← Back to blog

CMMC Levels Explained for DoD Contractors (2026)

July 29, 2026
CMMC Levels Explained for DoD Contractors (2026)

If your contract involves Controlled Unclassified Information (CUI), you almost certainly need CMMC Level 2. If it involves only Federal Contract Information (FCI), Level 1 applies. Level 3 is reserved for the highest-value CUI and national-security-sensitive workloads. Your immediate next step: confirm whether your contract specifies FCI or CUI, then begin assembling your System Security Plan (SSP) and dated evidence artifacts.

Under CMMC 2.0, the DoD CIO has structured three certification levels, each mapped to a specific federal standard:

  • Level 1: basic safeguarding practices from FAR 52.204-21; annual self-affirmation
  • Level 2: controls from NIST SP 800-171 Rev. 2; self-assessment or C3PAO certification depending on contract designation
  • Level 3: Level 2 plus selected NIST SP 800-172 enhancements; assessed by DIBCAC (Defense Industrial Base Cybersecurity Assessment Center)

The assessment path is not something you choose. The contract language specifies it. A Certified Third-Party Assessment Organization (C3PAO) conducts Level 2 certification assessments for prioritized contracts; DoD's DIBCAC handles Level 3. Start by reading your solicitation carefully before committing to any compliance path.


Table of Contents

What does each CMMC 2.0 level actually require?

CMMC 2.0 replaced the original five-level model with three levels aligned directly to existing federal standards. That alignment matters because it means the requirements are not new inventions. They are the same controls DoD contractors have been expected to meet under DFARS 252.204-7012 for years.

Level 1: protecting FCI with basic safeguarding

Hands typing on laptop in home office

Level 1 covers Federal Contract Information, which is any information provided by or generated for the government under a contract that is not intended for public release. The requirements come from FAR clause 52.204-21, which specifies 15 basic safeguarding practices. These cover foundational controls such as limiting system access to authorized users, scanning for malware, and protecting information on publicly accessible systems.

Infographic illustrating three CMMC levels hierarchy

Assessment at Level 1 is a self-assessment conducted annually by the contractor. A senior official with appropriate authority must affirm the results. No third-party assessor is required.

Level 2: protecting CUI with NIST SP 800-171

Level 2 is where most DoD contractors land. It applies whenever a contract involves CUI, which includes technical data, export-controlled information, and a wide range of sensitive but unclassified categories. The 110 controls in NIST SP 800-171 Rev. 2 are organized into 14 control families, covering areas such as access control, incident response, configuration management, and system and communications protection.

The assessment path depends on how the contract is designated. Non-prioritized CUI contracts may allow a self-assessment with SPRS entry. Prioritized contracts require a C3PAO certification assessment. Both run on a three-year cycle with annual senior-official affirmation in between.

Level 3: protecting high-value CUI against advanced threats

Level 3 builds on a completed Level 2 certification and adds selected NIST SP 800-172 requirements assessed by DIBCAC. These enhancements target Advanced Persistent Threat (APT) activity and apply to contractors working on the most sensitive national-security programs. You cannot pursue Level 3 until you have achieved Final Level 2 (C3PAO) status and closed out any open POA&M items.

Standards and control counts at a glance

CMMC LevelData Type ProtectedStandard ReferenceControl CountAssessment Path
Level 1FCIFAR 52.204-2115 practicesAnnual self-assessment
Level 2CUINIST SP 800-171 Rev. 2110 controlsSelf-assessment or C3PAO (contract-specified)
Level 3High-value CUI / national securityNIST SP 800-172 (+ Level 2)selected controls and enhancementsDIBCAC/DoD-led

FCI vs. CUI: how to classify your data

Data TypeExamplesLikely CMMC Level
FCIContract deliverables, procurement dataLevel 1 (15 practices)
CUITechnical drawings, export-controlled data, personally identifiable informationLevel 2 (110 controls)
High-value CUIAdvanced weapons system specs, critical program dataLevel 3 (110 controls + selected enhancements)

What changed from CMMC 1.0 to CMMC 2.0

CMMC 1.0 had five levels and introduced practices not drawn from existing federal standards. CMMC 2.0 collapsed that to three levels, removed the novel practices, and aligned each level directly to FAR 52.204-21, NIST SP 800-171 Rev. 2, and NIST SP 800-172. Critically, 2.0 introduced self-assessment paths for Level 1 and certain Level 2 contracts, and it allowed limited POA&M use for conditional certification status. Those changes reduced burden for some contractors while raising the stakes for those whose contracts require C3PAO certification.


