AuditXYZ

Lesson 1 of 6

CMMC Level 1 vs Level 2 vs Level 3: Which One Do You Need?

13 min readBeginner

CMMC Level 1 vs Level 2 vs Level 3

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's program for verifying that contractors actually implement the cybersecurity requirements they have been contractually obligated to meet for years. CMMC 2.0 has three levels, and the level you need is determined by the type of information you handle — not by your company size, revenue, or preference.

Getting the level question right is the single most important decision in your CMMC journey. Aim too low and you become ineligible for contracts. Aim too high and you may spend six figures on controls and assessments you never needed. This lesson breaks down what each level requires, how to determine yours, and what each one realistically costs.

The Short Version

  • Level 1 applies if you handle only Federal Contract Information (FCI). It requires 17 basic safeguarding practices and an annual self-assessment.
  • Level 2 applies if you handle Controlled Unclassified Information (CUI). It requires all 110 security controls from NIST SP 800-171 Rev 2, and for most contractors, a third-party assessment by a C3PAO every three years.
  • Level 3 applies to contractors handling CUI on the DoD's most sensitive programs. It adds 24 enhanced requirements from NIST SP 800-172 on top of Level 2 (134 total), assessed by the government itself (DIBCAC).

Under the phased rollout that began after the 32 CFR program rule took effect in December 2024 — and accelerated once the companion 48 CFR acquisition rule landed in 2025 — CMMC requirements are being written directly into new DoD solicitations. Over the phase-in period, essentially all defense contracts involving FCI or CUI will carry a CMMC level requirement.

CMMC Level 1: Foundational

Level 1 protects Federal Contract Information — information provided by or generated for the government under contract that is not intended for public release. Think delivery schedules, contract terms, performance reports, and routine correspondence. If you hold any DoD contract at all, you almost certainly handle FCI.

What it requires: 17 basic safeguarding practices derived from FAR 52.204-21. These are genuinely basic cybersecurity hygiene: limit system access to authorized users, use antivirus, patch your systems, control visitor access to facilities, sanitize media before disposal, and so on. Most reasonably run IT environments already do the majority of these.

How it is assessed: Annual self-assessment. You evaluate your own environment against the 17 practices, and a senior company official submits an affirmation of compliance in the Supplier Performance Risk System (SPRS). There is no third-party assessor and no POA&M allowed — you must fully meet all 17 practices to affirm.

Who it fits: Contractors who supply commercial products or services and never receive or generate CUI. A janitorial services provider, a commodity parts supplier, or a landscaping company working on a base would typically be Level 1.

CMMC Level 2: Advanced

Level 2 protects Controlled Unclassified Information — information that requires safeguarding under law, regulation, or government-wide policy. In the defense context this includes Controlled Technical Information (CTI), export-controlled data (ITAR/EAR), engineering drawings, specifications, and other sensitive-but-unclassified material.

What it requires: All 110 security controls from NIST SP 800-171 Rev 2, spanning 14 control families — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and system integrity. These map to 320 assessment objectives, and assessors check every one.

How it is assessed: Two tracks exist:

  • C3PAO assessment (the norm): A certified third-party assessment organization conducts an assessment every three years, with an annual affirmation in between. This applies to the large majority of Level 2 contracts, particularly anything involving information critical to national security.
  • Self-assessment (the exception): A small subset of Level 2 contracts permit a triennial self-assessment with annual affirmation. The contract tells you which track applies — you do not get to choose.

Level 2 permits a limited, conditional POA&M (Plan of Action and Milestones): you can achieve conditional certification with some lower-weighted controls unimplemented, provided you score at least 88 out of 110, none of the open items are among the highest-weighted controls, and you close every open item within 180 days. Miss the 180-day window and your conditional status lapses.

You must also have a current NIST SP 800-171 self-assessment score posted in SPRS. Scores range from -203 to a perfect 110, because unimplemented controls subtract 1, 3, or 5 points each depending on weight.

We cover Level 2 in depth in the next lesson.

CMMC Level 3: Expert

Level 3 applies to contractors supporting the DoD's highest-priority programs, where CUI is a target of advanced persistent threats — nation-state adversaries with significant resources.

What it requires: Everything in Level 2, plus 24 enhanced security requirements selected from NIST SP 800-172, for a total of 134 controls. The 800-172 enhancements go beyond hygiene into active defense: penetration-resistant architecture, damage-limiting operations, threat hunting, and cyber resiliency. Examples include employing deception techniques, conducting ongoing threat hunting, and dual authorization for critical operations.

How it is assessed: By the government itself — the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) — every three years. Before DIBCAC will assess you for Level 3, you must already hold a final CMMC Level 2 certification from a C3PAO. Level 3 is sequential, not parallel.

Who it fits: A small fraction of the defense industrial base — primes and key subcontractors on the most sensitive weapons, intelligence, and space programs. If Level 3 applies to you, your contracting officer and prime will make that unambiguous.

Side-by-Side Comparison

Level 1Level 2Level 3
Information protectedFCICUICUI on critical programs
Number of practices/controls17110 (NIST SP 800-171 Rev 2)134 (110 + 24 from NIST SP 800-172)
Assessment typeAnnual self-assessmentTriennial C3PAO assessment (most contracts); self-assessment for a small subsetTriennial DIBCAC (government) assessment
POA&M allowedNoYes, limited — minimum score 88, closed within 180 daysYes, limited, per program rules
Annual affirmationYesYesYes
PrerequisiteNoneNoneFinal Level 2 C3PAO certification
Typical preparation timeline1–3 months12–18 months18–24+ months
Typical all-in cost (SMB)Under $10K/year$50K–$150K+ to prepare, plus $30K–$60K per assessment cycleSignificantly higher; program-dependent

Cost figures vary widely with company size, existing maturity, and scope. For strategies to keep Level 2 costs down, see our guide to the cheapest path to CMMC.

