---
title: "CMMC Level 2 Compliance Software"
description: "CMMC Level 2 evidence for defense contractors: the 110 NIST 800-171 Rev. 2 requirements as hash-chained records a C3PAO can recompute, kept in your tenant."
url: https://policycortex.com/solutions/cmmc-compliance
sealed: 2026-09-02
amended: 2026-09-06
register: solutions/cmmc-compliance
records: 6
digest: sha3:3701ae4549ddbdcdef2dc62c87ce3de1338d8cb5f608742fda81278807bb3e4d
---

# CMMC Level 2 compliance and evidence software.

32 CFR Part 170 / NIST SP 800-171 Rev. 2

CMMC Level 2 assesses the 110 requirements of NIST SP 800-171 Rev. 2. PolicyCortex records the state of your cloud, every change to it, and every machine action against those requirements, hash chained inside your tenant, and hands your C3PAO a package built to be verified by recomputation rather than believed.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Access is reviewed. Scope and onboarding are agreed with your team.

## What a Level 2 assessment asks you to prove

CMMC Phase II is suspended. On July 13, 2026 the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. Phase I self-assessments and DFARS 252.204-7012 safeguarding obligations remain, and the Department has named NIST SP 800-171 Rev. 2 as the interim enforcement baseline: 110 requirements across 14 families, checked through self-assessment and selected government-led assessments.

The obligation is evidence, not narrative. For each requirement the assessor wants the technical state that satisfies it, the record of who or what changed that state and under what authority, and proof that the package handed over is the package that was assessed. The SPRS score you affirm rests on the same rows.

- **cmmc.baseline**: NIST SP 800-171 Rev. 2: 110 requirements, 14 families. The interim baseline named by the Department.
- **cmmc.phase-ii**: Suspended 2026-07-13 pending a 60-day reform review. Phase I self-assessment requirements remain in place.
- **cmmc.levels**: Level 1 self-attestation, Level 2 C3PAO assessment, Level 3 DIBCAC assessment, under 32 CFR Part 170.
- **cmmc.boundary**: The CUI enclave is a declared scope on every record. Azure Government, AWS GovCloud, and GCC High are observed clouds.
- **cmmc.source**: Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
- **cmmc.handoff**: The eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.

## The evidence a C3PAO receives for the 110 requirements

One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached. The families below are where the three proofs file.

- **AC · IA · SC**: Proof of state: point-in-time captures of access control, identification, and system protection settings, content hashed and regenerable to the date the assessor names.
- **CM · AU**: Proof of change: who or what altered a CUI-scope resource, under what authority, with before and after hashes and a rollback identifier, on a chain that cannot be edited without detection.
- **Machine actions**: Proof of agency: the envelope that permitted each autonomous action, the record of what it did, and the counterfactual that would have blocked it one notch different.
- **SSP · POA&M · SAR**: Generated from the one implementation record, not written beside it. Exports as OSCAL 1.1.2 with an eMASS and C3PAO handoff package.
- **SPRS**: SPRS-relevant evidence carried per requirement, so the score you affirm rests on rows you can recompute.

![The PolicyCortex control implementation table: CMMC Level 2 controls by family with implementation status and evidence counts](https://policycortex.com/images/pcx-system-control-collections-1600.webp)

Exhibit SB-3 · the 110-requirement table where evidence files, control by control, with implementation status and artifact counts. Illustrative demo data; the interface is real.

## How the C3PAO verifies the record

For Level 2 the recomputation is the C3PAO's: the OSCAL 1.1.2 package and the eMASS handoff carry the digests, so the assessor can confirm that the package handed over is the package that was assessed.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

**Stated limit.** PolicyCortex is not an assessor and does not certify anything. It produces the records a compliance decision rests on; the assessor, the authorizing official, or the accountable official makes the determination. What is not connected is not observed, and the record says so. Control identifiers cite NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2, PCI DSS 4.0, SOC 2 TSC, ISO/IEC 27001:2022 and 45 CFR 164 as published.