How do assessments work, and who performs them?

The assessment type is determined by the contract, not by the contractor's preference. Understanding which path applies to your situation is the first practical decision you need to make.

  • Level 1 self-assessment: Conducted internally by the contractor. Results are entered into the Supplier Performance Risk System (SPRS) by the organization. A senior official affirms results annually.
  • Level 2 self-assessment: Uses the same 110 NIST SP 800-171 Rev. 2 requirements as a C3PAO assessment. The contractor evaluates its own compliance, enters results in SPRS, and a senior official affirms annually. This path applies to non-prioritized CUI contracts.
  • Level 2 C3PAO certification assessment: An accredited C3PAO conducts the assessment. Results are entered into CMMC eMASS by the assessor and transmitted to SPRS. This path applies to prioritized CUI contracts.
  • Level 3 DIBCAC assessment: Conducted by DoD's Defense Industrial Base Cybersecurity Assessment Center. Requires Final Level 2 (C3PAO) status as a prerequisite.

Timing, cycles, and reporting

Third-party assessments operate on a three-year certification cycle with annual senior-official affirmation. The affirmation must be signed by a senior official with the authority to bind the organization. Missing an annual affirmation can affect contract eligibility.

The DoD's phased implementation schedule matters here. Phase 1 (beginning at the 48 CFR rule effective date) requires Level 1 and Level 2 self-assessments in applicable solicitations. Phase 2, beginning 12 months later, adds Level 2 certification requirements. Phase 3 (24 months after Phase 1) introduces Level 3 certification. Full implementation across all solicitations and contracts is targeted for Phase 4, 36 months after Phase 1 begins.

For self-assessments, the contractor enters results directly in SPRS. For C3PAO assessments, the assessor enters results in CMMC eMASS, which then transmits to SPRS. Your SPRS score is visible to contracting officers and directly affects award eligibility.

Pro Tip: The most common readiness mistake is treating scope as an afterthought. Assessors look for a pre-defined, documented assessment scope with every asset categorized before the assessment begins. Undocumented or miscategorized assets discovered during assessment can invalidate evidence you have already collected.


How do you prepare for a CMMC Level 2 assessment?

Preparation is not about purchasing tools. Assessors validate that controls actually operate, which means they examine logs, configurations, and interview staff. Vendor-supplied capabilities must be mapped to evidence the contractor controls, not just to a vendor's compliance claim.

Step-by-step preparation checklist

  1. Define your assessment scope. Identify every system, data flow, and asset that processes, stores, or transmits CUI. Categorize assets into the five Level 2 categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Asset categorization rules require that out-of-scope assets demonstrably cannot process, store, or transmit CUI.
  2. Build your System Security Plan (SSP). The SSP documents how each of the 110 controls is implemented within your scoped environment. It is the foundational document assessors review first. Every asset category must be documented in the SSP.
  3. Map controls to evidence at the assessment-objective level. NIST SP 800-171A breaks each of the 110 requirements into granular assessment objectives. A single requirement can have multiple objectives, and failing one objective marks the entire requirement as NOT MET. Track evidence per objective, not per high-level control.
  4. Assign control owners and collect dated evidence. Evidence must be final and dated. This includes system logs, configuration screenshots, training completion records, access control lists, and incident response test results. A well-documented incident response plan with test results satisfies multiple IR-domain objectives.
  5. Address high-point controls first. SPRS scoring assigns weights of 5, 3, or 1 to each requirement. Requirements weighted 5 or 3 generally cannot be placed on a POA&M. Implement these fully before assessment.
  6. Conduct an internal assessment rehearsal. Walk through each assessment objective as an assessor would. Identify gaps, remediate, and re-collect evidence before the formal assessment begins.
  7. Prepare your SPRS entry or eMASS package. For self-assessments, calculate your SPRS score and enter it with the affirmation. For C3PAO assessments, coordinate with your assessor on the eMASS submission process.

Subcontractor flow-down responsibilities

Prime contractors must flow down CMMC requirements to subcontractors who process, store, or transmit CUI. Subs must meet the same level specified in the prime's contract. Primes are responsible for verifying that applicable subs have the required CMMC status at time of award. Handling sensitive financial CUI in supply chains requires the same rigor; guidance on protecting client financial data offers useful parallels for contractors managing that category.

