Comparison · CMMC Guide

CMMC Level 1 vs Level 2: Which Does Your Contract Require?

The whole decision comes down to one question: does your contract involve CUI, or only FCI?

ComparisonCMMC Levels

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 19, 2026 · 5 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

The distinction between CMMC Level 1 and Level 2 comes down to one question: does your contract involve Controlled Unclassified Information (CUI), or only Federal Contract Information (FCI)? Get this wrong and you either overspend on unnecessary compliance or underprepare and put the award at risk.

The fundamental difference: FCI vs CUI

Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It excludes information the Government provides to the public and simple transactional information, such as what is needed to process payments (FAR 52.204-21(a)).

Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls; 32 CFR 170.4 adopts the definition in 32 CFR 2002.4(h). The National Archives CUI Registry lists the CUI categories and their marking requirements.

DoD selects the CMMC Status a procurement requires based on whether FCI or CUI will be processed, stored, or transmitted on your systems (32 CFR 170.3(d)), and the solicitation states it. FCI only points to Level 1. CUI points to Level 2 at minimum, and to Level 3 for the programs where DoD requires it.

CMMC Level 1: the basics

Level 1 requires the 15 basic safeguarding requirements derived from FAR 52.204-21. These are fundamental cybersecurity hygiene requirements that any business should implement regardless of government contracting. They cover access control basics, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.

Level 1 is a self-assessment, repeated every year. Every one of the 15 requirements must be MET, no POA&M is allowed, you enter the results in the Supplier Performance Risk System (SPRS), and your Affirming Official affirms continuing compliance at each assessment and annually (32 CFR 170.15, 170.21(a)(1), 170.22). No third-party assessment is required for Level 1.

CMMC Level 2: the full standard

Level 2 requires compliance with all 110 security requirements in NIST SP 800-171 Rev. 2 (32 CFR 170.14(c)(3)), organized across 14 control families ranging from Access Control and Audit and Accountability to System and Communications Protection and System and Information Integrity.

Level 2 has two assessment types: Level 2 (Self), which your organization performs, and Level 2 (C3PAO), a certification assessment by an authorized third-party assessor. DoD program managers select which one a procurement requires (32 CFR 170.3(d)). Since July 13, 2026, with Phase 2 suspended, a DoW CIO memorandum allows requiring activities to designate only Level 1 (Self) or Level 2 (Self), and directs that Level 2 (C3PAO) and Level 3 (DIBCAC) requirements be removed from active solicitations. Read your solicitation for the assessment type it states. See CMMC self-assessment vs C3PAO for the full breakdown.

Not sure whether you are looking at a 15-requirement Level 1 lift or the full 110-control Level 2 standard? A free 10-question gap check gives you a directional self-assessment (not an official SPRS score).

Run the free gap check →

What the DoD estimates the two levels cost

The figures below come from the DoD's published Regulatory Impact Analysis. Level 1 is shown per annual self-assessment, because Level 1 is repeated every year; the Level 2 figures cover a three-year cycle. In the DoD's model, most of each total is the contractor's own staff time and outside support rather than an assessor's fee. The model assumes the requirements are already implemented, so these figures do not include the cost of implementing or remediating them.

Path (DoD estimate)Small entityLarger entity
Level 1 self-assessment (per year)$5,977$4,042
Level 2 self-assessment (3-year cycle)$37,196$48,827
Level 2 certification, C3PAO (3-year cycle)$104,670$117,768

The C3PAO assessor engagement alone is modeled at $31,234 for a small entity and $52,056 for a larger one within that certification total. The gap between Level 1 and Level 2 is large, which is exactly why correctly identifying your required level matters before you commit budget. For a deeper breakdown, see our CMMC Level 2 certification cost guide.

Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), pp. 13-14 and 19-26; the same figures appear in the final rule, 89 FR 83092 (Oct. 15, 2024), at 83181 to 83186.

How to determine which level applies to you

Check your solicitation and contract. The required CMMC Status is stated there, through the DFARS CMMC clause (the final rule's preamble, 89 FR 83092, refers to DFARS clause 252.204-7021; confirm the current clause text in the DFARS). If you are unsure, look for these indicators.

Your contract likely requires Level 1 if it references FAR 52.204-21 only, you handle FCI but no technical data, no CUI markings appear on anything you receive or generate, and your contracting officer has confirmed no CUI is involved.

Your contract likely requires Level 2 if it references the DFARS safeguarding and CMMC clauses with Level 2 specified, you receive or generate technical data, engineering drawings, or test results, any information you handle carries CUI markings, or your prime has identified CUI flow-down in your subcontract.

If you hold multiple contracts, you may need different levels for different work. A CMMC Status attaches to the information systems in an assessment scope (32 CFR 170.4, 170.19), so plan each scope for the highest level required of the work those systems will handle.

The subcontractor trap

A subcontractor's level follows the information it handles, not its tier. If CUI flows down to you from the prime, or if you generate CUI as part of your subcontracted work, you need at least Level 2 (Self) regardless of your position in the supply chain (32 CFR 170.23(a)(2)). The flow-down applies to subcontractors at all tiers that will process, store, or transmit FCI or CUI.

Primes must require their subcontractors to comply with and flow down CMMC requirements at the level and assessment type 32 CFR 170.23 sets for each subcontract. Where the prime contract requires Level 2 (C3PAO) or Level 3 (DIBCAC), a subcontractor that handles CUI needs at least Level 2 (C3PAO).

What about Level 3?

CMMC Level 3 applies where DoD requires it for a program. It adds 24 requirements selected from NIST SP 800-172 (February 2021) on top of the 110 Level 2 requirements (32 CFR 170.4, 170.14(c)(4)), among them penetration testing at least annually and a cyber-incident response team that can be deployed within 24 hours. Level 3 certification assessments are performed by DCMA DIBCAC, not C3PAOs, and a Final Level 2 (C3PAO) status is a prerequisite (32 CFR 170.18(a)). During the Phase 2 suspension, requiring activities may not designate Level 3 (DIBCAC). If a solicitation requires Level 3, it says so.

Where Enclave AI fits

Enclave AI does not decide your level. Your solicitation states it, and the level decision stays with your team. Once you know you need Level 2, the Agent-as-a-Service (AaaS) agents compare your connected cloud and identity configuration against the 110 requirements, measuring the ones those sources can show, and on a readiness subscription they re-scan connected sources about every seven days and re-issue the SSP and POA&M on your tier's cycle. Your designated executive can approve or disapprove each delivered document, and your Affirming Official makes the affirmation decision. Level 1 checkout is not open yet.

The free gap check is a free first read; the $999 CMMC Level 2 Readiness Snapshot comes after it.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot compares your connected cloud and identity configuration against all 110 NIST 800-171 controls, measuring the controls those sources can show (intake-based if you connect none), and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. Each subscription tier also offers a month-to-month option.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures attributed to the DoD are its published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost; $999 is Enclave AI's own price for the CMMC Level 2 Readiness Snapshot.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee any CMMC status or certification. A Level 2 certification assessment is conducted by an authorized or accredited C3PAO (32 CFR 170.17). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.