Level 1 is a 17-control annual self-attestation. Level 2 is a 110-control requirement that most DoD subcontractors handling CUI will need to pass through a Certified Third-Party Assessment Organization (C3PAO). The gap between the two is significant – in documentation burden, remediation cost, and time to certification.
What Is CMMC Level 1?
CMMC Level 1 applies to contractors who handle Federal Contract Information (FCI) but not Controlled Unclassified Information (CUI). It covers 17 practices drawn from FAR 52.204-21: basic cybersecurity hygiene covering antivirus, access control, password management, and similar foundational controls.
Level 1 is self-attested annually. You document your implementation, a senior official signs off, and you submit to the Supplier Performance Risk System (SPRS). No third-party assessor required.
What Is CMMC Level 2?
CMMC Level 2 aligns directly to NIST SP 800-171 Rev 2 – all 110 security requirements across 14 domains. It applies to any contractor or subcontractor whose work involves CUI: technical specifications, controlled drawings, export-controlled data, military design documents, and similar sensitive material.
For most contractors, Level 2 requires a triennial assessment by a C3PAO credentialed by the Cyber AB. Some lower-risk Level 2 programs may allow self-attestation, but if your contracting officer specifies C3PAO assessment in the solicitation, that is what you need.
How Do You Know Which Level Applies to You?
Look at your contract. Specifically, look for DFARS clause 252.204-7012. If it is present, you are handling CUI and Level 2 applies. If your contract references FAR 52.204-21 only and does not involve CUI, Level 1 is your baseline.
When in doubt, ask your contracting officer what data you handle under the contract and whether any of it is CUI under the National Archives CUI Registry. If the answer is yes, plan for Level 2.
The Practical Difference in Cost and Effort
Level 1 self-attestation can typically be completed in a few days with basic documentation. Level 2 is a different scope entirely. A full gap assessment against 110 controls typically takes one to two weeks. Remediation can run months and tens of thousands of dollars depending on your environment. The C3PAO assessment itself is a formal engagement with evidence review, interviews, and a final report.
This is why the readiness phase matters. Before you spend on remediation, you need to know what you are actually remediating and what your current SPRS score reflects.
What If I Am a Subcontractor to a Prime?
Flow-down is the key concept. If a prime contractor receives CUI and passes any portion of that work or related data to you, the CMMC requirement flows down. Your level depends on what data you touch, not whether your name is on the prime contract.
Many subcontractors underestimate this. If you manufacture to controlled specifications, support a system that processes CUI, or access any government IT system as part of your work, assume Level 2 applies and verify with your prime.
Init Cyber provides fixed-fee or hourly CMMC Level 2 gap assessments and program management for DoD prime and subcontractors.