CMMC guide
CMMC Level 1 vs Level 2: which one your contract actually needs
The difference is the information, not the size of your company. Level 1 applies when you handle Federal Contract Information and asks for 15 basic practices and an annual self assessment. Level 2 applies when you handle Controlled Unclassified Information and asks for all 110 requirements of NIST SP 800-171, with evidence. Your contract clauses say which one you owe, and the answer is usually visible in ten minutes.
What is the difference in one table?
| Compared | Level 1 | Level 2 |
|---|---|---|
| What it protects | Federal Contract Information (FCI). | Controlled Unclassified Information (CUI). |
| The source of the requirements | FAR 52.204-21, fifteen practices. | NIST SP 800-171 Rev 2, 110 requirements across 14 families. |
| Who assesses | You, every year, posted to SPRS with an affirmation. | You, every year, plus a third party C3PAO assessment for most contracts once that requirement is in force (suspended since July 2026). |
| Open items allowed | No. | A limited plan of action, closed within 180 days. |
| The paperwork | A short self assessment. | A System Security Plan, an asset inventory, the four scoping artifacts, and evidence for every requirement. |
| Typical cost | Days of work and a few tools you likely already have. | A program measured in months, with the CUI boundary deciding most of the price. |
FCI versus CUI, in two paragraphs
Federal Contract Information is the non public information that comes with doing business with the government: the contract itself, the pricing, the schedule, the emails about delivery. It is not for public release, but nobody has marked it as controlled. Every government contractor has FCI, which is why Level 1 is the floor.
Controlled Unclassified Information is information that a law, regulation or government policy says must be protected, marked under 32 CFR Part 2002. In defense work it is most often the technical data: drawings, specifications, part files, test results, the technical data package attached to the purchase order. It arrives marked, or with a distribution statement, or under a clause that says it will. The moment that lands in your inbox, Level 2 applies to every system it touches.
Which clauses tell you?
Open your active contract or purchase order and search for these.
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Present in almost every federal contract. This is the Level 1 clause.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. If this is in the contract, the government expects CUI and expects NIST SP 800-171 to be implemented. This is the Level 2 signal.
- DFARS 252.204-7019 and 7020. You must have a current NIST SP 800-171 self assessment score posted in SPRS before award, and the government may assess you. These travel with 7012.
- DFARS 252.204-7021. The CMMC clause itself, which names the level the contract requires. Being phased in since November 2025.
Two patterns to know. A prime can flow 7012 down to you even when your own piece of the work feels small; the clause follows the data. And a contract can carry 7012 without any CUI ever arriving. If the clause is there, plan for Level 2. If marked data arrives and the clause is not there, call the contracting officer, because the paperwork is wrong and the data is still yours to protect.
A yes or no walk, in text
Do you hold any federal contract or subcontract? If no, neither level applies. If yes, continue.
Does any contract carry DFARS 252.204-7012, or has a prime ever sent you a document marked CUI or with a distribution statement? If no to both, you are Level 1 today: fifteen practices, an annual self assessment, done. If yes to either, continue.
Does that information touch your general office network, email, file shares and laptops? If yes, your whole environment is in scope for Level 2 and the project is large. If you can keep it on a small set of machines, or in an enclave, the project is a fraction of the size. Either way, Level 2 applies.
What changes in cost and time between the levels?
Level 1 is mostly things a well run small business already does: unique logins, limits on who can access what, patching, malware protection, a locked door, a reasonable visitor policy. A shop with a competent IT provider can document it in a week.
Level 2 adds the requirements that cost money and calendar: multifactor authentication everywhere, logging that ties an action to a named person and keeps the record, a controlled configuration baseline, encryption of CUI in transit and at rest, a boundary around the CUI systems, incident response that reports within 72 hours, and the System Security Plan that describes all of it. The single biggest decision is scope. Keeping the shop floor and the general office out of scope, with an enclave for the ten people who open drawings, is the difference between a program and a company wide rebuild.
Who assesses each level?
Level 1 is always a self assessment, every year, with a senior official's affirmation in SPRS.
Level 2 is a self assessment every year as well, and the CMMC rule also made a third party assessment by a C3PAO the default for most Level 2 contracts, on a three year cycle. On July 13, 2026 the Department of War suspended that third party requirement pending a reform review, and said it would keep enforcing compliance through self assessments and select government led assessments. The requirements themselves did not move.
The part that matters whichever way the review lands: the affirmation is signed by a named officer. An inflated self assessment is a false statement to the government, and the False Claims Act settlements of 2025 were against contractors who certified what they had not built.
What should you do once you know?
If you are Level 1: do the fifteen practices properly, write a one page self assessment, post it, and keep the evidence. Do not buy a Level 2 program you do not owe.
If you are Level 2: draw where CUI goes before you buy anything, get an honest score against all 110 requirements, post the real number, and fix in order. Our gap assessment does the scoring and the ordering for a published price. If the whole program is more than you want to run yourself, that is what CMMC In A Container is for.
Questions contractors ask
FAQCan I be Level 1 if I have DFARS 7012 in my contract?
Not safely. 7012 means the government expects CUI and expects NIST SP 800-171. Treat it as Level 2 and raise it with the contracting officer if you believe no CUI will ever arrive.
My prime says I only need Level 1. Is that final?
Your prime decides what flows down in the subcontract. If the subcontract carries 7012 or you receive marked data, Level 2 applies regardless of what was said on the phone. Get it in writing.
Is Level 2 just a bigger Level 1?
The fifteen Level 1 practices are inside the 110, so yes in structure. In practice Level 2 is a different kind of project because of the evidence, the SSP and the scoping work.
Does a Level 2 certification cover Level 1?
Yes. A valid Level 2 assessment satisfies a Level 1 requirement for the same systems.
Do I need Level 3?
Almost certainly not. Level 3 is for a small set of high value programs and is assessed by the government directly. Your contract will say so explicitly.
Already know you want to talk?
BOOK A CALLSkip the form. Pick a time and talk to us directly.
What happens in 30 minutes
- We learn about your business and the defense contracts you hold or are bidding on.
- We walk you through a gap assessment, the first step toward CMMC, and what it covers.
- If you qualify, we help you apply for an in-kind grant from Cyber Grants Alliance to cover it. No slides.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the work itself, including CMMC Level 1 and Level 2 gap assessments, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.