CMMC has three levels. Level 1 covers contractors handling only Federal Contract Information (FCI) and requires 15 basic safeguarding requirements from FAR 52.204-21, checked by annual self-assessment. Level 2 covers contractors handling Controlled Unclassified Information (CUI) and requires all 110 security requirements in NIST SP 800-171. Level 3 adds 24 selected requirements from NIST SP 800-172 on top of Level 2 and is assessed by the government for the highest-priority programs. The levels are codified in 32 CFR Part 170 and have been stable. What keeps moving is how each gets verified: in July 2026 the Department of War suspended the third-party assessment phase pending a 60-day review.
CMMC levels at a glance
| Dimension | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Information protected | Federal Contract Information (FCI) only | Controlled Unclassified Information (CUI) | CUI on the highest-priority programs |
| Number of requirements | 15 | 110 | 110 plus 24 enhanced (134 total) |
| Source standard | FAR 52.204-21(b)(1) | NIST SP 800-171 Rev 2 | NIST SP 800-172 (Feb 2021), selected requirements |
| Who assesses | You (self-assessment) | You, or a C3PAO (third-party), depending on the contract | The government (DIBCAC) |
| How often | Annually, with annual affirmation in SPRS | Every 3 years, with annual affirmation in SPRS | Every 3 years, with annual affirmation |
| Typical contractor | Suppliers of commercial goods and services with no CUI: janitorial, office supplies, basic logistics | The bulk of the Defense Industrial Base: machine shops, engineering firms, software vendors, subsystem suppliers | A small subset handling data on critical programs of adversary interest |
| Prerequisite | None | Meets Level 1 scope as a floor | Requires a Level 2 (C3PAO) certification first |
What are the 3 levels of CMMC?
The three levels are Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). They map to what you hold: FCI at Level 1, CUI at Level 2, and CUI on programs needing protection against advanced threats at Level 3. The levels are cumulative, so Level 3 includes everything in Level 2.
CMMC started in 2020 as a five-level model with "maturity processes" layered on the technical controls. CMMC 2.0 cut it to three levels and dropped process maturity entirely, which makes the name misleading today: despite the word "maturity" in Cybersecurity Maturity Model Certification, the program does not score you along a curve the way organizational maturity assessments typically do. It is pass or fail against a fixed control list, with limited credit for partial implementation through a Plan of Action and Milestones (POA&M).
What is CMMC Level 1?
CMMC Level 1 is the foundational tier for contractors handling FCI but no CUI. It requires 15 basic safeguarding requirements from FAR 52.204-21(b)(1): limiting system access to authorized users, sanitizing media before disposal, running antivirus, controlling physical access. You self-assess annually and a senior company official affirms the result in the Supplier Performance Risk System (SPRS).
One point of persistent confusion: many sources still say Level 1 has 17 practices. That number came from the 2021 CMMC 2.0 announcement, which split one FAR requirement into three. The final rule at 32 CFR 170.14 counts them as they appear in the FAR, at 52.204-21(b)(1)(i) through (xv), so the authoritative number is 15. The security expectations did not change, only the counting.
Level 1 has no POA&M allowance: you meet all 15 or you have no Level 1 status. Most small suppliers get there without a consultant, since the requirements track hygiene they already have in some form.
What is CMMC Level 2?
CMMC Level 2 applies to any contractor that stores, processes, or transmits CUI, and it requires all 110 security requirements of NIST SP 800-171 Rev 2. This is where the real work sits: multifactor authentication, audit logging and review, incident response, configuration and change management, media protection, and a System Security Plan covering your CUI boundary. DoD's rulemaking estimated roughly 80,000 companies would fall into Level 2 certification.
Level 2 has two statuses, and they are not interchangeable. Level 2 (Self) is an annual self-assessment affirmed in SPRS. Level 2 (C3PAO) is a triennial assessment by an accredited CMMC Third-Party Assessment Organization. A contract calling for Level 2 (C3PAO) cannot be satisfied by a self-assessment, and the contracting officer sees which status you hold.
Level 2 does allow a limited POA&M. Certain heavily weighted requirements must be fully met at assessment time, and the rest closed within 180 days, after which a conditional status expires. That clock catches people who treat a conditional certification as a finish line.
What is CMMC Level 3?
CMMC Level 3 applies to a small number of contractors on programs whose loss would give an adversary a strategic advantage. It layers 24 enhanced requirements selected from NIST SP 800-172 on top of the full 110 from Level 2, and the assessment is run by the government's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not a commercial assessor. You cannot go straight to Level 3: a Level 2 (C3PAO) certification for the same scope is a prerequisite.
These controls target advanced persistent threats rather than general hygiene: threat hunting, dual authorization for critical changes, segmentation designed to contain an intrusion. If Level 3 applies to you, the contracting officer will tell you. It is not something you opt into.
What is the difference between CMMC Level 1 and Level 2?
