CMMC Practices Guide

Understanding practices by level and how they're assessed in CMMC audits

Affiliate Disclosure: This site contains affiliate links to security tools and consulting services. If you purchase through our links, we may earn a commission at no cost to you. We only recommend products we've thoroughly researched.
Status update · October 2026CMMC Phase 2 is paused. On July 13, 2026 the DoD suspended the November 10, 2026 move to mandatory third-party (C3PAO) certification while a reform task force reviews the program. Self-assessments, NIST SP 800-171, SPRS scores and DFARS 252.204-7012 still apply. No new date has been set. The practices on this page are the same either way. See the current timeline →

CMMC runs on "practices" — specific things you actually have to do, not just checkboxes you fill out. I'll walk you through what practices are, how they line up across the three CMMC 2.0 levels, and how assessors decide whether you're really doing them or just pretending.

What Are CMMC Practices?

A practice is a security requirement you actively perform — not just documentation, but real actions. Assessors don't just ask "do you have this control?" They ask "show me evidence you're actually doing this, the way your system security plan says you do."

CMMC 2.0 practice IDs tell you the domain, the level, and the source requirement. Level 1 IDs point to the FAR clause (for example AC.L1-b.1.i = FAR 52.204-21(b)(1)(i)). Level 2 IDs point to NIST SP 800-171 (for example AC.L2-3.1.1 = NIST requirement 3.1.1). If you see IDs like "AC-1.001" or "AC.1.001", that's the retired CMMC 1.0 model.

Example CMMC Practice

Practice AC.L2-3.1.1: Authorized Access Control — limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

To satisfy this practice, you should be able to show that you:

  • Identify the authorized users, the processes acting on their behalf, and the devices allowed to connect
  • Limit system access to exactly those users, processes, and devices
  • Document who approved each user's access (an access request or approval record works)
  • Implement the authorization in your systems (directory service, firewall, application permissions, etc.)
  • Update access when roles change or people leave
  • Keep records you can hand an assessor

The assessment objectives for every Level 2 practice come straight from NIST SP 800-171A. Just having a policy isn't enough — the requirement has to be implemented, and you have to be able to prove it.

Practices vs NIST Controls

In CMMC 2.0 the practices are the federal requirements, not an extra layer on top of them:

  • Level 1: the 15 basic safeguarding requirements in FAR 52.204-21, presented as 17 practices
  • Level 2: the 110 security requirements in NIST SP 800-171 Rev 2, one-for-one, with the same wording. Example: NIST 3.5.7 "Enforce a minimum password complexity and change of characters when new passwords are created" is CMMC practice IA.L2-3.5.7
  • Level 3: everything in Level 2 plus 24 selected requirements from NIST SP 800-172

CMMC 1.0 added "processes" and maturity levels on top of the practices. CMMC 2.0 dropped all of that. What you're measured on is whether each requirement is met.

CMMC Level 1: Foundational Practices (17 Practices)

Level 1 applies to companies that handle only Federal Contract Information (FCI). It's the 15 basic safeguarding requirements in FAR 52.204-21. CMMC counts them as 17 practices because the physical-access requirement (b.1.ix) maps to three NIST requirements (escort visitors, keep access logs, manage physical access devices). They fall into 6 domains:

Level 1 Practice Distribution

Domain Number of Practices Focus
Access Control (AC) 4 Authorized users and devices, limiting what users can do, external connections, public information
Identification & Authentication (IA) 2 Identify users, processes, and devices; authenticate them before access
Media Protection (MP) 1 Sanitize or destroy media containing FCI before disposal or reuse
Physical Protection (PE) 4 Limit physical access, escort visitors, access logs, manage keys and badges
System & Communications Protection (SC) 2 Boundary protection; separate public-facing systems from internal networks
System & Information Integrity (SI) 4 Fix flaws, malicious code protection, keep it updated, scan systems and files
TOTAL 17 (15 FAR 52.204-21 requirements)

Sample Level 1 Practices

  • Give each user a unique account and require authentication before access
  • Limit users to the functions their job requires
  • Control what gets posted on your public website and social accounts
  • Lock up equipment and escort visitors
  • Run anti-malware, keep it updated, and patch systems in a timely manner
  • Wipe or destroy drives before disposal

Level 1 Assessment

Self-assessed, every year. No third-party auditor. Each practice is MET or NOT MET, and all of them must be met — there's no point score and no POA&M at Level 1. Your organization posts the result in SPRS, and a senior official affirms it annually. Low cost, high organizational responsibility.

CMMC Level 2: Intermediate Practices (110 Practices)

Level 2 applies to companies that handle Controlled Unclassified Information (CUI). It covers all 110 security requirements in NIST SP 800-171 Rev 2, across 14 families.

Level 2 Practice Distribution (NIST 800-171 Map)

Domain Practices Primary Requirements
Access Control 22 User management, least privilege, role-based access
Awareness & Training 3 Annual security training for all staff
Audit & Accountability 9 System logging, audit trail protection
Configuration Management 9 Baselines, change control, security reviews
Identification & Authentication 11 MFA, password policies, credential management
Incident Response 3 Incident handling, reporting procedures
Maintenance 6 System maintenance, remote access controls
Media Protection 9 Encryption, secure disposal, transport
Personnel Security 2 Screening before access; protecting CUI when people leave or transfer
Physical & Environmental 6 Facility access, visitor logs
Risk Assessment 3 Vulnerability scans, risk analysis
Security Assessment 4 Security testing, assessments
System & Comms Protection 16 Encryption, firewalls, boundary protection
System & Information Integrity 7 Patching, malware protection
TOTAL 110

Level 2 Key Characteristics

Level 2 practices require:

  • A system security plan (3.12.4) describing how each requirement is met
  • Formal implementation with evidence of deployment
  • Ongoing monitoring of security controls (3.12.3)
  • Evidence documentation for assessor review
  • A scored assessment: 110 points under the DoD Assessment Methodology (Final status = 110; Conditional status with a POA&M needs at least 88); since the July 13, 2026 Phase 2 pause, solicitations call for a Level 2 self-assessment posted in SPRS; third-party C3PAO certification is currently voluntary unless a prime or contract requires it

CMMC Level 3: Expert (Level 2 + 24 Requirements)

Level 3 is Level 2 plus 24 selected requirements from NIST SP 800-172 (enhanced security requirements for protecting CUI against advanced persistent threats) — 134 requirements in total. You need Final Level 2 (C3PAO) status first, and the Level 3 assessment is done by the government (DCMA's DIBCAC), not a C3PAO. Level 3 was originally scheduled for a later rollout phase, which is also on hold pending the reform review.

What the NIST 800-172 Requirements Add

The added requirements push you toward an active defense posture, for example:

  • Security operations and incident response: a security operations center and a cyber incident response team that can respond quickly
  • Threat hunting and threat-informed risk assessment: using threat intelligence to look for adversaries already in your environment
  • Penetration testing: periodic testing of your defenses
  • Supply chain risk: a plan for managing risks from suppliers and components
  • Advanced awareness training: training on advanced persistent threat tactics such as social engineering

Not Sure Which Level You Need?

Use our readiness assessment tool to determine your current readiness and required CMMC level.

Start Assessment

How Each Practice Is Scored

CMMC 2.0 has no maturity scale. Each practice gets one of three findings, judged against its assessment objectives:

MET

Every assessment objective for the practice is satisfied, with evidence. Nothing is deducted.

NOT MET

One or more objectives aren't satisfied. At Level 1, any NOT MET means you can't affirm until it's fixed. At Level 2, the requirement's weight (5, 3, or 1 points) comes off the 110-point score.

NOT APPLICABLE

The practice doesn't apply to your environment (for example, wireless practices when you have no wireless). It's treated as met, but you need a justification.

At Level 2, Conditional status requires a score of at least 88 out of 110, and only certain 1-point requirements may be on the POA&M (with limited exceptions). POA&M items must be closed within 180 days. Final status means all 110 are met.

Top 10 Most Challenging CMMC Practices to Implement

Challenging CMMC practices

High-Difficulty Practices

These practices require significant planning, tooling, and organizational change. Start here for risk reduction.

Practice Difficulty Key Challenge
SC.L2-3.13.16 (Data at Rest) High Requires cryptographic tools, key management, and system redesign
CM.L2-3.4.3 (System Change Management) High Requires organizational discipline and workflow tools
CA.L2-3.12.3 (Security Control Monitoring) High Requires ongoing monitoring so you know controls are still working; tools help
SI.L2-3.14.6 (Monitor Communications for Attacks) High Requires extensive logging, log aggregation, and analysis
AC.L2-3.1.12 (Control Remote Access) Medium-High Requires VPN, MFA, and session logging infrastructure
AC.L2-3.1.4 (Separation of Duties) Medium-High Requires role redesign and identity governance tools
PS.L2-3.9.2 (Personnel Actions) Medium Requires workflows and cross-system cleanup procedures
IA.L2-3.5.3 (Multifactor Authentication) Medium Requires MFA deployment and strong password enforcement
AU.L2-3.3.1 (System Auditing) Medium Requires log configuration, retention, and centralization
MP.L2-3.8.6 (Portable Storage Encryption) Medium Requires encryption of all portable devices and USB drives

