compli.ai
From the blog

CMMC 2.0 Levels 1 vs 2 vs 3: Requirements Explained

A practitioner's breakdown of CMMC 2.0 Levels 1, 2, and 3 - control counts, assessment types, the phase-in timeline, and how to find your required level.

CMMC 2.0 has three levels. Level 1 covers Federal Contract Information (FCI) with 15 basic safeguarding requirements and an annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI) with 110 requirements drawn from NIST SP 800-171 Revision 2, assessed either by self-assessment or by a certified third party depending on the contract. Level 3 adds 24 selected requirements from NIST SP 800-172 on top of Level 2 and is assessed by the government. The level you need is set by the Department of War (DoW) in each specific solicitation - it is not your choice. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect: contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS, and DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 security requirements. This guide explains what each level demands, who assesses it, and how to work out which one applies to you.

The short version: a side-by-side comparison

Everything about CMMC flows from one question: what kind of data will you touch on your own systems? FCI gets you Level 1. CUI gets you Level 2. The most sensitive CUI, on programs facing advanced persistent threats, gets you Level 3.

Level 1Level 2Level 3
Data protectedFederal Contract Information (FCI)Controlled Unclassified Information (CUI)CUI on the highest-priority programs
Requirement count15 (from FAR 52.204-21)110 (NIST SP 800-171 Rev 2)110 + 24 selected from NIST SP 800-172
Assessment typeAnnual self-assessmentSelf-assessment or C3PAO, set by contractGovernment (DCMA DIBCAC)
Assessment frequencyAnnualEvery three years (self or C3PAO)Triennial
AffirmationAnnual, by a senior officialAnnual, by a senior officialAnnual, by a senior official
Where results goSPRSSPRS / CMMC eMASSCMMC eMASS

Source: DoD CMMC Model Overview and 32 CFR Part 170; control counts and assessment types verified against the CMMC program rule (effective December 16, 2024).

Level 1: FCI and the 15 basics

Level 1 is the floor. It applies to any contract where you will process, store, or transmit Federal Contract Information - information provided by or generated for the government under a contract that is not intended for public release, but is not sensitive enough to be CUI. Think of a delivery schedule or a non-public statement of work.

The 15 requirements at Level 1 are exactly the 15 basic safeguarding requirements from FAR 52.204-21, the clause that has been in most federal contracts since 2016 and was renumbered FAR 52.240-93 on February 1, 2026. If you have ever complied with that clause, you have already met the substance of CMMC Level 1. They cover fundamentals: limit system access to authorized users, authenticate identities, sanitize media before disposal, control physical access, and so on.

Assessment: Level 1 is always a self-assessment. You perform it annually and a senior company official signs an affirmation attesting to it, with results recorded in the Supplier Performance Risk System (SPRS). There is no third-party requirement at Level 1 and no partial-credit scoring - you either meet all 15 or you do not.

If you handle only FCI and never touch CUI, Level 1 is where you stop. Do not over-build toward Level 2 controls you will never need to assess against - scope discipline is what keeps a small contractor's compliance affordable.

Level 2: CUI and the 110

Level 2 is where most defense contractors live, and it is the level that carries real weight. It applies when you handle Controlled Unclassified Information (CUI) on your own information systems. (For a deeper walk-through of what CUI actually is and how to scope it, see our guide to what counts as CUI.)

Level 2 maps 1:1 to NIST SP 800-171 - 110 security requirements across 14 control families, covering access control, audit and accountability, incident response, configuration management, and more. CMMC currently assesses against Revision 2 of 800-171. Revision 3 was finalized in May 2024 and drops the count to 97 requirements, but DoW has not adopted it for assessments: Class Deviation 2024-O0013 ties DFARS 252.204-7012 to Rev 2 until it is rescinded, and a rule to move to Rev 3 that was targeted for July 2026 had not been published as of late September 2026. When you see "Level 2 = 110 controls," that is Rev 2, and it is correct today. Treat any claim of a firm Rev 3 effective date as unconfirmed.

