Foundations

CMMC Levels Explained: Level 1 vs Level 2 vs Level 3

Last updated: 2026-08-25

The Three Levels at a Glance Level 1 Level 2 Level 3 FCI vs CUI Which Level You Need

The Three Levels at a Glance

CMMC (the Cybersecurity Maturity Model Certification) has three levels, codified in 32 CFR Part 170. The level that applies to you is not something you choose. It is set by the sensitivity of the information a given contract involves, and it determines how many requirements you must meet and who verifies that you meet them.

Most of the confusion around CMMC is really confusion about which level applies. The short answer: the type of data drives the level. Federal Contract Information points to Level 1, Controlled Unclassified Information points to Level 2, and a small set of the most sensitive programs point to Level 3.

Level 1Protects Federal Contract Information (FCI). 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment and an annual affirmation. No third party required.
Level 2Protects Controlled Unclassified Information (CUI). The 110 NIST SP 800-171 requirements. For most contracts, a C3PAO third-party assessment every three years.
Level 3Highest level, for programs at greatest risk from advanced persistent threats. The 110 Level 2 requirements plus a subset of the enhanced NIST SP 800-172 requirements. Assessed by the government (DIBCAC).

One current note: in July 2026 the Department of War paused the Phase 2 third-party certification mechanism pending a reform review. The levels themselves, and the underlying obligations to protect FCI and CUI, did not change. See what the Phase 2 suspension changed for the current state.

CMMC Level 1: Basic Safeguarding of FCI

Level 1 is the entry level. It applies to contractors that handle Federal Contract Information, which is non-public information provided by or generated for the government under a contract, but that is not Controlled Unclassified Information. Think of the routine, non-public details of doing business on a federal contract that are still not meant for public release.

The Level 1 bar is the 15 basic safeguarding requirements in FAR 52.204-21. They cover fundamentals: limiting system access to authorized users, controlling who can do what, sanitizing media before disposal, applying updates, and using basic boundary protection. Level 1 is verified by an annual self-assessment and an annual affirmation from a senior official. No commercial assessor is involved.

Who needs Level 1
Contractors whose only sensitive data under a contract is Federal Contract Information, and who never store, process, or transmit CUI. The moment CUI enters the picture, the requirement jumps to Level 2.

CMMC Level 2: Protecting CUI

Level 2 is where most of the defense industrial base lives. It applies to any contractor that stores, processes, or transmits Controlled Unclassified Information: technical drawings, specifications, test data, controlled program information, and the many other categories of CUI that flow down through the supply chain.

The Level 2 standard is the 110 requirements of NIST SP 800-171, spanning 14 security domains. For the large majority of Level 2 contracts, compliance is verified by an accredited C3PAO through a third-party assessment on a three-year cycle, not by self-attestation. A limited set of Level 2 programs may be met with a self-assessment, but you should assume a C3PAO assessment applies unless your contract states otherwise.

If Level 2 is your target, start with the plain-English CMMC Level 2 overview and the 110-requirement checklist, then look at what to look for in a Level 2 platform. 1TEN is an air-gapped, on-premises platform built specifically to take a small contractor through all 110 requirements; see the platform.

Who needs Level 2
Any contractor or subcontractor that handles CUI under a DoD contract, regardless of company size. A ten-person machine shop that receives a controlled technical data package is held to the same 110 requirements as a large prime.

CMMC Level 3: The Highest Bar

Level 3 applies to a small number of programs that carry the greatest risk from advanced persistent threats, the well-resourced nation-state actors that specifically target defense information. It is not something most contractors will encounter, and a contract will make it explicit when it applies.

Level 3 builds on Level 2: you must first meet all 110 NIST SP 800-171 requirements, then add a subset of the enhanced requirements from NIST SP 800-172. Assessment is conducted by the government, through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), rather than by a commercial C3PAO. In practice, a Level 3 program means a mature Level 2 program first.

