GovCon Cybersecurity | | 18 min read
CMMC 2.0 Levels Explained: Level 1, 2, and 3 Requirements
Key Takeaways
Your CMMC level is set by the data you handle, not the size of your company.
Follow the Data
Federal Contract Information puts you at Level 1, CUI at Level 2, and CUI on the highest risk programs at Level 3. The information in the contract decides the level, not company size.
Know the Three Tiers
Level 1 covers 15 FAR safeguarding requirements, Level 2 all 110 from NIST SP 800-171, and Level 3 adds 24 from NIST SP 800-172 for 134 total.
Effort Rises in Steps
The jump from 15 to 110 requirements is the largest move, and shifting from a self assessment to a third party assessment adds real burden even when the requirement count is unchanged.
Match the Assessment Path
Level 1 self attests annually, Level 2 runs on a three year cycle by self or third party assessment, and Level 3 is government led. Confirm which path your contract requires before you scope the work.
CMMC 2.0 does not have a level for big companies and a level for small ones.
It has a level for each kind of information.
That is the point contractors miss most often. They assume the level scales with company size, headcount, or contract value, and they guess their way to the wrong target. A small supplier handling Controlled Unclassified Information can face the same Level 2 requirements as a prime with thousands of employees. The information decides the level. Everything else follows.
Get that straight and the rest of CMMC 2.0 becomes readable.
There are three levels. Each protects a specific kind of information, each rests on a specific standard, and each carries a specific assessment path. This guide lays them out side by side, then shares original GS Consulting research on the one thing the tier list hides: how sharply the effort rises between levels.
Confirm the level your contracts actually require.
GS Consulting helps defense contractors read their data obligations, target the right CMMC level, and plan the work to reach it.
Request a CMMC Level ReviewThe Three Levels at a Glance
Before the detail, hold the shape of the whole thing in your head. Level 1 protects Federal Contract Information, the routine non public information under a contract. Level 2 and Level 3 both protect Controlled Unclassified Information, the more sensitive material the government marks for protection, with Level 3 reserved for the highest risk programs.
Notice what changes as you move up. The requirement count climbs from 15 to 110 to 134. The source standard shifts from a single FAR clause to the full NIST SP 800-171, then adds selected requirements from NIST SP 800-172. And the assessment moves from a self assessment you run yourself, to a third party assessment where required, to a government led assessment at the top. Each step up raises both the number of controls and the level of scrutiny.
Level 1: Protecting Federal Contract Information
Level 1 is the entry tier. It applies when your contract involves Federal Contract Information but no Controlled Unclassified Information. FCI is information provided by or generated for the government under a contract that is not intended for public release, but it is not the sensitive, marked material that CUI represents.
The requirements come from FAR 52.204-21, the basic safeguarding clause, and there are 15 of them. They cover fundamentals: limiting system access to authorized users, controlling who can run what, protecting information at boundaries, and keeping systems patched. These are the security basics any responsible organization should already have.
Level 1 is met through an annual self assessment, with a company official affirming the results in the government's system. There is no third party involved. For a supplier who never touches CUI, Level 1 is the entire CMMC story, and it is achievable without a heavy program.
Level 2: Protecting Controlled Unclassified Information
Level 2 is where most of the defense industrial base lives, and it is a real step up. It applies when your contract involves Controlled Unclassified Information. The requirements are all 110 from NIST SP 800-171 Rev 2, organized across 14 families that span access control, identification and authentication, audit and accountability, configuration management, incident response, and more.
The assessment path splits here, and the split matters. Depending on what the contract specifies, Level 2 is met either through a self assessment or through a third party assessment performed by a certified assessor organization. A self assessment resembles Level 1 in form but covers all 110 requirements. A third party assessment is an independent evaluation that results in a certification, valid for three years with an annual affirmation in between.
Because CMMC Level 2 adopts NIST SP 800-171 wholesale, contractors who have taken their NIST SP 800-171 obligations seriously are already most of the way there. The gap is usually not the controls themselves but the evidence that proves they operate. If your AI or automation tooling touches CUI, our guide on NIST SP 800-171 controls for AI covers the specific requirements those systems raise.
Level 3: The Highest Risk Programs
Level 3 protects CUI on the programs the government considers most at risk from advanced threats. It is not a common tier, and you do not choose it. The contract calls for it.
Level 3 builds directly on Level 2. It adds 24 selected requirements drawn from NIST SP 800-172, the enhanced requirements designed to counter sophisticated adversaries, for a total of 134. A contractor must achieve Level 2 first, because Level 3 assumes the full NIST SP 800-171 baseline is already in place and proven.
The assessment is also different. Rather than a commercial assessor, Level 3 involves a government led assessment. That raises the bar on both the controls and the rigor of the evaluation. Few suppliers will need Level 3, but those who do should plan for it as an extension of a mature Level 2 program, not as a separate project.
Original Research: The Jump Between Levels
The requirement counts tell you the levels are different. They do not tell you how much harder each one is to reach and hold. The jump from 15 to 110 requirements is obvious. The jump that surprises people is the one between a Level 2 self assessment and a Level 2 third party assessment, where the requirement count does not change at all but the burden of proof does.
To make that visible, GS Consulting built a Level Effort Index. We anchored the top of the scale at Level 3 as 100, then estimated the relative implementation, evidence, and assessment effort for each path based on requirement counts and assessment type. The result shows effort rising in steps, not in a straight line.
Two things stand out. First, the leap from Level 1 to Level 2 is the largest single move, because you go from 15 requirements to 110 and from basic safeguarding to the full NIST SP 800-171 baseline. Second, staying at 110 requirements but moving from self assessment to a third party assessment still adds meaningful effort, because an independent assessor demands evidence that a self assessment lets you gloss over. The controls are identical; the proof is not.
