Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
CMMC Level 1 vs Level 2
Learn about the difference: CMMC Level 1 vs Level 2
One of the most common questions defense contractors ask is whether they need CMMC Level 1 or Level 2. The answer affects everything from implementation cost to timeline to ongoing maintenance burden.
This guide compares CMMC Level 1 vs Level 2 in plain terms. You’ll understand the key differences, learn how to determine which level applies to you, and get a clear picture of what each certification requires.
The Fundamental Difference
The core difference between Level 1 and Level 2 comes down to what information you’re protecting.
Level 1 protects Federal Contract Information (FCI). FCI is information provided by or generated for the government under contract that isn’t intended for public release. Think contract documents, project schedules, meeting notes, and general business information related to your government work.
Level 2 protects Controlled Unclassified Information (CUI). CUI is more sensitive information that requires safeguarding per laws, regulations, or government policies. Examples include technical specifications, engineering data, export-controlled information, and other data specifically marked or designated as CUI.
If you only handle FCI, you need Level 1. If you handle CUI (which also includes FCI), you need Level 2.
Requirements Comparison
The number of requirements differs dramatically between levels.
Level 1: 15 Practices
Level 1 includes 15 basic cybersecurity practices drawn from FAR 52.204-21. These are fundamental security measures that any business should already have in place:
- Limit system access to authorized users
- Limit system access to authorized transaction types
- Verify and control connections to external systems
- Control information posted on public systems
- Identify system users and processes
- Authenticate user identities
- Sanitize or destroy media containing FCI
- Limit physical access to systems
- Escort visitors and monitor visitor activity
- Maintain audit logs of physical access
- Control and manage physical access devices
- Protect and monitor the physical facility
- Update malicious code protection
- Perform periodic scans and real-time scans
- Update system flaws in a timely manner
These practices focus on basic access control, identification, physical security, and malware protection.
Level 2: 110 Requirements
Level 2 encompasses all 110 security requirements from NIST SP 800-171 Revision 2. These requirements span 14 control families:
- Access Control (22 requirements)
- Awareness and Training (3 requirements)
- Audit and Accountability (9 requirements)
- Configuration Management (9 requirements)
- Identification and Authentication (11 requirements)
- Incident Response (3 requirements)
- Maintenance (6 requirements)
- Media Protection (9 requirements)
- Personnel Security (2 requirements)
- Physical Protection (6 requirements)
- Risk Assessment (3 requirements)
- Security Assessment (4 requirements)
- System and Communications Protection (16 requirements)
- System and Information Integrity (7 requirements)
Level 2 builds on Level 1 basics and adds significant depth. You’re implementing enterprise-grade security controls including encryption, multi-factor authentication, network segmentation, continuous monitoring, incident response capabilities, and much more.
Assessment Type Comparison
How you prove compliance differs significantly between levels.
Level 1: Self-Assessment
Level 1 requires only a self-assessment. Your organization evaluates its own implementation of the 15 practices, documents the results, and affirms compliance.
The self-assessment process:
- Evaluate each of the 15 practices
- Document your implementation
- Calculate your compliance status
- Submit results to SPRS
- Affirm compliance through your authorized representative
No external auditor visits your facility. No third-party review of your documentation. You’re responsible for honest, accurate self-evaluation.
Using Greypike’s Obolix platform, the entire Level 1 self-assessment process takes just one week. Obolix provides guided workflows, pre-built templates, and automated evidence collection that eliminate guesswork and dramatically accelerate your path to compliance.
Level 2: Third-Party or Self-Assessment
Level 2 assessment requirements depend on the sensitivity of CUI you handle.
Third-Party Assessment (C3PAO): Most Level 2 certifications require assessment by a Certified Third-Party Assessment Organization. A C3PAO is an independent organization authorized by The Cyber AB to conduct CMMC assessments.
The C3PAO assessment process:
- Submit your SSP and documentation for review
- Schedule assessment dates
- Support on-site or virtual assessment activities
- Respond to assessor questions and evidence requests
- Receive preliminary findings
- Address any issues identified
- Receive final certification
Self-Assessment: Some Level 2 situations allow self-assessment rather than C3PAO assessment. This applies when contracts involve less sensitive CUI as determined by the DoD. However, self-assessment Level 2 still requires compliance with all 110 requirements and formal affirmation.
Your contract language and the specific DFARS clauses will indicate whether C3PAO assessment is required.
Scope and Complexity
The scope of what gets assessed differs substantially.
