Updated September 29, 2026
Your level depends on what your customer sends you, not on how big you are. Contract paperwork that isn't public means Level 1: 15 basic safeguards, checked by you, every year. Sensitive technical data the government marks as controlled means Level 2: 110 security requirements. Level 3 applies only when a contract names it, and most small suppliers will never see one.
Most owners arrive at this question the same way. A prime contractor sends a supplier questionnaire, or a new contract shows up with a paragraph about "CMMC Level 2," and nobody in the building knows whether that means a weekend of settings changes or a year-long project. The difference between the levels is exactly that big. Level 1 is a short checklist most offices already mostly meet. Level 2 is a security program with written plans, logs, training, and a score that a senior person at your company signs for every year.
This page explains what each level asks, how to tell which one applies to you, and what it costs to prove.
First, the two kinds of information
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that checks whether its suppliers protect government information. It cares about two kinds.
FCI, federal contract information, is information about a government contract that isn't meant for the public: purchase orders, delivery schedules, quantities, prices, statements of work. The legal definition excludes information the government already publishes and "simple transactional information," like what it takes to process a payment (FAR 52.204-21). If you have a DoD contract or subcontract, you almost certainly hold FCI.
CUI, controlled unclassified information, is the sensitive material: engineering drawings, specifications, technical data, test results, and export-controlled information the government has decided needs protection. It's not classified, but it can't be shared freely. It usually arrives labeled. Look for "CUI" or "CONTROLLED" in the banner at the top and bottom of a page, or a distribution statement on a technical drawing. Statement A means approved for public release. Statements B through F mean distribution is limited to the government, its contractors, or a named office (DTIC marking guide). A drawing with Distribution Statement D and an ITAR warning is CUI in practice, and you should treat it that way until the customer tells you otherwise in writing.
The rule ties the level to the information on your systems, and the government picks the level for each contract (32 CFR 170.3(d)). A ten-person machine shop cutting parts from a controlled drawing needs Level 2. A 400-person distributor that only sees order quantities needs Level 1.
The three levels side by side
| Level 1 | Level 2 | Level 3 | |
|---|---|---|---|
| Protects | FCI | CUI | CUI on programs DoD designates |
| Requirements | 15 basic safeguards | 110 requirements | Level 2's 110, plus 24 more |
| Where they come from (for your IT person) | FAR 52.204-21(b)(1)(i)–(xv) | NIST SP 800-171 Rev. 2 | NIST SP 800-172, selected requirements |
| Who assesses | You | You, or a C3PAO (an accredited third-party assessor) if the contract says so | DoD's own assessors (DCMA DIBCAC), after a C3PAO certificate on the same systems |
| How often | Every year | Every 3 years | Every 3 years |
| Senior official signs an affirmation | Every year | Every year | Every year |
| Open items allowed | None | Limited, closed within 180 days | Limited, closed within 180 days |
The requirement counts come from 32 CFR 170.14, the rules on open items from 170.21, and the Level 3 prerequisite from 170.18.
Level 1: fifteen basics, all of them
Level 1 exists to keep contract information away from strangers. The 15 safeguards come straight from a clause that took effect in federal contracts on June 15, 2016. In plain terms, they ask you to:
- Give access only to people and devices you've approved, and only to what their job needs.
- Know who's logging in, and make them prove it with a password or better.
- Control connections to outside systems, and be careful what you post publicly.
- Wipe or destroy drives and devices before you throw them out or reuse them.
- Lock up the office and the equipment, escort visitors, and keep a log of who came in.
- Protect the edge of your network, and keep public-facing systems like your website separate from internal ones.
- Patch security flaws promptly, run antivirus, keep it updated, and scan files that come in from outside.
That's the whole list, grouped. Most small offices already do most of it. The catch is the word "all." Level 1 has no partial credit and no grace period. Every safeguard must be met on the day you affirm, and the rule allows no plan of action for gaps (32 CFR 170.21(a)(1)). You assess yourself, enter the result in SPRS (the Supplier Performance Risk System, DoD's database of supplier cyber scores), and a senior official affirms it. You repeat that every year.
Level 2: the 110 requirements
Level 2 is where the real work is. The 110 requirements come from a government standard called NIST SP 800-171 and cover 14 areas: access control, training, audit logs, configuration, identity, incident response, maintenance, media, personnel, physical security, risk assessment, security assessment, system protection, and system integrity.
In owner terms, Level 2 means you can show, with evidence, things like these. Everyone who touches CUI logs in with multi-factor authentication (a code or app prompt on top of the password). Laptops are encrypted. Logs are kept and someone reviews them. Staff get security awareness training. There's a written incident response plan that's been tested. And there's a System Security Plan (SSP), the document that describes your environment and how you meet each requirement. Without an SSP there is no assessment at all.
Each requirement has a point value of 1, 3, or 5. A perfect score is 110, and every requirement you miss subtracts its value, so the score can go well below zero (32 CFR 170.24). How the score works →
Level 2 does allow some open items, but the limits are narrow. You can claim a Conditional status if your score is at least 88 out of 110. Only 1-point requirements can go on the plan of action (the POA&M, your written list of open items with dates), plus encryption when you encrypt but the encryption isn't FIPS-validated. Six requirements can never go on it: external connections (3.1.20), control of public information (3.1.22), the three visitor and physical access requirements (3.10.3, 3.10.4, 3.10.5), and the SSP itself (3.12.4). Everything on the POA&M has to be closed and re-scored within 180 days, or the Conditional status expires (170.21). Conditional vs. Final →
Whether you assess yourself or hire a C3PAO is written in the contract. You don't choose. Either way, the requirements are identical. A Level 2 status also covers Level 1 for the same systems, so you never need both (32 CFR 170.16(a)).
