Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Which CMMC level does my contract require?
If you’re a defense contractor or subcontractor, knowing which CMMC level your contract requires is critical for maintaining eligibility to bid on and perform DoD work. Starting November 10, 2025, CMMC requirements became enforceable in defense contracts—and failing to meet the specified level means you cannot be awarded a contract.
This guide explains exactly where to find your required CMMC level, how it’s determined, and what to do if the requirement isn’t clear.
Where to Find Your Required CMMC Level
Look for DFARS 252.204-7025 in the Solicitation
When the Department of Defense issues a solicitation that includes CMMC requirements, contracting officers include a provision called DFARS 252.204-7025 (Notice of Cybersecurity Maturity Model Certification Level Requirements).
This provision appears in the solicitation and explicitly states:
“The CMMC level required by this solicitation is: _________”
The blank will be filled in with one of these options:
- Level 1 (Self)
- Level 2 (Self)
- Level 2 (C3PAO)
- Level 3 (DIBCAC)
This is your clearest indicator of what certification you’ll need before contract award.
Check for DFARS 252.204-7021 in the Contract
Once awarded, your contract will include DFARS 252.204-7021 (Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement). This clause establishes your contractual obligation to:
- Have a current CMMC certificate or self-assessment at the required level
- Maintain that CMMC level for the duration of the contract
- Flow down appropriate CMMC requirements to subcontractors
- Submit annual affirmations of continuous compliance in SPRS
The clause explicitly states: “The Contractor shall have a current (i.e. not older than 3 years) CMMC certificate at the CMMC level required by this contract.”
How Your CMMC Level Is Determined
The Department of Defense—specifically program managers and requiring activities—determines which CMMC level applies to each contract based on the type of information you’ll handle.
Level 1: Federal Contract Information (FCI) Only
CMMC Level 1 is required when you’ll only process, store, or transmit Federal Contract Information (FCI).
What is FCI?
According to FAR 52.204-21, FCI is “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government.”
Examples of FCI include:
- Contract performance reports
- Invoicing and payment information
- Delivery schedules and logistics data
- Technical specifications provided by the government
- Meeting notes and correspondence about contract work
- Organizational charts for the contract team
Indicators your contract requires Level 1:
- Contract includes FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems)
- No CUI marking or CUI-related clauses present
- Work involves only routine government contract administration
Level 1 Requirements:
- 15 basic security practices
- Annual self-assessment
- Submit assessment results to SPRS
- Executive affirmation of compliance
- No third-party certification required
Level 2: Controlled Unclassified Information (CUI)
CMMC Level 2 is required when you’ll process, store, or transmit Controlled Unclassified Information (CUI).
What is CUI?
CUI is more sensitive than FCI. According to 32 CFR 2002.4(h), CUI is “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.”
Examples of CUI include:
- Technical data with export controls (ITAR/EAR)
- Sensitive acquisition information
- Critical infrastructure information
- Privacy-protected information
- Proprietary business information
- Unclassified technical drawings and specifications
Indicators your contract requires Level 2:
- Contract includes DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
- Documents are marked “CUI” or “Controlled”
- References to NIST SP 800-171 compliance
- Export-controlled technical data involved
Level 2 Requirements:
- 110 NIST SP 800-171 security controls
- Either self-assessment OR C3PAO certification (contract specifies which)
- Submit assessment results to SPRS
- Triennial assessments (every 3 years)
- Annual affirmations between assessments
- Conditional Status available with 88/110 minimum score
Level 3: Highly Sensitive CUI
CMMC Level 3 is required for the most sensitive contracts involving critical national security information or technologies requiring protection against Advanced Persistent Threats (APTs).
Who needs Level 3:
- Less than 1% of the Defense Industrial Base
- Contracts involving breakthrough technologies
- Significant aggregations of highly sensitive CUI
- Critical command and control systems
- Nuclear weapons and sensitive missile defense systems
Indicators your contract requires Level 3:
- Program office explicitly specifies Level 3 requirement
- Handling of highly sensitive CUI with national security implications
- Contract involves cutting-edge defense technologies
Level 3 Requirements:
- 134 total security controls (110 NIST 800-171 + 24 NIST 800-172)
- Government assessment by DIBCAC only
- Must have Final Level 2 (C3PAO) before pursuing Level 3
- Triennial assessments for BOTH Level 2 and Level 3
- 24/7 security operations center required
For Subcontractors: Understanding Flowdown Requirements
If you’re a subcontractor, your CMMC level is determined by the type of information the prime contractor flows down to you—not necessarily the prime’s required level.
Flowdown Rules Under 32 CFR 170.23
According to DFARS 252.204-7021, paragraph (c):
“The Contractor shall ensure that subcontractors have a current CMMC certificate at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor.”
