Interweave Technologies
Sep 17

What CMMC Level Do You Need? How to Choose the Right One

The CMMC level you need depends entirely on the type of Department of Defense data your company processes, stores, or transmits under its contracts. Companies that handle only Federal Contract Information (FCI) need Level 1. Companies that receive Controlled Unclassified Information (CUI) need Level 2. A small group of companies supporting the most critical programs need Level 3.

Below we break down the three levels, the data type that triggers each one, who performs each assessment, where your contract states the requirement, and the step by step method we use with government contractors to land on the correct level the first time.

What CMMC Level Do You Need for a DoD Contract?

The CMMC level you need is set by the sensitivity of the government data in your environment, not by your company size, revenue, or headcount. Company size never appears in the determination. The Cybersecurity Maturity Model Certification (CMMC) program ties each level to a data category, and each data category carries its own security requirements and its own assessment route.

Federal Contract Information triggers Level 1. Controlled Unclassified Information triggers Level 2. Critical CUI tied to breakthrough technology or large aggregations of defense data triggers Level 3. The table below draws its requirement counts and cadences from 32 CFR Part 170, the program rule that governs CMMC, along with the source standards published by NIST.

CMMC LevelData TypeSecurity RequirementsSource RegulationAssessment TypeCadenceLevel 1 (Foundational)FCI only15 basic safeguarding requirementsFAR 52.204-21Self-assessmentAnnualLevel 2 (Advanced)CUI110 security requirementsNIST SP 800-171 Rev. 2C3PAO certification or self-assessmentEvery 3 years, annual affirmationLevel 3 (Expert)Critical CUILevel 2 plus 24 enhanced requirementsNIST SP 800-172Government-led (DIBCAC)Every 3 years, annual affirmation

What Are the Three CMMC Levels?

The three CMMC levels are Level 1 Foundational, Level 2 Advanced, and Level 3 Expert. Each level stacks on the one below it, so Level 2 contains everything in Level 1, and Level 3 contains everything in Level 2. This stacking matters during scoping, because a company that later moves up a tier keeps the work it already finished rather than starting over.

CMMC Level 1: Foundational

Level 1 applies to companies that handle Federal Contract Information and nothing more sensitive. Federal Contract Information covers records the government gives you or that you create for the government under a contract, such as delivery schedules, personnel rosters, and project status reports, none of which are meant for public release. Records not meant for public release still sit below the CUI threshold when they carry no safeguarding marking.

Level 1 requires 15 basic safeguarding requirements, which 32 CFR 170.14 pulls verbatim from FAR 52.204-21. Those 15 requirements cover access limits, external connection control, media disposal, physical access control, boundary protection, and malicious code protection. A senior company official verifies them through an annual self-assessment and affirms the result. No third party audits a Level 1 environment, and the program rule allows no gaps at this level, so every requirement must be met on the day you self-assess.

CMMC Level 2: Advanced

Level 2 applies to companies that receive Controlled Unclassified Information, and it is where most of the defense supply chain lands. DoD estimates published with the program rule place 37 percent of the Defense Industrial Base, more than 80,000 organizations, at Level 2. Those 80,000 organizations implement 110 security requirements drawn from NIST SP 800-171 Revision 2, which NIST SP 800-171A expands into 320 separate assessment objectives.

The 320 assessment objectives cover multifactor authentication, encryption of CUI at rest and in transit, audit logging, configuration management, incident response, and personnel screening. Personnel screening and the other 13 control domains together form the full CMMC certification model, which organizes all requirements across 14 domains from Access Control through System and Information Integrity.

CMMC Level 3: Expert

Level 3 applies to a narrow group of companies working on the programs an advanced adversary would target first. DoD estimates place roughly 1 percent of the Defense Industrial Base, about 1,500 organizations, at Level 3. Those 1,500 organizations meet all 110 Level 2 requirements plus 24 enhanced requirements selected from NIST SP 800-172, and a government team rather than a commercial assessor verifies the result.

