Skip to content

Reference · Phase 2 enforcement 10 Nov 2026

Every CMMC Level 2 requirement,
plain English.

110 controls. 14 families. The questions assessors actually ask, the gaps that fail companies, and the fixes that work. No padding, no marketing pretending to be guidance.

Last verified · 6 May 2026
110
Controls explained
14
Security families
8
Sections per page
100%
Source-cited

Where to start

Three ways in. Pick the one that matches where you are.

Most readers fall into one of three buckets. Every section of this site is built around one of them.

PATH 01

I'm new to CMMC.

Start here if you don't yet know what CMMC is, what level you need, what CUI is, or why this is suddenly on your plate. Foundations explains the framework before it asks you to implement any of it.

PATH 02

I'm hunting a specific control.

Search by name (FIPS, MFA, POA&M) or jump straight to the family. Every requirement page has the same eight sections — no cross-referencing, no "see also."

PATH 03

I'm preparing for assessment.

The C3PAO date is on the calendar. You need to know what the four phases look like, what evidence the assessor will examine, and what a finding-free assessment day actually requires.

Anatomy of a requirement page

One page per requirement. No cross-referencing.

Every one of the 110 requirement pages follows the same eight-section structure. Once you've read one, you can scan any of them in under two minutes.

01

The One-Liner

Instant pass/fail gut check. If you can't say yes to this, the rest of the page tells you why.

02

What It Actually Means

The requirement in plain English. No jargon, no quoting NIST verbatim and calling it explained.

03

Pass or Fail

The yes/no checklist your assessor walks through. If any answer is "no," you fail the requirement.

04

What to Have Ready

The documents, people, and live demos the assessor will ask for. Build the binder against this list.

05

The Assessor's Playbook

The actual questions — verbatim. Have the answers ready before the C3PAO walks in the door.

06

Where Companies Trip Up

Named failure patterns and the fixes that work. Most findings cluster around the same five mistakes.

07

How to Talk About It

CEO/Board version and Engineering version. Same control, two audiences, two registers.

08

Implementation

Cloud platform steps for AWS, Azure, GCP, and Microsoft 365. Client access only.

All content verified
6 May 2026
Re-verified quarterly. Phase 2 enforcement: 10 Nov 2026.
Maintained by
Deepak Pal Singh
Founder & Principal, Ancitus Limited
Sources
Primary cited
32 CFR Part 170, NIST SP 800-171, DoD Assessment Guide. Spot an error? [email protected]
Credentials
Cyber AB RP (in process)
UK-registered company; targeting US DIB.