CMMC ANSWER ENGINE

CMMC Level 1 vs Level 2 vs Level 3 — which level do I need?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

Per the DoD CIO's CMMC Level Determination guidance and 32 CFR §§ 170.15–170.18, your CMMC level is determined by the type of information your contract requires you to handle. Your size, your preference, and your IT maturity do not change which level applies.

The decision flow

  1. Does your contract require you to process, store, or transmit CUI? If no → Level 1 (assuming you handle Federal Contract Information).
  2. If yes — is the CUI in the NARA CUI Registry's Defense Organizational Index Grouping (OIG)?
    • No (CUI is in the NARA Registry but not in the Defense OIG) → Level 2 (Self-Assessment) is the minimum.
    • Yes → Level 2 (Certification) by a C3PAO is the minimum.
  3. Does the DoD Program Manager identify the CUI as especially critical, requiring NIST SP 800-172 protections? If yes → Level 3 (Certification) by DCMA DIBCAC is required, in addition to maintaining Final Level 2 (C3PAO) status for the same scope.

Side-by-side comparison

ItemLevel 1Level 2 (Self-Assessment)Level 2 (Certification)Level 3 (Certification)
Triggered byFCI handlingCUI in NARA Registry, not in Defense OIGCUI in NARA Registry's Defense OIGDoD-designated critical CUI; NIST 800-172 applies
StandardFAR 52.204-21 (17 practices)NIST SP 800-171 Rev 2 (110 practices)NIST SP 800-171 Rev 2 (110 practices)110 NIST 800-171 practices + 24 enhanced practices from NIST SP 800-172
Conducted byOSA (self)OSA (self)C3PAO (independent)DCMA DIBCAC
Affirmation requiredYes, annually by senior official, in SPRSYes, annually by senior official, in SPRSYes, annually after certification, in SPRSYes, annually after certification, in SPRS
PrerequisiteNoneNoneNoneFinal Level 2 (C3PAO) status for the same scope, with all POA&M items closed
Asset categories in scopeL1 scope per L1 Scoping Guidance5 categories per L2 Scoping Guide5 categories per L2 Scoping Guide4 categories per L3 Scoping Guide (no CRMAs)

Where Phase 1 implementation matters

Per the DoD CIO CMMC page (current as of May 2026), CMMC Phase 1 Implementation runs from Nov 10, 2025 through Nov 9, 2026 and focuses primarily on CMMC Level 1 and Level 2 self-assessments. Contractors should not interpret "Phase 1" as a grace period — the requirement to know your level, perform the assessment, and affirm in SPRS applies now where the relevant DFARS clauses are in the contract.

How to actually determine your level

  1. Read the DFARS clauses in your contract. 252.204-7012 indicates CUI handling; 252.204-7019 / 7020 / 7021 are CMMC-related clauses signaling level requirements.
  2. Identify the specific CUI categories. Ask your contracting officer or program manager to confirm whether the information falls in the NARA CUI Registry, and whether it is in the Defense OIG.
  3. Check for L3 designation. L3 is identified on the contract by the DoD Program Manager based on criticality.
  4. Document the determination. The level determination decision should be part of your SSP, with the contractual basis cited.

Common errors

  • Self-selecting a lower level to reduce cost. If your CUI is in the Defense OIG, L2 Self-Assessment is not sufficient regardless of contractor preference.
  • Treating Phase 1 as a deferral. Phase 1 sequences the rollout; it does not waive the requirement for contracts that already include CMMC clauses.
  • Confusing FCI handling with CUI handling. FCI is broader (any non-public contract information); CUI is narrower (categories defined in the NARA Registry). Level 1 covers the FCI floor; CUI requires Level 2.

Sources

  • CMMC Levels Determination Brief — link
  • 32 CFR Part 170 — §§ 170.15, 170.16, 170.17, 170.18 — link
  • CMMC Assessment Scope — Level 2 (v2.13) — link
  • CMMC Assessment Scope — Level 3 (v2.13) — link
  • DoW CIO CMMC Program Page — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170, effective 2024-12-16); Phase 1 Implementation began 2025-11-10; new DFARS rule (48 CFR Parts 204, 212, 217, 252) published 2025-09-10
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.