
CMMC Level 1 applies when a defense contract puts only federal contract information (FCI) on your systems: 15 basic safeguards from FAR 52.204-21, checked by your own self-assessment every year, with no open items allowed. Level 2 applies as soon as controlled unclassified information (CUI) is involved: the 110 requirements of NIST SP 800-171 Revision 2, a self-assessment every three years, a senior official's affirmation every year and a short, time-limited plan for minor gaps. The information you receive sets the level, not the size of your company.
We checked the Department of War CIO's About CMMC page on October 10, 2026: Phase II is still suspended, so no new contract can require a third-party assessment. Our CMMC compliance services work out which level your contracts carry and build the controls behind it; we are not a C3PAO and certify no one. If you already know Level 1 is all you need, our CMMC Level 1 checklist goes through the 15 requirements one at a time. This is general information, not legal advice.
What is the difference between CMMC Level 1 and Level 2?
The two levels protect different information, so they draw on different rulebooks. The CMMC program rule, 32 CFR Part 170, builds Level 1 from the 15 requirements in FAR 52.204-21 and makes Level 2 identical to the 110 requirements of NIST SP 800-171 Revision 2. Everything else follows from that choice: how you are assessed, how often, and what happens when one control is missing.
| CMMC Level 1 | CMMC Level 2 | |
|---|---|---|
| Information protected | Federal contract information (FCI) | Controlled unclassified information (CUI) |
| Requirements | 15, from FAR 52.204-21 | 110, from NIST SP 800-171 Rev. 2, in 14 families |
| Assessment today | Self-assessment every year | Self-assessment every three years; no contract may require a C3PAO assessment while Phase II is suspended |
| Senior official's affirmation | After each annual self-assessment | After each assessment and every year in between |
| Gaps allowed | None: every requirement must be met | A limited POA&M, closed within 180 days |
| Scoring | Met or not met, in full | A score out of 110, losing 5, 3 or 1 point for each requirement not met |
| Scope documents | A defined set of systems that handle FCI | An asset inventory, a System Security Plan and a network diagram covering five asset categories |
| Cloud services that hold the data | No cloud authorization rule in FAR 52.204-21 | FedRAMP Moderate authorized, or equivalent |
| Where the work goes | Configuring 15 safeguards and keeping the evidence | Finding where CUI lives, implementing 110 requirements and writing the plan that describes them |
How do you tell whether a contract needs Level 1 or Level 2?
Start with the information, then read the clauses. FAR 52.204-21 defines FCI as information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service, leaving out information the government makes public and simple transactional information, such as what is needed to process payments. CUI is a more sensitive category. Under 32 CFR 2002.4, it is information the government creates or possesses, or that an entity creates or possesses for the government, that a law, regulation or government-wide policy requires or permits to be handled with safeguarding or dissemination controls.
- Usually FCI only: non-public contract documents, delivery schedules and the project correspondence around them.
- Usually CUI: drawings, specifications or technical data marked CUI, especially under a contract that includes DFARS 252.204-7012.
- Subcontracts: 32 CFR 170.23 makes Level 1 (Self) the requirement for a subcontractor that handles FCI but not CUI, and Level 2 (Self) the minimum for one that handles CUI.
If you cannot tell, ask the prime or the contracting officer in writing what the work will put on your systems and which CMMC level the subcontract carries. That answer decides the size of the project.
What does Level 2 add on top of Level 1?
Level 2 covers everything Level 1 does: under 32 CFR 170.16, a Level 2 (Self) status also satisfies Level 1 (Self) for the same assessment scope. The extra work sits in families Level 1 never touches, such as audit logging, configuration baselines, incident response, security awareness training, risk assessment and personnel screening. Three requirements tend to cost the most:
- Multi-factor authentication (IA.L2-3.5.3). Level 1 only asks you to verify who users are before granting access. At Level 2 the scoring rule takes 5 points if no one uses MFA and 3 points if only remote and privileged users do.
- FIPS-validated encryption for CUI (SC.L2-3.13.11). Encryption that is not FIPS-validated costs 3 points; no encryption costs 5.
- The System Security Plan (CA.L2-3.12.4). It must exist at the time of assessment, describe every system in scope, and can never be deferred to a plan of action.
Physical controls get stricter too. Escorting visitors, keeping physical access logs and managing physical access are worth only 1 point each, yet they are three of the six requirements that 32 CFR 170.21 bars from a POA&M by name.
How are Level 1 and Level 2 assessed and scored?
Both levels are self-assessed today, and both use the assessment objectives in NIST SP 800-171A, with FCI read in place of CUI at Level 1. If one objective is not satisfied, the whole requirement is scored as not met. The scoring itself works differently.
Level 1 is pass or fail. Every one of the 15 requirements must be fully met, no plan of action is permitted, and you repeat the self-assessment every year. The result goes into the Supplier Performance Risk System (SPRS), where your Affirming Official, the senior person responsible for CMMC compliance, affirms it.
Level 2 is a score. It starts at 110 and loses 5, 3 or 1 point for each requirement not met, so it can go below zero. A requirement that does not apply counts as met, and only final evidence counts: drafts and unapproved policies do not. You can hold a Conditional Level 2 (Self) status with open items only if you score at least 88, every open item is worth 1 point (non-FIPS encryption is the one exception), none of them is one of the six barred requirements, and you close them all with a closeout self-assessment within 180 days. A final status lasts three years, the affirmation repeats every year, and the About CMMC page warns that the assessment lapses if an annual affirmation is missed. Keep the evidence for six years.
