CMMC Ready Now
Compliance Guide

CMMC Level 1 vs Level 2: Which Does Your Contract Actually Require?

Your CMMC level is not a function of your revenue, your headcount, your NAICS code or how long you have been in the defense industrial base. It is a function of exactly two things: what category of government information touches your systems, and what the contract clauses say. Everything else is noise, and getting this wrong costs you either an unnecessary six-figure program or a failed assessment on an award you already signed.

This matters right now for an unglamorous reason. Inside Defense reported on September 8, 2026 that assessment firms are cutting staff and audits are slipping while the industry waits on potential program changes, with Phase 2 suspended. That has made some contractors assume the whole obligation has paused. It has not. The information handling obligations under DFARS 252.204-7012 and the assessment and reporting obligations under DFARS 252.204-7019 and 252.204-7020 exist independently of the CMMC phase-in and predate it. Knowing your correct level is the prerequisite for everything you do next, whenever the certification machinery restarts.

What Actually Decides the Level: FCI or CUI?

The dividing line is the information type.

Federal Contract Information (FCI) is defined in FAR 52.204-21 and FAR 2.101 as information not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It excludes information the Government makes public and simple transactional information such as payment processing data. Unclassified delivery schedules, non-public statements of work, internal correspondence about contract performance: that is FCI.

Controlled Unclassified Information (CUI) is information the Government requires safeguarding or dissemination controls for under law, regulation or government-wide policy, per 32 CFR Part 2002 and the DoD CUI Registry. In practice, on a DoD contract, this is usually controlled technical information, export controlled data, or information carrying a distribution statement.

The rule of thumb is short. If the only non-public government information you touch is FCI, you are looking at Level 1. If CUI is processed, stored or transmitted on your systems, you are looking at Level 2. There is no in-between tier that lets you handle CUI at Level 1.

The trap is the word “touch.” A contractor who never receives a drawing but whose engineers generate controlled technical information under the statement of work is handling CUI. A contractor who receives a single export controlled PDF by email is handling CUI in their email system. CUI arrives far more often through email, shared drives and supplier portals than through a formal data transfer.

Which Clauses in Your Contract Tell You the Answer?

Read the clause list before you read anything else. The pattern is diagnostic.

  • FAR 52.204-21 only, no DFARS safeguarding clauses. This is the FCI-only signature. Level 1 territory.
  • DFARS 252.204-7012 present. The Government anticipates covered defense information, which is CUI in DoD’s vocabulary. Level 2 territory, and the clause brings its own obligations including 72 hour cyber incident reporting to DIBNet and the FedRAMP Moderate or equivalent requirement for cloud service providers handling that data.
  • DFARS 252.204-7019 and 252.204-7020 present. You owe a current NIST SP 800-171 assessment score posted in SPRS, and you owe flow down of 7020 to applicable subcontractors. These have applied since November 2020 and have nothing to do with the CMMC phase-in.
  • DFARS 252.204-7021 present. The CMMC clause itself. Under the acquisition rule, the requiring activity identifies the level and the assessment type, and that designation should be discoverable in the solicitation. If the clause is present and you cannot find the level, ask the contracting officer in writing.

One exclusion worth knowing: CMMC requirements do not attach to solicitations and contracts exclusively for commercially available off-the-shelf items. If your entire scope is COTS resale, the analysis is different, and you should confirm it in writing rather than assume it.

If the clauses contradict the data you are actually receiving, the data wins for risk purposes and the contracting officer wins for contractual purposes. Raise the discrepancy. Contractors routinely receive CUI on contracts whose clause list never anticipated it, and that is a conversation to have with the CO, not a problem to absorb quietly.

What Does Level 1 Require, and What Does It Not?

Level 1 is the basic safeguarding requirement set in FAR 52.204-21(b)(1), carried into the CMMC model. Counts vary in the wild depending on whether you are counting FAR paragraphs or CMMC practice identifiers, so do not be alarmed if you see both 15 and 17 quoted.

