What CMMC Level Do You Actually Need?

You don't pick a CMMC level — your data does. Three questions determine whether you're targeting the 17 practices of Level 1 or the 110 requirements of Level 2, and your contracts already hold the answers.

The Short Answer

Your CMMC level is set by the most sensitive category of government information that touches your systems — not by company size, revenue, or how much of your business is defense work.

Three Questions That Decide Your Level

  1. Do you handle Federal Contract Information?

    If you hold a DoD contract — or subcontract under one — the answer is almost certainly yes. Contract terms, technical correspondence, performance details: if the government provided it or you generated it for them, and it isn't public, it's FCI. That makes Level 1 your floor: the 17 basic safeguarding practices of FAR 52.204-21, self-assessed annually.

  2. Does CUI reach your systems?

    This is the question that separates Level 1 from Level 2 — and it's about what actually reaches your environment, not what the program handles overall. Common CUI for defense contractors: technical drawings and specs with distribution statements, export-controlled data (ITAR/EAR), and anything marked CUI or CDI. If any of it is received, created, or stored on your systems, your target is Level 2 — all 110 requirements of NIST SP 800-171.

  3. Are you on DoD's most sensitive programs?

    A small set of programs facing advanced persistent threats will designate Level 3, which layers 24 enhanced NIST SP 800-172 requirements on top of Level 2 and is assessed by the government. You'll know from the program itself — for the overwhelming majority of contractors, the real decision is between Levels 1 and 2.

Your Contracts Already Tell You

Before guessing, read the clauses. Each one maps to a concrete obligation:

Subcontractors: your level follows what flows down to you. If the prime holds CUI but only FCI reaches your systems, Level 1 is your target — get that in writing from your prime. And if you sell solely commercially available off-the-shelf (COTS) items, CMMC doesn't apply to you at all.

What Each Level Involves

Level 1 — Foundational

17 Practices · FCI

Basic safeguarding from FAR 52.204-21. Verified by an annual self-assessment with a leadership affirmation in SPRS. Most small subcontractors land here — and you can self-assess free in your browser.

Level 2 — Advanced

110 Requirements · CUI

The full NIST SP 800-171 baseline, scored into SPRS. Verified today by self-assessment and select government-led assessments; the C3PAO third-party mandate is suspended pending DoD's program review.

Level 3 — Expert

Level 2 + NIST 800-172

Enhanced requirements for the most sensitive programs, assessed by the government. Program-designated — if this is you, you already know.

Know Your Level? Here's the Next Step.

Frequently Asked Questions

What CMMC level do I need if I only handle FCI?

Level 1. If your contracts involve Federal Contract Information but no Controlled Unclassified Information, your target is the 17 Level 1 practices drawn from FAR 52.204-21 — basic safeguarding like access control, media handling, and boundary protection — verified by an annual self-assessment with an affirmation from company leadership.

How do I know if I handle CUI?

Look at what you receive and produce: technical drawings and specifications with distribution statements, export-controlled technical data (ITAR/EAR), and documents marked CUI or Covered Defense Information are the common cases for DoD contractors. Check whether your contracts carry DFARS 252.204-7012 — that clause exists to protect CUI. If you're genuinely unsure, ask your contracting officer or prime in writing; the answer determines whether you're building toward 17 practices or 110.

What CMMC level do subcontractors need?

The level follows the information that actually flows down to you, not your prime's level. If the prime holds CUI but only Federal Contract Information reaches your systems, Level 1 is your target; if CUI flows down, you need Level 2. Primes are responsible for flowing requirements to subcontractors, so expect them to ask for evidence either way.

Did the July 2026 CMMC suspension change what level I need?

No. The suspension paused the Phase 2 rollout — chiefly the C3PAO third-party assessment mandate — not the underlying obligations. Your target level is still determined by the information you handle: FCI means Level 1, CUI means Level 2. Phase 1 self-assessments, DFARS 252.204-7012, and NIST SP 800-171 remain in force, and an inflated SPRS score still carries False Claims Act exposure.

Is anyone exempt from CMMC?

Contractors that sell solely commercially available off-the-shelf (COTS) items are excluded from CMMC requirements. Beyond that, expect a level: virtually every other defense contract involves at least Federal Contract Information, which puts Level 1 on the table as the floor.

CMMC Phase 2 Is Suspended.
Your Security Obligations Are Not.

Jul 13, 2026

DoD suspended the CMMC Phase 2 requirements — originally set to take effect November 10, 2026 — along with pending implementation milestones, while a task force reviews the program.

Still in force

Phase 1 self-assessments, DFARS 252.204-7012, and NIST SP 800-171 — now enforced through self-assessments and select government-led assessments. An inflated SPRS score still carries False Claims Act exposure.

60 days

The CMMC Reform Task Force reports on the program's future within 60 days. Requirements can return — reshaped — on short notice; contractors who keep implementing won't be starting over.

The certification pause is not a security pause: your contracts still require NIST 800-171, and the government is still checking. Read the plain-English breakdown of the suspension.

Not Sure Which Level? Ask an Assessor

Whether you're starting from scratch or preparing for a formal assessment, let's talk through where you stand and what it takes to get compliant. Every inquiry starts with a free 30-minute consultation — no obligation.

Senior-led, capacity-limited. Every engagement is led personally by a Lead Certified CMMC Assessor (LCCA) — never handed off to junior staff. To protect that standard, I take on a limited number of clients at a time. Most inquiries get a reply within 1–2 business days.
Book Your Free 30-Minute Consultation

Pick a time that works for you — no back-and-forth email.

Your information is kept confidential and never shared. See our privacy policy.

Message sent!

Thanks for reaching out. Neal will be in touch within 1–2 business days.