If you’re working with the Department of Defense or in the defense industrial base, understanding the different CMMC levels is key to meeting compliance and protecting sensitive information. The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework has three levels, Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert), each designed to correspond with the type of information you handle, and the security controls required.
Level 1 (Foundational) is where most contractors start. This level focuses on protecting Federal Contract Information (FCI), which includes information provided by or generated for the government but not intended for public release. The cybersecurity practices required here are basic controls, like access control, physical protection, and system integrity, totaling about 15 security requirements aligned with the Federal Acquisition Regulation (FAR) clause 52.204-21. Level 1 does not require formal documentation of processes and allows annual self-assessments to confirm compliance. It’s perfect for companies handling only FCI without stored or processed Controlled Unclassified Information (CUI).
Level 2 (Advanced) is significantly more demanding. It targets contractors who handle CUI, a broader category of sensitive but unclassified information that requires stricter controls. Level 2 aligns with the NIST SP 800-171 standard and includes 110 security controls designed to prevent unauthorized access or disclosure. This level requires organizations to document and follow established cybersecurity processes consistently. Assessments for Level 2 involve either third-party audits conducted by Certified Third-Party Assessment Organizations (C3PAOs) or, in some cases, self-assessments with annual executive affirmations, depending on the sensitivity of the CUI handled. Reassessments usually occur every three years. Level 2 acts as a bridge between foundational cybersecurity hygiene and expert-level protection.
Level 3 (Expert) is the highest certification tier and is reserved for contractors working with the most sensitive CUI that is critical to national security. It builds on Level 2 controls by adding an additional set of requirements from NIST SP 800-172, addressing advanced persistent threats and sophisticated cyber-attacks. Organizations at Level 3 undergo government-led assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) every three years, plus annual executive affirmations. This level demands a robust cybersecurity posture, including continuous monitoring, incident response, and risk management processes tailored to defend against highly capable adversaries.
These levels are cumulative. To be certified at a higher level, a company must meet all requirements at that level and all lower levels. The DoD specifies which level contractors need to achieve based on the contracts and the sensitivity of the information involved. For example, subcontractors handling only FCI typically require Level 1, whereas prime contractors managing CUI usually need Level 2 certification. Those involved in programs with national security implications may be subject to Level 3.
Certification requirements differ by level not just in controls but also in assessment type and frequency. Level 1 requires annual self-assessments with no allowances for gaps, Level 2 generally requires third-party assessments every three years (with allowances for corrective action plans/POA&M’s addressing any deficiencies within a specified timeframe), and Level 3 involves government-led assessments for the highest level of scrutiny.
Ultimately, understanding which CMMC level applies to your organization is critical. It guides the scope of cybersecurity controls you must implement, the type of assessments you must prepare for, and the ongoing maintenance of your cybersecurity posture. Preparing early, documenting your cybersecurity processes, and engaging with authorized assessors can help ensure smooth certification and sustained compliance, keeping you eligible for DoD contracts.