Home/ Frameworks/ CMMC 2.0
Framework · CMMC 2.0

CMMC 2.0 certification. Required to keep—and win—DoD contracts.

The Department of Defense began enforcing CMMC 2.0 requirements in late 2024. Defence contractors and subcontractors handling Controlled Unclassified Information (CUI) must now demonstrate certification—not just self-attest. Sentrix maps your security controls to CMMC Level 1 and Level 2 practices and prepares your System Security Plan for third-party assessment.

110
CMMC Level 2 practices derived from NIST SP 800-171—all pre-mapped in Sentrix
2024
CMMC 2.0 enforcement began in new DoD contracts—self-attestation alone is no longer sufficient for Level 2
17
Practice domains in CMMC 2.0 Level 2—all continuously monitored with automated evidence collection
C3PAO
Sentrix prepares your evidence package for your C3PAO third-party assessment—no evidence sprints
CMMC 2.0 levels

Level 1 self-attestation. Level 2 C3PAO assessment. Sentrix prepares both.

CMMC 2.0 simplified the original five-level model to three levels. Level 1 (17 practices) applies to Federal Contract Information and allows annual self-attestation. Level 2 (110 practices, aligned to NIST SP 800-171) applies to CUI and requires triennial third-party assessment by a Certified Third-Party Assessor Organization (C3PAO).

  • Level 1: 17 foundational practices, annual self-attestation by senior official
  • Level 2: 110 advanced practices (NIST 800-171), C3PAO assessment every 3 years
  • Level 3: 24 additional practices from NIST 800-172, government-led assessment
  • SPRS score tracking—Sentrix calculates your Supplier Performance Risk System score continuously

CMMC Level 2 · Domain coverage

110 PRACTICES
AC — Access Control (22)21 / 22
AU — Audit & Accountability (9)9 / 9
CM — Configuration Management (9)7 / 9
IA — Identification & Auth (11)11 / 11
IR — Incident Response (3)3 / 3
RM — Risk Management (3)2 / 3
SPRS Score: +98 / 110 · 3 open POA&M items
Full CMMC capabilities

From SPRS score to C3PAO assessment package.

800-171 control mapping

All 110 CMMC Level 2 practices mapped directly to their NIST SP 800-171 counterparts. Continuous evidence collection means your assessment package is complete before your C3PAO schedules the first call.

SPRS score tracking

Your Supplier Performance Risk System score is calculated continuously based on your current control implementation status. Sentrix tracks your score over time and alerts you when changes affect it.

System Security Plan

The SSP is required for CMMC assessment. Sentrix generates your SSP from your actual control implementations—system boundary, control descriptions, implementation status, and responsible parties all populated automatically.

POA&M management

Every open practice gap gets a Plan of Action and Milestones entry. Track remediation owners, scheduled completion dates, and evidence of closure—in the format your C3PAO expects to review.

CUI data flow mapping

CMMC requires you to know where CUI lives. Sentrix maps CUI data flows from your cloud and on-premise systems, identifying which environments are in scope for assessment.

CPCSC crosswalk

Canadian defence suppliers pursuing both CMMC and CPCSC manage both from one Sentrix program. The two frameworks share substantial control overlap—Sentrix maps the common ground automatically.

See your CMMC Level 2 readiness and SPRS score live.

We map your practices to your actual infrastructure and calculate your score before the call ends.