IT Compliance

CMMC Level 1 vs Level 2: Which One Does Your Business Need?

October 7, 2026 • 9 min read • By Workplace IT

Level 1 is 15 basic safeguards and a yearly self-assessment. Level 2 is 110 NIST 800-171 controls and, for most contracts, an outside assessor. The difference comes down to one question: do you handle FCI or CUI?

When a Colorado manufacturer, engineering firm, or subcontractor first hears that a prime contractor wants them "CMMC compliant," the next question is almost always the same: which level? Picking the wrong one is expensive in either direction. Over-scope and you spend months building controls your contracts don't require. Under-scope and you can be ineligible for an award, or worse, signing affirmations that aren't true.

This guide breaks down CMMC Level 1 and Level 2 side by side: what each protects, what each requires, how each is assessed, and how to tell which one your contracts actually call for.

The One-Sentence Difference

Level 1 protects Federal Contract Information (FCI). Level 2 protects Controlled Unclassified Information (CUI). If CUI ever touches your systems, Level 1 is not enough.

FCI is information provided by or generated for the government under a contract that isn't intended for public release: contract details, delivery schedules, internal correspondence with a contracting officer. Nearly every company with a DoD contract or subcontract has FCI.

CUI is a narrower, more sensitive category that the government has designated as requiring safeguarding: technical drawings, specifications, engineering data, export-controlled (ITAR/EAR) data, and similar information. It's usually marked "CUI" or carries a distribution statement, and it's the reason most Colorado defense suppliers land at Level 2.

CMMC Level 1 vs Level 2 at a Glance

Level 1 Foundational Level 2 Advanced
Protects Federal Contract Information (FCI) Controlled Unclassified Information (CUI)
Requirements 15 basic safeguarding requirements from FAR 52.204-21 110 security requirements from NIST SP 800-171 Rev. 2, across 14 families
Assessment Self-assessment Self-assessment or third-party (C3PAO) certification, depending on the contract; most CUI contracts will require a C3PAO
How often Every year Every 3 years, plus an annual affirmation
Scoring Pass/fail: all 15 must be met Scored out of 110 using the DoD Assessment Methodology
POA&Ms allowed? No Limited: a score of at least 88/110 earns Conditional status, and open items must close within 180 days
Documentation Light: evidence the practices are in place Heavy: System Security Plan (SSP), policies, procedures, and evidence for every control
Results reported in SPRS, with a senior-official affirmation SPRS (self-assessments) or CMMC eMASS (C3PAO), with a senior-official affirmation
Typical timeline Weeks 3–9+ months for most small businesses

What CMMC Level 1 Requires

Level 1 is cyber hygiene. Its 15 requirements come straight from the FAR 52.204-21 clause that has been in federal contracts for years, so if you have a DoD contract, you're likely already obligated to do them. In practice, Level 1 means:

Each year, your organization performs a self-assessment against all 15 requirements, enters the result in the Supplier Performance Risk System (SPRS), and a senior official affirms that it's accurate. There's no partial credit: every requirement must be fully met. Level 1 does not allow a Plan of Action & Milestones (POA&M) for open gaps.

What CMMC Level 2 Requires

Level 2 is a full security program. It requires all 110 security requirements in NIST SP 800-171, organized into 14 families including access control, audit and accountability, configuration management, incident response, risk assessment, and system and communications protection. The 15 Level 1 requirements are included, so Level 2 is a superset.

What makes Level 2 a significant lift isn't just the number of controls. It's what they demand:

Level 2 is scored using the DoD Assessment Methodology: you start at 110 and subtract 1, 3, or 5 points for each unmet requirement. To reach Conditional status, you need at least 88 points, and only certain lower-weighted requirements can be left on a POA&M. Those items must be closed within 180 days to reach Final status.

Level 2 Self-Assessment vs C3PAO Certification

Level 2 comes in two flavors, and the contract decides which one applies. Some solicitations allow a Level 2 self-assessment. Most contracts involving CUI that's critical to national security will require a Level 2 certification assessment performed by an authorized CMMC Third-Party Assessment Organization (C3PAO). Either way, the 110 requirements are the same; what changes is who verifies them.

