
CMMC Level 1 vs Level 2: Key Differences Explained
Many defense contractors struggle to understand which CMMC level applies to their contracts, what requirements they must meet, and how the assessment process differs between Level 1 and Level 2.
Understanding the key differences between CMMC Level 1 vs Level 2 requirements CMMC Level 1 and Level 2 can help contractors identify the right compliance requirements and prepare for the appropriate assessment.
CMMC Level 1 vs Level 2 Requirements: The Core Differences That Affect Your Contracts
CMMC is the Unified standard for protecting sensitive government data. Based on the information that contractors are exposed to, the levels are determined. There is level 1 that involves Federal Contract Information (FCI), and level 2 is about Controlled Unclassified Information (CUI).
There are significant differences between CMMC Level 1 vs Level 2 requirements, namely, the type of data, the number of control requirements, assessment and certification of entities, the length of the assessment, and eligibility for inclusion.
CMMC Level 1 Requirements: What Small Suppliers Must Implement First
FCI is unclassified and does not contain CUI. Therefore, the data is protected by FAR: Basic Protection of Covered Defense Information. On the other hand, CUI entails information that has been restricted and needs to be controlled properly and, consequently, applies to level 2.
Generally, the CMMC Level 1 controls are primarily based on foundational cybersecurity activities and the rudimentary defense of FCI. Companies must conduct a self-assessment, present applicable supporting documents, and submit an affirmation to the SPRS system as a final step after completing Level 1 requirements.
CMMC Level 2 Requirements: Protecting CUI and Passing a C3PAO Assessment
CMMC Level 2 applies to the teams responsible for owning or using CUI. This refers to the information, which requires being protected, but does not possess any classification. This includes specifications, engineering drawings, or information relating to the privacy of an individual covered by a contract. Level 2 has 110 security requirements that encompass 14 areas, including access control, auditing and logging, configuration control, and incident response, among others, based on NIST SP.
A CMMC Level 2 assessment is conducted by a Certified Third-Party Assessment Organization. Necessity for an assessment can be required for contract award or a timeline of activities for organizations that have been given an assessment window.
Limited use of fix plans (POA&Ms) is allowed for specific items. The certification is valid for three years ,with annual affirmation required.
CMMC Level 2 Assessment vs Level 1 Self-Assessment:
The two paths feel very different. Level 1 is light: you scope FCI systems, apply 17 practices, and collect basic proof. Level 2 is formal: you scope the CUI environment, document deep controls, and show evidence across 110 requirements with interviews and testing.
Time and cost reflect that gap. Level 1 can be done in weeks with little outside spending. Level 2 often needs months of prep, documentation, and fixes before the CMMC assessment. If you’re bidding on CUI work, plan ahead.
Aspect | CMMC Level 1 Self-Assessment | CMMC Level 2 Assessment (C3PAO) |
Who performs | Your team (internal) | Independent C3PAO |
Scope | FCI systems | CUI environment (14 areas) |
Evidence depth | Basic configs, short policies | Full SSP, SOPs, logs, tests |
Outcome | SPRS affirmation | 3-year certification + yearly affirmations |
Typical time | Days to weeks | Weeks to months (plus prep) |

(CUI) vs FCI: How Data Type Decides Your CMMC Path
FCI is contract info not meant for the public. CUI is a specific kind of sensitive info that must be protected by law or policy. Calling CUI “just FCI” is a fast way to fail an audit.
Examples help: FCI might offer pricing or internal contract notes. CUI often includes files marked with CUI banners, export-controlled data, or privacy data tied to performance. Your CMMC compliance requirements start with getting this right, especially when your organization needs structured IT compliance services to maintain security and regulatory requirements.
Quick way to tell if you handle CUI:
Do your contracts include DFARS 252.204-7012 or CUI clauses?
Are files marked with CUI banners or sharing limits?
Do you get technical data packages from primes or the government?
Do subs send you design or test data under NDA with CUI marks?
CMMC Compliance Requirements Across the Supply Chain:
CMMC rules flow down the chain. Primes must make sure subs handling CUI meet the needed level. Subs must show their controls and share proof during prime audits. Even small companies are in scope if they touch CUI.
Cloud tools help but don’t finish the job. FedRamped services (like Microsoft 365 or AWS) cover part of the stack, but you still own settings, access, logging, and incident response. You must prove your side of the setup.
Common gaps we see:
Missing or old System Security Plan (SSP) and SOPs
No clear incident reporting path to the DoD
Incomplete network boundary diagrams
Irregular access reviews and offboarding
Conclusion
The CMMC Level 1 vs Level 2 requirements play a critical role in ensuring that companies meet compliance and avoid significant costs associated with unplanned interruptions to operations. Understanding the differences between the levels and their control requirements simplifies the assessment process and reduces its costs.
Frequently Asked Questions
What is the main difference between CMMC Level 1 vs Level 2 requirements?
The main difference between CMMC Level 1 vs Level 2 requirements is the data type that companies work with. FCI applies to Level 1, while CUI applies to Level 2. Additionally, Level 1 involves 17 practices and a self-assessment, and Level 2 involves 110 controls and a C3PAO assessment.
Do I need CMMC Level 2 if I only handle FCI?
If a company only works with FCI data and not CUI, it can apply for Level 1. It is critical that such a company confirms that its contracts or data do not contain CUI.
Can I do a CMMC Level 1 self-assessment without a C3PAO?
Yes, Level 1 assessment applies only to internal controls and does not require a C3PAO.
What does a CMMC Level 2 assessment involve?
A CMMC Level 2 assessment involves a C3PAO auditor who reviews the controls based on 110 requirements, reviews the company’s System Security Plan and Standard Operating Procedures, collects evidence, performs tests or interviews, and confirms the certification.
How many controls are in CMMC Level 1 vs Level 2?
CMMC Level 1 contains 17 controls, while CMMC Level 2 contains 110 controls.
How often do I need to recertify for CMMC?
For CMMC Level 2, companies should maintain the recertification every three years with annual affirmation. In turn, for CMMC Level 1, an annual affirmation is sufficient.
What happens if I fail a CMMC Level 2 assessment?
During the assessment, the auditor can notify the company of any findings and may allow limited fixes with approved Corrective Action Plans to remediate the issues.
Does using Microsoft 365 or AWS make me CMMC-compliant?
Using FedRAMP solutions such as Microsoft 365 or AWS can assist in ensuring CMMC compliance because they cover many controls.
How do CMMC compliance requirements flow down to subcontractors?
Primes must ensure that the subcontractors they work with have the appropriate CMMC certifications.
How long does it take to get CMMC Level 2 certified?
The timeframe depends on the auditor, but many organizations typically spend several months preparing for the C3PAO assessment.


