DEFENSE CONTRACTOR COMPLIANCE
What Are the CMMC Levels? Level 1 vs Level 2 vs Level 3 Explained
The three CMMC levels, in plain English — what each requires, who needs it, and how to know which applies to your DoD contracts.
⏱ 6 min read
If your company works with the DoD, you have probably been told you need to meet CMMC — but not which of the CMMC levels applies to you. Most of that confusion comes from the CMMC levels themselves. The Cybersecurity Maturity Model Certification (CMMC) has three tiers, and your tier determines how many security controls you must implement, how you demonstrate it, and the overall cost. Get this right at the outset and the path to certification is smooth; get it wrong and months of spend can be wasted.
Below, we break down all three CMMC levels in plain English, who needs each one, and how to determine where your organization falls.
What Are the CMMC Levels?
CMMC 2.0 consists of three levels that build on each other. The more sensitive the information you handle for the DoD, the higher your required level. Your company size is not what dictates the level — the type of data moving through your contracts is.
Protects Federal Contract Information (FCI) with 15 basic safeguards.
Protects Controlled Unclassified Information (CUI) using NIST 800-171.
Protects CUI against the highest-level, advanced threats.
CMMC Level 1: Foundational
Level 1 applies to contractors that handle only Federal Contract Information (FCI) — basic information provided by or generated for the government but not intended for public release. It aligns with the 15 basic safeguarding requirements in FAR 52.204-21, covering fundamentals such as access control, strong passwords, anti-virus, and physical security.
The burden of proof is light. Level 1 involves an annual self-assessment and an executive affirmation in the Supplier Performance Risk System (SPRS) — no third-party assessment required. For many contractors, Level 1 is attainable with disciplined IT hygiene rather than a major security overhaul.
What Is CMMC Level 2? (Advanced)
Most defense contractors fall into CMMC Level 2, because most handle Controlled Unclassified Information (CUI) at some point. So what does CMMC Level 2 look like? It aligns directly with the 110 security controls of NIST SP 800-171 across 14 control families — access control, incident response, configuration management, encryption, and more.
The requirements take on a more serious tone at Level 2. Most companies processing CUI will need an assessment from a Certified Third-Party Assessment Organization (C3PAO) every three years, plus an annual affirmation. Some contracts may allow self-assessment, but assume a C3PAO assessment unless your contract explicitly states otherwise.
Level 2 often includes writing a System Security Plan (SSP), documenting a Plan of Action and Milestones (POA&M) for any gaps, implementing controls such as multifactor authentication and logging, and maintaining evidence that controls are operational day to day.
Assume a C3PAO assessment at Level 2 unless your contract explicitly says otherwise.
CMMC Level 3: Expert
Level 3 is reserved for contractors on the DoD’s most critical programs and most sensitive CUI. It covers all 110 Level 2 controls plus a subset of the enhanced requirements from NIST SP 800-172 that are designed to protect against advanced persistent threats (APTs).
Level 3 assessments are performed by the government itself, via the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), rather than a commercial C3PAO. Relatively few contractors need Level 3 — but those who do require a mature, well-resourced security program.
Which CMMC Level Do You Need?
Start with one question: what type of government data do you interact with? If you only handle FCI, you are likely Level 1. If any contract involves CUI, plan for Level 2. If you support flagship programs handling the most sensitive CUI, you may be pushed to Level 3.
The fastest way to be sure is to examine your contract language — specifically DFARS 252.204-7012 and 252.204-7021 — and trace where CUI actually flows in your environment. A structured CMMC compliance checklist makes this far easier.
Get Your CMMC Level Confirmed
Guessing your CMMC level is expensive in both directions. If you are a DoD contractor in the DC, Maryland, or Northern Virginia region, our CMMC consultants can review your contracts, map where your CUI lives, and confirm exactly which level you need — before you spend a dollar on the wrong controls.