Level 2 Self vs Level 2 C3PAO

This is the split that trips people up. Level 2 comes in two assessment flavors, and the contract tells you which one applies - you do not get to pick the easier path:

  • Level 2 (Self): a self-assessment every three years, with a senior-official affirmation at each assessment and annually in between (32 CFR 170.16). The rule designed it for programs where the CUI is less sensitive, and while Phase 2 is suspended, contracts can still require it.
  • Level 2 (C3PAO): a triennial assessment by an authorized Certified Third-Party Assessment Organization (C3PAO), plus annual affirmations in the intervening years. It was to become the standard requirement for most CUI contracts under Phase 2, which the Department suspended on July 13, 2026 while it reviews the program.

DoW sets the required level and the assessment type in the specific solicitation, based on the sensitivity of the CUI involved. Read the clauses and the notice of CMMC level requirements in your solicitation (DFARS 252.204-7025); they will tell you exactly what you must produce before award.

The artifact both paths depend on is your System Security Plan - the document that describes your environment and how each of the 110 requirements is met. If your SSP is thin, your assessment stalls before it starts. See how to write an SSP.

Level 3: 800-172 and DIBCAC

Level 3 is for the highest-priority programs - those the Department judges to be at risk from advanced persistent threats (APTs), meaning well-resourced, persistent adversaries. It is rare, and you will know if you are headed for it because the contract will say so.

Level 3 requires everything in Level 2 (C3PAO) plus 24 selected requirements from NIST SP 800-172, a companion publication of enhanced security requirements built specifically to counter APTs. Level 3 sits on top of an existing Level 2 (C3PAO) certification - you cannot reach Level 3 without first holding a clean third-party Level 2 result.

Assessment: Level 3 is assessed by the government, specifically the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), on a triennial basis. No commercial C3PAO conducts Level 3 assessments.

Which level do you need? A decision path

Your contract sets your level, but you can work out where you are likely to land before a solicitation lands on your desk. Walk it in order:

  1. Will you handle any government contract information on your own systems at all? If no, as when you supply only commercial off-the-shelf (COTS) products, CMMC generally does not attach, and COTS-only contracts are exempt.
  2. Is the information FCI only, with no CUI? If yes, you are looking at Level 1. Meet the 15 FAR 52.204-21 requirements, self-assess annually, affirm.
  3. Will you process, store, or transmit CUI? If yes, you are at Level 2 at minimum. Now check the sensitivity: less-sensitive CUI programs may allow Level 2 (Self), and most were slated to require Level 2 (C3PAO) once Phase 2 began, a phase DoW has suspended. The solicitation's CMMC notice provision states which applies.
  4. Is this a top-tier program flagged for APT protection? If the contract specifies it, you are at Level 3 - Level 2 (C3PAO) plus the 24 enhanced 800-172 requirements, assessed by DIBCAC.

When in doubt, size for the CUI you will actually hold and confirm against the contract language. Guessing high wastes money; guessing low costs you the award.

The phase-in timeline: where we are in 2026

CMMC was set to roll out over a three-year phase-in keyed to the acquisition rule's effective date of November 10, 2025. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phases 3 and 4 are on hold as well. Phase 1 remains in effect: contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS, and DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 security requirements. As of late September 2026, the review's recommendations have not been made public and no new Phase 2 date has been announced.

PhaseOriginal startWhat it adds to applicable contracts
Phase 1 (in effect)Nov 10, 2025Level 1 (Self) and Level 2 (Self) required as a condition of award, with affirmations in SPRS.
Phase 2 (suspended)Was scheduled for Nov 10, 2026Was to add Level 2 (C3PAO) certification as a standard condition of award. Suspended July 13, 2026 while DoW reviews the program, with no new date announced.
Phase 3 (on hold)Was scheduled for Nov 10, 2027Was to add Level 3 (DIBCAC) requirements to applicable solicitations and contracts.
Phase 4 (on hold)Was scheduled for Nov 10, 2028Full implementation across all applicable contracts (except COTS-only).

Source: 32 CFR 170.3(e) for the original schedule; DoW's July 13, 2026 suspension of Phase 2.

