Cybersecurity Compliance

CMMC 2.0 Levels Explained: Level 1 vs 2 vs 3

CMMC 2.0 has three certification levels Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert) each tied to the sensitivity of the government data a contractor handles. Level 1 covers Federal Contract Information (FCI) with 17 basic practices and an annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI) with the 110 controls in NIST SP 800-171. Level 3 adds enhanced protections against advanced persistent threats and requires a government-led assessment.

Your required level isn't a choice it's set by your DoD contract, based on the type of information you handle. This guide breaks down exactly what each level requires, who needs it, and how to determine your own requirement.

What Is CMMC 2.0?

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors and subcontractors in the Defense Industrial Base protect sensitive government information. CMMC 2.0, the current version, streamlined the original five-level model into three levels and aligned each one directly to an existing federal standard FAR 52.204-21, NIST SP 800-171, and NIST SP 800-172 rather than introducing a new, DoD-specific rulebook. As of November 10, 2025, CMMC is fully in effect: DoD contracts now require contractors to demonstrate compliance at the level specified in the contract. For the full picture of what CMMC compliance involves beyond the levels, see our complete CMMC compliance guide.

CMMC Level 1 Foundational

Who needs it: Contractors that handle Federal Contract Information (FCI) only information provided by or generated for the government under a contract, not intended for public release, but not CUI.

Requirements: 17 basic safeguarding practices drawn from FAR 52.204-21, covering fundamentals like access control, identification and authentication, media protection, and physical protection.

Assessment: Annual self-assessment. No third-party audit, no POA&Ms (Plans of Action and Milestones) allowed every practice must be fully implemented, not partially implemented with a remediation plan.

Level 1 is the entry point. If your contract only ever exposes you to FCI, this is likely your ceiling.

CMMC Level 2 Advanced

Who needs it: Contractors that handle Controlled Unclassified Information (CUI) the level most defense contractors and subcontractors actually need.

Requirements: 110 security controls, identical to NIST SP 800-171 Revision 2. These span 14 control families, including access control, incident response, risk assessment, and system and communications protection.

Assessment: Depends on the contract. Some Level 2 contracts allow self-assessment; others require third-party certification from a C3PAO (CMMC Third-Party Assessment Organization). Our CMMC assessment process guide walks through what a C3PAO engagement actually looks like.

POA&Ms: Limited use is allowed only for select requirements scored as 1-point NOT MET, and only when your overall score is at or above 80% of total Level 2 requirements. Any approved POA&M items must be remediated within 180 days.

Level 2 is where most of the compliance work lives, because it requires implementing and evidencing all 110 NIST 800-171 controls not just checking a box.

CMMC Level 3 Expert

Who needs it: Contractors handling the highest-priority, most sensitive CUI programs, where the DoD wants protection against advanced persistent threats (APTs) sophisticated, well-resourced adversaries.

Requirements: Level 2's 110 controls, plus a selected set of enhanced requirements from NIST SP 800-172, focused on defending against APT-level attacks.

Assessment: Government-led, conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) not a C3PAO. A prerequisite is holding a current Level 2 (C3PAO) certification first.

Level 3 applies to a much smaller slice of the contractor base than Level 1 or 2, but where it applies, there's no self-assessment path.

CMMC 2.0 Levels at a Glance

Level 1 Foundational Level 2 Advanced Level 3 Expert
Protects Federal Contract Information (FCI) Controlled Unclassified Information (CUI) High-priority CUI / APT defense
Standard FAR 52.204-21 NIST SP 800-171 (110 controls) NIST SP 800-171 + NIST SP 800-172
Assessment type Annual self-assessment Self-assessment or C3PAO third-party, depending on contract Government-led (DIBCAC)
POA&Ms allowed No Limited (1-point items, score ≥ 80%, 180-day remediation) No
Who typically needs it Contractors handling FCI only Most defense contractors and subcontractors handling CUI A small subset handling the most sensitive programs

How to Know Which Level You Need

Your level isn't self-selected it's driven by two factors:

  • What information you handle. FCI-only → Level 1. Any CUI → Level 2 minimum.
  • What your specific contract requires. The contracting officer specifies the CMMC level in the solicitation; subcontractors inherit requirements that flow down from the prime contract, regardless of their own size or role.

If you're unsure whether the data you handle qualifies as FCI or CUI, that's the first question to resolve see Who Needs CMMC Compliance for a breakdown of FCI vs. CUI and how flow-down requirements work across the supply chain.

CMMC 2.0 vs. CMMC 1.0

CMMC 1.0 used five maturity levels with DoD-specific practices layered on top of NIST 800-171. CMMC 2.0, finalized to reduce cost and complexity for contractors, cut that down to three levels mapped directly to existing federal standards, added a self-assessment path for Level 1 and some Level 2 contracts, and introduced limited POA&M flexibility that CMMC 1.0 didn't allow.

Frequently Asked Questions

How many levels does CMMC 2.0 have?

Three: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). CMMC 1.0 had five levels; CMMC 2.0 consolidated them.

What's the difference between CMMC Level 1 and Level 2?

Level 1 covers 17 basic practices for protecting FCI and requires only an annual self-assessment. Level 2 covers the 110 NIST SP 800-171 controls for protecting CUI and, depending on the contract, may require third-party certification from a C3PAO.

Can a small business get CMMC Level 2 certified through self-assessment?

Sometimes. Some Level 2 contracts permit self-assessment; others require a C3PAO-led third-party assessment. The contract terms not company size determine which path applies.

Do I need CMMC Level 3?

Only if your contract involves the DoD's highest-priority CUI programs requiring defense against advanced persistent threats. Level 3 also requires holding a current Level 2 certification first, and the assessment is government-led rather than self- or third-party.

Are POA&Ms allowed at every CMMC level?

No. Level 1 and Level 3 do not allow POA&Ms all applicable practices must be fully implemented. Level 2 allows limited use for 1-point NOT MET requirements when the overall score is at or above 80%, with a 180-day remediation window.

Next Steps

Determining your CMMC level is the first step implementing the controls and preparing for assessment is where most contractors need help. SG Computers has 15+ years of experience helping small and mid-market organizations in manufacturing, biotech, and other regulated industries navigate CMMC readiness, from gap assessments through certification support. Talk to our compliance team about where your organization stands today.

Download Newsletter

Know First

Follow closely and receive content about our company and the news of the current market.