CMMC 2.0 LEVEL 1 vs LEVEL 2
CMMC 2.0 level If you sell to the Department of Defense, you’ve probably heard three claims about CMMC 2.0 in the same week: that Level 1 needs 15 practices, that it needs 17, and that Level 2 is “basically the same thing but audited.” None of those claims is exactly wrong, and none of them is exactly right either — and the gap between them is exactly where contractors lose bids. CMMC Level 1 and Level 2 aren’t two versions of the same checklist. They protect different categories of information, use different assessment methods, and — as of November 2026 — sit on opposite sides of a hard enforcement line. This guide walks through what actually separates them, how to tell which one your contract requires, and what changes once Phase 2 of the rollout takes effect.
Quick Answer – Level 1 protects Federal Contract Information (FCI) — 15 basic practices, self-assessed annually, no partial credit allowed.
Level 2 protects Controlled Unclassified Information (CUI) — 110 practices from NIST SP 800-171, assessed either by self-attestation or by an accredited third party (C3PAO), depending on contract sensitivity.
The 2026 shift: starting November 10, 2026, most CUI-handling contracts move from self-assessment to mandatory C3PAO certification as a condition of contract award.
CMMC 2.0 level at a Glance
| Level 1 — Foundational | Level 2 — Advanced | |
|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Practice count | 15 practices (FAR 52.204-21) | 110 practices (NIST SP 800-171) |
| Assessment objectives | 58 | 320 |
| Assessment method | Annual self-assessment | Self-assessment or C3PAO certification, per contract |
| Assessment cycle | Every 12 months | Every 12 months (self) or every 3 years (C3PAO) |
| POA&M allowed? | No — must be fully MET | Yes, with limits and a 180-day closeout |
| Typical prep timeline | Weeks to a few months | 6–18 months |
| Typical cost range | Low — largely internal effort | $20,000–$100,000+ depending on scope and maturity |
Why CMMC 2.0 Has Levels at All
The Cybersecurity Maturity Model Certification exists because self-attestation, on its own, wasn’t working. For years, contractors claimed compliance with NIST SP 800-171 through their own word alone, and the Department of Defense had no reliable way to verify it — while cyberattacks against the defense industrial base kept climbing. CMMC 2.0 replaced a five-tier draft model with three levels, each tied to a specific category of information and a specific verification method: Level 1 (Foundational) for FCI, Level 2 (Advanced) for CUI, and Level 3 (Expert) for the smaller set of programs handling the most sensitive CUI, assessed directly by the government. For the vast majority of contractors and subcontractors in the defense industrial base, the real decision comes down to just two of those three levels — which is why this comparison matters more than the broader framework overview.
CMMC 2.0 level: Foundational
CMMC Level 1 applies to any organization that handles Federal Contract Information — non-public information the government provides or generates in connection with a contract, but that isn’t intended for public release and isn’t Controlled Unclassified Information. Contract numbers, delivery schedules, invoices, and routine status reports are typical examples. If your business touches a DoD contract at all but never receives CUI, Level 1 is almost certainly your ceiling, not a stepping stone.
The requirements come directly from FAR Clause 52.204-21 — basic safeguarding practices like limiting system access to authorized users, sanitizing media before disposal, and controlling physical access to systems that process FCI. Level 1 is deliberately lightweight: the DoD’s own model documentation notes that Level 1 organizations “may only be able to perform these practices in an ad-hoc manner,” and process maturity — meaning documented, repeatable policy — isn’t assessed at this level the way it is at Level 2. Verification is a self-assessment: your organization evaluates itself against all 15 requirements, submits the score to the Supplier Performance Risk System (SPRS), and files an annual executive affirmation. There is no partial credit — every requirement must be fully met, with no Plan of Action and Milestones (POA&M) allowed to cover gaps.
Where the “15 vs. 17” Confusion Comes From
CMMC 2.0 level original 2021 model documentation described Level 1 as 17 separate practices, because one FAR requirement — 52.204-21(b)(1)(ix) — was split into three sub-controls for assessment purposes.
The finalized CMMC rule (32 CFR § 170.14(c)(2)) reverts to the FAR clause’s own count of 15 security requirements, assessed against 58 underlying objectives drawn from NIST SP 800-171A. You’ll still see “17 practices” on plenty of older blog posts and vendor pages — it isn’t wrong historically, it’s just describing the pre-final-rule model.
CMMC Level 2: Advanced
CMMC Level 2 applies once your organization creates, receives, stores, or transmits Controlled Unclassified Information — data that’s unclassified but still requires safeguarding under law, regulation, or government-wide policy, such as export-controlled technical data, certain unclassified DoD technical information, or personally identifiable information tied to a covered contract. Level 2 is built on all 110 security requirements in NIST SP 800-171, assessed against 320 detailed objectives — roughly five and a half times the scope of Level 1 in both practice count and assessment depth.
The defining difference from Level 1 is verification. Level 2 splits into two paths depending on how sensitive the specific contract’s CUI is: some contracts still accept an annual Level 2 self-assessment, while contracts touching more critical or prioritized CUI require certification by a Certified Third-Party Assessment Organization (C3PAO) — an accredited, independent assessor — on a three-year cycle, with annual affirmations in between. Unlike Level 1, a limited Plan of Action and Milestones is permitted at Level 2 for certain lower-weighted requirements, but it comes with a hard 180-day closeout window and doesn’t cover every control — some requirements must be fully implemented before an assessment can even begin.
