Skip to main content
Skip to main content
CMMC Level 2 Compliance

CMMC Level 2 — Practice C017

Federal contractors must achieve CMMC Level 2 to maintain eligibility for DoD contracts. ThirdProof assesses vendors against NIST SP 800-171 controls and flags prohibited entity exposure.

Assess a Vendor Free →

One vendor, no account · No credit card required

CMMC Level 2 — Practice C017 (Supply Chain Risk)

CMMC Level 2 requires organizations to implement supply chain risk management practices including screening for prohibited entities under FAR 4.2102 and assessing foreign ownership, control, or influence (FOCI). ThirdProof automates these checks and produces C3PAO-ready documentation.

ThirdProof uses a deterministic rules engine to assign risk tiers. AI writes the narrative — rules drive the decision.

CMMC Level 2-specific findings

CriticalFAR 4.2102 prohibited entity check (Huawei, ZTE, Kaspersky, etc.)
CriticalForeign ownership, control, or influence (FOCI) assessment
IncludedCUI handling and flow-down requirement documentation
FlaggedCountry of origin for software components

C3PAO-ready evidence package

ThirdProof documentation is structured for submission to Certified Third-Party Assessment Organizations during CMMC certification reviews.

// CMMC C017 Practice Evidence
Prohibited entity check: Clear ✓
FOCI assessment: No foreign control ✓
CUI handling: Documented
DFARS 7012: Incident reporting — review
Country of origin: US / NATO ✓

Placing CUI with a cloud vendor? DFARS 252.204-7012 expects FedRAMP Moderate or equivalent, and the authorization covers a named offering, not the vendor. Read how to check which FedRAMP offering a vendor actually holds.

Vendors assessed under CMMC Level 2

ThirdProof has investigated these vendors with CMMC Level 2-specific compliance framing.

How ThirdProof works for CMMC Level 2

1
Enter the vendor

Name, domain, and data access level. ThirdProof auto-detects your industry context.

2
27 sources queried

Sanctions, cyber risk, business registry, adverse media, and more — with CMMC Level 2-specific controls layered on top.

3
Download the report

PDF report with CMMC Level 2 evidence statements, risk tier, confidence score, and individual findings.

Start your CMMC Level 2 vendor assessment

Run your first vendor assessment now — no account, no credit card. Report time: under 10 minutes.

Assess a Vendor Free →

One vendor, no account · No credit card required

Read our full methodology · View pricing