## Access and onboarding inside a CUI enclave

During agreed read-only onboarding in Azure Government, AWS GovCloud, or GCC High, the CUI enclave boundary is declared on every record and captured evidence is mapped to the 110 requirements.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

- **eval.mode**: SHADOW. Watch only; nothing executes.
- **eval.onboarding**: Access is reviewed. Scope and onboarding are agreed with your team.
- **eval.location**: Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- **eval.egress**: None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- **eval.after**: You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.

## Delivery, if you want the record stood up for you

If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee: $15,000 flat for the standard scope, one primary cloud environment. A cleared delivery team collects the evidence, writes the policies and assessment documents, coordinates approved technical remediation, prepares control owners, and stays through assessor review for in-scope follow-up at no additional cost. The independent assessor makes the certification decision. No certification is guaranteed.

- **engagement.price**: $15,000 flat for the standard engagement scope. No hourly, no overages.
- **engagement.scope**: 30 days. One primary cloud environment. NIST SP 800-171 Rev. 2, 110 requirements.
- **engagement.package**: SSP, POA&M, OSCAL 1.1.2 bundle, and the evidence behind them, organized by control objective.
- **engagement.review**: In-scope assessor follow-up is included. The C3PAO remains independent and makes the decision.

[Every term of the engagement, on its own page.](https://policycortex.com/engagement)

## Questions assessors and buyers ask

**Q: Did the Department of War cancel CMMC?**
A: No. On July 13, 2026, the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. All Phase I self-assessment requirements remain in place.

**Q: What remains enforceable during the pause?**
A: The Department says NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments. DFARS 252.204-7012 safeguarding obligations also remain contractually binding.

**Q: Does PolicyCortex make us compliant?**
A: No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

**Q: Level 2 or Level 3, which do we need?**
A: Most contractors handling CUI need Level 2, assessed by a C3PAO. Level 3 applies to organizations supporting high-priority programs and is assessed by DIBCAC. The evidence base is the same; the control selection differs.

**Q: What does the delivery engagement include?**
A: Thirty days, one primary cloud environment, $15,000 flat: the 110-requirement baseline, CUI boundary analysis, coordinated and approved technical remediation, an SSP, POA&M, and OSCAL bundle with the evidence behind them, and support through assessor review. The independent assessor decides; no certification is guaranteed.

**Q: Does PolicyCortex submit to CMMC eMASS?**
A: No. Your C3PAO controls the official assessment package and eMASS submission. PolicyCortex prepares the control-mapped evidence, change history, SSP, POA&M, and OSCAL bundle so the assessor can review, select, and submit with less manual cleanup.

**Q: Can we use a different C3PAO?**
A: Yes. The output is C3PAO-agnostic: the OSCAL package and evidence bundle work with any C3PAO. We do not lock you to an assessor.

**Q: What about CMMC 2.0 versus 3.0?**
A: The current CMMC final rule (32 CFR Part 170) defines three maturity levels: Level 1 self-attestation, Level 2 C3PAO assessment, Level 3 DIBCAC assessment. The record is kept against the requirement text in force; a revision is a new mapping over the same rows, and existing evidence is not relabeled.

**Q: What happens when a collector is down?**
A: The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Hand the assessor a package built to be verified. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | OBLIGATION | e770493b6a3f | a5c2da4c4d6d |
| REC 0001 | EVIDENCE | 9b72cd01aaee | e770493b6a3f |
| REC 0002 | VERIFICATION | 5ca6a79bb04f | 9b72cd01aaee |
| REC 0003 | EVALUATION | d33aa16f6cfa | 5ca6a79bb04f |
| REC 0004 | DELIVERY | e8e989762172 | d33aa16f6cfa |
| REC 0005 | QUESTIONS | 3701ae4549dd | e8e989762172 |

Head sha3:3701ae4549ddbdcdef2dc62c87ce3de1338d8cb5f608742fda81278807bb3e4d. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
