Correct Answer: B
CMMC Level 2 requires full implementation of the 110 security requirements specified in NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. These practices form the foundation for safeguarding CUI across defense contractor systems.
* NIST SP 800-53 is a broader catalog of security controls for federal systems, not specific to CUI in the defense contractor environment.
* 48 CFR 52.204-21 establishes basic safeguarding requirements for Federal Contract Information (FCI) and corresponds to CMMC Level 1.
* DFARS 252.204-7012 defines safeguarding and incident reporting obligations but does not enumerate the specific security practices required.
Thus, Level 2 practices are aligned to NIST SP 800-171.
Reference Documents:
* CMMC Model v2.0 Overview, December 2021
* NIST SP 800-171 Rev. 2