CMMC levels

CMMC levels 1, 2 and 3 — and which one is yours.

There are three CMMC levels, and which one applies to you is decided by the information a contract puts on your systems, not by your size or your revenue. Level 1 covers Federal Contract Information. Level 2 covers Controlled Unclassified Information and carries all 110 NIST 800-171 requirements. Level 3 adds 24 more for the programs DoD considers highest risk. This page sets out what each level requires, who assesses it, how long it lasts, and how to work out which one your next contract will name.

Last reviewed

The three levels at a glance glance

Everything that differs between them, in one place.

Level 1Level 2Level 3
Information protectedFCICUICUI on the highest-priority programs
Requirements15, from FAR 52.204-21110, from NIST SP 800-171 Rev 2Level 2 plus 24 selected from NIST SP 800-172
Who assessesYou do — self-assessmentSelf-assessment or a C3PAO, depending on the contractDCMA DIBCAC
How oftenAnnuallyEvery three yearsEvery three years
AffirmationAnnual, in SPRSAnnual, in SPRSAnnual, in SPRS
Plan of action allowedNo — all 15 must be metYes, within limits, closed out in 180 daysYes, within limits, closed out in 180 days
PrerequisiteNoneNoneA Level 2 (C3PAO) certification first

Per 32 CFR part 170, the CMMC Program rule. Status as at 23 August 2026.

Which CMMC level do I need?

Four questions, in order. The first one does most of the work.

1. Does the contract put CUI on your systems? If yes, you are looking at Level 2 or Level 3. If the only non-public government information you handle is Federal Contract Information — information generated for or provided by the government under a contract, not intended for public release, but not marked CUI — you are at Level 1.

2. Does the solicitation say? It should. The required level and assessment type are stated in the solicitation and carried in the contract. Do not infer a level from your NAICS code or from what a competitor was asked for; read the clause.

3. Are you a subcontractor? Then your level is driven by what actually flows to you. If you will handle only FCI in performance of the subcontract, Level 1 (Self) is the requirement. If you will handle CUI and the prime contract carries a Level 3 requirement, the minimum for you is Level 2 with a C3PAO certification. Primes are required to flow this down and to confirm you meet it before award.

4. Is it a commercial off-the-shelf product? Contracts solely for COTS items are excluded from the CMMC requirement altogether. This exclusion is narrower than people hope — it is about what is being bought, not about how standard your product feels to you.

One trap worth naming. Companies routinely conclude they hold no CUI, then find drawings, specifications, or a technical data package sitting in a shared mailbox. CUI arrives without ceremony and is frequently unmarked in practice. Work from what is on your systems, not from what you believe should be.

CMMC Level 1

Fifteen requirements, self-assessed annually, and no room to defer any of them.

CMMC Level 1 applies where a contract involves Federal Contract Information and no CUI. Its 15 requirements are the basic safeguarding requirements already in FAR 52.204-21 — the clause in almost every federal contract — so Level 1 asks for nothing that was not already owed. It is basic hygiene: limit system access to authorized users, control who can do what, sanitize media before disposal, run antivirus, apply updates, control physical access.

The mechanics are what people get wrong. Level 1 is assessed by you, annually, and the result is affirmed in SPRS by a named Affirming Official who is accountable for the claim. There is no plan of action at Level 1: partial implementation is not a passing state, so all 15 must be met at the point of affirmation. It is the easiest level to satisfy and the easiest to make a false statement on, which is why the affirming official is named.

CMMC Level 2

The level nearly everyone means when they say “CMMC”, and the one the July 2026 suspension changed.

CMMC Level 2 is the 110 requirements of NIST SP 800-171 Revision 2 — the ones you already owe under DFARS 252.204-7012 — with an assessment attached. It applies where a contract puts CUI on your systems. There are two assessment types, and the contract decides which you get: Level 2 (Self), where you assess and affirm; and Level 2 (C3PAO), where a CMMC Third-Party Assessor Organization does it and DoD records the certification.