What this means practically: today, only some contracts carry CMMC, and where they do, the obligation is usually a Level 1 or Level 2 self-assessment. Broad mandatory third-party (C3PAO) certification was scheduled to arrive with Phase 2, and the Department has not announced a new date for it. The underlying work is the same either way, so the smart move now is to get your SSP written, your score in SPRS, and your gaps on a POA&M.

Scoping notes: draw your boundary before you assess

The single biggest lever on CMMC cost and effort is scope - how much of your environment falls inside the assessment boundary. A common and expensive mistake is to let CUI spread across the whole enterprise, dragging every laptop, server, and cloud tenant into the assessment.

The alternative is an enclave: a deliberately bounded environment (often a separate cloud tenant or network segment) where CUI is stored and processed, walled off from the rest of the business. Scope the enclave, protect the enclave, assess the enclave. Everything outside it that never touches CUI stays out of scope.

Getting scoping right requires a clear-eyed CUI inventory and a data-flow map - work that pays for itself many times over at assessment time. Our CMMC certification cost guide breaks down exactly how scope drives price.

FAQ

What is CMMC Level 2?

CMMC Level 2 is the certification tier for contractors that handle Controlled Unclassified Information (CUI). It requires meeting all 110 security requirements in NIST SP 800-171 Revision 2, documented in a System Security Plan. Depending on the contract, Level 2 is verified by a self-assessment every three years or by a triennial assessment from a Certified Third-Party Assessment Organization (C3PAO), with annual affirmations either way. The Department has suspended Phase 2, which was to make the C3PAO assessment the standard requirement, while it reviews the program.

What document defines the scope of a CMMC assessment?

The System Security Plan (SSP) defines the boundary and scope of a CMMC assessment. It describes the system environment, the assessment boundary, and how each applicable requirement is implemented. Assessors use the SSP, together with a CMMC Assessment Scope guide published by the Department for each level, to determine what is in and out of scope.

Who needs CMMC certification?

Any organization in the defense supply chain that processes, stores, or transmits FCI or CUI on its own information systems will need a CMMC status at the level its contracts specify. This includes prime contractors and subcontractors, since CMMC requirements flow down. Contracts solely for commercial off-the-shelf (COTS) items are exempt.

What is the difference between CMMC Level 1 and Level 2?

Level 1 protects FCI with 15 basic requirements and an annual self-assessment. Level 2 protects CUI with 110 requirements from NIST SP 800-171 Rev 2 and is assessed by self-assessment or a third-party C3PAO, depending on the contract. Level 2 is substantially more demanding and requires a full SSP. Under the original phase-in, most Level 2 contracts would also have required third-party verification, but DoW has suspended that phase while it reviews the program.

How do I know which CMMC level my contract requires?

The solicitation states it. Under the CMMC clauses, the Department includes a Notice of CMMC Level Requirements (DFARS 252.204-7025) that specifies the required level and assessment type. You do not select your level - the contracting activity sets it based on the sensitivity of the information involved.

Does CMMC use NIST 800-171 Rev 2 or Rev 3?

CMMC Level 2 assessments currently use Revision 2 (110 requirements). Revision 3 was finalized in May 2024 and reduces the count to 97, but DoW has not adopted it for assessments. Class Deviation 2024-O0013 keeps Rev 2 as the operative baseline until it is rescinded, and no transition date to Rev 3 has been set: the interim final rule that would make the change had not been published as of late September 2026.

CMMC is a paperwork-heavy framework, and the level you land on decides how much of that paperwork you owe.

Compli.ai keeps that record inside your own Microsoft 365 tenant. It carries all 110 NIST SP 800-171 requirements with their SSP implementation statements and 320 assessment objectives, runs a POA&M that enforces the 32 CFR 170.21 rules, and tracks your SPRS score as you close gaps, so you walk into a self-assessment, or a C3PAO assessment if one is required, with the record already built.

See how it works on our CMMC compliance platform and CMMC compliance software pages, and book a demo to see your required level mapped end to end.