The Three Levels at a Glance
CMMC (the Cybersecurity Maturity Model Certification) has three levels, codified in 32 CFR Part 170. The level that applies to you is not something you choose. It is set by the sensitivity of the information a given contract involves, and it determines how many requirements you must meet and who verifies that you meet them.
Most of the confusion around CMMC is really confusion about which level applies. The short answer: the type of data drives the level. Federal Contract Information points to Level 1, Controlled Unclassified Information points to Level 2, and a small set of the most sensitive programs point to Level 3.
| Level 1 | Protects Federal Contract Information (FCI). 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment and an annual affirmation. No third party required. |
| Level 2 | Protects Controlled Unclassified Information (CUI). The 110 NIST SP 800-171 requirements. For most contracts, a C3PAO third-party assessment every three years. |
| Level 3 | Highest level, for programs at greatest risk from advanced persistent threats. The 110 Level 2 requirements plus a subset of the enhanced NIST SP 800-172 requirements. Assessed by the government (DIBCAC). |
One current note: in July 2026 the Department of War paused the Phase 2 third-party certification mechanism pending a reform review. The levels themselves, and the underlying obligations to protect FCI and CUI, did not change. See what the Phase 2 suspension changed for the current state.
CMMC Level 1: Basic Safeguarding of FCI
Level 1 is the entry level. It applies to contractors that handle Federal Contract Information, which is non-public information provided by or generated for the government under a contract, but that is not Controlled Unclassified Information. Think of the routine, non-public details of doing business on a federal contract that are still not meant for public release.
The Level 1 bar is the 15 basic safeguarding requirements in FAR 52.204-21. They cover fundamentals: limiting system access to authorized users, controlling who can do what, sanitizing media before disposal, applying updates, and using basic boundary protection. Level 1 is verified by an annual self-assessment and an annual affirmation from a senior official. No commercial assessor is involved.
CMMC Level 2: Protecting CUI
Level 2 is where most of the defense industrial base lives. It applies to any contractor that stores, processes, or transmits Controlled Unclassified Information: technical drawings, specifications, test data, controlled program information, and the many other categories of CUI that flow down through the supply chain.
The Level 2 standard is the 110 requirements of NIST SP 800-171, spanning 14 security domains. For the large majority of Level 2 contracts, compliance is verified by an accredited C3PAO through a third-party assessment on a three-year cycle, not by self-attestation. A limited set of Level 2 programs may be met with a self-assessment, but you should assume a C3PAO assessment applies unless your contract states otherwise.
If Level 2 is your target, start with the plain-English CMMC Level 2 overview and the 110-requirement checklist, then look at what to look for in a Level 2 platform. 1TEN is an air-gapped, on-premises platform built specifically to take a small contractor through all 110 requirements; see the platform.
CMMC Level 3: The Highest Bar
Level 3 applies to a small number of programs that carry the greatest risk from advanced persistent threats, the well-resourced nation-state actors that specifically target defense information. It is not something most contractors will encounter, and a contract will make it explicit when it applies.
Level 3 builds on Level 2: you must first meet all 110 NIST SP 800-171 requirements, then add a subset of the enhanced requirements from NIST SP 800-172. Assessment is conducted by the government, through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), rather than by a commercial C3PAO. In practice, a Level 3 program means a mature Level 2 program first.
FCI vs CUI: The Distinction That Sets Your Level
Because the data drives the level, the single most important question is whether you handle Federal Contract Information, Controlled Unclassified Information, or both.
| Federal Contract Information (FCI) | Non-public information provided by or generated for the government under a contract to develop or deliver a product or service. Not intended for public release, but not designated as CUI. Drives Level 1. |
| Controlled Unclassified Information (CUI) | Information the government creates or possesses, or that an entity creates for the government, that a law, regulation, or policy requires to be safeguarded. In the DIB this includes controlled technical information, drawings, and specifications. Drives Level 2. |
Getting this classification right is the foundation of everything downstream. Contractors routinely under-scope by missing CUI they actually hold, or over-scope by treating ordinary business data as CUI. For the detail, see how to scope CUI for CMMC and what counts as CUI and how to handle it.
How to Tell Which Level Your Contract Requires
You do not have to guess. The required level is written into the contract, and you can confirm it in a few steps.
| Check the contract clause | DFARS 252.204-7021 is the clause that requires CMMC, and it specifies the level. If it names Level 2, that is your requirement. See the DFARS cyber clause decoder for how 7021 relates to 7012, 7019, and 7020. |
| Identify your data | Determine whether the work involves FCI only, or CUI. CUI anywhere in scope means Level 2. If you receive drawings, specifications, or technical data from a prime, you are almost certainly handling CUI. |
| Ask your prime | As a subcontractor, your level follows the CUI you receive under the prime's contract. If the flow-down is unclear, confirm in writing rather than assume Level 1. |
| Default to Level 2 if CUI is involved | When in doubt and CUI is in the picture, plan for Level 2 with a C3PAO assessment. It is the level the majority of the defense industrial base has to meet. |
For most small defense manufacturers and suppliers, the answer is Level 2, because they handle CUI. If that is you, the practical next step is to map your environment against the 110 requirements and track an honest SPRS score while you close gaps.