed point value for each NIST SP 800-171 practice left open in the POA&M — some practices are worth more points than others. That means the highest-leverage remediation work is whichever unmet practice has the largest point value, not whichever is easiest to fix or alphabetically first — a software engineering team scoping a remediation sprint should sort by point value, not effort.
Practice-to-evidence traceability, worked
| Practice | Evidence artifact (not a narrative) |
|---|---|
| AC.L2-3.1.1 — Limit system access to authorized users | IAM policy export + access-review log with timestamps |
| AU.L2-3.3.1 — Create and retain system audit logs | Append-only audit-log schema + retention configuration (see this cluster's observability practice for the schema pattern) |
| CM.L2-3.4.1 — Establish baseline configurations | Infrastructure-as-code repository + config-drift detection output |
Engineering reference only. Not formal regulatory counsel. Consult the current CMMC model documentation and your C3PAO for a specific assessment.
Artifact: cmmc-practice-evidence-ledger-template.md
Generated client-side; no server round-trip, no account required.
# CMMC Practice-to-Evidence Ledger (template, v1.0.0)
One row per CMMC Level 2 practice (aligned to NIST SP 800-171). Engineering
reference template only.
| Practice ID | Practice (short) | Implementation evidence | SPRS score contribution | Status |
|---|---|---|---|---|
| AC.L2-3.1.1 | Limit system access to authorized users | IAM policy + access review log | | Met / Partially met / Not met |
| AU.L2-3.3.1 | Create and retain system audit logs | Append-only audit-log schema + retention config | | |
| CM.L2-3.4.1 | Establish baseline configurations | IaC repository + config-drift detection | | |
| IR.L2-3.6.1 | Establish an incident-response capability | IR plan + tested runbook | | |
| SC.L2-3.13.1 | Monitor and control communications at boundaries | Firewall/segmentation config + logs | | |
## Notes
- SPRS (Supplier Performance Risk System) scoring is 110 minus a weighted
deduction per unmet practice -- unmet practices with the largest point
values should be prioritized first, not addressed alphabetically.
- Evidence column should point to an artifact (config file, log query,
policy document with a version/date), never a narrative claim.
Useful next step
Provenance & review state
- Last reviewed
- Sources
-
- NIST SP 800-171 Rev. 2 — National Institute of Standards and Technology
- CMMC 2.0 Model Overview — U.S. Department of Defense
- Ingested from
-