CMMC 2.0 Level 1 vs Level 2: What’s the Difference (2026 Guide)

CMMC 2.0 LEVEL 1 vs LEVEL 2

CMMC 2.0 level If you sell to the Department of Defense, you’ve probably heard three claims about CMMC 2.0 in the same week: that Level 1 needs 15 practices, that it needs 17, and that Level 2 is “basically the same thing but audited.” None of those claims is exactly wrong, and none of them is exactly right either — and the gap between them is exactly where contractors lose bids. CMMC Level 1 and Level 2 aren’t two versions of the same checklist. They protect different categories of information, use different assessment methods, and — as of November 2026 — sit on opposite sides of a hard enforcement line. This guide walks through what actually separates them, how to tell which one your contract requires, and what changes once Phase 2 of the rollout takes effect.

CMMC 2.0 Level

Quick Answer  – Level 1 protects Federal Contract Information (FCI) — 15 basic practices, self-assessed annually, no partial credit allowed.

Level 2 protects Controlled Unclassified Information (CUI) — 110 practices from NIST SP 800-171, assessed either by self-attestation or by an accredited third party (C3PAO), depending on contract sensitivity.

The 2026 shift: starting November 10, 2026, most CUI-handling contracts move from self-assessment to mandatory C3PAO certification as a condition of contract award.

CMMC 2.0 level at a Glance

Level 1 — Foundational Level 2 — Advanced
Protects Federal Contract Information (FCI) Controlled Unclassified Information (CUI)
Practice count 15 practices (FAR 52.204-21) 110 practices (NIST SP 800-171)
Assessment objectives 58 320
Assessment method Annual self-assessment Self-assessment or C3PAO certification, per contract
Assessment cycle Every 12 months Every 12 months (self) or every 3 years (C3PAO)
POA&M allowed? No — must be fully MET Yes, with limits and a 180-day closeout
Typical prep timeline Weeks to a few months 6–18 months
Typical cost range Low — largely internal effort $20,000–$100,000+ depending on scope and maturity

Why CMMC 2.0 Has Levels at All

The Cybersecurity Maturity Model Certification exists because self-attestation, on its own, wasn’t working. For years, contractors claimed compliance with NIST SP 800-171 through their own word alone, and the Department of Defense had no reliable way to verify it — while cyberattacks against the defense industrial base kept climbing. CMMC 2.0 replaced a five-tier draft model with three levels, each tied to a specific category of information and a specific verification method: Level 1 (Foundational) for FCI, Level 2 (Advanced) for CUI, and Level 3 (Expert) for the smaller set of programs handling the most sensitive CUI, assessed directly by the government. For the vast majority of contractors and subcontractors in the defense industrial base, the real decision comes down to just two of those three levels — which is why this comparison matters more than the broader framework overview.

CMMC 2.0 level: Foundational

CMMC Level 1 applies to any organization that handles Federal Contract Information — non-public information the government provides or generates in connection with a contract, but that isn’t intended for public release and isn’t Controlled Unclassified Information. Contract numbers, delivery schedules, invoices, and routine status reports are typical examples. If your business touches a DoD contract at all but never receives CUI, Level 1 is almost certainly your ceiling, not a stepping stone.

The requirements come directly from FAR Clause 52.204-21 — basic safeguarding practices like limiting system access to authorized users, sanitizing media before disposal, and controlling physical access to systems that process FCI. Level 1 is deliberately lightweight: the DoD’s own model documentation notes that Level 1 organizations “may only be able to perform these practices in an ad-hoc manner,” and process maturity — meaning documented, repeatable policy — isn’t assessed at this level the way it is at Level 2. Verification is a self-assessment: your organization evaluates itself against all 15 requirements, submits the score to the Supplier Performance Risk System (SPRS), and files an annual executive affirmation. There is no partial credit — every requirement must be fully met, with no Plan of Action and Milestones (POA&M) allowed to cover gaps.

Where the “15 vs. 17” Confusion Comes From

CMMC 2.0 level original 2021 model documentation described Level 1 as 17 separate practices, because one FAR requirement — 52.204-21(b)(1)(ix) — was split into three sub-controls for assessment purposes.

The finalized CMMC rule (32 CFR § 170.14(c)(2)) reverts to the FAR clause’s own count of 15 security requirements, assessed against 58 underlying objectives drawn from NIST SP 800-171A. You’ll still see “17 practices” on plenty of older blog posts and vendor pages — it isn’t wrong historically, it’s just describing the pre-final-rule model.

CMMC Level 2: Advanced

CMMC Level 2 applies once your organization creates, receives, stores, or transmits Controlled Unclassified Information — data that’s unclassified but still requires safeguarding under law, regulation, or government-wide policy, such as export-controlled technical data, certain unclassified DoD technical information, or personally identifiable information tied to a covered contract. Level 2 is built on all 110 security requirements in NIST SP 800-171, assessed against 320 detailed objectives — roughly five and a half times the scope of Level 1 in both practice count and assessment depth.

The defining difference from Level 1 is verification. Level 2 splits into two paths depending on how sensitive the specific contract’s CUI is: some contracts still accept an annual Level 2 self-assessment, while contracts touching more critical or prioritized CUI require certification by a Certified Third-Party Assessment Organization (C3PAO) — an accredited, independent assessor — on a three-year cycle, with annual affirmations in between. Unlike Level 1, a limited Plan of Action and Milestones is permitted at Level 2 for certain lower-weighted requirements, but it comes with a hard 180-day closeout window and doesn’t cover every control — some requirements must be fully implemented before an assessment can even begin.