How to Determine Your Level

Your required level is dictated by your contracts, not by self-selection. Work through this checklist:

  • Read your current contracts and active solicitations. Look for DFARS 252.204-7012 (CUI safeguarding), 252.204-7019/7020 (SPRS scoring), and 252.204-7021 (CMMC). The solicitation will state the required CMMC level.
  • Ask your prime contractor in writing. Subcontractors inherit CMMC requirements when FCI or CUI flows down to them. Get the required level, and what data will flow to you, documented.
  • Inventory the information you actually receive and generate. Do you handle drawings, technical specifications, export-controlled data, or anything marked CUI/CTI? That points to Level 2. Only routine contract information? Level 1.
  • Check whether CUI actually needs to touch your systems. If a prime can restrict you to non-CUI work, or you can isolate CUI in a small enclave, you may be able to limit scope — see our small business guide.
  • When in doubt, ask your contracting officer. Guessing wrong in either direction is expensive.

A common trap: companies assume they are "just Level 1" because nobody has sent them anything stamped CUI. Marking discipline in the supply chain is imperfect. If you receive technical drawings for a defense article, treat the Level 2 question seriously even if the markings are missing.

Timelines: How Long Each Level Takes

  • Level 1: Most organizations can implement the 17 practices, document them, and complete a self-assessment in one to three months.
  • Level 2: Industry experience consistently shows 12 to 18 months from a standing start to assessment readiness. The long poles are technical remediation (FIPS-validated encryption, logging, MFA everywhere), documentation (the System Security Plan alone is a major effort), and C3PAO scheduling — assessor capacity is limited, and lead times of several months for a booking are common. If you are up against a contract deadline, read our guide on the quickest route to CMMC.
  • Level 3: Add 6 to 12 months on top of a completed Level 2, since you must hold a final Level 2 certificate first and the 800-172 enhancements often require architectural changes.

Consequences of Non-Compliance

CMMC is a condition of award. The consequences of not having the required level are direct and financial:

  1. Contract ineligibility. Under the phased rollout, new solicitations require the stated CMMC level at award. No certification, no contract — and primes are already screening subcontractors accordingly.
  2. Loss of existing revenue streams. Recompetes and option exercises will pick up CMMC requirements. Incumbency does not exempt you.
  3. False Claims Act exposure. Annual affirmations are signed by a senior official. Affirming compliance you do not have has already produced multi-million-dollar settlements under the Department of Justice's Civil Cyber-Fraud Initiative. This is the sharpest edge of the program.
  4. Supply chain removal. Primes are consolidating their supplier bases around certified vendors. Being the last uncertified shop in your niche is a bad competitive position.

Which Level Should You Target?

Target the level your contracts require — no more, no less. For most readers of this course, that means Level 2, because that is where CUI, C3PAO assessments, and the bulk of the cost and effort live. If you are certain you only handle FCI, get Level 1 done quickly and document it well. If someone tells you that you need Level 3, verify it with your contracting officer before spending a dollar, because Level 3 is rare.

For a structured breakdown of the framework's control families and program mechanics, see the CMMC framework page. If terms like FCI, CUI, C3PAO, or SPRS are still fuzzy, our glossary has plain-English definitions.

Frequently Asked Questions

Can I choose to self-assess at Level 2 to save money?

No. The assessment track is specified in the contract. The DoD has indicated that the large majority of Level 2 contracts require a C3PAO assessment, with self-assessment reserved for a small subset of acquisitions involving less sensitive CUI. Plan for a C3PAO assessment unless your contract explicitly says otherwise.

How long is a CMMC certification valid?

Level 2 C3PAO certifications and Level 3 DIBCAC assessments are valid for three years, with an annual affirmation of continued compliance required in each intervening year. Level 1 requires a fresh self-assessment and affirmation every year.

What happens if I fail my C3PAO assessment?

If you score at least 88 and your open items are POA&M-eligible, you can receive conditional certification and have 180 days to close the gaps, verified through a closeout assessment. If you score below 88 or fail must-pass controls, you do not certify and must remediate and re-engage the C3PAO — paying for assessment time again. This is why thorough readiness reviews before the real assessment matter.

Do subcontractors need the same level as the prime?

Not necessarily. You need the level corresponding to the information that flows down to you. A prime holding a Level 2 contract can use a Level 1 subcontractor if that sub only ever receives FCI. But if CUI flows to you, Level 2 applies regardless of your position in the chain.

Is CMMC Level 1 really just a self-assessment — can I ignore it?

You can self-assess, but you cannot ignore it. The annual affirmation in SPRS is signed by a senior official and carries False Claims Act risk if it is inaccurate. Treat the 17 practices as real requirements with real evidence behind them.

Does a SOC 2 report or ISO 27001 certificate count toward CMMC?

No framework substitutes for CMMC, but there is real overlap in underlying controls — access management, logging, incident response, and vendor management work carries over. If you already maintain SOC 2 or ISO 27001, you will start with meaningful maturity, but you must still map to NIST SP 800-171 and complete the CMMC assessment process.


Comparing readiness platforms, RPOs, and C3PAOs is half the battle of a CMMC project. AuditXYZ helps you compare compliance automation tools and auditors side by side — features, framework coverage, and pricing — so you can build your CMMC stack with confidence.