Level 1 Scope
Level 1 scoping focuses on systems that process, store, or transmit FCI. The CMMC Level 1 Scoping Guidance identifies asset categories:
- FCI Assets: Systems handling Federal Contract Information
- Out-of-Scope Assets: Systems with no connection to FCI
Level 1 scoping is relatively straightforward. If a system touches FCI, it’s in scope. If not, it’s out.
Level 2 Scope
Level 2 scoping is more complex. The CMMC Level 2 Scoping Guidance defines five asset categories:
- CUI Assets: Systems that process, store, or transmit CUI
- Security Protection Assets: Systems providing security functions for CUI assets (firewalls, SIEM, authentication systems)
- Contractor Risk Managed Assets: Systems that could but shouldn’t access CUI
- Specialized Assets: IoT, OT, and constrained devices requiring special consideration
- Out-of-Scope Assets: Systems completely isolated from CUI
Each category has different assessment implications. CUI Assets and Security Protection Assets receive full assessment. Contractor Risk Managed Assets require documentation and risk management but limited assessment.
Proper Level 2 scoping requires careful analysis of data flows, network architecture, and access paths. It’s significantly more involved than Level 1 scoping.
Documentation Requirements
Both levels require documentation, but the depth differs dramatically.
Level 1 Documentation
Level 1 doesn’t mandate a formal System Security Plan. However, you should document:
- How you implement each of the 15 practices
- Evidence supporting your implementation
- Your self-assessment results
Many organizations create simple documentation showing each practice, how it’s addressed, and what evidence exists. This supports your self-assessment and prepares you for potential questions from primes or contracting officers.
Level 2 Documentation
Level 2 requires extensive documentation:
System Security Plan (SSP): This comprehensive document describes your CUI environment and explains how you implement each of the 110 requirements. The SSP is the primary document assessors review.
Policies: Written policies for each of the 14 control families establishing organizational expectations and requirements.
Procedures: Detailed step-by-step instructions for implementing policies and security controls.
Plans: Supporting plans including incident response plan, configuration management plan, and others.
Evidence: Documentation proving controls are implemented and operating effectively.
Level 2 documentation often runs hundreds of pages. Organizations typically maintain an SSP of 50-100+ pages plus supporting policies, procedures, and evidence packages.
Technical Control Differences
The technical depth of controls differs significantly.
Level 1 Technical Controls
Level 1 technical controls are basic:
- User accounts with passwords
- Antivirus software that updates automatically
- Regular system patching
- Basic access restrictions
- Session timeouts
Most small businesses already have these measures in place. The challenge is usually documentation and consistent implementation rather than deploying new technology.
Level 2 Technical Controls
Level 2 requires enterprise-grade security:
Multi-Factor Authentication: Required for remote access, privileged access, and access to CUI systems. Simple passwords aren’t sufficient.
Encryption: CUI must be encrypted at rest and in transit. This includes full-disk encryption, database encryption, and TLS for network communications.
Network Segmentation: CUI systems should be separated from general business systems. This often requires firewall rules, VLANs, or dedicated network segments.
Centralized Logging: Security events must be logged to a central system (SIEM) with retention, protection, and review capabilities.
Endpoint Detection and Response: Advanced endpoint protection beyond basic antivirus, capable of detecting and responding to sophisticated threats.
Vulnerability Management: Regular vulnerability scanning with remediation processes and timelines.
Access Control: Role-based access control, privileged access management, and enforcement of least privilege principles.
Many Level 2 technical requirements demand security tools and infrastructure that small businesses may not have. Implementation often requires investment in new technology and potentially managed security services.
Cost Comparison
The cost difference between levels is substantial.
Level 1 Costs
Level 1 costs are relatively modest:
- Technology: Most organizations already have necessary tools (antivirus, basic access controls)
- Implementation: Internal effort for documentation and verification
- Assessment: Self-assessment has no direct assessment cost
- Consulting: Optional but can accelerate timeline
- Platforms: Greypike’s Obolix provides cost-effective guided compliance
For many small contractors, Level 1 costs range from minimal (if doing it yourself) to a few thousand dollars for platforms or light consulting support.
Level 2 Costs
Level 2 costs vary widely based on organization size, current security posture, and scope:
Technology investments may include:
- Multi-factor authentication solutions
- SIEM or log management platform
- Endpoint detection and response tools
- Encryption solutions
- Network security appliances
- Backup and recovery systems
Technology costs can range from $10,000 to $100,000+ depending on environment size and existing infrastructure.
