CMMC 2.0 Level 2 (NIST SP 800-171)
Cybersecurity Maturity Model Certification 2.0 Level 2 — the controls (derived from NIST SP 800-171) that U.S. defense contractors must meet to handle Controlled Unclassified Information (CUI). EchelonGraph live-scores the technical practices against your cloud posture so you enter the assessment with evidence, not spreadsheets.
Authorized Access Control
Limit system access to authorized users and processes.
Least Privilege
Employ least privilege, including for privileged accounts.
Monitor & Control Remote Access
Monitor and control remote-access sessions.
System Auditing
Create and retain system audit logs.
Multifactor Authentication
Use MFA for local and network access to privileged accounts.
Data in Transit
Use cryptography to protect CUI in transit.
FIPS-Validated Cryptography
Employ FIPS-validated cryptography to protect CUI.
Data at Rest
Protect the confidentiality of CUI at rest.
Flaw Remediation
Identify, report, and correct system flaws timely.
System Baselining
Establish and maintain baseline configurations.
Audit Information Protection
Protect audit information from unauthorized modification.
Vulnerability Scanning
Scan for vulnerabilities periodically and on new disclosures.