How Many Levels of CMMC Are There and What Happened to Levels 4 and 5?

There are three levels of CMMC today, and Levels 4 and 5 were eliminated when the Department of Defense restructured the program in 2021. The original 2020 model used five levels with maturity processes layered on top of technical practices. Those maturity processes added paperwork without adding measurable security, so the restructured model folded the old Level 2 into Level 1, merged the old Levels 4 and 5 into a single expert tier, and dropped the process maturity scoring entirely.

Scoring in the current model rests on technical requirements alone. If a checklist, template, or training deck in your files still references CMMC Level 4 or Level 5, it predates the restructuring and no longer matches any contract requirement. The same holds for older material describing Level 1 as 17 practices. Both counts describe the same safeguards, since earlier CMMC versions split two of the FAR requirements into separate practices. The final rule counts 15, and the substance never changed.

What Is the Difference Between FCI and CUI?

The difference between FCI and CUI is sensitivity and marking: FCI is non-public contract information with no safeguarding category attached, while CUI is information the government has designated for specific protection under a published category. The National Archives maintains the CUI Registry, which sorts CUI into 20 organizational index groupings covering categories such as controlled technical information, export control data, and privacy information.

Controlled technical information is the category most defense suppliers encounter, and it covers engineering drawings, specifications, process sheets, test data, and technical manuals with military application. Technical manuals and drawings arrive from a prime contractor far more often than from the government directly, which is why so many subcontractors carry CUI without ever having signed a contract that used the term. The practical distinction is simple: a parts count on a shipping manifest is FCI, while the dimensioned drawing of the part itself is CUI.

How Do You Know If You Handle CUI or Only FCI?

You know whether you handle CUI by mapping where government data enters your systems, where it travels, and where it comes to rest. Data entering your systems arrives through a handful of predictable doors, and each door deserves a direct look:

  • Email attachments from contracting officers and prime contractor buyers
  • Supplier portals and file transfer sites operated by primes
  • Engineering file shares, CAD workstations, and version control systems
  • ERP and quoting systems that store drawings alongside part numbers
  • Laptops, shop-floor machines, and backup copies held by a cloud provider

Backup copies held by a cloud provider count as part of your environment, and so does any machine that stores a drawing for even a short window. Any system that touches marked data pulls that system into the assessment boundary, which makes the data flow map the true starting point of a level determination. We build that map during the gap analysis before anyone writes a single policy.

Where Does Your Contract Tell You Which CMMC Level You Need?

Your contract tells you which CMMC level you need through the DFARS clause the contracting officer inserts into the solicitation and the award. DFARS 252.204-7021, titled Cybersecurity Maturity Model Certification Requirements, is the clause that obligates you to hold and maintain the stated level for the life of the contract. The solicitation provision that accompanies it states the specific level and assessment type required before award.

Award documents in 2026 look different from the ones your team learned to read. On February 1, 2026, a set of class deviations issued under the Revolutionary FAR Overhaul renumbered several familiar clauses. FAR 52.204-21 became FAR 52.240-93 with its 15 safeguarding requirements unchanged. DFARS 252.204-7019 was deleted, and DFARS 252.204-7020 became DFARS 252.240-7997, which removed the standalone basic self-assessment and folded assessment reporting into the CMMC structure. DFARS 252.204-7012 and DFARS 252.204-7021 were left alone.

Left alone is the important part, because 7012 still carries the NIST SP 800-171 obligation and the 72-hour cyber incident reporting requirement independent of anything CMMC does. A contract review that searches only for the legacy clause numbers will miss the current ones, so we check both sets when we read a solicitation against the current CMMC requirements.

Can You Self Certify CMMC Level 2 or Do You Need a Certification Assessment?

