Explainer
CMMC Level 1 vs Level 2 vs Level 3: What Each Level Requires and Who Needs It
CMMC has three levels, and the level that applies to your contract decides how many security requirements you must meet and who checks your work. This post explains what separates Level 1, Level 2, and Level 3 in plain language, using the federal rule and official DoD and NIST sources, so contractors can size up their obligations and providers can point clients to a clear reference.
Published: September 23, 2026 · 7 min read
The short version
CMMC has three levels. The level named in your contract sets both the number of security requirements you must meet and how your compliance is verified.
Level 1 covers Federal Contract Information and maps to 15 basic safeguarding requirements. Level 2 covers Controlled Unclassified Information and maps to the 110 requirements in NIST SP 800-171. Level 3 adds a subset of NIST SP 800-172 controls for the most sensitive programs.
Who assesses you also changes by level: Level 1 and some Level 2 work is self-assessed, most Level 2 is assessed by an authorized C3PAO, and Level 3 is assessed by the government.
Why there are three levels
The CMMC program uses a tiered model so that security requirements scale with the sensitivity of the information a contractor handles. The structure and the requirements for each level are set out in the federal rule at 32 CFR Part 170, which took effect in December 2024.
Two kinds of information drive the model. Federal Contract Information, or FCI, is information provided by or generated for the government under a contract that is not intended for public release. Controlled Unclassified Information, or CUI, is information the government requires to be safeguarded under law, regulation, or government-wide policy. The more sensitive the information, the higher the level.
CMMC Level 1: Foundational
Level 1 applies to contractors that handle FCI but not CUI. It maps to the 15 basic safeguarding requirements in Federal Acquisition Regulation clause 52.204-21. These are widely considered baseline cyber hygiene, such as limiting system access to authorized users and controlling who can access the systems that process FCI.
Under the program, Level 1 is met through an annual self-assessment, with a senior company official affirming the results. There is no third-party assessment requirement at this level.
Protects: Federal Contract Information (FCI)
Requirements: the 15 basic safeguards in FAR 52.204-21
Verification: annual self-assessment plus a senior official affirmation
CMMC Level 2: Advanced
Level 2 applies to contractors that handle CUI. It maps to the 110 security requirements in NIST Special Publication 800-171. This is the level most defense contractors in the supply chain are focused on, because CUI is common across the Defense Industrial Base.
Verification at Level 2 depends on what the contract requires. Some Level 2 work is met through self-assessment, while most is assessed by a Certified Third-Party Assessment Organization, known as a C3PAO. If you are trying to figure out whether your contract points to a self-assessment or a C3PAO assessment, that requirement comes from your specific contract language.
Protects: Controlled Unclassified Information (CUI)
Requirements: the 110 requirements in NIST SP 800-171
Verification: self-assessment or a C3PAO assessment, depending on the contract
CMMC Level 3: Expert
Level 3 applies to the highest-priority programs and the most sensitive CUI. It builds on the 110 Level 2 requirements and adds a subset of the enhanced requirements from NIST Special Publication 800-172, which are designed to increase protection against advanced persistent threats.
Level 3 assessments are conducted by the government rather than by a commercial third party. A contractor must generally achieve Level 2 status first before pursuing Level 3.
Protects: CUI in the most sensitive programs
Requirements: the 110 Level 2 requirements plus a subset of NIST SP 800-172
Verification: assessed by the government
How to find the level that applies to you
You do not choose your CMMC level. It is set by the requirements of the contract or solicitation you are pursuing. The practical first step is to read your current and target contracts for the CMMC level and assessment type they name, and to confirm whether you handle FCI, CUI, or both.
The timing of when specific assessment requirements appear in contracts is governed by the program rollout, which has changed over time. For the current status of the phased rollout, see our Phase 2 status tracker.
Frequently asked questions
How many requirements are in CMMC Level 2?
Level 2 maps to the 110 security requirements in NIST Special Publication 800-171.
What is the difference between Level 2 and Level 3?
Level 2 covers the 110 requirements in NIST SP 800-171 and is generally assessed by a C3PAO or through self-assessment depending on the contract. Level 3 adds a subset of the enhanced requirements in NIST SP 800-172 for the most sensitive programs and is assessed by the government.
Do I pick my own CMMC level?
No. The level that applies is determined by the information you handle and the requirements named in your contract or solicitation.
Sources
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
- DoD CIO, About CMMC
- NIST SP 800-171, Protecting Controlled Unclassified Information (csrc.nist.gov)
- NIST SP 800-172, Enhanced Security Requirements for Protecting CUI (csrc.nist.gov)
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov)
This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.
Keep reading