CMMC ANSWER ENGINE

What's the difference between CMMC Level 1 self-assessment and Level 2 C3PAO assessment?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

The key differences between L1 self-assessment and L2 C3PAO certification, drawn from 32 CFR §§ 170.15 and 170.17 and the CMMC Assessment Scope guides.

What's being assessed

DimensionLevel 1 Self-AssessmentLevel 2 C3PAO Certification
StandardFAR 52.204-21 basic safeguarding (17 CMMC practices)NIST SP 800-171 Rev 2 (110 practices)
Assessment scopePer CMMC L1 Scoping Guide (FCI processing assets)Per CMMC L2 Scoping Guide v2.13 (5 asset categories)
Who performs itThe OSA (your team or your consultants acting as you)An independent Certified Third-Party Assessor Organization (C3PAO) authorized by the Cyber AB
Assessment methodsSelf-determination of MET / NOT METExamine, Interview, and Test per NIST SP 800-171A; assessor reaches an objective determination
ResultScore submitted to SPRSFinal Level 2 (C3PAO) CMMC Status entered in SPRS and the eMASS CMMC instance
Validity periodAnnual; new self-assessment + affirmation each year3 years between certification assessments, with annual affirmations during the period
AffirmationRequired annually by senior company official, in SPRSRequired annually by senior company official, in SPRS, in addition to the certification
POA&M permitted at conclusionNo — all practices must be METYes for most controls, with closeout required within 180 days; some controls cannot be on a POA&M
Cost driverInternal time + toolingC3PAO assessor fees + internal preparation cost

What a C3PAO assessment actually involves

The C3PAO assessment is conducted using the three NIST SP 800-171A methods:

  • Examine — review documents, records, mechanism configurations.
  • Interview — discuss practices and procedures with personnel responsible for the controls.
  • Test — observe controls operating, including hands-on testing of authentication, logging, configuration, etc.

For each of the 110 practices, the assessor evaluates the assessment objectives in NIST SP 800-171A. Each practice receives a finding of MET or NOT MET. A score is calculated using the DoD Assessment Methodology: each practice is worth 1, 3, or 5 points; the maximum score is 110 and contracts specify the minimum required.

What the L1 self-assessment requires you to do

  1. Perform an annual self-assessment against the 17 L1 practices implementing FAR 52.204-21.
  2. Document evidence supporting each practice's MET status (or remediate to MET before affirming).
  3. Enter your score in SPRS.
  4. Have a senior company official sign the affirmation in SPRS asserting compliance.
  5. Maintain documentation supporting the assessment for the period required by your contract.

Important nuance: there is also a Level 2 Self-Assessment

The L2 Self-Assessment is a third path that confuses many contractors. It is a self-assessment against the full 110-practice NIST SP 800-171 standard, performed by the OSA, with the score and annual affirmation entered in SPRS. It applies when the CUI is in the NARA CUI Registry but not in the Defense OIG. It is not the same as L1 self-assessment, even though both are self-conducted. The C3PAO path is required only when the CUI is in the Defense OIG, as confirmed by the CMMC Level Determination guidance.

Sources

  • 32 CFR Part 170 — § 170.15 — Level 1; § 170.16 — Level 2 self-assessment; § 170.17 — Level 2 certification; § 170.22 — Affirmation — link
  • CMMC Levels Determination Brief — link
  • NIST SP 800-171A — Assessing Security Requirements for Controlled Unclassified Information — link
  • FAR 52.204-21 — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170)
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.