Level 1 and 2 Requirements

One of the most common points of confusion around CMMC 2.0 is understanding which level applies to your organization. Many contractors assume they need the highest level of certification, while others underestimate what is required and risk losing eligibility for DoD contracts. 

Understanding the difference between CMMC Level 1 and Level 2 certification requirements is critical for primes and subcontractors that want to stay compliant without overspending or underpreparing. 

Overview of CMMC 2.0 Levels

CMMC 2.0 simplifies the original framework into fewer levels, each aligned to the type of information an organization handles. 

At a high level: 

  • CMMC Level 1 focuses on basic safeguarding of information 
  • CMMC Level 2 aligns closely with NIST 800-171 and protects more sensitive data 

The level required is determined by the type of data in scope, not company size or contract value. 

CMMC Level 1 Certification Requirements

Who Level 1 Applies To 

CMMC Level 1 is designed for organizations that handle Federal Contract Information (FCI) but do not handle Controlled Unclassified Information (CUI). 

This level often applies to: 

  • Smaller subcontractors 
  • Vendors providing basic services 
  • Organizations with limited system complexity 

Level 1 Control Requirements 

CMMC Level 1 consists of 17 basic cybersecurity practices, focused on foundational cyber hygiene. 

These controls cover areas such as: 

  • Password protection 
  • Device usage policies 
  • Physical security basics 

Assessment Requirements 

  • No third-party audit required 
  • Results must be affirmed by leadership 

While Level 1 is simpler, accuracy still matters. Incorrect scoping or incomplete controls can result in noncompliance. 

Why a CMMC Gap Assessment Is So Important

Skipping a gap assessment is one of the biggest mistakes contractors make. 

Without one, organizations often: 

  • Underestimate how many controls apply to them 
  • Miss documentation requirements 
  • Discover gaps too late to remediate 
  • Fail assessments due to preventable issues 

A gap assessment helps reduce risk by replacing assumptions with evidence. 

 

CMMC Level 2 Certification Requirements

Who Level 2 Applies To 

CMMC Level 2 applies to organizations that handle Controlled Unclassified Information (CUI). 

This includes many: 

  • Prime contractors 
  • Engineering firms 
  • Subcontractors supporting sensitive programs 

If your organization stores, processes, or transmits CUI, Level 2 is likely required. 

 

Level 2 Control Requirements 

CMMC Level 2 aligns with the 110 security controls in NIST SP 800-171. 

These controls span 14 domains, including: 

  • System and communications protection 

In addition to technical safeguards, Level 2 places heavy emphasis on policies, procedures, and documentation. 

 

Assessment Requirements 

Most organizations pursuing Level 2 must complete: 

  • third-party assessment conducted by a C3PAO 
  • Recertification every three years 

Some limited cases may allow for self-assessments, but these are the exception—not the rule. 

Key Differences Between CMMC Level 1 and Level 2

Area 

CMMC Level 1 

CMMC Level 2 

Data Type 

FCI 

CUI 

Number of Controls 

17 

110 

Assessment Type 

Self-assessment 

Third-party assessment 

Alignment 

Basic cyber hygiene 

NIST 800-171 

Documentation 

Minimal 

Extensive 

Time to Prepare 

Shorter 

Significantly longer 

Understanding these differences early helps contractors avoid choosing the wrong compliance path. 

 

Why Scoping Matters More Than the Level Itself

One of the biggest mistakes contractors make is misunderstanding scope. 

If CUI exists anywhere in your environment—even indirectly—Level 2 requirements may apply. Improper scoping can: 

  • Delay certification 

Accurate scoping ensures you only implement controls that actually apply to your environment. 

What Contractors Should Do First

Before committing to Level 1 or Level 2 certification, contractors should establish a baseline understanding of their current posture. 

CMMC checkup or readiness assessment helps organizations: 

  • Identify whether FCI or CUI is in scope 
  • Determine the correct CMMC level 
  • Understand control gaps and documentation needs 
  • Estimate timelines and costs 
  • Compare compliance paths before committing resources 

Starting with a structured checkup allows for informed conversations and avoids reactive decision-making later. 

Choosing the Right Path Forward

CMMC Level 1 and Level 2 serve very different purposes, and choosing the wrong approach can either waste resources or jeopardize eligibility for future contracts. 

When contractors understand which level applies—and what it actually requires—they gain the ability to plan compliance on their terms instead of reacting under pressure.