Resources

Client Portal

Tech Insights

Our Managed IT Services give you the technology support you need—no headaches, no hassles, no hidden costs.

CMMC Level 1 vs Level 2

CMMC Level 1 vs Level 2: Key Differences Explained

September 09, 20266 min read

Many defense contractors struggle to understand which CMMC level applies to their contracts, what requirements they must meet, and how the assessment process differs between Level 1 and Level 2.

Understanding the key differences between CMMC Level 1 vs Level 2 requirements CMMC Level 1 and Level 2 can help contractors identify the right compliance requirements and prepare for the appropriate assessment.

CMMC Level 1 vs Level 2 Requirements: The Core Differences That Affect Your Contracts

CMMC is the Unified standard for protecting sensitive government data. Based on the information that contractors are exposed to, the levels are determined. There is level 1 that involves Federal Contract Information (FCI), and level 2 is about Controlled Unclassified Information (CUI).

There are significant differences between CMMC Level 1 vs Level 2 requirements, namely, the type of data, the number of control requirements, assessment and certification of entities, the length of the assessment, and eligibility for inclusion.

CMMC Level 1 Requirements: What Small Suppliers Must Implement First

FCI is unclassified and does not contain CUI. Therefore, the data is protected by FAR: Basic Protection of Covered Defense Information. On the other hand, CUI entails information that has been restricted and needs to be controlled properly and, consequently, applies to level 2.

Generally, the CMMC Level 1 controls are primarily based on foundational cybersecurity activities and the rudimentary defense of FCI. Companies must conduct a self-assessment, present applicable supporting documents, and submit an affirmation to the SPRS system as a final step after completing Level 1 requirements.

CMMC Level 2 Requirements: Protecting CUI and Passing a C3PAO Assessment

CMMC Level 2 applies to the teams responsible for owning or using CUI. This refers to the information, which requires being protected, but does not possess any classification. This includes specifications, engineering drawings, or information relating to the privacy of an individual covered by a contract. Level 2 has 110 security requirements that encompass 14 areas, including access control, auditing and logging, configuration control, and incident response, among others, based on NIST SP.

A CMMC Level 2 assessment is conducted by a Certified Third-Party Assessment Organization. Necessity for an assessment can be required for contract award or a timeline of activities for organizations that have been given an assessment window.

Limited use of fix plans (POA&Ms) is allowed for specific items. The certification is valid for three years ,with annual affirmation required.

CMMC Level 2 Assessment vs Level 1 Self-Assessment:

The two paths feel very different. Level 1 is light: you scope FCI systems, apply 17 practices, and collect basic proof. Level 2 is formal: you scope the CUI environment, document deep controls, and show evidence across 110 requirements with interviews and testing.

Time and cost reflect that gap. Level 1 can be done in weeks with little outside spending. Level 2 often needs months of prep, documentation, and fixes before the CMMC assessment. If you’re bidding on CUI work, plan ahead.

Aspect

CMMC Level 1 Self-Assessment

CMMC Level 2 Assessment (C3PAO)

Who performs

Your team (internal)

Independent C3PAO

Scope

FCI systems

CUI environment (14 areas)

Evidence depth

Basic configs, short policies

Full SSP, SOPs, logs, tests

Outcome

SPRS affirmation

3-year certification + yearly affirmations

Typical time

Days to weeks

Weeks to months (plus prep)

cmmc level 1 vs level 2 requirements

(CUI) vs FCI: How Data Type Decides Your CMMC Path

FCI is contract info not meant for the public. CUI is a specific kind of sensitive info that must be protected by law or policy. Calling CUI “just FCI” is a fast way to fail an audit.

Examples help: FCI might offer pricing or internal contract notes. CUI often includes files marked with CUI banners, export-controlled data, or privacy data tied to performance. Your CMMC compliance requirements start with getting this right, especially when your organization needs structured IT compliance services to maintain security and regulatory requirements.

Quick way to tell if you handle CUI:

  • Do your contracts include DFARS 252.204-7012 or CUI clauses?

  • Are files marked with CUI banners or sharing limits?

  • Do you get technical data packages from primes or the government?

  • Do subs send you design or test data under NDA with CUI marks?

CMMC Compliance Requirements Across the Supply Chain:

CMMC rules flow down the chain. Primes must make sure subs handling CUI meet the needed level. Subs must show their controls and share proof during prime audits. Even small companies are in scope if they touch CUI.

Cloud tools help but don’t finish the job. FedRamped services (like Microsoft 365 or AWS) cover part of the stack, but you still own settings, access, logging, and incident response. You must prove your side of the setup.

Common gaps we see:

  • Missing or old System Security Plan (SSP) and SOPs

  • No clear incident reporting path to the DoD

  • Incomplete network boundary diagrams

  • Irregular access reviews and offboarding

Conclusion

The CMMC Level 1 vs Level 2 requirements play a critical role in ensuring that companies meet compliance and avoid significant costs associated with unplanned interruptions to operations. Understanding the differences between the levels and their control requirements simplifies the assessment process and reduces its costs.

Frequently Asked Questions

What is the main difference between CMMC Level 1 vs Level 2 requirements?

The main difference between CMMC Level 1 vs Level 2 requirements is the data type that companies work with. FCI applies to Level 1, while CUI applies to Level 2. Additionally, Level 1 involves 17 practices and a self-assessment, and Level 2 involves 110 controls and a C3PAO assessment.

Do I need CMMC Level 2 if I only handle FCI?

If a company only works with FCI data and not CUI, it can apply for Level 1. It is critical that such a company confirms that its contracts or data do not contain CUI.

Can I do a CMMC Level 1 self-assessment without a C3PAO?

Yes, Level 1 assessment applies only to internal controls and does not require a C3PAO.

What does a CMMC Level 2 assessment involve?

A CMMC Level 2 assessment involves a C3PAO auditor who reviews the controls based on 110 requirements, reviews the company’s System Security Plan and Standard Operating Procedures, collects evidence, performs tests or interviews, and confirms the certification.

How many controls are in CMMC Level 1 vs Level 2?

CMMC Level 1 contains 17 controls, while CMMC Level 2 contains 110 controls.

How often do I need to recertify for CMMC?

For CMMC Level 2, companies should maintain the recertification every three years with annual affirmation. In turn, for CMMC Level 1, an annual affirmation is sufficient.

What happens if I fail a CMMC Level 2 assessment?

During the assessment, the auditor can notify the company of any findings and may allow limited fixes with approved Corrective Action Plans to remediate the issues.

Does using Microsoft 365 or AWS make me CMMC-compliant?

Using FedRAMP solutions such as Microsoft 365 or AWS can assist in ensuring CMMC compliance because they cover many controls.

How do CMMC compliance requirements flow down to subcontractors?

Primes must ensure that the subcontractors they work with have the appropriate CMMC certifications.

How long does it take to get CMMC Level 2 certified?

The timeframe depends on the auditor, but many organizations typically spend several months preparing for the C3PAO assessment.


Back to Blog

How can we help?

Call us at (407) 833-6506 or fill in the form below and we'll help in any way we can.