The Full Side-by-Side

Dimension Level 1 (Foundational) Level 2 (Advanced)
Governing source FAR Clause 52.204-21 NIST SP 800-171 / SP 800-171A
Data in scope Federal Contract Information (FCI) Controlled Unclassified Information (CUI)
Documentation maturity assessed? No — ad-hoc performance is acceptable Yes — policies and processes are evaluated
Who can assess The contractor itself The contractor itself, or a C3PAO
Score reporting Executive affirmation + SPRS score SPRS score + affirmation; C3PAO status recorded federally
Typical audience Small subcontractors, admin/logistics vendors Engineering, IT, and CUI-handling primes and subs

The 2026 Phase 2 Deadline

CMMC enforcement is rolling out in four phases tied to the DFARS clause 252.204-7021, which took effect on November 10, 2025. Phase 1 opened with Level 1 and Level 2 self-assessments becoming a condition of award in applicable solicitations. The date that matters most right now is Phase 2: beginning November 10, 2026, C3PAO certification becomes the expected standard for Level 2 contracts involving CUI, rather than an option contracting officers can choose to require. That doesn’t mean every contractor needs a certificate by a single deadline — CMMC applies contract by contract, tied to the specific solicitation’s requirements — but it does mean that for most organizations working with CUI, self-assessment stops being sufficient the moment a new or renewed contract lands after that date.

Phase Effective Date What Changes
Phase 1 Nov 10, 2025 Level 1 and Level 2 self-assessments required in applicable solicitations; contracting officers may opt to require C3PAO certification early.
Phase 2 Nov 10, 2026 C3PAO certification becomes the expected requirement for applicable Level 2 (CUI) contracts.
Phase 3 Nov 10, 2027 Level 3 assessments begin for the highest-sensitivity CUI programs.
Phase 4 Nov 10, 2028 Full implementation — CMMC requirements apply across all applicable new contracts and renewals.

Don’t Forget: CMMC Flows Down

If your organization is a subcontractor, your required level isn’t set only by your own relationship with the DoD — it flows down from your prime.

A prime holding Level 2 (C3PAO) status will generally require any subcontractor that handles CUI on its behalf to meet the same standard, regardless of the subcontractor’s size.

Waiting for your prime to raise this in the contract renewal conversation is a common way small and mid-sized suppliers get blindsided close to award time.

Common Mistakes Contractors Make

  • Assuming Level 1 is sufficient because “we’ve never technically received CUI” — without a documented data-flow review to confirm it.
  • Treating a Level 2 self-assessment as the finish line when the actual contract requires C3PAO certification.
  • Starting C3PAO preparation only after a contracting officer raises it — Level 2 readiness realistically takes 6 to 18 months.
  • Not confirming flow-down requirements with prime contractors until late in a renewal cycle.
  • Scoping the assessment boundary too broadly, pulling systems that never touch FCI or CUI into an unnecessarily expensive assessment.

A Practical Roadmap

  • Step 1 — Classify your data. Map every system, contract, and workflow that touches government-provided information, and determine whether it’s FCI, CUI, or neither.
  • Step 2 — Confirm your required level from the contract. Your solicitation or DFARS clause — not your own assumption — determines whether Level 1 or Level 2 applies, and whether Level 2 needs a C3PAO.
  • Step 3 — Run a gap assessment. Compare current practices against the 15 (Level 1) or 110 (Level 2) requirements and document what’s missing.
  • Step 4 — Remediate and document. Level 2 in particular expects documented, repeatable processes — not just technical controls.
  • Step 5 — Assess and submit. Self-assess and score in SPRS, or schedule a C3PAO assessment with enough lead time before your contract’s award date.

Why Getting This Right Matters

Choosing the wrong level, or waiting too long to prepare for the right one, has a direct commercial cost: contracting officers use SPRS to verify CMMC status before award, and a missing or mismatched certification can take a business out of consideration entirely, not just delay it. On the other hand, over-scoping — pursuing Level 2 C3PAO certification for a business that only ever touches FCI — burns budget and calendar time that could go toward the actual contract work. The goal isn’t the highest level available; it’s the level your contracts genuinely require, backed by evidence that holds up under DoD scrutiny.

How B4Q Assurance Helps

B4Q Assurance works with defense contractors and subcontractors to classify FCI and CUI exposure, scope the correct CMMC level and assessment boundary, close gaps against the 15 Level 1 or 110 Level 2 requirements, and prepare the documentation and evidence needed for a self-assessment or a C3PAO certification — so contract eligibility isn’t left to guesswork.

CMMC 2.0 level Resources

CMMC 2.0 level FAQs

Does Level 1 ever require a third-party assessment?

No. Level 1 is always a self-assessment, submitted annually to SPRS with an executive affirmation. Third-party involvement only enters at Level 2, and only for contracts requiring C3PAO certification.

Yes — many contractors maintain Level 1 status for lines of business that only touch FCI while pursuing Level 2 for divisions or contracts that handle CUI. The required level is tied to the contract and the data involved, not the company as a single entity.

CMMC requirements generally apply to new contracts, solicitations, and option-period exercises rather than retroactively rewriting contracts already in place — but renewals and new task orders after November 10, 2026 are where the Phase 2 requirement is most likely to appear.

For some Level 2 contracts involving less critical CUI, yes — self-assessment remains acceptable. But contracting officers are increasingly specifying C3PAO certification for CUI-heavy work, and that requirement becomes the default expectation once Phase 2 takes effect.

Most organizations should plan for 6 to 18 months from initial gap assessment through certification, depending on existing security maturity, scope size, and C3PAO availability — which is itself limited, since the assessor pool is still growing.

What do you think?