SPRS scoring and POA&M eligibility

SPRS scores range from a maximum of 110 down to negative values when high-weight controls are not implemented. Requirements weighted 5 or 3 must be fully implemented before assessment. Only certain 1-point requirements are eligible for POA&M deferral. Conditional certification status requires a minimum score and a compliant POA&M. Final status requires all requirements implemented and any POA&M closed out.

Pro Tip: Work by assessment objective, not by control number. A single NIST SP 800-171 requirement often maps to four or five objectives in NIST SP 800-171A. Contractors who track evidence at the objective level rarely get surprised during assessment; those who track at the control level frequently do.


What happens after your assessment?

Passing an assessment is not the end of the compliance obligation. Continuous monitoring, annual affirmations, and POA&M management are ongoing requirements.

  • Conditional vs. Final status: Conditional Level 2 (C3PAO) status means the assessment found eligible POA&M items. The contractor must close those items within 180 days of when results are finalized and submitted to SPRS or CMMC eMASS. Failure to close a POA&M within 180 days results in an expired CMMC status, which affects contract eligibility.
  • POA&M eligibility rules: Only 1-point requirements and narrow exceptions are eligible for POA&M deferral. Requirements weighted 5 or 3 must be fully implemented before the assessment concludes. Placing an ineligible requirement on a POA&M will prevent Final status.
  • Annual affirmation: A senior official must affirm compliance annually throughout the three-year certification cycle. Missing an affirmation is treated as a lapse in status.
  • Continuous monitoring: Evidence must remain current. Logs, configurations, and policy documents that go stale between assessments create re-assessment risk. Managed cybersecurity monitoring supports continuous evidence generation.
  • Subcontractor compliance reporting: Primes must confirm that applicable subs maintain current CMMC status. Subs should be prepared to provide status documentation to primes on request.
  • Remediation priority: Focus remediation effort on the highest-point controls first. Document every fix with dated evidence and re-test before closing a POA&M item. Contracting officers can see SPRS scores; a low or negative score can remove a contractor from award consideration even before a formal assessment.
  • Contract risk for non-compliance: Under the Final Rule, enforceable as of November 10, 2025, DoD solicitations specify the minimum CMMC level required at contract award. Contractors without the required status are ineligible for award on those contracts.

Common CMMC questions from contracting officers and primes

How many controls does each level require? Level 1 requires 15 practices from FAR 52.204-21. Level 2 requires 110 controls from NIST SP 800-171 Rev. 2. Level 3 requires those 110 controls plus selected enhancements from NIST SP 800-172.

What is the difference between Level 2 and Level 3? Level 2 addresses broad CUI protection. Level 3 adds controls specifically designed to reduce risk from Advanced Persistent Threats, drawn from NIST SP 800-172. Level 3 also requires a DIBCAC-led assessment rather than a C3PAO assessment, and it requires Final Level 2 (C3PAO) status as a prerequisite.

Does a Level 2 self-assessment mean a lower technical bar? No. A Level 2 self-assessment requires meeting the exact same 110 NIST SP 800-171 Rev. 2 requirements as a C3PAO certification assessment. The difference is who conducts the evaluation, not what is evaluated. "MET" requires final, dated evidence for every applicable assessment objective regardless of assessment type.

Who typically needs Level 3? Level 3 applies to contractors working on the most sensitive national-security programs, typically those involving advanced weapons systems or critical defense technologies. Most small and mid-size defense contractors will fall at Level 1 or Level 2.

When do primes flow Level 2 requirements to subs? Primes must flow down CMMC requirements to any subcontractor that will process, store, or transmit CUI in performance of the contract. The sub must meet the same CMMC level specified in the prime's contract. Primes bear responsibility for verifying sub status at award.


Key Takeaways

Most DoD contractors handling CUI need CMMC Level 2, which requires implementing all 110 NIST SP 800-171 Rev. 2 controls, maintaining dated evidence at the assessment-objective level, and completing either a self-assessment or C3PAO certification as specified by the contract.

