CMMC Level 1 β Foundational
Level 1 applies if your contracts involve only FCI. It focuses on basic cyber hygiene to protect that information from simple threats. This level requires implementing 15 security requirements from the FAR clause 52.204-21. These requirements cover IT security fundamentals such as:
- Limiting system access to authorized users
- Using unique logins and strong authentication
- Keeping antivirus and software updated
- Controlling physical access to facilities and devices
- Properly sanitizing or destroying media before disposal
- Basic vulnerability monitoring
No detailed documentation or formal System Security Plan (SSP) is requiredβjust straightforward actions that many small businesses already do or can implement quickly.
Assessment requirements: An annual self-assessment is required. A senior company representative submits the results and affirms full compliance in the Supplier Performance Risk System (SPRS). No third-party auditor is needed, and Plans of Action and Milestones (POA&Ms) are not allowed. All security controls must be fully implemented at the time of affirmation.
Level 1 is the simplest and least costly option. Most small contractors can achieve this level of CMMC certification in a few weeks using standard tools like strong passwords, antivirus software, and basic access controls.
CMMC Level 2 β Advanced
This is the level most DoD contractors will need if they handle, store, or transmit CUI. It aligns with the 110 security requirements from NIST SP 800-171 Rev. 2, organized into 14 control families (access control, awareness training, incident response, configuration management, risk assessment, system integrity, encryption, etc.). and Unlike Level 1, Level 2 requires:
- Documented policies and procedures
- A System Security Plan (SSP)
- Evidence that controls are consistently applied and monitored
Assessment details:
- In most cases (especially for higher-risk or "prioritized" CUI), you need a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) every three years, plus annual affirmations.
- For certain "non-prioritized" contracts with lower-risk CUI, annual self-assessments may be allowed β but this must be specified in the contract.
Limited POA&Ms are allowed for some non-critical controls, but they generally must be closed within 180 days.
Scoping is critical for CMMC Level 2. Businesses can limit costs by using an "enclave" approach β applying full Level 2 controls only to the systems that actually touch CUI.
CMMC Level 3 β Expert
Level 3 builds on Level 2 by adding 24 enhanced controls from NIST SP 800-172 (for a total of 134 controls). It provides protection against sophisticated threats like Advanced Persistent Threats (APTs), often from nation-state actors. This level applies only to a small number of contractors working on the DoDβs most critical, high-priority programs where a breach could seriously affect national security.
Requirements:
- First achieve a Final Level 2 certification (via C3PAO) for the same in-scope systems.
- Implement the additional 24 controls, which focus on proactive measures such as advanced threat hunting, enhanced monitoring, supply chain risk management, penetration testing, and stronger configuration/integrity checks.
Assessment details: Conducted exclusively by the Defense Contract Management Agencyβs Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) β a government-led review every three years. An organization seeking certification must also provide annual leadership affirmations.
Limited POA&Ms are allowed for some non-critical controls (with a 180-day resolution window in most cases).
Scoping remains important: Only the enclave or systems handling the relevant high-risk CUI need to meet Level 3 standards. Because this level is resource-intensive and rare, most small businesses will never need it.
If your contract calls for CMMC Level 3, confirm the requirement with your contracting officer, complete your Level 2 C3PAO assessment first, and then prepare for the DIBCAC review.
CMMC 2.0 Levels Comparison for Small Business Contractors

Actionable Recommendations for Government Contractors
Consult with a CMMC 2.0 Expert
Work closely with an experienced CMMC 2.0 partner to obtain the required CMMC certification and stay compliant.Determine Your CMMC Level
Ask your contracting officer or review your contract/solicitation carefully. The DoD specifies the required CMMC level.Focus on Scoping
Only certify the systems that actually process, store, or transmit FCI or CUI. This is one of the best ways to control costs.Use Free DoD Resources
Visit dodcio.defense.gov/CMMC for official guides, scoping documents, and assessment templates.Check Project Spectrum for free webinars, training, and self-assessment tools.Plan for the Long Term
Compliance is ongoing. Budget time and resources for annual affirmations in SPRS, plus any required third-party or DIBCAC assessments. Stricter requirements are being phased in through 2027β2028.Act Quickly
Getting compliant helps you stay competitive as more contracts include CMMC clauses. Delaying compliance efforts will limit your bidding opportunities.