You can self certify CMMC Level 2 only when your contract involves non-defense CUI, because guidance the Department of Defense issued on January 17, 2025 ties Level 2 certification to the CUI category itself. The category that drives certification is the National Archives Defense Organizational Index Grouping, which contains five CUI types:

  • Controlled Technical Information
  • DoD Critical Infrastructure Security Information
  • Naval Nuclear Propulsion Information
  • Privileged Safety Information
  • Unclassified Controlled Nuclear Information, Defense

Companies that receive any of these five types should expect their contracts to require a Level 2 certification assessment. Companies that receive CUI outside the defense grouping, such as procurement-sensitive or privacy information, fall into the Level 2 self-assessment lane. The Cyber AB has stated that fewer than 5 percent of Level 2 awards are likely to qualify for self-assessment, so manufacturers and engineering firms holding drawings should plan for the certification path rather than hope for the exception.

The exception matters less than the preparation either way, since both paths assess the same 110 requirements against the same 320 objectives. Only the auditor changes.

Who Performs a CMMC Level 2 Assessment?

A CMMC Level 2 certification assessment is performed by a CMMC Third-Party Assessment Organization (C3PAO) authorized by the accreditation body. The accreditation body authorizes each C3PAO, and assessors working under it hold Certified CMMC Assessor credentials. Certified assessors record certification results in the CMMC Enterprise Mission Assurance Support Service, while self-assessment results go into the Supplier Performance Risk System (SPRS) under your own signature.

Your own signature carries weight beyond the score itself, because the annual affirmation is a statement to the government about the state of your environment. A C3PAO also cannot consult and assess the same company, which is why readiness work, remediation, and system security plan development happen with a separate partner before the assessor arrives.

Who Can Conduct a Level 3 CMMC Assessment?

Only the government can conduct a Level 3 CMMC assessment, specifically the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). DIBCAC sits inside the Defense Contract Management Agency and runs the assessment directly, so a company pursuing Level 3 cannot select its own auditor the way a Level 2 company selects a C3PAO. Selection of the environment still belongs to you, but scheduling and scoring belong to the government team.

The government team also expects a valid Level 2 certification already in hand. Level 3 builds on Level 2, so a company must pass a C3PAO certification assessment first and only then submit to the DIBCAC review of the enhanced requirements.

What Is the Difference Between CMMC Level 2 and Level 3?

The difference between CMMC Level 2 and Level 3 is 24 additional security requirements, a government assessor instead of a commercial one, and a much narrower population of companies. Population size is the fastest way to see the gap: DoD estimates put more than 80,000 organizations at Level 2 and roughly 1,500 at Level 3. Level 2 verifies that CUI is protected to the NIST SP 800-171 baseline, while Level 3 verifies that the environment can withstand a persistent, well-resourced attacker who is already inside the perimeter.

An attacker already inside the perimeter is the design assumption behind NIST SP 800-172, the standard the Level 3 requirements come from. That assumption shifts the work from prevention alone to detection, containment, and resilience.

What Does CMMC Level 3 Require?

CMMC Level 3 requires all 110 Level 2 security requirements plus 24 enhanced requirements selected from NIST SP 800-172. The 24 enhanced requirements cluster around advanced threat awareness training, threat-informed risk assessment, supply chain risk response, authoritative repositories for approved software, automated asset inventory, automated detection and remediation, and dual authorization for high-impact actions. Automated detection and remediation in particular assumes continuous monitoring rather than periodic review, which pushes most Level 3 environments toward 24/7 security operations coverage.

Continuous coverage of this kind builds directly on the NIST compliance foundation a company already has at Level 2, rather than replacing it.

When Is CMMC Level 3 Required?

CMMC Level 3 is required only on contracts supporting the most critical defense programs and technologies, and Department of Defense guidance instructs contracting officials to avoid overuse of the Level 3 requirement. That guidance identifies three situations where a Level 3 requirement is appropriate:

  1. The contractor will receive CUI associated with a breakthrough or advanced technology.
  2. The contract involves a significant aggregation or compilation of CUI in a single information system or IT environment.
  3. An attack on that single system or environment would create widespread vulnerability across the Department.