Implementation costs include:
- Internal staff time
- Consulting support for gap assessment, documentation, and implementation
- Training for personnel
Consulting fees vary but commonly range from $25,000 to $150,000+ for full Level 2 implementation support.
Assessment costs for C3PAO assessment depend on scope complexity and assessor rates. Expect $30,000 to $100,000+ for the assessment itself.
Ongoing costs include:
- Security tool subscriptions and maintenance
- Continuous monitoring services
- Annual assessments
- Training programs
- Compliance platform subscriptions
Total Level 2 costs commonly range from $50,000 for well-prepared small organizations to $500,000+ for larger or less-prepared companies.
Timeline Comparison
Implementation timelines differ significantly.
Level 1 Timeline
Level 1 certification can be achieved quickly:
- With Obolix: 1 week
- Traditional approach: 1-3 months
The speed depends on your starting point. If you already have basic security measures in place, Level 1 is primarily a documentation and verification exercise. Obolix accelerates this by providing templates, guided workflows, and automated evidence collection.
Level 2 Timeline
Level 2 requires substantially more time:
- Well-prepared organizations: 6-9 months
- Average organizations: 12-18 months
- Starting from scratch: 18-24 months
The timeline includes scoping, gap assessment, SSP development, policy creation, technical implementation, training, evidence collection, and assessment scheduling. Each phase takes weeks to months depending on organization complexity and available resources.
C3PAO scheduling adds additional time. As CMMC enforcement expands, assessor availability may become constrained, requiring advance booking.
Who Needs Which Level
Determining your required level depends on the information you handle.
You Need Level 1 If:
- Your contracts involve only Federal Contract Information
- You don’t receive, process, or create CUI
- Your contracts don’t include DFARS 252.204-7012
- You’re a subcontractor whose prime doesn’t flow down CUI
Level 1 applies to contractors providing basic goods and services without access to sensitive technical data or other controlled information.
You Need Level 2 If:
- Your contracts involve Controlled Unclassified Information
- Your contracts include DFARS 252.204-7012
- You receive technical data, engineering specifications, or other sensitive information
- Your work involves export-controlled information (ITAR/EAR)
- Your prime contractor flows down CUI requirements
Level 2 applies to most contractors performing technical work, manufacturing, engineering, or other services involving sensitive defense information.
You Need Level 3 If:
- You work on programs critical to national security
- You handle the most sensitive CUI requiring enhanced protection
- The DoD specifically notifies you that Level 3 is required
Level 3 is relatively rare and applies to contractors on high-priority programs where advanced persistent threats are a significant concern.
Contractual Indicators
Your contracts contain clues about required levels.
DFARS Clauses to Look For:
DFARS 252.204-7012 (Safeguarding Covered Defense Information): This clause indicates CUI involvement and typically means Level 2.
DFARS 252.204-7019 (NIST SP 800-171 Assessment Notice): Indicates assessment requirements are in effect.
DFARS 252.204-7020 (NIST SP 800-171 Assessment Requirements): Requires NIST SP 800-171 implementation, pointing to Level 2.
DFARS 252.204-7021 (CMMC Requirements): Explicitly states CMMC requirements and specifies the required level.
FAR 52.204-21 (Basic Safeguarding): This clause addresses FCI protection and aligns with Level 1.
If you only see FAR 52.204-21 without DFARS 7012, you likely need Level 1. If DFARS 7012 is present, plan for Level 2.
When Contracts Don’t Specify:
If your contracts aren’t clear, take these steps:
- Contact your contracting officer for clarification
- Ask your prime contractor about flow-down requirements
- Review the type of information you actually handle
- When in doubt, prepare for Level 2
It’s better to over-prepare than to lose contract opportunities because you certified at the wrong level.
Ongoing Maintenance Comparison
Both levels require ongoing compliance, but the burden differs.
Level 1 Ongoing Requirements
Level 1 requires annual self-assessment and affirmation. Each year:
- Review your 15 practices
- Verify continued implementation
- Update documentation as needed
- Submit annual affirmation to SPRS
The ongoing burden is relatively light. Most organizations can complete annual affirmation in a day or two.
Level 2 Ongoing Requirements
Level 2 requires continuous compliance with recertification every three years:
Continuous monitoring: Regular review of security controls, log analysis, vulnerability scanning, and control effectiveness verification.
Change management: Evaluating security impact of system changes and updating documentation accordingly.
