Skip to content
PlanetISO
CMMC and NIST SP 800-171Short courseFoundation

CMMC Level 2 and NIST SP 800-171 Overview

What a Level 2 assessment expects, how the 110 requirements are organized and how to build a program that passes

Duration
3 hours
Modules
6
Final exam
70% to pass
Certificate
No expiry
$99
  • Lifetime access to the course and your certificate
  • Verifiable Certificate of Completion. Certificate does not expire.
  • 3 exam attempts
  • Progress saved to your account on every slide
Buying for a team? Volume pricing from 5 seats
1 to 4 seatsList price
5 to 10 seats15% off
11 to 20 seats25% off
21 or more seats35% off

$420.75

5 × $84.15 · save $74.25

Each seat is a single-use code. Send one to each learner; they sign in with their own account and earn their own certificate. Track progress on your Team page.

About this course

CMMC Level 2 is the level every defense supplier that handles controlled unclassified information must reach. It verifies the 110 requirements of NIST SP 800-171 Rev 2 that DFARS 252.204-7012 has required since 2017, through a self-assessment where DoD allows it or a certification assessment by a C3PAO, valid for 3 years with annual affirmation. The programme rule is 32 CFR Part 170 and the clause that brings it into contracts, DFARS 252.204-7021, phases in over several years from late 2025.

This short course is for the people who have to make Level 2 happen in a small or mid-sized supplier. It starts with the landscape: the four DFARS clauses, the three levels, phased implementation, conditional versus final status and the plan of action rules. It then covers scoping, including the 5 asset categories, enclaves, cloud services and external providers. Two modules walk through all 14 requirement families in plain language with the evidence an assessor expects. The fifth module explains the system security plan, the plan of action and milestones, SPRS scoring from 110 down to -203, the NIST SP 800-171A objectives, the three evidence types and what happens during a C3PAO assessment week. The last module shows how to build the program: roles, policies, employee responsibilities, the failures that most often produce no status, a 12-month roadmap and the path to Level 3.

The course is an overview at awareness and practitioner level. It is anchored on 32 CFR Part 170, the DFARS clauses, NIST SP 800-171 Rev 2 and NIST SP 800-171A and the CMMC Assessment and Scoping Guides published by the DoD CIO. It does not give legal advice, does not qualify anyone as a CMMC assessor or professional, and does not replace your company's procedures or the official guides.

The course closes with a 20-question examination drawn from a bank of 30. On passing you receive a PlanetISO Certificate of Completion with lifetime access to the course content and your certificate. The certificate does not expire.

What you will be able to do

  • Explain the roles of DFARS 252.204-7012, 7019, 7020 and 7021 and of 32 CFR Part 170, and describe the three CMMC levels and the phased implementation.
  • Distinguish Level 2 self-assessment from C3PAO certification and state the rules for conditional and final status, the 88-point threshold, plan of action eligibility and the 180-day close-out.
  • Classify assets into the 5 CMMC scoping categories, explain how an enclave limits scope and state what cloud services and external providers must demonstrate.
  • Summarize what each of the 14 NIST SP 800-171 Rev 2 families requires and name the evidence an assessor expects for each.
  • Describe the content of a system security plan and a plan of action and milestones, and calculate a DoD Assessment Methodology score including the multi-factor authentication and FIPS partial cases.
  • Outline how a C3PAO assessment is planned and conducted using NIST SP 800-171A objectives and the examine, interview and test methods.
  • Identify the common failures that leave a company with no status and lay out a 12-month program with roles, policies and employee responsibilities.

Course outline

  1. 1

    The landscape: DFARS clauses, CMMC 2.0 and Level 2 status

    DFARS 252.204-7012, 7019, 7020 and 7021, the CMMC programme rule at 32 CFR Part 170, phased implementation, self-assessment versus C3PAO certification, conditional versus final status, annual affirmation and Level 3 in brief.

    About 30 minutes, then a module quiz

  2. 2

    Scoping: assets, enclaves and external providers

    The 5 asset categories of the CMMC Level 2 Scoping Guide, how an enclave shrinks the assessment, and what external service providers and cloud services must show.

    About 28 minutes, then a module quiz

  3. 3

    The 14 families, part 1: Access Control to Maintenance

    Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response and Maintenance: what each family asks in plain language and the evidence an assessor expects.

    About 35 minutes, then a module quiz

  4. 4

    The 14 families, part 2: Media Protection to System and Information Integrity

    Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection and System and Information Integrity: what each asks and the evidence to keep.

    About 35 minutes, then a module quiz

  5. 5

    The SSP, the POA&M, scoring and how an assessment runs

    What goes in the system security plan and the plan of action and milestones, how SPRS scoring works, the assessment objectives of NIST SP 800-171A, the three evidence types and what happens during a C3PAO assessment.

    About 32 minutes, then a module quiz

  6. 6

    Building a program that passes

    Roles, the policy set, what every employee owns, the failures that most often produce no status, a 12-month roadmap, keeping status after the assessment and the path to Level 3.

    About 30 minutes, then a module quiz

  7. Final examination and certificate

    20 questions drawn from the course bank. Score 70% or higher to receive your Certificate of Completion.

  • CMMC and NIST SP 800-171Awareness

    Insider Threat Awareness

    Recognize and report the indicators that protect your colleagues, your company and controlled information

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    Phishing and Email Security

    Spot the message that is trying to trick you, and know exactly what to do next

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    Social Engineering Prevention

    Recognize manipulation in person, on the phone and online, and verify before you act

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    CUI Handling and Marking

    Recognize controlled unclassified information, mark it correctly and handle it safely

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course
  • CMMC and NIST SP 800-171Awareness

    CMMC Level 1 Overview

    The 15 basic safeguards for federal contract information and how the annual self-assessment works

    Duration
    1.5 hours
    Level
    Foundation
    $59
    View course