The Short Answer
Your CMMC level is set by the most sensitive category of government information that touches your systems — not by company size, revenue, or how much of your business is defense work.
- You handle FCI only → Level 1. Federal Contract Information is information provided by or generated for the government under contract that isn't intended for public release. Nearly every defense contract involves it.
- You handle CUI → Level 2. Controlled Unclassified Information — export-controlled technical data, drawings with distribution statements, Covered Defense Information — triggers the full 110 requirements of NIST SP 800-171.
- Level 3 is rare — and DoD will tell you. It applies to CUI on the most sensitive programs, adds 24 enhanced requirements from NIST SP 800-172, and is assessed by the government. If Level 3 applies to you, it will be explicit in the program — it's not something you elect.
Three Questions That Decide Your Level
-
Do you handle Federal Contract Information?
If you hold a DoD contract — or subcontract under one — the answer is almost certainly yes. Contract terms, technical correspondence, performance details: if the government provided it or you generated it for them, and it isn't public, it's FCI. That makes Level 1 your floor: the 17 basic safeguarding practices of FAR 52.204-21, self-assessed annually.
-
Does CUI reach your systems?
This is the question that separates Level 1 from Level 2 — and it's about what actually reaches your environment, not what the program handles overall. Common CUI for defense contractors: technical drawings and specs with distribution statements, export-controlled data (ITAR/EAR), and anything marked CUI or CDI. If any of it is received, created, or stored on your systems, your target is Level 2 — all 110 requirements of NIST SP 800-171.
-
Are you on DoD's most sensitive programs?
A small set of programs facing advanced persistent threats will designate Level 3, which layers 24 enhanced NIST SP 800-172 requirements on top of Level 2 and is assessed by the government. You'll know from the program itself — for the overwhelming majority of contractors, the real decision is between Levels 1 and 2.
Your Contracts Already Tell You
Before guessing, read the clauses. Each one maps to a concrete obligation:
- FAR 52.204-21 — basic safeguarding of FCI: the source of the Level 1 practices. If this is your only security clause, Level 1 is your likely target.
- DFARS 252.204-7012 — safeguarding Covered Defense Information and cyber incident reporting. This clause means CUI is in play: NIST SP 800-171 applies, and Level 2 is your track.
- DFARS 252.204-7019 / 7020 — require a current NIST SP 800-171 self-assessment score in SPRS and give DoD the right to a higher-level government assessment.
- DFARS 252.204-7021 — the CMMC clause that writes a specific level into the contract. Its Phase 2 rollout is suspended as of July 13, 2026, but Phase 1 self-assessment requirements are already appearing in solicitations.
Subcontractors: your level follows what flows down to you. If the prime holds CUI but only FCI reaches your systems, Level 1 is your target — get that in writing from your prime. And if you sell solely commercially available off-the-shelf (COTS) items, CMMC doesn't apply to you at all.
What Each Level Involves
17 Practices · FCI
Basic safeguarding from FAR 52.204-21. Verified by an annual self-assessment with a leadership affirmation in SPRS. Most small subcontractors land here — and you can self-assess free in your browser.
110 Requirements · CUI
The full NIST SP 800-171 baseline, scored into SPRS. Verified today by self-assessment and select government-led assessments; the C3PAO third-party mandate is suspended pending DoD's program review.
Level 2 + NIST 800-172
Enhanced requirements for the most sensitive programs, assessed by the government. Program-designated — if this is you, you already know.