Does the Phase II suspension change which level you need?
No. It changes who checks, not what you owe. On July 13, 2026 the Under Secretary of War for Acquisition and Sustainment signed a memo implementing the suspension. Solicitations may include only Level 1 (Self) or Level 2 (Self), program offices may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, and contracts that already carry those requirements are to lose them at the next option period or administrative modification. No waivers will be granted during the review.
The same memo says the Department will enforce NIST SP 800-171 Revision 2 through Level 1 and Level 2 self-assessments and select government-led assessments, and that DFARS 252.204-7012 remains in effect. Phase I, which began on November 10, 2025, is still running. The memo says further guidance will follow the CIO's 60-day review; as of October 10, 2026, none had been posted.
Which CMMC level fits a small team?
The data picks the level, but a small company controls how much of itself each level touches.
- FCI only: Level 1 across the systems that handle it. For a team already on Microsoft 365 with managed devices, most of the 15 requirements are met with settings in Microsoft 365, Entra ID and Intune, plus physical rules for the office.
- Occasional CUI: keep it in a separate enclave, such as a dedicated cloud environment or a segmented network, used only by the people who need it. Level 2 then applies to the enclave rather than to every laptop in the company.
- Both: a Level 2 status covers Level 1 only for the same scope, so FCI that lives outside the enclave still needs its own Level 1 self-assessment and affirmation.
Out-of-scope systems must be physically or logically separated from CUI assets, and you should be ready to explain why they cannot handle CUI. An enclave only works if staff keep CUI inside it, so the training and the file-handling rules matter as much as the technology.
What drives the cost and effort of each level?
We publish no prices, and with Phase II suspended there is no third-party assessor's fee to budget for today. The cost of either level comes from the work itself:
- Scope. The number of people, devices, applications and locations that touch FCI or CUI. This is the largest lever at Level 2, where every asset that handles CUI is assessed against all 110 requirements.
- Starting point. A company that already enforces MFA, manages its devices and keeps logs has far less to build.
- Cloud environment. Cloud services that store CUI must meet the FedRAMP Moderate baseline or its equivalent, which can mean moving CUI to a different Microsoft 365 environment.
- Documentation. Level 2 needs a System Security Plan, an asset inventory and a network diagram, plus final evidence for each requirement.
- Running it. Annual affirmations, patching, monitoring, current evidence, and a fresh self-assessment every year at Level 1 or every three years at Level 2.
For the detail behind the bigger project, our guide to CMMC Level 2 requirements lists all 14 families and explains how an enclave shrinks the scope.
How does NetSys help with CMMC Level 1 and Level 2?
We start from the contract and the data, not the framework. We review your contracts and flow-down clauses to establish whether you hold FCI, CUI or both, map where that information goes, and draw the smallest boundary you can defend. Inside it we implement the requirements in Microsoft 365, Entra ID and Intune, and help you choose between commercial Microsoft 365, GCC and GCC High based on the data you hold.
We then write the System Security Plan from the configuration we deployed, prepare the self-assessment score with the Department's scoring method, and keep the controls running with monitoring, patching and an annual affirmation package for the official who signs. We are not a C3PAO, our agreements run month to month, and you can start with our free remote external penetration test, limited to available information and an agreed external scope.
Book a call with a NetSys engineer if you are not sure which level your contracts carry. Bring the clauses and a description of the files you receive, and we will go through what is in scope with you.
Frequently asked questions
What is the difference between CMMC Level 1 and Level 2?
Level 1 protects federal contract information with 15 basic safeguards from FAR 52.204-21, self-assessed every year with no gaps allowed. Level 2 protects controlled unclassified information with the 110 requirements of NIST SP 800-171 Revision 2, self-assessed every three years and affirmed every year, with a limited plan of action allowed for gaps worth 1 point.
Which CMMC level fits a small company?
The one your contracts require, and that depends on whether you receive CUI. A small company that only handles FCI needs Level 1. One that receives CUI needs Level 2, and usually keeps the cost down by holding CUI in an enclave used by the few people who need it.
What affects the cost of reaching Level 1 or Level 2?
Scope, your starting point and the cloud environment matter most. Level 1 is mostly configuration and evidence. Level 2 adds MFA across the scope, FIPS-validated encryption for CUI, logging, incident response, a System Security Plan and the staff time to keep all of it current. There is no C3PAO fee while Phase II is suspended.
Does CMMC Level 2 include Level 1?
Yes, for the same scope. 32 CFR 170.16 says a Level 2 (Self) status also satisfies Level 1 (Self) for the same assessment scope. If FCI also lives on systems outside your Level 2 enclave, those systems still need a Level 1 self-assessment.
Can a contract require a C3PAO assessment for Level 2 today?
Not during the suspension. The July 13, 2026 memo allows only Level 1 (Self) and Level 2 (Self) designations and directs contracting officers to remove C3PAO and DIBCAC requirements from existing contracts at the next option period or administrative modification. We checked on October 10, 2026, and no new guidance had been posted.
Related reading
ComplianceCMMC Level 2 Requirements: The 110 Controls Explained
Read Article
ComplianceCMMC vs NIST 800-171: The Requirements and the Program That Checks Them
Read Article
Cost GuidesCMMC Certification Cost: What Level 1 and Level 2 Cost in 2026
Read ArticleAlso on this topic: CMMC Level 1 Checklist: The 15 Requirements Explained
Discuss cmmc 2.0 compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
