• Client Portal
  • Remote Connect
  • Sales: 844.TEL.RAIN
  • info@rain.tech
  • About Us
    • Testimonials
    • Careers
  • Solutions
    • AI Services
    • Cybersecurity
    • Infrastructure Management
    • Backups and Disaster Recovery
    • Cloud Solutions
    • Compliance
    • Service Desk
    • Microsoft Services
    • IT Projects
    • Database/ERP
    • Business Intelligence
    • vCIO
  • Industries
    • Federally Qualified Health Centers
    • Healthcare
    • Construction
    • Nonprofit
    • Private Equity
    • Education
  • Resources
    • Blog
    • Case Studies
    • Webinars
    • In the News
  • Let’s Connect
  • Menu Menu

CMMC 2.0 Level 2 Checklist: Policies, POA&Ms, and SPRS Requirements

November 11, 2025/in Blogs, CMMC, Construction, Cybersecurity/by RainTech

Why This Matters Now

The CMMC Level 2 checklist has never been more important. The CMMC Program final rule (32 CFR Part 170) is now in effect, and the DoD is implementing CMMC in contracts via a DFARS/48 CFR acquisition rule. This means that solicitations will specify the required level and assessment type, self-assessment versus C3PAO.

Translation: if you touch CUI, you need an executable plan today.

What DoD Reviewers Look For First (By Level)

  • Level 1 (FCI): Annual self-assessment along with an annual affirmation. No POA&Ms are allowed, and results must be submitted to SPRS.
  • Level 2 (CUI): Contractors must complete either a self-assessment or a C3PAO assessment as specified in the solicitation, which occurs every three years, in addition to an annual affirmation. Results are reported in SPRS/eMASS.
  • Level 3 (Expert): DIBCAC-led certification is required every three years, accompanied by an annual affirmation. 

The Three Big Things That Decide Readiness and Success

Policies, procedures, and an SSP aligned with NIST 800-171

  • The DoD is not evaluating your tool list. They are verifying that you have implemented the required controls and documented them in your policies and System Security Plan (SSP).
  • Make sure everything directly maps to the 110 NIST 800-171 requirements, specifying who, what, and where for each control objective.
  • For Level 2, a practice is only considered “MET” if it satisfies all objectives in NIST 800-171A.

RainTech tip:

Tailor policies to your actual environments, including users, enclaves, ESPs/CSPs, and contractor-risk-managed assets, so evidence lines up with what assessors will see in scope.

POA&Ms: When and How They Are Allowed

POA&Ms are permitted only in specific cases and on a strict clock:

  • Level 1: POA&Ms are not permitted.
  • Level 2: You can achieve Conditional status with a score of at least 80% of the maximum (88 out of 110), but only specified items may be included in a POA&M. Certain higher-risk or weighted practices cannot be POA&M’d, and encryption can be POA&M’d only if it’s in use but not yet FIPS-validated. Once assessment results are submitted to SPRS/eMASS, the 180-day clock starts to close all open items, which must be verified through a POA&M closeout assessment, or the Conditional status will expire.
  • Level 3: Follows a similar 80%/180-day Conditional path with additional exclusions.

Note: The rule distinguishes operational plans of action, such as ongoing ops items like patches or configurations, from assessment POA&Ms. Only the latter trigger the 180-day closeout and Conditional status.

SPRS Scores: What They Signal and How to Use Them

  • Max score is 110; scores can be negative under the DoD NIST 800-171 assessment methodology.
  • You must have a current NIST 800-171 assessment score posted in SPRS, no older than 3 years, by award. Contracting officers check SPRS before award. Keep it current and accurate.

Your CMMC 2.0 Checklist (Level 2 Focused)

✅ Documented policies and procedures mapped to all 110 NIST 800-171 controls.

✅ A complete SSP reflecting your real environment, including assets, enclaves, ESPs/CSPs, and diagrams.

✅ POA&Ms, if used, that meet the rule: ≥ 80% score, only eligible items, and a 180-day close plan.

✅ SPRS score submission and annual affirmation, plus triennial self or C3PAO assessment as applicable.

✅ Flow-down readiness for subs.