Widespread vulnerability of that kind describes research and development work, integration environments that concentrate data from many programs, and a handful of prime contractor systems. Around Huntsville, where missile defense, space, and aviation programs cluster tightly, the Level 3 question surfaces more often in early conversations than it does nationally, and in practice most of those companies still land at Level 2 once the data is mapped. If your contracts involve routine production, sustainment, or professional services, Level 3 almost certainly does not apply to you.

What Is Needed for CMMC Level 2?

CMMC Level 2 needs 110 implemented security requirements, a system security plan that documents them, a current assessment score in SPRS, and an annual affirmation signed by a senior company official. The system security plan is the anchor document, because it defines the assessment boundary, names the systems inside it, and describes how each requirement is met. Each requirement described in the plan must match what an assessor finds running in the environment, since the plan is the first artifact any assessor reads.

Assessors also read the POA&M, which records requirements that are not yet met and the dates they will be. Requirements recorded there carry a deadline, which brings the scoring rules into play.

What Is a Passing Score for CMMC Level 2?

A passing score for CMMC Level 2 is 88 out of 110 points for a Conditional status, and a perfect 110 for a Final status. Scoring starts at 110 and subtracts 1, 3, or 5 points for each unmet requirement based on its security impact, so a handful of high-value gaps sinks a score faster than a longer list of minor ones. A score at or above 88 earns a Conditional CMMC Status, and the company then has 180 days to close every open item and convert that status to Final.

Closing every open item within 180 days is not optional, and certain requirements cannot be placed on a POA&M at all. Multifactor authentication, FIPS-validated encryption of CUI, and other 5-point requirements must be fully met at the time of assessment. Companies that discover this late usually discover it during the assessment itself, which is the most expensive possible moment.

Is FIPS Required for CMMC Level 2?

Yes, FIPS-validated cryptography is required for CMMC Level 2 wherever CUI is encrypted at rest or in transit. Encryption alone does not satisfy the requirement, because the standard calls for modules validated under the Federal Information Processing Standard 140 program rather than any strong algorithm. A module that has been submitted but not yet validated does not count, and assessors verify the certificate number.

Certificate numbers apply to the specific module and configuration, so a product that ships with a FIPS mode must actually have that mode enabled. This detail sits behind a large share of assessment findings and connects directly to how a company approaches file encryption across laptops, servers, and backups.

Do You Need GCC High for CMMC Level 2?

No, you do not need GCC High for CMMC Level 2, because the requirement is the security outcome rather than a specific cloud tenant. The security outcome includes FIPS-validated encryption, US persons handling of CUI where the contract calls for it, and a cloud service that meets the FedRAMP Moderate baseline or its equivalent when it stores or processes CUI. A government community cloud is one way to reach that outcome, and for companies handling export-controlled technical data it is frequently the cleanest way.

The cleanest way is not the only compliant way. Companies whose CUI is limited and well-contained sometimes meet the same outcome inside a commercial tenant with the right configuration, encryption, and boundary controls. The correct choice follows from your data map, not from a vendor recommendation made before anyone looked at your environment.

Can Scoping Reduce the CMMC Level You Need?

Scoping does not reduce the level your contract requires, but it sharply reduces how much of your company that level applies to. The level follows the contract and the data, while the boundary follows your architecture. A manufacturer that lets drawings circulate freely across email, file shares, and shop-floor machines has pulled its entire network into the assessment, and every one of those systems then carries all 110 requirements.

Carrying 110 requirements across an entire network costs far more than carrying them across a segmented enclave. The program rule sorts assets into categories, and the two that drive the most work are CUI assets, which store or process CUI, and security protection assets, which provide protection to those systems. Assets that are separated from CUI entirely fall outside the boundary. Building that separation early is the single most effective cost control in a CMMC project, and it is why we design the enclave before we start remediation in a managed compliance engagement.

