All posts
Compliance Frameworks8 min readAug 16, 2026

CMMC levels

Ashish / CEO/Co-Founder
CMMC levels

CMMC has three levels. For decision-making, the practical starting point is the information you handle: FCI generally points toward Level 1 preparation, CUI generally points toward Level 2 preparation, and Level 3 should be treated as a higher-protection path only when the Department makes it a contract requirement. The required level is specified in the solicitation, contract, or subcontract—not, more accurately, by a generic website checklist.

Current preparation should also account for status: the Department states that CMMC implementation is paused in Phase 1 after the suspension of Phase II requirements, while Phase I self-assessment requirements remain in place.

What are the CMMC levels?

CMMC 2.0 is a three-level model for cybersecurity requirements in the defense industrial base. The CMMC Model Overview Version 2.13 describes three independent levels:

  • Level 1 uses the 15 basic safeguarding requirements in FAR 52.204-21. This level is associated with Federal Contract Information, or FCI.
  • Level 2 aligns with the 110 requirements in NIST SP 800-171 Rev. 2. This level is associated with Controlled Unclassified Information, or CUI.
  • Level 3 uses a DoD-selected subset of NIST SP 800-172 requirements in addition to the Level 2 foundation. It is the higher-protection path for CUI when required by contract.

A useful way to think about the levels is: Level 1 protects nonpublic contract information, Level 2 protects CUI, and Level 3 adds enhanced safeguards for higher-risk CUI environments. That is a scoping guide, not a legal conclusion, the CMMC Program FAQs state that the Department specifies the required CMMC level in the solicitation and resulting contract.

CMMC levels comparison table

CMMC levelInformation typeMapped requirement sourceCurrent assessment/status notesAffirmation, SPRS, and POA&M notesCurrent readiness action
Level 1FCI15 basic safeguarding requirements in FAR 52.204-21, as mapped in the CMMC Model OverviewDuring the current Phase 1 pause, the Department states that CMMC may require Level 1 annual self-assessments where the applicable CMMC contractual requirement applies.Level 1 results and affirmations are entered in SPRS; annual affirmations may apply; Level 1 does not permit POA&Ms, according to the Department’s current CMMC status page.Confirm where FCI is stored, processed, transmitted, or created; collect evidence that the 15 safeguarding requirements are implemented.
Level 2CUI110 requirements in NIST SP 800-171 Rev. 2, as mapped in the CMMC Model OverviewDuring the current Phase 1 pause, the Department describes Level 2 self-assessments every three years where applicable. Verify any different assessment language directly in the contract.Level 2 self-assessment results and affirmations are entered in SPRS; annual affirmations may apply; limited Level 2 POA&Ms are subject to program rules and a 180-day closeout period, according to the current CMMC status page.Confirm CUI scope, identify systems and users that touch CUI, and organize evidence around NIST SP 800-171 requirements.
Level 3CUI requiring higher protection when contractually requiredLevel 2 foundation plus 24 selected NIST SP 800-172 requirements when the Department makes Level 3 a contract requirement, according to the CMMC Program FAQs.Not part of the currently stated Phase 1 self-assessment path; confirm contract language and current Department guidance before planning an assessment path.Do not assume Level 3 timing or assessment details from older rollout materials.Treat as a specialized path; validate the requirement, then build from a strong Level 2 foundation.

One important wording issue: current CMMC Level 1 mapping uses 15 FAR requirements, not “17 practices.”

FCI vs CUI: the information type that usually drives your level

The level decision usually starts with the type of information in scope.

FAR 52.204-21 defines FCI as nonpublic information provided by or generated for the Government under a contract, with exclusions such as public information and simple payment-processing information. In practical terms, FCI can include nonpublic contract-related information your organization receives or creates while performing government work, but the exact classification depends on the contract and context—the contract context.

CUI is different. CUI is information the Government, or an entity acting for it, creates or possesses that requires or permits safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not just “sensitive-looking” business information; it must be identified and governed through the applicable rules, markings, contract language, or program instructions.

That distinction matters because:

  • FCI in scope is the common signal for Level 1 preparation.
  • CUI in scope is the common signal for Level 2 preparation.
  • Higher-protection CUI requirements may point toward Level 3, but only when the Department makes that level a contract requirement.

Do not classify data by intuition alone. A public brochure, for example, is not FCI merely because it relates to a defense customer. A nonpublic draft deliverable generated for contract performance may be FCI. A package clearly identified as CUI requires a different level of scoping attention. When in doubt, confirm against the solicitation, contract, subcontract, markings, data handling instructions, and qualified advice.

