Skip to content
English - United States
  • There are no suggestions because the search field is empty.

CMMC Levels Explained: Level 1 vs Level 2 vs Level 3

Level 1 for FCI. Level 2 maps to NIST 800-171 for CUI. Level 3 adds government-led assessment.

CMMC Level 1 covers basic protection of Federal Contract Information and is self-assessed. Level 2 requires the 110 NIST SP 800-171 controls for Controlled Unclassified Information and, for most contracts, a third-party assessment. Level 3 adds further requirements and a government-led assessment for the most sensitive programs. Which level you need is set by the data in your contract, not by your company size.

Level 1: Foundational

  • Data: Federal Contract Information (FCI), information provided by or generated for the government under contract that is not intended for public release.
  • Requirements: a short list of basic safeguards drawn from federal acquisition rules: access control, identification and authentication, media handling, physical protection, system boundaries and malware protection.
  • Assessment: annual self-assessment with an executive affirmation.

Level 2: Advanced

  • Data: Controlled Unclassified Information (CUI), such as technical drawings, specifications and export-controlled information.
  • Requirements: all 110 requirements of NIST SP 800-171, across 14 families including access control, audit and accountability, configuration management, incident response, and system and communications protection. See what is NIST 800-171.
  • Assessment: a certification assessment by an authorized third-party organization (C3PAO) every three years for most contracts, with annual affirmations. A limited set of contracts allow self-assessment.

Level 3: Expert

  • Data: CUI on the highest-priority programs.
  • Requirements: Level 2 plus a subset of NIST SP 800-172 enhanced requirements.
  • Assessment: conducted by the government's Defense Industrial Base Cybersecurity Assessment Center.

How to tell which you need

Read the contract and the flow-down from your prime. If you only receive FCI, Level 1. If you receive or generate CUI, Level 2. If a prime tells you a program requires Level 3, it will say so explicitly. When in doubt, ask the prime's contracts office in writing.

Scope strategy

Many companies keep CUI in a segmented enclave, often built on Microsoft 365 GCC High and a dedicated network, so only that environment must meet Level 2. See what is GCC High and what is CMMC for the program overview.

Mentis Group helps DFW manufacturers and engineering firms determine level, scope an enclave and implement the controls through Enhanced Cybersecurity. Program specifics are published by the DoD CIO.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.