The Short Answer
CMMC Level 1 has 17 basic safeguarding practices. CMMC Level 2 has 110 controls, drawn directly from NIST SP 800-171, organized into 14 families. Level 3 adds a further set of enhanced requirements on top of a certified Level 2 baseline. Which count applies to you depends entirely on which level your contracts require.
See our CMMC 2.0 guide for the level structure, or our CMMC certification cost breakdown for the budget side.
The 110 Level 2 Controls by Family
NIST SP 800-171's 110 controls are organized into 14 families, each addressing a distinct area of protection for Controlled Unclassified Information:
- Access Control — the largest family, covering account management, least privilege, and remote access
- Awareness and Training — security awareness and role-based training requirements
- Audit and Accountability — logging, log review, and accountability for system actions
- Configuration Management — baseline configurations and change control
- Identification and Authentication — user identification and authentication, including MFA
- Incident Response — incident handling, reporting, and testing
- Maintenance — controlled system maintenance activities
- Media Protection — protecting and sanitizing media containing CUI
- Personnel Security — screening and access termination procedures
- Physical Protection — physical access limits for systems and facilities
- Risk Assessment — periodic risk assessments and vulnerability scanning
- Security Assessment — assessing, authorizing, and monitoring controls
- System and Communications Protection — boundary protection and network security
- System and Information Integrity — flaw remediation, malicious code protection, monitoring
Access Control carries the largest share of the 110 total, reflecting how central who-can-reach-what is to protecting CUI. Every family contributes at least a handful of controls, and none can be skipped entirely, though applicability within a family still depends on your specific environment.
Level 1: A Much Smaller Set
Level 1's 17 basic safeguarding practices come from FAR 52.204-21, not NIST 800-171, and protect Federal Contract Information rather than CUI. The gap between 17 and 110 reflects a real difference in data sensitivity, not just a smaller version of the same list. Level 1 is self-assessed; none of its 17 practices require third-party validation.
Level 3: Built on Top of Level 2, Not Separate From It
Level 3 doesn't replace the 110 Level 2 controls, it adds to them. Contractors must hold a certified Level 2 baseline first, then implement a further set of enhanced security requirements from NIST SP 800-172, designed specifically to defend against advanced persistent threats. Level 3 applies to a small subset of contractors handling the most sensitive CUI and is assessed by DIBCAC, the government's own assessment organization, rather than a commercial C3PAO.
Not sure which of the 110 controls actually apply to your environment?
A gap analysis maps your current state against all 110 and tells you exactly what's applicable before you commit to a C3PAO date.
Get a Free QuoteSame 110 Controls, Different Scope
The control list is identical for every Level 2 contractor. What genuinely differs is scope, which systems and data flows the 110 controls actually have to be evidenced against. A contractor with CUI isolated to one tightly controlled enclave produces far less evidence per control than one with CUI spread across the whole network, even though both are assessed against the same 110-item list. This is why CUI scoping is consistently the biggest lever for both cost and timeline at Level 2.
Ready to map the 110 controls to your CUI environment?
We've guided contractors through NIST 800-171 gap analysis and C3PAO assessment preparation.
Talk to an Avantcert ExpertFrequently asked questions about CMMC controls
Why does Level 1 have so many fewer requirements than Level 2?
Because they protect different data. Level 1's 17 practices come from FAR 52.204-21 and protect Federal Contract Information, a lower sensitivity category. Level 2's 110 controls come from NIST SP 800-171 and protect Controlled Unclassified Information, which carries a materially higher protection requirement.
Which NIST 800-171 control family has the most individual controls?
Access Control, with the largest share of the 110 total, covering account management, least privilege, remote access, and related requirements. Audit and Accountability and System and Communications Protection are also relatively large families.
Do all 110 Level 2 controls have to be fully implemented before assessment?
Most do, but a limited number of lower-weighted controls can remain open on a Plan of Action and Milestones at assessment time, with a committed closure timeline, typically 180 days. High-weighted controls, particularly multi-factor authentication, generally must be fully implemented before the C3PAO assessment.
What does CMMC Level 3 add on top of Level 2's 110 controls?
Level 3 builds on a certified Level 2 baseline and adds a further set of enhanced security requirements drawn from NIST SP 800-172, designed to defend against advanced persistent threats. Level 3 applies to a small subset of contractors handling the most sensitive CUI and is assessed by DIBCAC rather than a commercial C3PAO.
Are the 110 controls the same for every CMMC Level 2 contractor?
The control list is identical for every Level 2 contractor; what differs is scope, which systems and data flows the controls actually apply to. A tightly scoped CUI enclave means fewer systems evidencing each control, not fewer controls to satisfy.
How does the control count affect certification cost and timeline?
Directly. Each of the 110 controls needs to be assessed against your actual environment, so more in-scope systems means more evidence to produce for the same 110 controls. This is why CUI scoping is repeatedly the single biggest lever for both cost and timeline at Level 2.
About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through CMMC readiness, NIST 800-171 remediation, and C3PAO assessment preparation. See our CMMC certification service or request a free quote.