How to determine your likely CMMC level

Use this worksheet to develop a level hypothesis. Not legal advice, assessment advice, or a substitute for contract interpretation.

  1. Read the solicitation, contract, or subcontract first.
    Look for CMMC level language, FAR 52.204-21, DFARS clauses, FCI, CUI, assessment, SPRS, affirmation, or flow-down terms. The CMMC Program FAQs state that the required level is specified in the solicitation and resulting contract.

  2. Identify where FCI exists.
    List systems, shared drives, ticketing tools, email flows, collaboration platforms, endpoints, and third parties that store, process, transmit, or create FCI for contract performance.

  3. Identify whether CUI exists.
    Check contract documents, prime contractor instructions, markings, attachments, data repositories, engineering packages, deliverables, and workflows for CUI indicators.

  4. Separate enterprise systems from the in-scope environment.
    If only a subset of systems handles FCI or CUI, document the boundary. If CUI is spread across the business, Level 2 preparation will likely be broader and more complex.

  5. Check whether the contract states a level or assessment path.
    If the contract says Level 1, Level 2, or Level 3, treat that as the controlling input. If the language is unclear, resolve it before committing to an assessment plan.

  6. Use the information type as a starting point.
    If only FCI is in scope, Level 1 may be the likely starting point. If CUI is in scope, Level 2 preparation is likely relevant. If Level 3 or higher-protection language appears, get specialized review.

  7. Account for subcontract flow-down.
    DFARS 252.204-7012 requires covered flow-down to subcontracts involving operationally critical support or covered defense information, subject to the clause’s terms. CMMC requirements may also flow to subcontractors when contractually required.

  8. Document assumptions.
    Keep a short record of why you believe a system, business unit, vendor, or data flow is in or out of scope. So the level decision does not become a verbal assumption that cannot be defended later.

What the current DoD-stated pause means for CMMC preparation

The Department’s current CMMC page says that CMMC implementation is paused in Phase 1 following the July 13, 2026 suspension of Phase II requirements. It also says that Phase I self-assessment requirements remain in place.

That means contractors should avoid two opposite mistakes:

  • Do not rely on outdated rollout deadlines as if they are current.
  • Do not stop cybersecurity readiness work if current contracts already require safeguarding, self-assessment, affirmation, or NIST SP 800-171 activity.

The pause also does not remove existing obligations under applicable DFARS 252.204-7012 clauses. Under DFARS 204.7302, contractors required to implement NIST SP 800-171 under that clause must have a current Basic NIST SP 800-171 DoD Assessment at award, unless the solicitation specifies a shorter period.

Stable concepts: the three-level model, the FCI/CUI distinction, and the FAR/NIST mappings.

Confirm before action: enforcement timing, assessment terms in a specific contract, Level 3 details, and any flow-down obligations from a prime contractor.

What to prepare now by level

For Level 1, focus on scope and evidence:

  • Confirm which systems handle FCI.
  • Understand the 15 FAR 52.204-21 safeguarding requirements.
  • Retain evidence that safeguards are implemented, not just assigned.
  • Where the applicable CMMC contractual requirement applies, be ready for Level 1 self-assessment, SPRS entry, and annual affirmation as described by the Department.

For Level 2, start with CUI boundaries:

  • Confirm where CUI is stored, processed, transmitted, or created.
  • Map users, systems, vendors, and processes that touch CUI.
  • Organize evidence around NIST SP 800-171 requirements.
  • Where applicable, prepare for Level 2 self-assessment, SPRS entry, annual affirmation, and limited POA&M rules.
  • If DFARS 252.204-7012 applies, separately confirm current NIST SP 800-171 assessment obligations under that clause.

For Level 3, stay conservative:

  • Do not assume Level 3 applies unless contract language or Department direction supports it.
  • Treat Level 3 as a specialized higher-protection path for CUI.
  • Build a credible Level 2 foundation first, then confirm the additional Level 3 expectations before investing in a detailed plan.

Across all levels, documentation should reflect how controls actually operate. A folder of policies is not the same as repeatable control execution.

Next step: turn level understanding into scoped readiness

Your immediate goal is not to declare yourself “CMMC ready.” It is to form a defensible level hypothesis, validate contract language, identify systems handling FCI or CUI, and organize evidence around the right requirement set.

Once that scope is clear, the hard part is operationalizing readiness: assigning control ownership, maintaining evidence, tracking remediation, and keeping documentation aligned with how systems actually work. Ciphrix approaches compliance as an operating system rather than a one-time document project, helping teams manage readiness work more consistently without replacing legal, contractual, or assessment judgment along the way.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents