Skip to content
Framework · US Department of Defense 2.0 (final rule 2024)

CMMC 2.0

The certification framework defense contractors must meet to bid on DoD contracts. Level 2 requires third-party assessment; Level 3 requires DIBCAC assessment.

110 Talarity controls mapped
Who it's for: Defense industrial base contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Talarity coverage

Mapped, monitored, and audit-ready.

Every CMMC 2.0 control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

110
Talarity controls mapped

Talarity's pre-built control library covering CMMC 2.0, with linked evidence, owners, and testing schedules.

Cross-maps to
NIST 800-171NIST 800-172NIST CSF

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • System Security Plan (SSP) with control implementation statements
  • Plan of Action and Milestones (POA&M) for any unmet controls
  • CUI inventory and handling procedures
  • Incident reporting records (DFARS 7012)
  • FedRAMP-equivalent or higher cloud service provider attestations

Your CMMC 2.0 dashboard

Every completed CMMC 2.0 assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed CMMC 2.0 assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

CMMC L2 maps to NIST 800-171 r2 — but the assessment objectives are subtly different and there's no single source of truth.

Talarity

Talarity ships CMMC 2.0 with NIST 800-171 r2 + r3 mappings and the official assessment objectives. Score against any of them; report against the one your contract requires.

Pain

The SSP and POA&M are the gating artifacts — and most defense primes ask to see them quarterly.

Talarity

SSP generates from your control implementations. POA&M auto-populates from any 'Other than Satisfied' result. Both export to PDF on demand.

Pain

DFARS 7012 requires 72-hour incident reporting — most teams don't have a fast enough notification path.

Talarity

Incident workflows with DFARS 7012 routing. Severity triggers automatic ticket creation, evidence preservation, and DoD reporting templates.

Pain

Subcontractor flow-down is a black hole — primes can't easily verify their subs are compliant.

Talarity

Vendor Management tracks subcontractor CMMC status, BAA equivalents (FCI/CUI agreements), and quarterly attestations.

CMMC 2.0 — common questions

What are the CMMC levels and which one applies to us?
CMMC has three levels. Level 1 covers basic safeguarding of Federal Contract Information and is met by self-assessment. Level 2 aligns to the NIST SP 800-171 security requirements and applies where Controlled Unclassified Information is handled, with assessment either self-performed or by a third party depending on the contract. Level 3 adds a subset of NIST SP 800-172 requirements for the highest-priority programmes. Your required level is set by the contract, so the flow-down clauses are what determine scope.
What is the difference between CMMC and NIST SP 800-171?
NIST SP 800-171 is the underlying set of security requirements for protecting Controlled Unclassified Information in non-federal systems. CMMC is the Department of Defense programme that verifies those requirements are actually met, rather than only asserted. In practice you implement 800-171 and CMMC is the assessment mechanism layered over it, which is why an existing 800-171 programme is the bulk of the work already done.
What is an SPRS score and how is it calculated?
The Supplier Performance Risk System score reflects your self-assessment against the NIST SP 800-171 requirements. It starts at 110 and points are deducted for each requirement not fully implemented, weighted by the requirement's impact, so the score can fall below zero. Contractors are generally expected to have a current score posted, and unimplemented requirements need to be covered by a plan of action with milestones.
Do subcontractors need CMMC too?
Requirements flow down. If a prime passes Controlled Unclassified Information to a subcontractor, the subcontractor must meet the level appropriate to the information it receives. That makes your supplier inventory part of your compliance evidence — you need to know which suppliers touch CUI and hold their status, not just your own.

Working with CMMC 2.0

Step-by-step walkthroughs from the Talarity library.

Ready to ship CMMC 2.0?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.