Skip to main content
Course

CMMC Level 2 Certification Bootcamp

Become the analyst who gets a defense contractor through a CMMC Level 2 assessment.

Intermediate

Level

6

Modules

27

Lessons

6

Graded quizzes

6

Assignments

22 hours

Estimated time

What you will be able to do

  • Explain the CMMC 2.0 ecosystem: FCI vs CUI, the three levels, C3PAOs and DIBCAC
  • Map the 110 NIST SP 800-171 requirements across the 14 control families
  • Scope a CUI environment and categorize assets correctly
  • Write System Security Plan control statements an assessor will accept
  • Calculate an SPRS score and manage a compliant POA&M within the 180-day rule
  • Walk through a C3PAO assessment and judge a control MET / NOT MET / N-A
  • Assess a real defense contractor's controls in the hands-on lab

What is inside

6 modules, 27 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    CMMC 2.0 & the Defense Industrial Base

    Before you can assess or remediate a single control, you have to know what game you are playing. This module explains what CMMC 2.0 is, why the Department of Defense built it, the difference between FCI and CUI, the three levels and who assesses each, the people and bodies in the CMMC ecosystem, how CMMC sits on top of NIST SP 800-171, the DFARS clauses that put it in your contract, the SPRS score that lives in a federal database, and the phased rollout. You finish by advising a small manufacturer that just won a DoD subcontract involving CUI.

    5 lessons · 16 quiz questions · assignment

  2. 02

    The 110 Requirements: Families, Objectives & Assessment Methods

    Module 1 told you why CMMC exists and how the program runs. This module opens the engine: the 110 security requirements of NIST SP 800-171 organized across 14 families, how a single requirement decomposes into 800-171A assessment objectives, the three methods an assessor uses to gather evidence (Examine, Interview, Test), and how a requirement is finally judged MET, NOT MET, or NOT APPLICABLE. You finish by writing an assessor-style breakdown of five requirements from five different families.

    4 lessons · 16 quiz questions · assignment

  3. 03

    Scoping the CUI Environment & the SSP

    Before you implement a single control, you have to answer one question: what exactly is being assessed? This module teaches the five CMMC asset categories, how each one is treated in a Level 2 assessment, how enclaves shrink your scope, and how to map CUI data flows to draw the assessment boundary. Then you learn the System Security Plan, the document the assessor reads first, and how to write a control statement a C3PAO will actually accept. You finish by scoping six assets for the fictional Ironclad Machining and writing three real 800-171 control statements.

    5 lessons · 18 quiz questions · assignment

  4. 04

    Implementing the Controls & Gathering Evidence

    Earlier modules taught you what CMMC Level 2 is: 110 requirements drawn from NIST SP 800-171, assessed by a C3PAO every three years, scored into SPRS. This module is where you stop talking about the requirements and start proving them. You will walk family by family through the most assessment-critical requirements, covering Access Control, Identification and Authentication, Audit and Accountability, Configuration Management, Incident Response, Media Protection, System and Communications Protection, and System and Information Integrity, and for each one you will learn the exact artifact that makes an assessor stop arguing. You finish by building a six-requirement evidence plan for a fictional defense contractor.

    4 lessons · 16 quiz questions · assignment

  5. 05

    SPRS Scoring, POA&M & Staying Compliant

    You have learned the 110 requirements. Now you learn the scoreboard. This module teaches the SPRS scoring methodology, where you start at 110, subtract weighted points for each gap, and land somewhere between -203 and +110, and how to turn a gap list into a number. You will learn what a POA&M can and cannot hold under CMMC, the strict 180-day closeout clock, the senior-official affirmation, and the annual-and-three-year rhythm that keeps a certification alive. You finish by scoring a real gap list and drafting a POA&M.

    4 lessons · 16 quiz questions · assignment

  6. 06

    The C3PAO Assessment & CMMC Capstone

    You built the program; now you live through the exam. This module walks the CMMC Assessment Process (CAP) end to end: the phases, the assessment team and its roles, how examine, interview and test gather objective evidence, how each of the 110 requirements is scored MET or NOT MET, and what a finding actually looks like. You will learn why most contractors fail, what the certificate means and why it lasts three years, how to sustain compliance after the assessor leaves, and the CMMC career paths (CCP, CCA, RP). You finish with a capstone: a readiness memo for Ironclad Machining that pulls the whole course together.

    5 lessons · 18 quiz questions · assignment