Compliance frameworks
CMMC Level 2
CMMC Level 2 requires the 110 security requirements of NIST SP 800-171 Rev. 2. 32 CFR Part 170 provides two ways to meet it: a self-assessment, or a certification assessment by an accredited C3PAO (Certified Third-Party Assessor Organization). With Phase II suspended since July 13, 2026, Level 2 is currently met by self-assessment and an annual affirmation. Flaw remediation (SI.L2-3.14.1) and CUI flow control (AC.L2-3.1.3) are among the requirements most directly evidenced at the source-code level.