Practice Documentation Requirements

For each practice, you should be able to show:

  • Policy: Written statement of the organization's intent (e.g., "We encrypt all CUI in transit and at rest")
  • Procedure: Step-by-step instructions on how the practice is performed (e.g., encryption tool configuration steps)
  • Implementation Evidence: Screenshots, logs, or outputs proving the practice is active (e.g., encryption status reports)
  • Assessment Records: Documentation of practice testing or audits (e.g., quarterly encryption audits)
  • Approval/Authorization: Sign-off from management that the practice is approved and in effect

How Practices Are Assessed During CMMC Audits

During a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessment (C3PAO certification is voluntary while Phase 2 is paused, but DoD can still run Medium or High assessments of your SPRS score), assessors will:

  1. Review documentation — Examine policies, procedures, and evidence
  2. Interview staff — Ask employees about practice performance (e.g., "Show me your backup procedure")
  3. Observe systems — Check system configurations and security tool settings
  4. Test controls — Perform security tests (e.g., try accessing a system without authorization)
  5. Verify evidence — Confirm that logs and records support your claims
  6. Score each practice — MET, NOT MET, or NOT APPLICABLE against the assessment objectives in NIST SP 800-171A

Key Assessment Principle: Assessors look for evidence, not intentions. A practice is MET only if every one of its assessment objectives is satisfied and you can prove it.

Practice Implementation Order: What to Tackle First

Prioritize implementation by impact and effort:

Phase 1: Foundation (Months 1-3)

High impact, moderate effort. Foundation for all other practices.

  • IA.L2-3.5.3 and IA.L2-3.5.7 (MFA and password complexity)
  • SC.L2-3.13.1 (Boundary protection)
  • AU.L2-3.3.1 (Audit logging)
  • AC.L2-3.1.1 (Access authorization)

Phase 2: Hardening (Months 4-6)

High impact, moderate-high effort. Reduces exploitation risk.

  • SC.L2-3.13.8 and SC.L2-3.13.16 (Encryption in transit and at rest)
  • SI.L2-3.14.1 (Flaw remediation / patching)
  • CM.L2-3.4.3 (Change control)
  • SI.L2-3.14.2 (Malware protection)

Phase 3: Monitoring & Detection (Months 7-9)

High impact, high effort. Enables incident response.

  • CA.L2-3.12.3 (Security control monitoring)
  • IR.L2-3.6.1 (Incident handling)
  • AU.L2-3.3.5 (Audit record review and correlation)

Phase 4: Organizational (Months 10-12)

Moderate effort, completes compliance picture.

  • AT.L2-3.2.1 (Security awareness training)
  • PS.L2-3.9.2 (Access termination)
  • RA.L2-3.11.2 (Vulnerability scanning)
  • PE.L2-3.10.1 (Physical access controls)

Frequently Asked Questions

How many practices do I need to satisfy for CMMC Level 2?

All 110 must be MET for Final Level 2 status. Conditional status is possible with a score of at least 88 out of 110, as long as the open items are ones allowed on a POA&M (certain 1-point requirements, with limited exceptions), and those items must be closed within 180 days. Practices that don't apply to your environment can be marked not applicable with a justification.

Can I implement Level 2 practices and skip Level 1?

Level 1 and Level 2 are separate assessments, and which one you need depends on whether you handle only FCI (Level 1) or CUI (Level 2). The 110 Level 2 requirements include everything the Level 1 requirements cover, so implementing Level 2 means you've done the Level 1 work. Post whichever assessment your contracts actually call for in SPRS.

What if a practice doesn't apply to my organization?

Some practices may not apply if you lack certain systems. For example, if you don't use wireless networks, wireless security practices may not apply. Mark them not applicable and document the justification in your SSP; if you pursue C3PAO certification, the assessor will need to agree.

How often should practices be reviewed and updated?

Annually minimum. Many organizations review quarterly. Practices should evolve as threats change and new vulnerabilities emerge. Level 1 self-assessments are annual, and Level 2 assessments run on a 3-year cycle with annual affirmations, so your practices need to stay current year-round.

Can I use third-party tools to automate practice implementation?

Yes. Tools like SIEM platforms, identity management systems, patch management tools, and configuration management systems can automate many practices. You still need documented procedures and evidence.

What's the difference between a practice and a control?

In CMMC 2.0, they're essentially the same thing. Level 1 practices are the FAR 52.204-21 requirements and Level 2 practices are the NIST SP 800-171 requirements, word for word; CMMC adds the ID format and the assessment rules. The maturity levels and processes from CMMC 1.0 no longer exist.