Skip to main content
Guide

CMMC Level 1 vs Level 2: Which Do You Need? Complete Comparison

Understand the key differences between CMMC Level 1 (17 practices, self-assessment) and Level 2 (110 controls, C3PAO assessment). Learn which level your contracts require.

CMMC Command Team
Compliance Engineering
Mar 11, 20269 min read

The Two Levels That Matter

CMMC 2.0 streamlined the original five levels into three, but for most defense contractors, the decision comes down to Level 1 or Level 2. Here's the definitive comparison.

Level 1: Federal Contract Information (FCI)

Level 1 applies to contractors who handle Federal Contract Information (FCI) — information provided by or generated for the government under contract that isn't intended for public release.

Requirements

  • 17 practices derived from FAR 52.204-21
  • Self-assessment only — no third-party audit required
  • Annual affirmation submitted to SPRS.mil
  • Covers basic cyber hygiene: antivirus, password policies, physical access, user awareness

Who Needs Level 1

If your contract includes FAR 52.204-21 but not DFARS 252.204-7012, you likely only need Level 1. This typically includes contractors who:

  • Provide commercial off-the-shelf (COTS) products
  • Perform services that don't involve sensitive technical data
  • Handle general contract correspondence but not CUI

Cost and Effort

Most contractors can achieve Level 1 in 2-4 weeks with minimal investment. The 17 practices are basic IT hygiene that most organizations already partially implement.

Level 2: Controlled Unclassified Information (CUI)

Level 2 is where it gets serious. This level applies to contractors who process, store, or transmit Controlled Unclassified Information (CUI) — technical drawings, specifications, test data, source code, and other sensitive-but-unclassified information.

Requirements

  • 110 controls from NIST SP 800-171 Rev 2
  • C3PAO third-party assessment (for most contracts as of November 2026)
  • 320 assessment objectives from NIST SP 800-171A
  • SPRS score submitted to SPRS.mil
  • Comprehensive SSP and POA&M documentation

Who Needs Level 2

If your contract includes DFARS 252.204-7012, you handle CUI and need Level 2. This includes:

  • Any contractor receiving technical data or specifications marked as CUI
  • Subcontractors with CUI flow-down from primes
  • IT providers managing systems that store or process CUI
  • Manufacturers with CUI-marked drawings or processes

Cost and Effort

Level 2 typically requires 3-6 months of preparation and $10,000-$100,000+ depending on your approach (software-first vs. consultant-heavy).

Side-by-Side Comparison

AspectLevel 1Level 2
Information TypeFCICUI
Controls17 (FAR 52.204-21)110 (NIST 800-171)
AssessmentSelf-assessmentC3PAO third-party
SPRS Score RangeN/A-203 to 110
SSP RequiredNoYes
POA&M RequiredNoYes
Evidence VaultMinimalExtensive
Certification ValidityAnnual3 years
Typical Timeline2-4 weeks3-6 months
Typical Cost$1,000-5,000$10,000-100,000+

The Subcontractor Question

The most common confusion: do subcontractors need Level 2?

If your prime contractor flows CUI down to you — yes. Check your subcontract for DFARS 252.204-7012. If it's there, you need Level 2 regardless of your company size.

Many small subcontractors (10-50 employees) are discovering they need Level 2 for the first time. The good news: tools like CMMC Command make it achievable without a six-figure consulting engagement.

What If You're Not Sure?

  1. Check your contracts for DFARS 252.204-7012 — if present, you need Level 2
  2. Check for FAR 52.204-21 without DFARS — Level 1 is sufficient
  3. Ask your contracting officer or prime contractor directly
  4. When in doubt, assess against Level 2 — it covers Level 1 automatically

Start Your Assessment

Whether you need Level 1 or Level 2, the first step is the same: understand your current posture.

Start your free CMMC assessment — all 110 controls assessed with real-time SPRS scoring, free forever.

CMMC Level 1CMMC Level 2FAR 52.204-21NIST 800-171

See where you stand on CMMC

Run through all 110 controls and get your SPRS score. Takes about 30 minutes. Free, no credit card.