How to Tell Which Level You Need

Don't guess. Look at your contracts and the data you actually receive:

  1. Check the clauses. FAR 52.204-21 alone points to FCI and Level 1. DFARS 252.204-7012 means you're expected to protect CUI under NIST 800-171. DFARS 252.204-7021 is the CMMC clause, and the solicitation will state the required level.
  2. Look at what's in your inbox. Drawings, specs, or documents marked "CUI," "Controlled," or with a distribution statement B through F are a strong signal you're handling CUI.
  3. Ask your prime. Primes are required to flow down the appropriate CMMC level to subcontractors. If they're sending you CUI, they should be telling you Level 2.
  4. Map where the data goes. If CUI lands in email, file shares, or engineering workstations, all of those systems are in scope.

A common mistake: assuming you're Level 1 because you're "just a small machine shop" or "just a subcontractor." Company size and tier don't set your level. The information does. If a prime emails you a controlled drawing, you're handling CUI.

Can You Reduce Your Level 2 Scope?

Yes, and for small businesses it's often the smartest move. Rather than bringing your entire network up to Level 2, you can build a CUI enclave: a separate, tightly controlled environment (often Microsoft 365 GCC High with dedicated endpoints) where CUI lives and is worked on. Systems outside the enclave stay out of Level 2 scope.

An enclave doesn't change the 110 requirements, but it shrinks the number of users, devices, and systems they apply to. That can cut both cost and assessment complexity substantially. Whether it fits depends on how many people need to touch CUI and how it flows through your business.

Where the Timeline Stands

CMMC requirements are entering DoD contracts in phases under the 48 CFR rule that took effect November 10, 2025:

Phase 2 is weeks away. If your contracts involve CUI and you haven't started a gap assessment, the 3–9 month path to Level 2 means you're already behind competitors who have. For a deeper look, read our guide to the November 2026 Level 2 deadline.

Frequently Asked Questions

Is CMMC Level 1 a stepping stone to Level 2?

In practice, yes. All 15 Level 1 requirements are included in Level 2, so meeting Level 1 is a solid foundation. But there's no requirement to certify at Level 1 first. If you handle CUI, go straight to Level 2.

Can I do a Level 2 self-assessment instead of hiring a C3PAO?

Only if the contract allows it. The solicitation specifies whether a Level 2 self-assessment or a C3PAO certification assessment is required. Most contracts involving CUI will require the third-party assessment as Phase 2 begins.

What happens if my SPRS score is below 88?

You can't achieve Conditional Level 2 status, and you won't be eligible for awards that require Level 2. You'll need to remediate gaps until you reach at least 88, with only POA&M-eligible items left open, before being assessed.

Do I need GCC High for Level 2?

Not by name, but any cloud service storing or processing CUI must meet FedRAMP Moderate or equivalent. Microsoft 365 GCC High is the most common way small contractors meet that bar, especially when ITAR data is involved.

How Workplace IT Helps Colorado Contractors

Workplace IT is a CMMC Registered Practitioner Organization (RPO) based in downtown Denver. We help defense suppliers figure out which level they actually need, then get them there:

  1. Scoping & level determination: we review your contracts and data flows to confirm Level 1 or Level 2 and define what's in scope
  2. Gap assessment: we score your environment against the applicable requirements and produce a prioritized remediation plan
  3. Remediation: MFA, encryption, logging, endpoint security, and GCC High or enclave builds, implemented by our own engineers
  4. Documentation: SSP, POA&M, policies, and procedures written for how your business actually operates
  5. Assessment readiness: evidence collection and preparation for your SPRS affirmation or C3PAO assessment

We work with contractors along the Front Range, including Denver, Colorado Springs, Boulder, Fort Collins, Greeley, and Pueblo, plus businesses statewide across Colorado.

Not sure if you're Level 1 or Level 2?

We'll review your contracts and data flows and tell you exactly which level applies and what it will take to get there. Free, no obligation.

Get a Free CMMC Assessment