How Do You Determine Which CMMC Level Applies to Your Company?

You determine which CMMC level applies by working through your contracts, your data, and your systems in a fixed order. The order below is the one our certified assessors follow, and each step depends on the answer from the step before it:

  1. Read every prime contract, subcontract, and flow-down clause. Look for DFARS 252.204-7012, DFARS 252.204-7021, FAR 52.204-21, and FAR 52.240-93, and note any stated CMMC level or assessment type.
  2. Map where government data enters, travels, and rests. Include email, portals, engineering shares, ERP systems, endpoints, cloud services, and backups.
  3. Classify that data as FCI or CUI. Check markings, and check with the source when markings are missing or inconsistent.
  4. Check the CUI category against the Defense Organizational Index Grouping. A hit on any of the five defense types points to a Level 2 certification assessment rather than a self-assessment.
  5. Draw the assessment boundary. Decide which systems stay inside, which get segmented out, and which need replacing.
  6. Confirm with the contracting officer or prime. Written confirmation settles ambiguity before you spend money on the wrong tier.
  7. Record your status in SPRS and affirm it. An accurate score protects your eligibility and your legal position.

Legal position matters here because primes are enforcing these obligations down their supply chains on their own schedule, independent of the government's. The flow-down requirements in your subcontracts are contractual promises regardless of what phase the federal rollout has reached.

Is CMMC Level 2 Suspended Right Now?

CMMC Level 2 third-party certification is suspended as a condition of award right now, while CMMC Level 1 and Level 2 self-assessments remain fully required. Self-assessment requirements took effect on November 10, 2025, when Phase 1 of the rollout began under the 48 CFR acquisition rule, and they have applied to new contracts ever since. On July 13, 2026, the Department of War suspended Phase 2 along with the later phases and stood up a CMMC Reform Task Force to run a 60-day review of the program. A class deviation issued on September 3, 2026 made that suspension binding on contracting officers rather than discretionary, and the task force recommendations were due to the Department's Chief Information Officer in mid-September 2026.

Mid-September recommendations do not change a single technical obligation. NIST SP 800-171 still applies through DFARS 252.204-7012. SPRS scores, annual affirmations, and Level 1 and Level 2 self-assessments all stand. Department leadership has been direct that the review targets the cost and bureaucracy of third-party assessment rather than the security standard itself, and the last time the program paused for review it returned in a leaner form within roughly a year.

Returning in a leaner form is the historical pattern, which makes the current window a preparation window rather than a pause. Readiness data shows why that matters: the accreditation body reported 431 final Level 2 certifications as of its October 2025 town hall and 896 as of February 2026, against the more than 80,000 organizations DoD expects to need that level. When third-party requirements return, assessor capacity will be the constraint, and the companies already documented and remediated will move first.

How Long Is a CMMC Certification Good For?

A CMMC certification is good for three years at Level 2 and Level 3, while a Level 1 self-assessment is good for one year. One year is also the interval for the affirmation at every level, so a Level 2 company submits an affirmation in each of the two years between assessments. The affirmation states that the company continues to meet the requirements, and a senior official signs it personally.

How Often Is a CMMC Level 2 Assessment Required?

A CMMC Level 2 assessment is required every three years, whether the assessment is a self-assessment or a C3PAO certification assessment. Certification assessments also restart the clock when your environment changes materially, since a new boundary, a new cloud platform, or a merger can invalidate the scope the assessor reviewed. Reviewing scope annually alongside the affirmation keeps that surprise off the table.

What Happens If You Certify at the Wrong CMMC Level?

Certifying at the wrong CMMC level puts your contract eligibility and your affirmation accuracy at risk, and the fix is straightforward when you catch it early. Catching it early usually means a re-scope: the boundary gets redrawn, the missing requirements get implemented, and the SPRS entry gets corrected before an award or an option exercise depends on it. Companies that certify too low and later find CUI on an out-of-scope system face remediation plus a fresh assessment of the corrected environment.

