Level 1 is 15 basic safeguards and a yearly self-assessment. Level 2 is 110 NIST 800-171 controls and, for most contracts, an outside assessor. The difference comes down to one question: do you handle FCI or CUI?
When a Colorado manufacturer, engineering firm, or subcontractor first hears that a prime contractor wants them "CMMC compliant," the next question is almost always the same: which level? Picking the wrong one is expensive in either direction. Over-scope and you spend months building controls your contracts don't require. Under-scope and you can be ineligible for an award, or worse, signing affirmations that aren't true.
This guide breaks down CMMC Level 1 and Level 2 side by side: what each protects, what each requires, how each is assessed, and how to tell which one your contracts actually call for.
Level 1 protects Federal Contract Information (FCI). Level 2 protects Controlled Unclassified Information (CUI). If CUI ever touches your systems, Level 1 is not enough.
FCI is information provided by or generated for the government under a contract that isn't intended for public release: contract details, delivery schedules, internal correspondence with a contracting officer. Nearly every company with a DoD contract or subcontract has FCI.
CUI is a narrower, more sensitive category that the government has designated as requiring safeguarding: technical drawings, specifications, engineering data, export-controlled (ITAR/EAR) data, and similar information. It's usually marked "CUI" or carries a distribution statement, and it's the reason most Colorado defense suppliers land at Level 2.
| Level 1 Foundational | Level 2 Advanced | |
|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Requirements | 15 basic safeguarding requirements from FAR 52.204-21 | 110 security requirements from NIST SP 800-171 Rev. 2, across 14 families |
| Assessment | Self-assessment | Self-assessment or third-party (C3PAO) certification, depending on the contract; most CUI contracts will require a C3PAO |
| How often | Every year | Every 3 years, plus an annual affirmation |
| Scoring | Pass/fail: all 15 must be met | Scored out of 110 using the DoD Assessment Methodology |
| POA&Ms allowed? | No | Limited: a score of at least 88/110 earns Conditional status, and open items must close within 180 days |
| Documentation | Light: evidence the practices are in place | Heavy: System Security Plan (SSP), policies, procedures, and evidence for every control |
| Results reported in | SPRS, with a senior-official affirmation | SPRS (self-assessments) or CMMC eMASS (C3PAO), with a senior-official affirmation |
| Typical timeline | Weeks | 3–9+ months for most small businesses |
Level 1 is cyber hygiene. Its 15 requirements come straight from the FAR 52.204-21 clause that has been in federal contracts for years, so if you have a DoD contract, you're likely already obligated to do them. In practice, Level 1 means:
Each year, your organization performs a self-assessment against all 15 requirements, enters the result in the Supplier Performance Risk System (SPRS), and a senior official affirms that it's accurate. There's no partial credit: every requirement must be fully met. Level 1 does not allow a Plan of Action & Milestones (POA&M) for open gaps.
Level 2 is a full security program. It requires all 110 security requirements in NIST SP 800-171, organized into 14 families including access control, audit and accountability, configuration management, incident response, risk assessment, and system and communications protection. The 15 Level 1 requirements are included, so Level 2 is a superset.
What makes Level 2 a significant lift isn't just the number of controls. It's what they demand:
Level 2 is scored using the DoD Assessment Methodology: you start at 110 and subtract 1, 3, or 5 points for each unmet requirement. To reach Conditional status, you need at least 88 points, and only certain lower-weighted requirements can be left on a POA&M. Those items must be closed within 180 days to reach Final status.
Level 2 comes in two flavors, and the contract decides which one applies. Some solicitations allow a Level 2 self-assessment. Most contracts involving CUI that's critical to national security will require a Level 2 certification assessment performed by an authorized CMMC Third-Party Assessment Organization (C3PAO). Either way, the 110 requirements are the same; what changes is who verifies them.
Don't guess. Look at your contracts and the data you actually receive:
A common mistake: assuming you're Level 1 because you're "just a small machine shop" or "just a subcontractor." Company size and tier don't set your level. The information does. If a prime emails you a controlled drawing, you're handling CUI.
Yes, and for small businesses it's often the smartest move. Rather than bringing your entire network up to Level 2, you can build a CUI enclave: a separate, tightly controlled environment (often Microsoft 365 GCC High with dedicated endpoints) where CUI lives and is worked on. Systems outside the enclave stay out of Level 2 scope.
An enclave doesn't change the 110 requirements, but it shrinks the number of users, devices, and systems they apply to. That can cut both cost and assessment complexity substantially. Whether it fits depends on how many people need to touch CUI and how it flows through your business.
CMMC requirements are entering DoD contracts in phases under the 48 CFR rule that took effect November 10, 2025:
Phase 2 is weeks away. If your contracts involve CUI and you haven't started a gap assessment, the 3–9 month path to Level 2 means you're already behind competitors who have. For a deeper look, read our guide to the November 2026 Level 2 deadline.
In practice, yes. All 15 Level 1 requirements are included in Level 2, so meeting Level 1 is a solid foundation. But there's no requirement to certify at Level 1 first. If you handle CUI, go straight to Level 2.
Only if the contract allows it. The solicitation specifies whether a Level 2 self-assessment or a C3PAO certification assessment is required. Most contracts involving CUI will require the third-party assessment as Phase 2 begins.
You can't achieve Conditional Level 2 status, and you won't be eligible for awards that require Level 2. You'll need to remediate gaps until you reach at least 88, with only POA&M-eligible items left open, before being assessed.
Not by name, but any cloud service storing or processing CUI must meet FedRAMP Moderate or equivalent. Microsoft 365 GCC High is the most common way small contractors meet that bar, especially when ITAR data is involved.
Workplace IT is a CMMC Registered Practitioner Organization (RPO) based in downtown Denver. We help defense suppliers figure out which level they actually need, then get them there:
We work with contractors along the Front Range, including Denver, Colorado Springs, Boulder, Fort Collins, Greeley, and Pueblo, plus businesses statewide across Colorado.
We'll review your contracts and data flows and tell you exactly which level applies and what it will take to get there. Free, no obligation.
Get a Free CMMC Assessment