Level 1 and 2 Requirements
One of the most common points of confusion around CMMC 2.0 is understanding which level applies to your organization. Many contractors assume they need the highest level of certification, while others underestimate what is required and risk losing eligibility for DoD contracts.
Understanding the difference between CMMC Level 1 and Level 2 certification requirements is critical for primes and subcontractors that want to stay compliant without overspending or underpreparing.
Overview of CMMC 2.0 Levels
CMMC 2.0 simplifies the original framework into fewer levels, each aligned to the type of information an organization handles.
At a high level:
- CMMC Level 1 focuses on basic safeguarding of information
- CMMC Level 2 aligns closely with NIST 800-171 and protects more sensitive data
The level required is determined by the type of data in scope, not company size or contract value.
CMMC Level 1 Certification Requirements
Who Level 1 Applies To
CMMC Level 1 is designed for organizations that handle Federal Contract Information (FCI) but do not handle Controlled Unclassified Information (CUI).
This level often applies to:
- Smaller subcontractors
- Vendors providing basic services
- Organizations with limited system complexity
Level 1 Control Requirements
CMMC Level 1 consists of 17 basic cybersecurity practices, focused on foundational cyber hygiene.
These controls cover areas such as:
- Password protection
- Device usage policies
- Physical security basics
Assessment Requirements
- Annual self-assessment
- No third-party audit required
- Results must be affirmed by leadership
While Level 1 is simpler, accuracy still matters. Incorrect scoping or incomplete controls can result in noncompliance.
Why a CMMC Gap Assessment Is So Important
Skipping a gap assessment is one of the biggest mistakes contractors make.
Without one, organizations often:
- Underestimate how many controls apply to them
- Miss documentation requirements
- Discover gaps too late to remediate
- Fail assessments due to preventable issues
A gap assessment helps reduce risk by replacing assumptions with evidence.
CMMC Level 2 Certification Requirements
Who Level 2 Applies To
CMMC Level 2 applies to organizations that handle Controlled Unclassified Information (CUI).
This includes many:
- Prime contractors
- Engineering firms
- IT and cybersecurity service providers
- Subcontractors supporting sensitive programs
If your organization stores, processes, or transmits CUI, Level 2 is likely required.
Level 2 Control Requirements
CMMC Level 2 aligns with the 110 security controls in NIST SP 800-171.
These controls span 14 domains, including:
- Audit and accountability
- System and communications protection
In addition to technical safeguards, Level 2 places heavy emphasis on policies, procedures, and documentation.
Assessment Requirements
Most organizations pursuing Level 2 must complete:
- A third-party assessment conducted by a C3PAO
- Recertification every three years
- Ongoing compliance maintenance between assessments
Some limited cases may allow for self-assessments, but these are the exception—not the rule.
Key Differences Between CMMC Level 1 and Level 2
Area | CMMC Level 1 | CMMC Level 2 |
Data Type | FCI | CUI |
Number of Controls | 17 | 110 |
Assessment Type | Self-assessment | Third-party assessment |
Alignment | Basic cyber hygiene | NIST 800-171 |
Documentation | Minimal | Extensive |
Time to Prepare | Shorter | Significantly longer |
Understanding these differences early helps contractors avoid choosing the wrong compliance path.
Why Scoping Matters More Than the Level Itself
One of the biggest mistakes contractors make is misunderstanding scope.
If CUI exists anywhere in your environment—even indirectly—Level 2 requirements may apply. Improper scoping can:
- Increase assessment risk
- Expand compliance costs unnecessarily
- Delay certification
Accurate scoping ensures you only implement controls that actually apply to your environment.
What Contractors Should Do First
Before committing to Level 1 or Level 2 certification, contractors should establish a baseline understanding of their current posture.
A CMMC checkup or readiness assessment helps organizations:
- Identify whether FCI or CUI is in scope
- Determine the correct CMMC level
- Understand control gaps and documentation needs
- Estimate timelines and costs
- Compare compliance paths before committing resources
Starting with a structured checkup allows for informed conversations and avoids reactive decision-making later.
Choosing the Right Path Forward
CMMC Level 1 and Level 2 serve very different purposes, and choosing the wrong approach can either waste resources or jeopardize eligibility for future contracts.
When contractors understand which level applies—and what it actually requires—they gain the ability to plan compliance on their terms instead of reacting under pressure.

