The 88-point passing score for L2 is one of the most-referenced numbers in CMMC. It is set in 32 CFR § 170.21, and the scoring methodology is the DoD Assessment Methodology for NIST SP 800-171, which DoW continues to use.
How the score is calculated
- Start at 110. Each of the 110 NIST SP 800-171 Rev 2 practices contributes 1, 3, or 5 points to the maximum, summing to 110.
- Deduct for each NOT MET practice. A NOT MET 5-pointer reduces the score by 5; a 1-pointer by 1.
- Deduct for each POA&M item too. POA&M items defer the remediation, but they do not pause the score. The score must reach 88 with the POA&M deductions counted.
- Partial credit on two practices. The Methodology allows partial credit on 3.5.3 (MFA) and 3.13.11 (FIPS cryptography). Instead of the full 5-point loss, a 3-point deduction may apply in certain partial-implementation cases.
The 1, 3, and 5 point weighting
| Point value | Practice character | Example practices |
|---|---|---|
| 5 points | Highest-impact practices; failure puts CUI directly at risk | 3.1.1, 3.1.2, 3.5.3 (MFA), 3.13.11 (FIPS), 3.14.x (malicious code protection) |
| 3 points | Moderate-impact practices | Many AC, IA, CM, SC practices |
| 1 point | Important practices but lower direct-CUI impact | Many AT, AU, PE practices |
What the 88-point floor means in practice
You have at most a 22-point budget of failures.
- 4 practices at 5 points each = 20 (fits).
- 5 practices at 5 points each = 25 (fails).
- 22 practices at 1 point each = 22 (fits exactly).
- Any combination summing above 22 fails.
The OSA should not come into the assessment with POA&M items
The 22-point budget is a ceiling on POA&M-eligible deductions, not a license to fail high-criticality practices. The POA&M mechanism exists for gaps that surface during the assessment, not for known undone work. An OSA that walks into the assessment with known POA&M items is signaling poor preparation, and the assessor will scrutinize the rest of the evidence accordingly.
Common errors
- Confusing the score with the DFARS 252.204-7019 score. Both use the DoD Assessment Methodology. The DFARS score is the self-reported NIST 800-171 score (-203 to 110 range) submitted in SPRS. The CMMC score is the assessment-derived score (0 to 110 range) used against the 88 threshold. Same Methodology, same 1/3/5 weights, different submissions.
- Thinking 80% means 80 out of 100. CMMC scoring is out of 110, so 80% = 88.
- Missing the partial-credit rule for 3.5.3 and 3.13.11. Used correctly, partial credit can be the difference between passing and failing.
Sources
Get a pre-assessment score review.
Wrightbrained Security runs pre-assessment scoring reviews against the DoD Assessment Methodology, including the partial-credit rules, so you know where you will land before the C3PAO arrives.
Talk with a Lead Assessor