CMMC 2.0 has three certification levels Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert) each tied to the sensitivity of the government data a contractor handles. Level 1 covers Federal Contract Information (FCI) with 17 basic practices and an annual self-assessment. Level 2 covers Controlled Unclassified Information (CUI) with the 110 controls in NIST SP 800-171. Level 3 adds enhanced protections against advanced persistent threats and requires a government-led assessment.
Your required level isn't a choice it's set by your DoD contract, based on the type of information you handle. This guide breaks down exactly what each level requires, who needs it, and how to determine your own requirement.
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that contractors and subcontractors in the Defense Industrial Base protect sensitive government information. CMMC 2.0, the current version, streamlined the original five-level model into three levels and aligned each one directly to an existing federal standard FAR 52.204-21, NIST SP 800-171, and NIST SP 800-172 rather than introducing a new, DoD-specific rulebook. As of November 10, 2025, CMMC is fully in effect: DoD contracts now require contractors to demonstrate compliance at the level specified in the contract. For the full picture of what CMMC compliance involves beyond the levels, see our complete CMMC compliance guide.
Who needs it: Contractors that handle Federal Contract Information (FCI) only information provided by or generated for the government under a contract, not intended for public release, but not CUI.
Requirements: 17 basic safeguarding practices drawn from FAR 52.204-21, covering fundamentals like access control, identification and authentication, media protection, and physical protection.
Assessment: Annual self-assessment. No third-party audit, no POA&Ms (Plans of Action and Milestones) allowed every practice must be fully implemented, not partially implemented with a remediation plan.
Level 1 is the entry point. If your contract only ever exposes you to FCI, this is likely your ceiling.
Who needs it: Contractors that handle Controlled Unclassified Information (CUI) the level most defense contractors and subcontractors actually need.
Requirements: 110 security controls, identical to NIST SP 800-171 Revision 2. These span 14 control families, including access control, incident response, risk assessment, and system and communications protection.
Assessment: Depends on the contract. Some Level 2 contracts allow self-assessment; others require third-party certification from a C3PAO (CMMC Third-Party Assessment Organization). Our CMMC assessment process guide walks through what a C3PAO engagement actually looks like.
POA&Ms: Limited use is allowed only for select requirements scored as 1-point NOT MET, and only when your overall score is at or above 80% of total Level 2 requirements. Any approved POA&M items must be remediated within 180 days.
Level 2 is where most of the compliance work lives, because it requires implementing and evidencing all 110 NIST 800-171 controls not just checking a box.
Who needs it: Contractors handling the highest-priority, most sensitive CUI programs, where the DoD wants protection against advanced persistent threats (APTs) sophisticated, well-resourced adversaries.
Requirements: Level 2's 110 controls, plus a selected set of enhanced requirements from NIST SP 800-172, focused on defending against APT-level attacks.
Assessment: Government-led, conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) not a C3PAO. A prerequisite is holding a current Level 2 (C3PAO) certification first.
Level 3 applies to a much smaller slice of the contractor base than Level 1 or 2, but where it applies, there's no self-assessment path.
| Level 1 Foundational | Level 2 Advanced | Level 3 Expert | |
|---|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | High-priority CUI / APT defense |
| Standard | FAR 52.204-21 | NIST SP 800-171 (110 controls) | NIST SP 800-171 + NIST SP 800-172 |
| Assessment type | Annual self-assessment | Self-assessment or C3PAO third-party, depending on contract | Government-led (DIBCAC) |
| POA&Ms allowed | No | Limited (1-point items, score ≥ 80%, 180-day remediation) | No |
| Who typically needs it | Contractors handling FCI only | Most defense contractors and subcontractors handling CUI | A small subset handling the most sensitive programs |
Your level isn't self-selected it's driven by two factors:
If you're unsure whether the data you handle qualifies as FCI or CUI, that's the first question to resolve see Who Needs CMMC Compliance for a breakdown of FCI vs. CUI and how flow-down requirements work across the supply chain.
CMMC 1.0 used five maturity levels with DoD-specific practices layered on top of NIST 800-171. CMMC 2.0, finalized to reduce cost and complexity for contractors, cut that down to three levels mapped directly to existing federal standards, added a self-assessment path for Level 1 and some Level 2 contracts, and introduced limited POA&M flexibility that CMMC 1.0 didn't allow.
Three: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). CMMC 1.0 had five levels; CMMC 2.0 consolidated them.
Level 1 covers 17 basic practices for protecting FCI and requires only an annual self-assessment. Level 2 covers the 110 NIST SP 800-171 controls for protecting CUI and, depending on the contract, may require third-party certification from a C3PAO.
Sometimes. Some Level 2 contracts permit self-assessment; others require a C3PAO-led third-party assessment. The contract terms not company size determine which path applies.
Only if your contract involves the DoD's highest-priority CUI programs requiring defense against advanced persistent threats. Level 3 also requires holding a current Level 2 certification first, and the assessment is government-led rather than self- or third-party.
No. Level 1 and Level 3 do not allow POA&Ms all applicable practices must be fully implemented. Level 2 allows limited use for 1-point NOT MET requirements when the overall score is at or above 80%, with a 180-day remediation window.
Determining your CMMC level is the first step implementing the controls and preparing for assessment is where most contractors need help. SG Computers has 15+ years of experience helping small and mid-market organizations in manufacturing, biotech, and other regulated industries navigate CMMC readiness, from gap assessments through certification support. Talk to our compliance team about where your organization stands today.
Follow closely and receive content about our company and the news of the current market.