
The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense's framework for verifying that contractors actually implement the security controls they have long been contractually required to have. If your organization handles Controlled Unclassified Information (CUI) — technical drawings, specifications, contract data — CMMC Level 2 is the bar you must clear.
Level 2 is not a new standard. It requires implementation of all 110 security requirements of NIST SP 800-171 Revision 2, the same controls referenced by DFARS 252.204-7012 since 2017. What CMMC changes is verification: self-attestation with an executive-level annual affirmation, and for many contracts, an independent assessment by a C3PAO (Certified Third-Party Assessment Organization).
The compliance landscape has moved quickly, so here is the current state of play:
Here is the critical point contractors get wrong: the pause is not a reprieve. Phase 1 remains fully in force. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in your contracts. Submitting an inflated SPRS score or a false affirmation is exactly the conduct the Department of Justice has pursued under the Civil Cyber-Fraud Initiative. Whatever shape Phase 2 takes after the review, the 110 controls are due now.
Roughly half of the 110 requirements concentrate in four families — and they are the ones that fail most often, because they demand system-enforced behavior, not documentation:
Databases, servers, and clusters holding CUI are where these controls become painful. Most infrastructure resources don't natively support SSO or MFA. Credentials get shared. Privileges accumulate. And when an assessor asks "show me every query run against this CUI database last quarter, attributed to a person" — native database logs rarely can.
Adaptive is a Just-in-Time infrastructure access platform, and it lands squarely on the four families above:
| NIST SP 800-171 family | Requirement examples | How Adaptive helps |
|---|---|---|
| Access Control (3.1) | 3.1.1, 3.1.2, 3.1.5 — authorized users only, least privilege | Just-in-Time access with approvals: privileges are granted per-request, scoped to the resource, and expire automatically — standing access to CUI systems disappears |
| Identification & Authentication (3.5) | 3.5.1–3.5.3 — unique IDs, MFA | SSO and MFA in front of every resource, including databases and legacy systems that don't support SAML/OIDC natively; shared credentials are eliminated because users never see real credentials — only ephemeral credentials |
| Audit & Accountability (3.3) | 3.3.1, 3.3.2, 3.3.8 — attributable, protected audit records | Session Recording and Activity Monitoring capture every query and command, attributed to the SSO identity, stored centrally and tamper-resistant — assessor-ready evidence by default |
| System & Communications Protection (3.13) | 3.13.1, 3.13.8 — boundary protection, encryption in transit | Ephemeral encrypted tunnels reach resources in any VPC or on-prem network; CUI databases and servers are never exposed to the internet, with no bastion or VPN sprawl |
| Media Protection / CUI confidentiality | 3.8.x concepts applied to data access | Data Masking keeps sensitive CUI fields hidden from users and tools that don't need them |
Because Adaptive deploys as an agentless, container-based gateway, it does not add software inside your CUI systems — it narrows the assessment boundary instead of expanding it, and it typically stands up in days.
Q: Do I need CMMC Level 2 if I only handle FCI, not CUI? No — contracts involving only Federal Contract Information require Level 1 (17 basic practices, annual self-assessment). CUI triggers Level 2.
Q: Is a C3PAO assessment required right now? As of this writing (August 2026), Phase 2 — which would broadly require C3PAO certification — is paused pending the CMMC Reform Task Force review, and certification requirements are being removed from solicitations. Self-assessment obligations under Phase 1 continue, and some primes still contractually demand third-party assessments.
Q: Should I implement NIST SP 800-171 Rev 2 or Rev 3? CMMC Level 2 is pinned to Revision 2. Implement Rev 2 for compliance today, but design controls (MFA everywhere, least privilege, centralized audit) that carry forward to Rev 3.
Q: How long does Level 2 readiness take? Typically 6–12 months from a cold start, dominated by scoping and the access/audit control families. A tight CUI enclave plus a centralized access layer shortens this dramatically.
Q: What does non-compliance actually cost? Loss of contract eligibility, and increasingly False Claims Act exposure for inaccurate SPRS scores or affirmations — settlements under the Civil Cyber-Fraud Initiative have reached into the millions.
CMMC Level 2 rewards contractors who make compliance a property of their infrastructure rather than a quarterly documentation scramble. The controls that decide your score — least privilege, MFA, attributable audit trails, encrypted access — are exactly the ones that are miserable to retrofit resource by resource, and trivial when enforced at a single access layer.
The 2026 program review may reshape how Level 2 is verified, but not what it requires. The 110 controls are already in your contracts. If access control, authentication, and audit evidence are your open POA&M items, Adaptive closes them at one layer, for every database, server, and cluster that touches CUI.