Level 3: you'll know if it's you
Level 3 is for CUI on programs DoD considers high-priority targets. It adds 24 requirements from a second standard, NIST SP 800-172, aimed at well-funded attackers: things like a security operations function, threat-informed risk assessment, and supply chain risk planning. DoD's own assessors at DCMA DIBCAC run it, and you can't start until you hold a Final Level 2 certificate from a C3PAO covering the same systems (170.18).
When DoD wrote the rule, it estimated 1,487 companies would ever need Level 3, against more than 139,000 at Level 1 (32 CFR 170 final rule). If no contract has named Level 3, plan for Level 2 and move on.
One common confusion: Level 3 has nothing to do with "Rev. 3" of NIST SP 800-171. The CMMC levels and NIST's revision numbers are separate numbering schemes, and Level 2 still uses Rev. 2. Rev. 2 vs. Rev. 3 →
What it costs to prove each level
DoD published cost estimates with the rule. For a small company, it estimated $5,977 a year for a Level 1 self-assessment and affirmation, $37,196 over three years for a Level 2 self-assessment, and $104,670 over three years for a Level 2 certificate from a C3PAO (32 CFR 170 final rule, cost analysis).
Read those numbers carefully. They cover the assessment and the paperwork, not the work of closing gaps. DoD left implementation costs out because the underlying requirements were already in contracts. Budget the fixes separately: licenses, device management, log storage, and your MSP's hours are all on top of those figures. What a readiness assessment costs →
What the July 2026 pause did to this picture
It changed the "who assesses" row for now. On July 13, 2026, DoD suspended the November 2026 step that would have made C3PAO certificates the normal requirement for CUI work, and told program offices to include only Level 1 (Self) or Level 2 (Self) while the suspension lasts. Class deviation 2026-O0025 turned that into instructions for contracting officers on July 16, and its current revision was signed September 3 (deviation memo).
The requirements didn't change. The 110 are still required by the DFARS 252.204-7012 clause in any contract where you handle CUI, and the C3PAO and DIBCAC paths are still in the rule. There's an irony here: when DoD sized the program, it expected only about 4,000 companies to use Level 2 (Self) and about 76,600 to need a C3PAO. For now, self-assessment is the path for everyone. What else the pause changed →
Sort your contracts in one afternoon
Open a spreadsheet with four columns: contract or PO number, customer, what they send you, and level.
Go through every active contract and purchase order. In the third column, write down what actually arrives: "PO and delivery schedule," "drawing set with Distribution Statement D," "specs marked CUI." Then fill in the level. Anything marked CUI, or delivered under a contract that includes DFARS 252.204-7012, is Level 2. Order data with nothing controlled is Level 1. If the contract already names a CMMC level in its 252.204-7021 clause, that settles it.
For any row you can't fill in, send the prime's contracts contact one email:
We're confirming our CMMC requirements for [contract/PO number]. Will performance involve CUI, and which CMMC level and assessment type (Self or C3PAO) applies to our subcontract? If CUI is involved, please confirm which documents or data sets are marked.
The answer decides whether you need 15 safeguards or 110 requirements. How to classify FCI and CUI →
The biggest mistake at this stage is deciding the whole company is Level 2 because one contract is. Level 2 applies to the people, computers, and cloud services that touch CUI. If CUI lives with four engineers, you can build the boundary around those four and keep the front office at Level 1. In a 60-person shop, that can mean 8 laptops in scope instead of 60. Scoping for small contractors → and enclave vs. whole company →
Common questions
Can I choose which level to get? No. The program office sets the level for each contract based on the information involved, and it appears in the solicitation. You can hold a higher status than a contract requires, because the clause accepts the required level or higher.
Does Level 2 cover Level 1? Yes, for the same systems. A Level 2 (Self) status satisfies a Level 1 (Self) requirement for the same assessment scope, so you don't file both for the same environment.
We only have one controlled drawing. Do we really need Level 2? For the systems that drawing touches, yes. The fix is to make that footprint small: one secured file location, a handful of named users, managed laptops. A small footprint is a small Level 2.
What happened to Levels 4 and 5? The first version of CMMC had five levels. In November 2021, DoD announced a revised program that cut it to three, and that's the version written into the 2024 rule.
Does company size matter? Not for the level. A two-person engineering firm handling CUI is Level 2. Size affects cost and effort, and DoD's cost estimates are split by small and larger businesses, but the requirements are the same.
How long does a Level 2 status last? A Final status lasts three years, with an affirmation from a senior official every year in between. A Conditional status lasts 180 days, during which you close the open items and re-score.
Where to go from here
Once you know the level, the next job is scoping: which people, laptops, and cloud services touch the information. That's where Garde1 starts. You tell it where CUI lives and who touches it, and it records each asset's category, writes your SSP and 14 domain policies from that one scope (or a single FCI safeguarding policy for Level 1), pulls evidence from the tools you already run, and runs a mock assessment against all 110 Level 2 requirements with your SPRS score, before you affirm anything.