Flow-Down to Subcontractors (Avoid Surprises)

CMMC flows down the supply chain. If a subcontractor handles CUI, they generally must meet Level 2, with assessment type per the solicitation or contract. Prime contractors are expected to require and verify sub-compliance. Start building your sub-onboarding and evidence collection around this now.

The Conditional to Final Path (Most Screenshot-Worthy)

  • Step 1: Perform your Level 2 assessment, self or C3PAO, and post results.
  • Step 2: If the score is ≥ 80% with only eligible items open, you can receive Conditional Level 2 status.
  • Step 3: Close all POA&M items within 180 days and complete a POA&M closeout assessment to convert to Final Level 2.
  • Step 4: Affirm annually in SPRS and re-assess every 3 years.

How RainTech (RPO) Gets You Award-Ready Without the Headache

  • Policy and SSP build-out: NIST-aligned, environment-specific, evidence-first
  • POA&M strategy and execution: Reach the 80% threshold, select eligible items, and close within the window
  • SPRS uplift: Score calculation, documentation, and regular updates
  • Sub flow-down program: Standardize requirements and evidence exchange with your suppliers
  • Zero-pressure checkup: We’ll baseline your controls, forecast your achievable score, and map a 180-day POA&M close plan

FAQs

  • What is a CMMC POA&M? A Plan of Action and Milestones lists the specific unmet requirements from your CMMC assessment, resources, and milestones to remediate them, and deadlines. At Level 2 or 3, you can earn Conditional status if you meet the minimum score and only place eligible items on the POA&M. You then have 180 days to close everything.
  • What’s a good SPRS score? 110 is perfect, though scores can be negative. The practical goal is to achieve a defensible, current score that meets award requirements and, if necessary, a score of ≥ 80% to achieve Conditional CMMC, while closing gaps. Post or update in SPRS and back it with evidence.
  • Do all contractors need written policies? Yes, especially for CMMC, Level 2. Assessors check that you have implemented controls and that your policies and SSP reflect your real environment, including assets, scope, ESPs/CSPs, and diagrams.
  • Will CMMC apply to my subs? If they process, store, transmit, or protect CUI for your program, expect Level 2 flow-down and be ready to collect evidence. Build this into sub onboarding and contracts.

Ready to get started? Click here to begin your compliance journey.

Tags: CMMC 2.0, CMMC Level 2, Cybersecurity readiness, DFARS compliance, DoD contractors, NIST 800-171, POA&M, RainTech RPO, SPRS score, System Security Plan (SSP)
Share this entry
  • Share on Facebook
  • Share on X
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
You might also like
CMMC for Subcontractors: Flowdown Requirements, Costs, and How to Get Started

Recent Posts

  • CMMC Readiness Without the Chaos: A Clear Guide for DoD Contractors
  • How to Choose an MSP Without Being Technical
  • How to Measure the Value of Your MSP 
  • What Does an MSP Actually Do? 
  • RainTech Announces Path to Full Employee Ownership

RainTech

Our commitment is to deliver IT solutions that not only embody innovation but are deeply rooted in a human-centric approach. Discover more about our tailored IT solutions and their transformative potential for your business.
Embark on transformation. Contact us now.

Contact Us

info@rain.tech
844.TEL.RAIN 719.536.9254
3 S Tejon St., Suite 400
Colorado Springs, CO 80903

Stay Connected

Join our mailing list to receive the latest news, updates, trends and promotional material from RainTech.

  • This field is for validation purposes and should be left unchanged.
  • We respect your privacy. We'll NEVER sell, rent or share your email address.

Dark Web Scan Affiliates
Sitemap Terms of Service Privacy Policy Client Communication Preferences

©2026 RainTech

Link to: CMMC Compliance Made Simple: What Contractors Need to Know and How RainTech Can Help Link to: CMMC Compliance Made Simple: What Contractors Need to Know and How RainTech Can Help CMMC Compliance Made Simple: What Contractors Need to Know and How RainTech... Link to: CMMC for Subcontractors: Flowdown Requirements, Costs, and How to Get Started Link to: CMMC for Subcontractors: Flowdown Requirements, Costs, and How to Get Started CMMC for Subcontractors: Flowdown Requirements, Costs, and How to Get Start...
Scroll to top Scroll to top Scroll to top
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.
Click here for more info on how to opt-out of cookies.
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
SAVE & ACCEPT