Here’s how it works:
If the prime flows down FCI only:
- You need Level 1 (regardless of whether the prime has Level 1, 2, or 3)
If the prime flows down CUI:
- You need Level 2 at minimum
If the prime flows down highly sensitive CUI on a Level 3 contract:
- You need Level 2 at minimum (Level 3 requirements rarely flow to subs)
Important for Subcontractors
- Ask your prime contractor what CMMC level you need
- Request in writing what type of information (FCI vs. CUI) you’ll receive
- Get clarification on which CMMC assessment type is required (self-assessment vs. C3PAO)
- Verify before accepting the subcontract that you can meet the requirements
- Document your CMMC UID in SPRS before subcontract award
Prime contractors are contractually obligated to verify your CMMC status in SPRS before awarding you a subcontract. Missing certification means no award.
What If the CMMC Level Isn’t Specified?
In some cases, you may encounter contracts or solicitations where the CMMC requirement isn’t clear. Here’s what to do:
Check These Contract Clauses
FAR 52.204-21 present but no DFARS 252.204-7012:
- Likely Level 1 (FCI only)
DFARS 252.204-7012 present:
- Likely Level 2 (CUI present)
Both present:
- Definitely Level 2 or higher
Ask Your Contracting Officer
If the CMMC level isn’t explicitly stated:
- Contact the contracting officer listed in the solicitation
- Request clarification on the required CMMC level
- Ask whether CUI will be involved in contract performance
- Get the answer in writing before submitting your proposal
Review the Statement of Work (SOW)
Look for language indicating:
- “Contractor will handle technical data subject to export controls” → Level 2
- “Work involves CUI” or “Controlled information” → Level 2
- “Basic contract administration only” → Likely Level 1
- “Critical national security application” → Possibly Level 3
Timeline for CMMC in Contracts
Phase 1: November 10, 2025 – November 9, 2026
- Level 1 (Self) and Level 2 (Self) may appear in contracts
- Inclusion determined by program offices (not automatic in all contracts)
- Contracting officers verify CMMC status in SPRS before award
Phase 2: November 10, 2026 – November 9, 2027
- Level 2 (C3PAO) third-party certifications become more common
- Self-assessments still allowed for some contracts
- Broader implementation across DoD
Phase 3: November 10, 2027 and beyond
- Level 3 (DIBCAC) requirements begin appearing in applicable contracts
- CMMC becomes standard requirement for most DoD contracts involving FCI or CUI
- Exceptions only for COTS items and micro-purchases
Critical Steps to Determine Your Required Level
- Review the solicitation for DFARS 252.204-7025 provision
- Check contract clauses for DFARS 252.204-7021, DFARS 252.204-7012, and FAR 52.204-21
- Identify the information type you’ll handle (FCI vs. CUI)
- Contact the contracting officer if requirements aren’t explicit
- For subcontractors: Clarify with your prime contractor what information you’ll receive
- Document everything in writing to avoid disputes later
- Verify your CMMC status in SPRS matches what the contract requires
Exemptions from CMMC
You do NOT need CMMC certification if:
- Commercially Available Off-The-Shelf (COTS) items only: Contracts solely for COTS products are exempt
- No FCI or CUI: If you won’t process, store, or transmit any government information
- Micro-purchases: Purchases under the simplified acquisition threshold
- Granted waiver: DoD issues a formal CMMC waiver (extremely rare)
What Happens If You Don’t Have the Required Level?
Before award:
- You are ineligible for contract award
- Your proposal will not be considered
- Contracting officers must verify your CMMC status in SPRS
During performance:
- If your CMMC status expires, you risk contract termination
- You cannot exercise option periods without current certification
- Missing annual affirmations invalidates your CMMC status
For subcontractors:
- Primes cannot award you a subcontract without proper CMMC level
- If your status lapses during performance, you may be removed from the contract
Key Takeaways
- The solicitation tells you: Look for DFARS 252.204-7025 stating the required level
- The contract obligates you: DFARS 252.204-7021 creates your compliance requirement
- Information type determines level: FCI = Level 1, CUI = Level 2, Highly Sensitive CUI = Level 3
- Subcontractors: Your level depends on what information you receive, not the prime’s level
- Get it in writing: Always clarify CMMC requirements with contracting officers or primes
- SPRS is mandatory: Your CMMC status must be current in SPRS for contract eligibility
- Start early: CMMC certification can take 9-18 months—don’t wait until you see a solicitation
Need Help Determining Your CMMC Requirements?
Understanding which CMMC level your contracts require is the first step toward compliance. If you’re unsure about:
- What information qualifies as FCI vs. CUI
- Whether you need self-assessment or third-party certification
- How to scope your systems for CMMC assessment
- What your implementation timeline should be
Greypike specializes in helping defense contractors navigate CMMC requirements and achieve certification efficiently. We’ve saved our clients an average of 156 hours per engagement through our structured approach to compliance.
Contact us today for a free consultation to review your contracts and determine your exact CMMC requirements.
Sources:
- 32 CFR Part 170 – CMMC Program Rule
- 48 CFR 204.7503 – DFARS Prescription for CMMC Clauses
- DFARS 252.204-7021 – Contractor Compliance with CMMC Level Requirement
- DFARS 252.204-7025 – Notice of CMMC Level Requirements
- Federal Register, September 10, 2025 – Final CMMC Acquisition Rule