The difference is the data and the standard. Level 1 protects FCI with 15 requirements from the FAR. Level 2 protects CUI with 110 requirements from NIST SP 800-171. That is roughly a sevenfold jump in scope, and the gap in effort is larger still, because Level 2 demands documented policies, a System Security Plan, and evidence that controls actually operated.
The practical test is what lands in your inbox. FCI is information generated for the government under a contract and not intended for public release, such as a delivery schedule. CUI is a defined category with markings, usually technical drawings, specifications, or export-controlled data. If a prime sends you a marked drawing so you can quote a part, Level 2 is your baseline.
Which CMMC level do I need?
Your level is set by the contract, not your preference. The requirement is stated via DFARS 252.204-7021, which names both the level and the assessment type, so read the solicitation. With no contract in hand, the question is whether you receive or generate CUI. FCI only means Level 1. Any CUI means Level 2 at minimum.
- No FCI and no CUI: CMMC does not apply. Suppliers of commercial off-the-shelf items are generally out of scope.
- FCI only: Level 1, annual self-assessment.
- CUI: Level 2. Whether it is self-assessed or C3PAO-assessed depends on what the contract designates.
- CUI on a critical program: Level 3, and the government will say so explicitly.
Do not assume you are out of scope because you are a subcontractor. Requirements flow down: a prime that holds CUI must pass the applicable level to any subcontractor handling it, and primes increasingly ask for proof before issuing a purchase order. Mid supply chain, you are on both sides of this, proving your status upward and collecting proof from the shops below you. That second job is ordinary vendor risk management.
Scope is the lever that decides your cost. Contractors cut Level 2 effort substantially by confining CUI to an enclave rather than letting it spread across the corporate network. The requirements apply to the boundary you define, so a smaller honest boundary means a smaller assessment.
Do I need a C3PAO assessment?
As of today, no new DoD contract can require one. In a memorandum dated July 10, 2026 and announced July 13, Department of War CIO Kirsten Davies suspended the CMMC phased implementation schedule, including the November 2026 Phase 2 transition. During the suspension, program managers may only designate Level 1 (Self) or Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC).
The memo goes further than pausing future work. Where an active solicitation already carries a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, program managers were directed to amend it out, and contracting officers were told to strip it from existing contracts by modification before the next option exercise. No waivers are being granted. Davies said the program as built "imposes significant and often prohibitive burdens on the Defense Industrial Base," and a CMMC Reform Task Force was chartered to report back within 60 days.
When does CMMC become mandatory?
Parts of it already are. The 48 CFR acquisition rule was published on September 10, 2025 and took effect on November 10, 2025, starting Phase 1 and making Level 1 and Level 2 self-assessment requirements enforceable in DoD contracts. Phase 1 remains in effect. What is suspended is the escalation to mandatory third-party assessment, not the program itself. Neither 32 CFR Part 170 nor the acquisition rule has been rescinded, and doing so would require new rulemaking, so the levels and the SPRS affirmation mechanics still stand and could be switched back on.
Your legal obligations did not move. DFARS 252.204-7012 remains in force, and with it the duty to implement NIST SP 800-171 and report cyber incidents. The Department confirmed it will enforce baseline compliance with NIST SP 800-171 Rev 2 through self-assessment and select government-led assessments during the suspension. An affirmation in SPRS is a representation to the government, and a false one carries False Claims Act exposure whether or not a C3PAO ever visits. The gate moved. The bar did not.
What to do next
If you were racing a November 2026 C3PAO date, you just got time back. The worst use of it is to stop. The verification method keeps changing; the technical baseline, NIST SP 800-171, does not.
- Confirm what you hold. Inventory whether FCI, CUI, or neither touches your systems. Most scoping errors trace back to nobody knowing which mailbox the marked drawings arrive in.
- Draw the boundary. Decide where CUI is allowed to live and keep it there. This decides your cost more than any tool you buy.
- Fix what you self-attest to. Your SPRS score should reflect reality today, because that is the representation being enforced right now.
- Keep the evidence habit. Access reviews, log reviews, and change approvals only count if you can show they happened on a date.
- Watch for the task force report. Recommendations are due within 60 days of July 13, 2026.
If you already run SOC 2 or ISO 27001, you are not starting from zero. NIST SP 800-171 overlaps heavily with both on access control, logging, change management, policy documentation, and risk assessment. The same access review that satisfies SOC 2 CC6 produces evidence a NIST 800-171 assessor would recognize. Complies does not ship a CMMC control library and will not tell you your CMMC status. What it does: track obligations with owners and due dates, let you map controls once across the frameworks it supports, and keep compliance evidence collection running on a schedule. The discipline transfers even where the framework label does not.
This article is educational and not legal advice. CMMC policy is moving quickly: confirm your requirements against the current text of your contract and with qualified counsel.
RUN IT, NOT JUST READ IT
Turn this into tracked rows with owners
Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.