Training: Ongoing security awareness and role-based training programs.
Assessment preparation: Building evidence continuously and preparing for triennial reassessment.
POA&M management: Tracking and remediating any identified weaknesses.
Level 2 ongoing compliance is essentially a permanent security program requiring dedicated resources and attention.
Can You Start with Level 1 and Move to Level 2?
Yes, and this is a smart strategy for many contractors.
Benefits of Starting with Level 1:
- Establishes basic security practices quickly
- Creates documentation habits
- Provides compliance experience before tackling Level 2
- Meets immediate contract requirements for FCI-only work
- Lower cost and shorter timeline to initial certification
Building Toward Level 2:
If you anticipate needing Level 2 in the future, implement Level 1 with Level 2 in mind:
- Use the same documentation structure you’ll need for Level 2
- Begin implementing technical controls beyond Level 1 minimums
- Start your SSP even though Level 1 doesn’t require it
- Train staff on broader security responsibilities
Level 1 practices align with a subset of Level 2 requirements. The 15 Level 1 practices map to corresponding NIST SP 800-171 requirements. Solid Level 1 implementation provides a foundation for Level 2.
Key Differences Summary
| Aspect | Level 1 | Level 2 |
|---|---|---|
| Information Protected | FCI | CUI (and FCI) |
| Number of Requirements | 15 practices | 110 requirements |
| Assessment Type | Self-assessment | C3PAO or self-assessment |
| SSP Required | No (recommended) | Yes |
| Timeline | 1 week to 3 months | 6 to 18 months |
| Typical Cost | Minimal to $5,000 | $50,000 to $500,000+ |
| Technical Complexity | Basic | Enterprise-grade |
| Recertification | Annual affirmation | Every 3 years |
| Primary Standard | FAR 52.204-21 | NIST SP 800-171 Rev. 2 |
Making Your Decision
If you’re unsure which level you need, follow this decision process:
Step 1: Review your current contracts for DFARS 252.204-7012. If present, plan for Level 2.
Step 2: Identify whether you receive, process, or create CUI. If yes, you need Level 2.
Step 3: Check with your contracting officer or prime contractor for explicit guidance.
Step 4: Consider future contract opportunities. If you want to pursue CUI work, prepare for Level 2.
Step 5: When uncertain, prepare for Level 2. You can always scale back if Level 1 proves sufficient.
Getting Started with Either Level
Regardless of which level you need, the path forward starts with action.
For Level 1, Greypike’s Obolix platform delivers compliance in just one week. You get pre-built templates for all 15 practices, guided implementation workflows, automated evidence collection, and clear preparation for SPRS submission. Instead of spending months figuring things out, you follow a proven process that gets results fast.
For Level 2, start with scoping and gap assessment. Understand your CUI environment, measure your current compliance, and build a realistic implementation roadmap. Consider engaging expert support to accelerate your timeline and avoid costly mistakes.
The contractors who start now will be positioned for success when certification requirements appear in their contracts. Those who wait may find themselves scrambling to compete.
Key Takeaways
Level 1 protects FCI with 15 basic practices and self-assessment. It’s faster, cheaper, and simpler.
Level 2 protects CUI with 110 requirements and typically requires third-party assessment. It’s more complex, costly, and time-consuming.
Your contracts determine your level. Look for DFARS 252.204-7012 as the key indicator of Level 2 requirements.
Level 1 can be achieved in one week using Greypike’s Obolix platform.
Level 2 typically takes 12-18 months depending on your starting point and resources.
Both levels require ongoing compliance through annual affirmation (Level 1) or continuous monitoring and triennial recertification (Level 2).
Starting with Level 1 is smart if you need quick compliance for FCI work while building toward future Level 2 certification.
Sources and References
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification (CMMC) Program Final Rule
- CMMC Model Overview — Department of Defense
- CMMC Level 1 Scoping Guidance — Department of Defense
- CMMC Level 1 Self-Assessment Guide — Department of Defense
- CMMC Level 2 Scoping Guidance — Department of Defense
- CMMC Level 2 Assessment Guide — Department of Defense
- NIST SP 800-171 Revision 2 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS Clause 252.204-7021 — CMMC Requirements
- Supplier Performance Risk System (SPRS) — DoD Contractor Assessment Repository
- The Cyber AB — CMMC Accreditation Body
Need help determining your CMMC level or getting started with compliance? Contact Greypike for expert guidance, or achieve Level 1 compliance in just one week with Obolix.