CMMC ANSWER ENGINE

What is the CMMC minimum passing score?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14
Quick answer. The CMMC Level 2 minimum passing score is 88 out of 110, which is 80%. Scoring uses the DoD Assessment Methodology: every practice is worth 1, 3, or 5 points; you start at 110 and lose the practice's point value for each NOT MET practice and for each POA&M item. POA&M items still deduct at assessment time. The OSA should not come into the assessment with known POA&M items, and every practice or objective that cannot go on a POA&M must be MET before the assessment. Level 1 has no point-based score; every L1 practice must be MET.

The 88-point passing score for L2 is one of the most-referenced numbers in CMMC. It is set in 32 CFR § 170.21, and the scoring methodology is the DoD Assessment Methodology for NIST SP 800-171, which DoW continues to use.

How the score is calculated

  1. Start at 110. Each of the 110 NIST SP 800-171 Rev 2 practices contributes 1, 3, or 5 points to the maximum, summing to 110.
  2. Deduct for each NOT MET practice. A NOT MET 5-pointer reduces the score by 5; a 1-pointer by 1.
  3. Deduct for each POA&M item too. POA&M items defer the remediation, but they do not pause the score. The score must reach 88 with the POA&M deductions counted.
  4. Partial credit on two practices. The Methodology allows partial credit on 3.5.3 (MFA) and 3.13.11 (FIPS cryptography). Instead of the full 5-point loss, a 3-point deduction may apply in certain partial-implementation cases.

The 1, 3, and 5 point weighting

Point valuePractice characterExample practices
5 pointsHighest-impact practices; failure puts CUI directly at risk3.1.1, 3.1.2, 3.5.3 (MFA), 3.13.11 (FIPS), 3.14.x (malicious code protection)
3 pointsModerate-impact practicesMany AC, IA, CM, SC practices
1 pointImportant practices but lower direct-CUI impactMany AT, AU, PE practices

What the 88-point floor means in practice

You have at most a 22-point budget of failures.

  • 4 practices at 5 points each = 20 (fits).
  • 5 practices at 5 points each = 25 (fails).
  • 22 practices at 1 point each = 22 (fits exactly).
  • Any combination summing above 22 fails.

The OSA should not come into the assessment with POA&M items

The 22-point budget is a ceiling on POA&M-eligible deductions, not a license to fail high-criticality practices. The POA&M mechanism exists for gaps that surface during the assessment, not for known undone work. An OSA that walks into the assessment with known POA&M items is signaling poor preparation, and the assessor will scrutinize the rest of the evidence accordingly.

Make sure that every practice and every assessment objective that cannot go on a POA&M is MET before the assessment. Items on the § 170.21(a)(2)(ii) point-value cap (anything worth more than 1 point in the CMMC Scoring Methodology, with only the FIPS carve-out) and items on the § 170.21(a)(2)(iii) named-six list cannot appear on a POA&M at all. If you go into the assessment with one of these NOT MET, you will fail the assessment and have to start all over with a new initial assessment, not just a closeout. The full list and the FIPS carve-out are detailed in Which CMMC controls can NOT be on a POA&M?.

Common errors

  • Confusing the score with the DFARS 252.204-7019 score. Both use the DoD Assessment Methodology. The DFARS score is the self-reported NIST 800-171 score (-203 to 110 range) submitted in SPRS. The CMMC score is the assessment-derived score (0 to 110 range) used against the 88 threshold. Same Methodology, same 1/3/5 weights, different submissions.
  • Thinking 80% means 80 out of 100. CMMC scoring is out of 110, so 80% = 88.
  • Missing the partial-credit rule for 3.5.3 and 3.13.11. Used correctly, partial credit can be the difference between passing and failing.

Sources

  • CMMC 101 Brief (Nov 2025). link
  • 32 CFR Part 170, § 170.21 Minimum passing score. link
  • DoD Assessment Methodology for NIST SP 800-171 v1.2.1. link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); DoD Assessment Methodology v1.2.1 (Jun 2020)

Get a pre-assessment score review.

Wrightbrained Security runs pre-assessment scoring reviews against the DoD Assessment Methodology, including the partial-credit rules, so you know where you will land before the C3PAO arrives.

Talk with a Lead Assessor
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.