A Level 2 status lasts three years, with an affirmation in SPRS each year in between. Achieving it does not require a perfect score on the day: if you score at least 88 of 110 you can be granted a Conditional status and carry the remainder on a plan of action, which must be closed and re-assessed within 180 days to become Final. What you cannot defer is the heavy end — the 3- and 5-point requirements have to be implemented, with a narrow carve-out around FIPS-validated cryptography. Multi-factor authentication is not something you can promise for later.

What changed in July 2026. Phase 2 — the point from 10 November 2026 at which Level 2 C3PAO certification would start appearing as a condition of award — was suspended on 13 July 2026, along with the phases after it, pending a reform review reporting in mid-September. Level 2 self-assessment requirements under Phase 1 were not suspended and are in solicitations now. Neither was the underlying 800-171 obligation. The certification deadline moved; the requirement did not.

CMMC Level 3

Rare, government-assessed, and gated behind Level 2.

CMMC Level 3 applies to a small population of programs where the consequence of compromise is judged highest. It layers 24 requirements selected from NIST SP 800-172 — enhanced controls aimed at advanced persistent threats — on top of all 110 at Level 2, and it is assessed by the government itself: the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center, DIBCAC.

You cannot go straight to it. A current Level 2 certification from a C3PAO is a prerequisite for scheduling a Level 3 assessment, which in practice makes Level 3 a two-assessment sequence with a queue in front of each. If a program office has told you Level 3 is coming, the Level 2 work is the critical path.

What to do about your level now now

The pause removed a deadline, not the work. This is the sequence that holds whatever the reform task force recommends.

  1. Establish the level each active contract implies
    Read the clauses rather than assuming. Where a contract is silent and CUI is plainly in play, plan for Level 2.
  2. Locate the CUI and draw the boundary
    Scope decides cost more than any other choice. An enclave is usually cheaper than the whole estate — if the segmentation is real.
  3. Self-assess against all 110 and post the score
    Honestly. The score is an attestation, and it is visible to the primes deciding whether to award you a subcontract.
  4. Close the 3- and 5-point gaps first
    They cost the most points and cannot be carried on a plan of action.
  5. Keep your own supply chain in view
    Whatever level you hold, you are answerable for the subcontractors you pass CUI to. Their attestation is a claim; what their perimeter shows is evidence.

CMMC level questions.

How many CMMC levels are there?
Three. Level 1 covers Federal Contract Information with 15 requirements from FAR 52.204-21; Level 2 covers CUI with the 110 requirements of NIST SP 800-171 Revision 2; Level 3 adds 24 requirements selected from NIST SP 800-172.
What is the difference between CMMC Level 1 and Level 2?
The information and the depth. Level 1 protects FCI with 15 basic requirements, self-assessed annually with no plan of action permitted. Level 2 protects CUI with 110 requirements, assessed every three years either by you or by a C3PAO depending on what the contract specifies.
Who decides which CMMC level applies to my contract?
DoD does, and it is stated in the solicitation and the resulting contract. For subcontracts, the prime flows the requirement down based on the information you will handle.
How long does a CMMC certification last?
A Level 2 or Level 3 status is valid for three years, with an affirmation of continued compliance submitted in SPRS every year in between. Level 1 is self-assessed and affirmed annually.
Can I get certified with outstanding gaps?
At Level 2 and Level 3, yes — conditionally. A score of at least 88 out of 110 can earn a Conditional status with the remaining items on a plan of action, which must be closed and re-assessed within 180 days. The 3- and 5-point requirements cannot be deferred this way, and Level 1 permits no plan of action at all.
Is CMMC Level 2 still required after the July 2026 suspension?
Level 2 self-assessment under Phase 1 is unaffected and appears in solicitations now. What was suspended is Phase 2, which would have begun requiring C3PAO certification from 10 November 2026, together with the later phases. The underlying NIST 800-171 obligation under DFARS 252.204-7012 is unchanged.

Know your level. Now know your suppliers’.

Book a 30-minute call and we will show you what your CUI-handling subcontractors look like from the outside — the evidence their attestation does not carry.