Frameworks
- CMMC L2U.S. Department of Defense
CMMC Level 2
110 practices · 14 domains · Assessment Guide Level 2 v2.13 (32 CFR Part 170)
The Cybersecurity Maturity Model Certification (CMMC) Level 2 comprises the 110 security requirements of NIST SP 800-171 Revision 2, assessed against the objectives in NIST SP 800-171A. Level 2 applies to defense contractors and subcontractors that process, store, or transmit Controlled Unclassified Information (CUI).
Practice statements and assessment objectives are quoted from the CMMC Assessment Guide — Level 2, Version 2.13 (drawing on NIST SP 800-171 Rev. 2 and NIST SP 800-171A). Primary references: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final and https://csrc.nist.gov/pubs/sp/800/171/a/final. U.S. government works, not subject to copyright in the United States.
Vote: which catalog should we quote next?
CMMC Level 2 is the current focus. The schema already supports other frameworks; which one should we quote next? Be the first to vote.
CMMC Level 3
0
Higher-assurance practices beyond Level 2.
FedRAMP
0
Cloud authorization baselines built on 800-53.
ISO/IEC 27001
0
Annex A controls with internationally familiar numbering.
NIST SP 800-53
0
Families and controls used across federal systems.
SOX ITGC
0
IT general controls for financial reporting environments.
Sign in to cast or change your vote. One vote per account.
Why seeding is slow on purpose
CMMC Level 3, ISO/IEC 27001:2022 Annex A, NIST SP 800-53 Rev. 5, SOX ITGC, and FedRAMP are all expressible in the existing schema. Each still needs a seed file with accurately quoted control text — which is the slow part, and deliberately so: ControlVerdict never paraphrases normative language. Votes above help us prioritize that work; they are not a shipping commitment.