The opposite error costs money instead of eligibility. Treating every system as though it holds CUI spreads 110 requirements across hardware, software, and staff time that never needed them. Both errors trace back to the same root cause, which is a data map that was never built, and both are avoidable during a compliance audit readiness review.

Frequently Asked Questions

Can You Self Certify CMMC Level 1?

Yes, you can self certify CMMC Level 1, and self-assessment is the only route available at that level. A company verifies its 15 basic safeguarding requirements internally, records the result in SPRS, and has a senior official affirm compliance annually. No third-party assessor is involved, and no gaps are permitted, since the program rule does not allow a POA&M at Level 1.

How Do You Obtain CMMC Level 1?

You obtain CMMC Level 1 by implementing the 15 safeguarding requirements, assessing your environment against each one, entering the result in SPRS, and submitting a senior official affirmation. The 15 requirements cover access control, identification and authentication, media protection, physical protection, boundary protection, and malicious code protection. Every requirement must be met at the time of the self-assessment, and the status must be renewed each year.

Does CMMC Apply If You Only Handle FCI?

Yes, CMMC applies if you only handle FCI, at Level 1. Federal Contract Information triggers the foundational tier even when no CUI ever reaches your systems, and DoD estimated that Phase 1 requirements would reach roughly 65 percent of the Defense Industrial Base. Companies that deliver commercial off-the-shelf items are the main exception.

Can a Subcontractor Need a Different CMMC Level Than the Prime?

Yes, a subcontractor can need a different CMMC level than the prime, because the level follows the data each company actually receives. A prime holding controlled technical information across a large program may sit at Level 2 certification while a subcontractor that receives only delivery schedules sits at Level 1. Primes flow down the requirement that matches what they send you, so ask for that determination in writing rather than assuming you inherit theirs.

What Is a POA&M in CMMC?

A POA&M in CMMC is a Plan of Action and Milestones, the document that records unmet security requirements along with the specific steps and dates for closing them. A POA&M supports a Conditional CMMC Status at Level 2 when the assessment score reaches at least 88 of 110 points, and the open items must be closed within 180 days. High-impact requirements worth 5 points cannot be deferred to a POA&M.

Do You Need CMMC If You Are Not a DoD Contractor?

No, you do not need CMMC if you are not a Department of Defense contractor or subcontractor, since the program applies through defense contract clauses. Other frameworks cover other sectors, including HIPAA in healthcare, the FTC Safeguards Rule in finance, and ISO 27001 across industries. Companies that plan to enter the defense supply chain later often build to NIST SP 800-171 early, because that baseline is the foundation Level 2 is assessed against.

The Bottom Line

The CMMC level you need comes down to one question answered honestly: what government data actually lives in your systems. FCI alone puts you at Level 1 with 15 requirements and an annual self-assessment. CUI puts you at Level 2 with 110 requirements, and the CUI category decides whether a C3PAO certifies you or you self-assess. Critical CUI on breakthrough programs puts you at Level 3 with 24 additional requirements and a government-led assessment, and that describes roughly 1 percent of the defense industrial base.

Everything else follows from the data map and the boundary you draw around it. A company that maps its data first usually finds its requirement is smaller and cheaper than it feared, and a company that skips that step usually pays for controls it never needed or fails an assessment it thought it would pass. With third-party requirements under review and assessor capacity waiting on the other side of that review, the preparation done now is the preparation that counts later.

We have spent more than 20 years helping organizations across Huntsville and the wider defense supply chain sort out exactly this question, and our certified staff walks it through with you from the first contract review to the day your status is posted. If you would like a second set of eyes on your contracts and your data flow, talk it through with our team, or reach us at (256) 837-2300. We are glad to help you land on the right level and build toward it at a pace that fits your business. That is the work Interweave Technologies does every day.