The Full Side-by-Side
| Dimension | Level 1 (Foundational) | Level 2 (Advanced) |
|---|---|---|
| Governing source | FAR Clause 52.204-21 | NIST SP 800-171 / SP 800-171A |
| Data in scope | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Documentation maturity assessed? | No — ad-hoc performance is acceptable | Yes — policies and processes are evaluated |
| Who can assess | The contractor itself | The contractor itself, or a C3PAO |
| Score reporting | Executive affirmation + SPRS score | SPRS score + affirmation; C3PAO status recorded federally |
| Typical audience | Small subcontractors, admin/logistics vendors | Engineering, IT, and CUI-handling primes and subs |
The 2026 Phase 2 Deadline
CMMC enforcement is rolling out in four phases tied to the DFARS clause 252.204-7021, which took effect on November 10, 2025. Phase 1 opened with Level 1 and Level 2 self-assessments becoming a condition of award in applicable solicitations. The date that matters most right now is Phase 2: beginning November 10, 2026, C3PAO certification becomes the expected standard for Level 2 contracts involving CUI, rather than an option contracting officers can choose to require. That doesn’t mean every contractor needs a certificate by a single deadline — CMMC applies contract by contract, tied to the specific solicitation’s requirements — but it does mean that for most organizations working with CUI, self-assessment stops being sufficient the moment a new or renewed contract lands after that date.
| Phase | Effective Date | What Changes |
|---|---|---|
| Phase 1 | Nov 10, 2025 | Level 1 and Level 2 self-assessments required in applicable solicitations; contracting officers may opt to require C3PAO certification early. |
| Phase 2 | Nov 10, 2026 | C3PAO certification becomes the expected requirement for applicable Level 2 (CUI) contracts. |
| Phase 3 | Nov 10, 2027 | Level 3 assessments begin for the highest-sensitivity CUI programs. |
| Phase 4 | Nov 10, 2028 | Full implementation — CMMC requirements apply across all applicable new contracts and renewals. |
Don’t Forget: CMMC Flows Down
If your organization is a subcontractor, your required level isn’t set only by your own relationship with the DoD — it flows down from your prime.
A prime holding Level 2 (C3PAO) status will generally require any subcontractor that handles CUI on its behalf to meet the same standard, regardless of the subcontractor’s size.
Waiting for your prime to raise this in the contract renewal conversation is a common way small and mid-sized suppliers get blindsided close to award time.
Common Mistakes Contractors Make
- Assuming Level 1 is sufficient because “we’ve never technically received CUI” — without a documented data-flow review to confirm it.
- Treating a Level 2 self-assessment as the finish line when the actual contract requires C3PAO certification.
- Starting C3PAO preparation only after a contracting officer raises it — Level 2 readiness realistically takes 6 to 18 months.
- Not confirming flow-down requirements with prime contractors until late in a renewal cycle.
- Scoping the assessment boundary too broadly, pulling systems that never touch FCI or CUI into an unnecessarily expensive assessment.
A Practical Roadmap
- Step 1 — Classify your data. Map every system, contract, and workflow that touches government-provided information, and determine whether it’s FCI, CUI, or neither.
- Step 2 — Confirm your required level from the contract. Your solicitation or DFARS clause — not your own assumption — determines whether Level 1 or Level 2 applies, and whether Level 2 needs a C3PAO.
- Step 3 — Run a gap assessment. Compare current practices against the 15 (Level 1) or 110 (Level 2) requirements and document what’s missing.
- Step 4 — Remediate and document. Level 2 in particular expects documented, repeatable processes — not just technical controls.
- Step 5 — Assess and submit. Self-assess and score in SPRS, or schedule a C3PAO assessment with enough lead time before your contract’s award date.
Why Getting This Right Matters
Choosing the wrong level, or waiting too long to prepare for the right one, has a direct commercial cost: contracting officers use SPRS to verify CMMC status before award, and a missing or mismatched certification can take a business out of consideration entirely, not just delay it. On the other hand, over-scoping — pursuing Level 2 C3PAO certification for a business that only ever touches FCI — burns budget and calendar time that could go toward the actual contract work. The goal isn’t the highest level available; it’s the level your contracts genuinely require, backed by evidence that holds up under DoD scrutiny.
How B4Q Assurance Helps
B4Q Assurance works with defense contractors and subcontractors to classify FCI and CUI exposure, scope the correct CMMC level and assessment boundary, close gaps against the 15 Level 1 or 110 Level 2 requirements, and prepare the documentation and evidence needed for a self-assessment or a C3PAO certification — so contract eligibility isn’t left to guesswork.
CMMC 2.0 level Resources
CMMC 2.0 level FAQs
Does Level 1 ever require a third-party assessment?
No. Level 1 is always a self-assessment, submitted annually to SPRS with an executive affirmation. Third-party involvement only enters at Level 2, and only for contracts requiring C3PAO certification.
Can a company hold both Level 1 and Level 2 status?
Yes — many contractors maintain Level 1 status for lines of business that only touch FCI while pursuing Level 2 for divisions or contracts that handle CUI. The required level is tied to the contract and the data involved, not the company as a single entity.
What happens if we're mid-contract when Phase 2 begins?
CMMC requirements generally apply to new contracts, solicitations, and option-period exercises rather than retroactively rewriting contracts already in place — but renewals and new task orders after November 10, 2026 are where the Phase 2 requirement is most likely to appear.
Is a Level 2 self-assessment ever enough on its own?
For some Level 2 contracts involving less critical CUI, yes — self-assessment remains acceptable. But contracting officers are increasingly specifying C3PAO certification for CUI-heavy work, and that requirement becomes the default expectation once Phase 2 takes effect.
How long does C3PAO certification actually take?
Most organizations should plan for 6 to 18 months from initial gap assessment through certification, depending on existing security maturity, scope size, and C3PAO availability — which is itself limited, since the assessor pool is still growing.