Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

CMMC Level 2 (32 CFR 170)

Defense-contractor audit & access control.

Applies to: US defense contractors handling CUI. Built · Phase 2 and C3PAO assessments suspended 13 Jul 2026 · DFARS 7012, self-assessments, SPRS scoring and annual affirmations still apply Suspended is not repealed: 32 CFR Part 170 remains on the books while the reform review runs

What the signed record shows

Audit-record creation, user traceability, and audit-information protection.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

State of play. Phase 2 and the C3PAO assessment requirement were suspended on 13 July 2026 and a Reform Task Force was stood up. The Task Force request for information, “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base”, issued 20 July 2026, closed to responses on 14 August 2026. The Task Force reports to the CIO in mid September 2026. 32 CFR Part 170 is suspended, not repealed, and DFARS 252.204-7012, self assessments, SPRS scoring, annual affirmations and FAR 52.204-21 all continue to apply. Checked 15 August 2026.

Citation: NIST SP 800-171 R2 §3.3.1/3.3.2/3.3.8/3.1.1

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the rule requires, section by section

U.S. Department of Defense, Cybersecurity Maturity Model Certification (CMMC) Program, 32 CFR Part 170 (final rule, effective 16 December 2024). CMMC Level 2's 110 security requirements are identical to NIST SP 800-171 Rev. 2; assessment is by self-assessment (32 CFR 170.16) or a C3PAO (32 CFR 170.17), with annual affirmations to SPRS. The acquisition rule (DFARS 252.204-7021, 48 CFR) took effect 10 November 2025, beginning a phased rollout. Requirements this mapper evidences from the per-event signed record:

NIST SP 800-171 Rev. 2, 3.3.1
Create and retain system audit logs and records to enable monitoring, analysis, investigation and reporting.
3.3.2
Ensure that the actions of individual system users can be uniquely traced to those users (accountability).
3.3.8
Protect audit information and audit logging tools from unauthorized access, modification and deletion.
3.1.1
Limit system access to authorized users.

Taken from the Regulayer entry for this instrument, which is built against the primary text.