The L3 Scoping Guide v2.13 and 32 CFR § 170.18 together define what Level 3 requires. The core constraint: L3 is a narrow population. Most defense contractors will never be designated for L3 even if they handle large volumes of CUI.
What triggers an L3 requirement
L3 is not selected by the contractor and is not driven by data volume. The DoD Program Manager identifies CUI as especially critical when its disclosure would create unacceptable risk — the same trigger that makes NIST SP 800-172's enhanced requirements apply to that CUI. When a contract designates L3, the contractor must achieve Level 3 (Certification) by DCMA DIBCAC.
The L3 prerequisites
- Final Level 2 (C3PAO) status for the same CMMC Assessment Scope. Self-assessment L2 is not a prerequisite for L3 — only the C3PAO-certified path qualifies.
- All L2 POA&M items must be closed before the L3 assessment begins.
- The L3 Assessment Scope may be the same as the L2 scope or a subset of it — for example, a more tightly controlled L3 enclave within a broader L2 enclave.
The four L3 asset categories
L3 uses fewer categories than L2 because the CRMA path is unavailable at L3. From the L3 Scoping Guide Table 1:
- CUI Assets. Includes the standard process/store/transmit CUI definition and assets that were CRMAs in L2 scope. CRMAs from L2 become CUI Assets at L3 if they're in the L3 scope.
- Security Protection Assets. Provide security functions or capabilities to the assessment scope, irrespective of whether they process CUI. Assessed against all Level 2 and Level 3 requirements relevant to the capabilities provided.
- Specialized Assets. GFE, IoT/IIoT, OT, Restricted Information Systems, Test Equipment. Limited check against L2 and assess against all L3 requirements. The L3 guide permits intermediary devices (boundary devices, proxies) to provide the capability for a specialized asset to meet one or more CMMC requirements.
- Out-of-Scope Assets. Same VDI exception as at L2.
The 24 enhanced requirements from NIST SP 800-172
NIST SP 800-172 organizes its enhanced requirements around three primary objectives: penetrate the perimeter, move laterally through the network, and persist undetected. The 24 enhanced requirements that map into CMMC L3 are organized into the same 14 families as 800-171 (AC, AT, AU, CM, IA, IR, MA, MP, PE, PS, RA, CA, SC, SI) and cover capabilities including:
- Dual authorization for highly privileged actions
- Restricted communication for highly privileged accounts
- Continuous and automated monitoring with risk-driven response
- Use of penetration testing in security assessments
- System and information integrity protections against advanced persistent threats
- Threat hunting and threat intelligence integration
- Tamper-resistant cryptographic modules
- Component authenticity validation
How L3 is assessed
- DCMA DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) conducts the L3 assessment. C3PAOs do not conduct L3 assessments.
- L3 SPAs are assessed against all Level 2 and Level 3 security requirements that are relevant to the capabilities provided.
- Specialized Assets at L3 receive a limited check against L2 and a full assessment against L3 unless physically or logically isolated.
- CSPs that process CUI for an L3 OSC must support the 24 L3 requirements; use of a CSP does not relieve the OSC of its 24-requirement obligation. The OSC must demonstrate inheritance via a Customer Implementation Summary / Customer Responsibility Matrix and an associated Body of Evidence.
If you don't have an L3 contract clause
You likely don't need Level 3. The L3 Scoping Guide makes clear that L3 is a contract-driven designation. Pursuing L3 voluntarily is possible but rarely justified by business case — the cost and scope of the assessment are significant, and there is no commercial market premium for L3 outside of contracts that require it.