FCI vs CUI: The Distinction That Sets Your Level

Because the data drives the level, the single most important question is whether you handle Federal Contract Information, Controlled Unclassified Information, or both.

Federal Contract Information (FCI)Non-public information provided by or generated for the government under a contract to develop or deliver a product or service. Not intended for public release, but not designated as CUI. Drives Level 1.
Controlled Unclassified Information (CUI)Information the government creates or possesses, or that an entity creates for the government, that a law, regulation, or policy requires to be safeguarded. In the DIB this includes controlled technical information, drawings, and specifications. Drives Level 2.

Getting this classification right is the foundation of everything downstream. Contractors routinely under-scope by missing CUI they actually hold, or over-scope by treating ordinary business data as CUI. For the detail, see how to scope CUI for CMMC and what counts as CUI and how to handle it.

How to Tell Which Level Your Contract Requires

You do not have to guess. The required level is written into the contract, and you can confirm it in a few steps.

Check the contract clauseDFARS 252.204-7021 is the clause that requires CMMC, and it specifies the level. If it names Level 2, that is your requirement. See the DFARS cyber clause decoder for how 7021 relates to 7012, 7019, and 7020.
Identify your dataDetermine whether the work involves FCI only, or CUI. CUI anywhere in scope means Level 2. If you receive drawings, specifications, or technical data from a prime, you are almost certainly handling CUI.
Ask your primeAs a subcontractor, your level follows the CUI you receive under the prime's contract. If the flow-down is unclear, confirm in writing rather than assume Level 1.
Default to Level 2 if CUI is involvedWhen in doubt and CUI is in the picture, plan for Level 2 with a C3PAO assessment. It is the level the majority of the defense industrial base has to meet.

For most small defense manufacturers and suppliers, the answer is Level 2, because they handle CUI. If that is you, the practical next step is to map your environment against the 110 requirements and track an honest SPRS score while you close gaps.

Frequently Asked Questions

How many CMMC levels are there?

Three. Level 1 covers basic safeguarding of Federal Contract Information (FCI). Level 2 covers protection of Controlled Unclassified Information (CUI) against the 110 NIST SP 800-171 requirements. Level 3 adds a subset of the enhanced NIST SP 800-172 requirements for the highest-priority programs.

What is the difference between CMMC Level 1 and Level 2?

Level 1 protects FCI using 15 basic safeguarding requirements from FAR 52.204-21, verified by an annual self-assessment. Level 2 protects CUI using the 110 NIST SP 800-171 requirements, and for most contracts it is verified by a C3PAO third-party assessment. The trigger is the data: FCI means Level 1, CUI means Level 2.

Do I need CMMC Level 1 or Level 2?

If you only handle Federal Contract Information, you need Level 1. If you store, process, or transmit Controlled Unclassified Information, you need Level 2. Most defense manufacturers and suppliers that receive drawings, specifications, or technical data handle CUI and therefore need Level 2.

What is CMMC Level 3?

Level 3 is the highest level, reserved for a small number of programs at greatest risk from advanced persistent threats. It requires the 110 NIST SP 800-171 requirements plus a subset of the enhanced NIST SP 800-172 requirements, and it is assessed by the government (DIBCAC), not a commercial C3PAO.

Is CMMC Level 2 a self-assessment or a third-party assessment?

For most Level 2 contracts, a third-party assessment by an accredited C3PAO is required every three years. A limited set of Level 2 programs may be met with a self-assessment, but assume a C3PAO assessment applies unless your contract specifically says otherwise.

How many requirements are in each CMMC level?

Level 1 has 15 requirements (FAR 52.204-21). Level 2 has 110 requirements (NIST SP 800-171). Level 3 has the 110 Level 2 requirements plus a subset of the enhanced requirements in NIST SP 800-172.
New to CMMC?

How to get CMMC certified.

The full path, from scoping your CUI boundary to passing the C3PAO assessment, in one step-by-step guide. Then see how 1TEN runs every step on-premises, inside your boundary.

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo