For defense suppliers handling Controlled Unclassified Information (CUI), compliance is not a paperwork exercise. It is an operational security requirement tied directly to contract eligibility, customer trust, and national security.
NIST SP 800-171 Rev. 2 defines 110 security requirements for protecting CUI in nonfederal systems. The related assessment guide, NIST SP 800-171A, breaks those requirements into 320 assessment objectives: the specific things an assessor will examine to determine whether the controls are actually implemented.
For organizations pursuing CMMC 2.0 Level 2, the message is direct: all 110 requirements and all 320 objectives matter. A partially secured environment, incomplete evidence, or an uncontrolled endpoint can create a serious assessment failure.
The Cybersecurity Protected Enclave (CPE Level 2) is designed to solve that problem with 100% coverage of the NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 technical scope out of the box.
What Do “110 Requirements” and “320 Objectives” Actually Mean?
The numbers can sound overwhelming until they are separated into plain English.
The 110 requirements
The 110 requirements are organized into 14 security families. Each requirement describes a security outcome your organization must achieve, such as:
- Restricting system access to authorized users, devices, and processes
- Enforcing least privilege
- Protecting CUI during transmission and storage
- Detecting and reporting cybersecurity incidents
- Creating and reviewing audit logs
- Securing physical and digital media
- Maintaining secure configurations
- Identifying and correcting vulnerabilities
These are not 110 separate software products. They are 110 required security outcomes that must be implemented across the people, processes, technologies, and systems that handle CUI.
The 320 assessment objectives
The 320 objectives are the assessor’s checklist. They translate the 110 requirements into specific questions and observable conditions.
For example, an access control requirement may require an assessor to determine whether:
- Authorized users are identified.
- Access permissions are approved.
- Privileged accounts are limited.
- Remote sessions are protected.
- Access is reviewed periodically.
- CUI flows only through approved paths.
A company may believe it has “access control” because it uses passwords and a firewall. That is not enough. CMMC assessment objectives require evidence that the control is configured, enforced, monitored, documented, and operating as intended.
The NIST SP 800-171 Rev. 2 publication provides the requirements. The NIST SP 800-171A assessment guide explains how those requirements are evaluated.
Why DFARS 252.204-7012 Matters
DFARS 252.204-7012 establishes cybersecurity obligations for contractors handling covered defense information. Among other obligations, the clause requires covered contractors to implement the security requirements in NIST SP 800-171.
That means a defense supplier cannot simply say, “Our IT provider handles security,” or “Our cloud platform is secure.” Responsibility remains with the contractor to define the CUI environment, apply appropriate safeguards, maintain evidence, and respond to incidents.
For suppliers moving toward CMMC 2.0 Level 2, NIST SP 800-171 Rev. 2 is the practical benchmark. The organization must be able to demonstrate that controls are not merely planned: they are implemented and operating.
Four High-Risk Failure Points
Although all 14 security families matter, four areas consistently expose weaknesses in typical defense supplier environments.
1. Access Control: Who Can Reach CUI?
Access Control includes 22 requirements. It addresses who can access systems, what they can do, which devices may connect, and how CUI moves through the environment.
Common failures include:
- Former employees retaining active accounts
- Excessive local administrator privileges
- Shared administrative credentials
- Remote access without strong authentication
- Unapproved personal devices connecting to business systems
- Inadequate session lock or termination settings
- CUI copied into email, file-sharing platforms, or unmanaged endpoints
- No documented access review process
The real issue is not simply authentication. It is authorization and containment. A compliant environment must ensure that users, devices, applications, and processes have only the access required for their assigned duties.
CPE Level 2 establishes a controlled environment with hardened configurations, access restrictions, protected remote connectivity, and defined CUI boundaries. CUI remains inside the enclave instead of spreading across the organization.
2. Incident Response: What Happens When Something Goes Wrong?
Incident Response includes 3 requirements, but those requirements carry significant operational weight.
A defense supplier must be prepared to:
- Detect and report incidents
- Analyze and contain malicious activity
- Eradicate threats and recover operations
- Assign roles and responsibilities
- Preserve evidence
- Coordinate required reporting
- Test and improve the response process
A common failure is having an incident response policy that exists only as a document. Assessors want evidence that personnel understand the plan, alerts are monitored, escalation paths are defined, and response activities are recorded.

CPE Level 2 combines managed security operations, continuous monitoring, technical reporting, and machine-assisted response. Planet Security does not expose client CUI to generic AI tools. Generic AI services cannot be trusted with sensitive client or government data. Where AI-enabled workflows are used, Planet Security emphasizes AI-obfuscated data to help protect the underlying information from Big-Tech data handling risks.
3. Audit and Accountability: Can You Prove What Happened?
Audit and Accountability includes 9 requirements. Logging is not a box to check once. It is the mechanism that allows an organization to answer:
- Who accessed the system?
- What did they access?
- When did the event occur?
- Which device or process was involved?
- Was the action authorized?
- Did anything suspicious happen afterward?
Frequent failures include logs that are:
- Not enabled on all relevant systems
- Stored locally where attackers can delete them
- Retained for insufficient periods
- Never reviewed
- Not correlated across endpoints, servers, and network devices
- Not connected to incident response procedures
A compliant logging program must generate, protect, retain, review, and act on security-relevant events.
With centralized monitoring, SIEM capabilities, protected audit records, and continuous reporting, CPE Level 2 is built to provide complete audit visibility across the protected environment. That creates the evidence trail assessors expect and gives leadership a factual view of security performance.
4. Media Protection: Where Does CUI Go Next?
Media Protection includes 9 requirements and applies to far more than USB drives.
It includes:
- Paper documents
- Removable media
- Laptops and mobile devices
- Backups
- External drives
- Printed drawings and specifications
- Archived project files
- Media transported between facilities
- Devices being reused or disposed of
Typical failures include untracked USB devices, unsecured printed CUI, unencrypted backups, and disposal processes that cannot prove sanitization or destruction.
CPE Level 2 supports controlled CUI handling through encryption, operational procedures, protected storage, access restrictions, and media lifecycle controls. The objective is simple: CUI must remain controlled from creation through destruction.
What CPE Level 2 Includes
CPE Level 2 is a complete protected operating environment: not a loose collection of security recommendations.
Key capabilities include:
- 100% coverage of all 110 CMMC 2.0 Level 2 requirements and 320 assessment objectives
- NIST-compliant infrastructure server architecture
- Defined CUI containment and enclave boundaries
- Hardened Microsoft Windows host configurations
- Network security reference architecture
- Enabled firewall and boundary protections
- Least-privilege access controls
- Protected remote access
- Strong authentication and account management
- FIPS-validated encryption capabilities
- Centralized audit logging and SIEM monitoring
- Continuous compliance monitoring and reporting
- Vulnerability management and secure configuration maintenance
- Incident detection, escalation, response, and evidence support
- Controlled paper and digital CUI procedures
- Media protection, transport, sanitization, and destruction processes
- Managed operations, maintenance, and security services
- Ongoing host and network compliance support
- AI-obfuscated data workflows where AI-assisted operations are appropriate
- Optional resilience enhancements, including EMP-hardened configurations

Deployment and Operating Model
Organizations need a solution that can be implemented quickly without sacrificing technical depth.
CPE Level 2 is available with an expedited 4-week deployment in most environments, with an extended 8-week deployment option for organizations that prefer a slower implementation pace.
For the standard configuration, the monthly service includes the protected enclave, managed operations, maintenance, continuous monitoring, compliance reporting, and support for up to 20 users at $1,299/month. Choosing an 8-week deployment instead of 4 weeks reduces the recurring price by $100/month.
The important point is not the price. The important point is reducing the risk of failed assessments, uncontrolled CUI, unmanaged technical debt, and last-minute remediation. A complete environment gives leadership a clear path forward.
Frequently Asked Questions
Is CMMC 2.0 Level 2 the same as NIST SP 800-171 Rev. 2?
They are closely aligned. CMMC 2.0 Level 2 uses the 110 NIST SP 800-171 Rev. 2 requirements as its core security standard. The 320 objectives come from the associated assessment methodology and define how implementation is evaluated.
Does having a firewall satisfy NIST SP 800-171?
No. A firewall addresses only part of the boundary protection and access control picture. Compliance requires coordinated administrative, technical, and physical safeguards across all 14 security families.
Can we keep CUI in our normal business network?
That approach often creates unnecessary scope and risk. A dedicated CPE Level 2 environment isolates CUI systems and users, making protection, monitoring, and evidence collection significantly more manageable.
Can generic AI tools be used with CUI?
Organizations should not trust generic AI platforms with client or government data. Data may be retained, analyzed, or exposed according to the provider’s terms and architecture. Planet Security’s AI-enabled approach uses AI-obfuscated data to reduce exposure and distinguish protected workflows from Big-Tech data practices.
Does CPE Level 2 eliminate the need for ongoing security management?
No serious security environment should be treated as “set and forget.” CPE Level 2 provides the technical foundation and managed capabilities for continuous monitoring, maintenance, reporting, and improvement. Security must remain operational every day: not only on assessment day.
Move From Compliance Uncertainty to Controlled Execution
The path to CMMC 2.0 Level 2 is clear: protect CUI, implement all 110 requirements, satisfy all 320 objectives, maintain evidence, and operate the controls continuously.
Trying to assemble those capabilities piecemeal creates gaps. CPE Level 2 delivers a complete, execution-driven solution with 100% coverage designed into the environment from the beginning.
We welcome a discussion on how we may assist in your CMMC success story!
| planetsecurity.net | 702.634.7233 | ![]() |
|---|