PointDetails
Determine your level earlyCheck contract language for FCI or CUI to confirm whether Level 1, 2, or 3 applies.
Build your SSP firstThe System Security Plan is the foundational document every assessor reviews before examining evidence.
Track evidence by assessment objectiveNIST SP 800-171A breaks each control into multiple objectives; failing one marks the whole requirement NOT MET.
Prioritize 5- and 3-point controlsThese cannot be placed on a POA&M and must be fully implemented before assessment.
Securetechie supports CMMC readinessSecuretechie provides compliance audits, managed infrastructure, and co-managed IT support to help DoD contractors build assessor-ready evidence.

The compliance trap most contractors don't see coming

There is a pattern worth naming directly: contractors who approach CMMC as a purchasing exercise rather than an evidence-building exercise consistently struggle at assessment time. Buying a compliant endpoint detection tool, subscribing to a managed SIEM, or deploying a cloud platform marketed as "CMMC-ready" does not produce compliance. It produces capability. Compliance requires that you demonstrate the capability is operating, configured correctly, and producing the outcomes the controls require.

That distinction has real consequences. A contractor can spend significantly on technology and still score poorly on SPRS because no one documented that the tools are configured to the required standards, no one tested the incident response procedures, and no one mapped the vendor's outputs to the specific assessment objectives in NIST SP 800-171A.

The other trap is scope creep in reverse: contractors who scope too broadly end up with an enormous assessment surface and insufficient time to collect evidence for every asset. Scoping too narrowly, on the other hand, risks leaving CUI-adjacent systems out of scope when they should be in. Getting scope right early, before SSP development begins, is the single highest-leverage decision in the preparation process.

For small and mid-size defense contractors, realistic Level 2 readiness timelines run from several months for organizations with mature IT practices to over a year for those starting from a low baseline. The internal hours required for SSP development, evidence collection, and assessment rehearsal are substantial. Many contractors find that co-managed IT support or a vCIO engagement significantly reduces that burden by providing structured evidence collection, policy templates, and ongoing monitoring that generates audit-ready artifacts continuously rather than in a pre-assessment sprint.


Securetechie helps DoD contractors get assessor-ready

DoD contractors who need to move from a compliance gap to a defensible SPRS score have a concrete path with Securetechie. Rather than managing CMMC preparation as a one-time project, Securetechie's approach integrates compliance into ongoing IT operations, so evidence is generated continuously and SSP documentation stays current.

Securetechie

Relevant services map directly to the preparation checklist above:

  • Compliance and security audits for gap analysis, SSP development, and assessor coordination
  • Managed infrastructure for secure configurations, logging, and evidence generation
  • Cybersecurity solutions including endpoint detection and 24/7 monitoring that produce the dated, examiner-ready artifacts assessors require
  • Co-managed IT and vCIO support for contractors who need structured ownership of control implementation and remediation tracking

Securetechie serves small to mid-size businesses and DoD supply-chain contractors across Southern California. To discuss your CMMC readiness posture and get a structured gap assessment, contact Securetechie and schedule a consultation.


Authoritative sources for CMMC compliance

These are the primary documents to bookmark and reference throughout your SSP development and assessment preparation:

  • CMMC Model Overview (Version 2.13) — The definitive policy document. Use this for level definitions, standard mappings, and control counts. Essential for SSP framing and assessor conversations.
  • CMMC Assessment Guide, Level 2 (Version 2.13) — The assessor's procedural guide. Use this to understand exactly how assessors evaluate each requirement, what evidence they examine, and how assessment objectives are structured. This is the most practical document for evidence preparation.
  • NIST SP 800-171 Rev. 2 — The source standard for all 110 Level 2 requirements. Available from the NIST Computer Security Resource Center. Use this alongside NIST SP 800-171A, which provides the granular assessment objectives.
  • NIST SP 800-172 — The enhanced requirements standard for Level 3. Relevant only for contractors pursuing DIBCAC assessment.
  • DoD CIO CMMC Program page — The official program overview including phase-in schedules, POA&M rules, and the DFARS clause references (252.204-7021). Bookmark this for procurement language and contract clause verification.
  • CMMC Scoping Guide, Level 2 — Available on the DoD CIO documentation site. Use this to correctly categorize assets and define your assessment boundary before SSP development begins.

This article provides general informational guidance on CMMC compliance requirements. It is not legal or regulatory advice. Contractors should verify current requirements with the DoD CIO's official CMMC documentation and consult a qualified compliance professional for their specific contract situation.