The L2 self versus C3PAO distinction is one of the most-misunderstood points in CMMC. The Levels Determination brief states the rule explicitly:
"Level 2 (Self-Assessment) is the minimum assessment requirement for contractors handling CUI that is in the National Archives and Records Administration (NARA) CUI Registry, but not in the Defense Organizational Index Grouping (OIG)."
"Level 2 (Certification) is the minimum assessment requirement for contractors handling CUI in the NARA CUI Registry's Defense OIG."
What this means in practice
- Identify each CUI category your contract requires you to handle. Your contracting officer or program manager should confirm the categories.
- For each category, determine whether it is in the NARA CUI Registry's Defense OIG. The NARA Registry organizes CUI into Organizational Index Groupings; Defense OIG is the grouping for Department of Defense-aligned categories (CTI, NNPI, Critical Information, etc.).
- If any category falls in the Defense OIG, Level 2 (Certification) by a C3PAO is required for that scope.
- If all CUI categories are in the NARA Registry but outside the Defense OIG, Level 2 (Self-Assessment) is the minimum.
The standard is the same; the assessor is not
Both L2 paths assess against the full 110 NIST SP 800-171 Rev 2 practices. The OSA's compliance obligations are identical between the two paths. What changes is who conducts the assessment:
| Item | L2 Self-Assessment | L2 Certification |
|---|---|---|
| Conducted by | The OSA | A C3PAO authorized by the Cyber AB |
| CMMC Status in SPRS | Final Level 2 (Self) | Final Level 2 (C3PAO) |
| Validity | Renewed annually with new self-assessment + affirmation | Valid for 3 years; annual affirmations during the period |
| Assessor cost | None — internal labor only | Independent assessor fees |
| Eligibility for L3 | No — L3 requires Final Level 2 (C3PAO) status as a prerequisite | Yes |
Common errors
- Self-selecting Self-Assessment to save cost. If any CUI category in your scope falls in the Defense OIG, Self-Assessment is not sufficient.
- Assuming Self-Assessment is easier. The standard is the same. Self-Assessment removes the independent assessor but adds the burden of self-determining MET/NOT MET defensibly, which can be harder without external eyes.
- Skipping affirmation. Even with a current C3PAO certification, the annual SPRS affirmation by a senior company official is still required. Without it you are not affirming continued compliance.
- Treating Self-Assessment as a stepping stone to L3. Only Final Level 2 (C3PAO) status qualifies as the prerequisite for L3.
What to do if you're unsure of the CUI category
Ask the contracting officer. The CMMC L2 path obligation flows from the CUI category, and that category is determined upstream from the contractor. Document the determination in the SSP with the CO's confirmation as part of the supporting record.