The distinction between CMMC Level 1 and Level 2 comes down to one question: does your contract involve Controlled Unclassified Information (CUI), or only Federal Contract Information (FCI)? Get this wrong and you either overspend on unnecessary compliance or underprepare and put the award at risk.
The fundamental difference: FCI vs CUI
Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It excludes information the Government provides to the public and simple transactional information, such as what is needed to process payments (FAR 52.204-21(a)).
Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls; 32 CFR 170.4 adopts the definition in 32 CFR 2002.4(h). The National Archives CUI Registry lists the CUI categories and their marking requirements.
DoD selects the CMMC Status a procurement requires based on whether FCI or CUI will be processed, stored, or transmitted on your systems (32 CFR 170.3(d)), and the solicitation states it. FCI only points to Level 1. CUI points to Level 2 at minimum, and to Level 3 for the programs where DoD requires it.
CMMC Level 1: the basics
Level 1 requires the 15 basic safeguarding requirements derived from FAR 52.204-21. These are fundamental cybersecurity hygiene requirements that any business should implement regardless of government contracting. They cover access control basics, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.
Level 1 is a self-assessment, repeated every year. Every one of the 15 requirements must be MET, no POA&M is allowed, you enter the results in the Supplier Performance Risk System (SPRS), and your Affirming Official affirms continuing compliance at each assessment and annually (32 CFR 170.15, 170.21(a)(1), 170.22). No third-party assessment is required for Level 1.
CMMC Level 2: the full standard
Level 2 requires compliance with all 110 security requirements in NIST SP 800-171 Rev. 2 (32 CFR 170.14(c)(3)), organized across 14 control families ranging from Access Control and Audit and Accountability to System and Communications Protection and System and Information Integrity.
Level 2 has two assessment types: Level 2 (Self), which your organization performs, and Level 2 (C3PAO), a certification assessment by an authorized third-party assessor. DoD program managers select which one a procurement requires (32 CFR 170.3(d)). Since July 13, 2026, with Phase 2 suspended, a DoW CIO memorandum allows requiring activities to designate only Level 1 (Self) or Level 2 (Self), and directs that Level 2 (C3PAO) and Level 3 (DIBCAC) requirements be removed from active solicitations. Read your solicitation for the assessment type it states. See CMMC self-assessment vs C3PAO for the full breakdown.
Not sure whether you are looking at a 15-requirement Level 1 lift or the full 110-control Level 2 standard? A free 10-question gap check gives you a directional self-assessment (not an official SPRS score).
Run the free gap check →What the DoD estimates the two levels cost
The figures below come from the DoD's published Regulatory Impact Analysis. Level 1 is shown per annual self-assessment, because Level 1 is repeated every year; the Level 2 figures cover a three-year cycle. In the DoD's model, most of each total is the contractor's own staff time and outside support rather than an assessor's fee. The model assumes the requirements are already implemented, so these figures do not include the cost of implementing or remediating them.
| Path (DoD estimate) | Small entity | Larger entity |
|---|---|---|
| Level 1 self-assessment (per year) | $5,977 | $4,042 |
| Level 2 self-assessment (3-year cycle) | $37,196 | $48,827 |
| Level 2 certification, C3PAO (3-year cycle) | $104,670 | $117,768 |
The C3PAO assessor engagement alone is modeled at $31,234 for a small entity and $52,056 for a larger one within that certification total. The gap between Level 1 and Level 2 is large, which is exactly why correctly identifying your required level matters before you commit budget. For a deeper breakdown, see our CMMC Level 2 certification cost guide.
Source: DoD CMMC Program Regulatory Impact Analysis (docket DoD-2023-OS-0063), pp. 13-14 and 19-26; the same figures appear in the final rule, 89 FR 83092 (Oct. 15, 2024), at 83181 to 83186.
How to determine which level applies to you
Check your solicitation and contract. The required CMMC Status is stated there, through the DFARS CMMC clause (the final rule's preamble, 89 FR 83092, refers to DFARS clause 252.204-7021; confirm the current clause text in the DFARS). If you are unsure, look for these indicators.
Your contract likely requires Level 1 if it references FAR 52.204-21 only, you handle FCI but no technical data, no CUI markings appear on anything you receive or generate, and your contracting officer has confirmed no CUI is involved.
Your contract likely requires Level 2 if it references the DFARS safeguarding and CMMC clauses with Level 2 specified, you receive or generate technical data, engineering drawings, or test results, any information you handle carries CUI markings, or your prime has identified CUI flow-down in your subcontract.
If you hold multiple contracts, you may need different levels for different work. A CMMC Status attaches to the information systems in an assessment scope (32 CFR 170.4, 170.19), so plan each scope for the highest level required of the work those systems will handle.
The subcontractor trap
A subcontractor's level follows the information it handles, not its tier. If CUI flows down to you from the prime, or if you generate CUI as part of your subcontracted work, you need at least Level 2 (Self) regardless of your position in the supply chain (32 CFR 170.23(a)(2)). The flow-down applies to subcontractors at all tiers that will process, store, or transmit FCI or CUI.
Primes must require their subcontractors to comply with and flow down CMMC requirements at the level and assessment type 32 CFR 170.23 sets for each subcontract. Where the prime contract requires Level 2 (C3PAO) or Level 3 (DIBCAC), a subcontractor that handles CUI needs at least Level 2 (C3PAO).
What about Level 3?
CMMC Level 3 applies where DoD requires it for a program. It adds 24 requirements selected from NIST SP 800-172 (February 2021) on top of the 110 Level 2 requirements (32 CFR 170.4, 170.14(c)(4)), among them penetration testing at least annually and a cyber-incident response team that can be deployed within 24 hours. Level 3 certification assessments are performed by DCMA DIBCAC, not C3PAOs, and a Final Level 2 (C3PAO) status is a prerequisite (32 CFR 170.18(a)). During the Phase 2 suspension, requiring activities may not designate Level 3 (DIBCAC). If a solicitation requires Level 3, it says so.
Where Enclave AI fits
Enclave AI does not decide your level. Your solicitation states it, and the level decision stays with your team. Once you know you need Level 2, the Agent-as-a-Service (AaaS) agents compare your connected cloud and identity configuration against the 110 requirements, measuring the ones those sources can show, and on a readiness subscription they re-scan connected sources about every seven days and re-issue the SSP and POA&M on your tier's cycle. Your designated executive can approve or disapprove each delivered document, and your Affirming Official makes the affirmation decision. Level 1 checkout is not open yet.
The free gap check is a free first read; the $999 CMMC Level 2 Readiness Snapshot comes after it.