The planning lesson is to be honest about which path your contracts require before you scope the work. A contractor budgeting for a self assessment who then wins a contract requiring third party assessment has underestimated the effort, sometimes badly.
How to Determine Your Level
Determining your level is a short decision, and it runs on data, not guesswork. Work down four questions in order.
Start at the top. Does the contract involve any Federal Contract Information or Controlled Unclassified Information at all? If not, no CMMC requirement applies, though basic FAR safeguarding still governs any FCI you do hold. If the contract involves FCI only, with no CUI, you are at Level 1. If it involves CUI on a standard program, you are at Level 2 and must meet all 110 NIST SP 800-171 requirements. If it involves CUI on the most sensitive programs, the contract may specify Level 3.
The contracting officer sets the required level in the solicitation, so the final word is in the contract language. But the data type is what drives that language, which is why mapping where CUI lives in your environment is the foundation of every level decision. Our walkthrough on building a CUI data flow map for CMMC is the practical starting point.
Assessment Paths and Timing
The level sets the assessment path, and the path sets the rhythm of your compliance program. It helps to see the four common situations side by side, because self assessment and certification are not the same thing.
Level 1 uses an annual self assessment. Level 2 by self assessment recurs every three years, as does Level 2 with a third party assessor, but only the third party path produces an independent certification. Level 3 uses a government led assessment on the same three year cycle. Across all of them, an annual affirmation keeps the posture current between assessments.
Timing matters because of the phased rollout. Level 1 and Level 2 self assessment requirements began appearing in November 2025. The third party Level 2 standard becomes common from November 2026, and Level 3 from November 2027. If you expect a contract that requires a third party assessment, the time to start is well before the solicitation lands, because assessor capacity is limited. For the full program view, see our complete guide to CMMC compliance.
Evidence That Proves Each Level
Each level asks you to prove a different amount, and the evidence stacks. Level 3 does not replace Level 2 evidence; it adds to it. Seeing the three side by side makes the escalation clear.
At Level 1, the evidence is light: a basic safeguarding self assessment, an annual affirmation, simple access and boundary records, and an asset list for the systems that touch FCI. At Level 2, the packet grows into a full system security plan covering all 110 requirements, an SPRS score with its calculation worksheet, a plan of action for open gaps, and the control evidence and assessment records that prove each requirement operates. At Level 3, you carry everything from Level 2 and add records for the 24 enhanced requirements, advanced threat protection evidence, and the results of the government assessment.
The through line is the same at every level. Readiness is what you can show, not what you intend. If you want the detailed artifact list and the order to build it in, our CMMC readiness checklist for government contractors walks through the full evidence packet.
Research Sources and Caveats
The GS CMMC Level Effort Index is a GS Consulting derived planning tool based on cited public sources and documented assumptions. It is not an official legal, audit, compliance, NIST, CMMC, DoD, or C3PAO determination. Requirement counts, source standards, data types, and assessment paths are drawn from the regulations and standards below. The effort index values are GS planning assumptions.
Your required CMMC level is set by your contract and the data you handle, as confirmed by your contracting officer. Use this guide to understand the levels, not to replace the level determination in your solicitation.
- 32 CFR Part 170: CMMC Program (eCFR)
- FAR 52.204-21: Basic Safeguarding of Covered Contractor Information Systems
- NIST SP 800-171 Rev 2
- NIST SP 800-172
- DoD CIO CMMC resources
Frequently Asked Questions About CMMC 2.0 Levels
What are the CMMC 2.0 levels?
CMMC 2.0 has three levels. Level 1 protects Federal Contract Information with 15 requirements from FAR 52.204-21 and an annual self assessment. Level 2 protects Controlled Unclassified Information with all 110 requirements from NIST SP 800-171 Rev 2, met by self assessment or a third party assessment depending on the contract. Level 3 protects CUI on the highest risk programs by adding 24 selected requirements from NIST SP 800-172, for 134 total, with a government led assessment.
How do I know which CMMC level I need?
Follow the data. If your contract involves no Federal Contract Information and no Controlled Unclassified Information, no CMMC level applies. If it involves FCI but not CUI, you are at Level 1. If it involves CUI on a standard program, you are at Level 2. If it involves CUI on the most sensitive programs, the contract may call for Level 3. The contracting officer sets the required level in the solicitation; the data type is what drives it.
What is the difference between Level 2 self assessment and a C3PAO assessment?
Both cover the same 110 NIST SP 800-171 requirements. The difference is who verifies them. In a self assessment, your own organization assesses and a company official affirms the results. In a third party assessment, a certified assessor organization independently evaluates your environment and issues the certification. The contract decides which one applies, and third party assessment becomes the standard for most CUI contracts as the rollout progresses.
How many requirements are in each CMMC level?
Level 1 has 15 requirements from FAR 52.204-21. Level 2 has 110 requirements from NIST SP 800-171 Rev 2. Level 3 has 134 requirements, which is the 110 from Level 2 plus 24 selected enhanced requirements from NIST SP 800-172. Each level builds on the one below it, so Level 3 assumes everything in Level 2 is already in place.
Is CMMC Level 2 the same as NIST 800-171?
Effectively yes on the requirements. CMMC Level 2 adopts all 110 security requirements from NIST SP 800-171 Rev 2. What CMMC adds is the verification step: instead of only self attesting to your NIST SP 800-171 implementation, you may be required to pass an independent assessment and hold a certification. The controls are the same; the proof burden is higher.