The substance is limited and familiar: access control and least privilege (AC.L1-3.1.1, AC.L1-3.1.2), controlling external and public-facing systems (AC.L1-3.1.20, AC.L1-3.1.22), identification and authentication (IA.L1-3.5.1, IA.L1-3.5.2), media sanitization before disposal or reuse (MP.L1-3.8.3), physical access controls including visitor escort and access device management (PE.L1-3.10.1, PE.L1-3.10.3, PE.L1-3.10.4, PE.L1-3.10.5), boundary protection and subnetwork separation for publicly accessible components (SC.L1-3.13.1, SC.L1-3.13.5), and flaw remediation and malicious code protection (SI.L1-3.14.1, SI.L1-3.14.2, SI.L1-3.14.4, SI.L1-3.14.5).

Level 1 is assessed by annual self-assessment with an affirmation by a senior official, per 32 CFR 170.15. What Level 1 does not include is as important as what it does. There is no audit and accountability domain, no incident response domain, no risk assessment domain, no security assessment domain, and no requirement for a system security plan. There is also no POA&M mechanism: Level 1 requires all requirements met at the time of self-assessment.

What Does Level 2 Require, and Which Flavor Applies?

Level 2 is the 110 security requirements of NIST SP 800-171, evaluated against the assessment objectives in NIST SP 800-171A. It is an order of magnitude more work than Level 1, not because any single requirement is exotic but because the evidence burden is continuous. You need a system security plan, defined scope, and artifacts that demonstrate each objective.

Level 2 comes in two flavors, and they are not interchangeable:

  • Level 2 self-assessment (32 CFR 170.16), annual, with senior official affirmation.
  • Level 2 certification assessment (32 CFR 170.17), performed by an authorized C3PAO on a three year cycle with annual affirmations in between.

The requiring activity determines which applies based on the sensitivity of the CUI involved. You do not choose. A contractor who builds toward self-assessment and then receives a certification requirement on a recompete has a gap, not a plan.

Level 2 also brings scoping categories that have no Level 1 equivalent: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and out-of-scope assets. Scoping is where Level 2 programs are won or lost. A well drawn enclave can reduce the assessed environment substantially. A poorly drawn one drags your entire corporate network into scope.

On POA&Ms: a Level 2 assessment can result in Conditional status with a POA&M only if the score meets the minimum threshold of 88 out of 110, with closeout required within 180 days. Certain requirements are not POA&M eligible at all. Check 32 CFR 170.21 against your specific gaps rather than assuming any given item can be deferred.

How Does Flow Down Change the Answer for a Subcontractor?

A subcontractor’s level is determined by the information the subcontractor will handle, not by the prime’s level. This is the single most common error we see.

If a Level 2 prime sends a supplier only scheduling data, quantities and non-public transactional information, that supplier is handling FCI and Level 1 is the appropriate flow down. If the prime sends controlled technical information, the supplier is at Level 2. Primes that flow Level 2 down to every supplier indiscriminately are creating cost they will eventually pay for in their own supply chain, and primes that flow Level 1 down while emailing drawings are creating a real exposure.

If you are a sub receiving an ambiguous flow down, ask the prime one precise question: what specific CUI categories, if any, will be provided to us or generated by us under this subcontract? The answer should be in writing.

Does the Phase 2 Suspension Change What You Owe Right Now?

It changes the certification mechanics. It does not change the underlying obligations, and it is not settled when or in what form the later phases resume. Treat any published date you see as commentary rather than as a fixed deadline.

What has not moved: DFARS 252.204-7012 safeguarding and incident reporting where that clause is in your contract, the SPRS score obligation under 252.204-7019 and 252.204-7020, and the accuracy of anything you have already affirmed. Affirmations are made under the False Claims Act exposure that applies to any representation to the Government, and the current pause on assessment activity does not retroactively soften a statement you made in SPRS.

A note on cost, since you will see numbers circulating. Third party estimates for Level 2 assessment and remediation spending vary enormously, they are not DoD figures, and they are heavily driven by scope size and starting maturity. Do not budget from a headline. Budget from your scoping decision and your gap assessment, in that order.

Not Sure Which Level Your Contract Requires?

If you are holding a solicitation and cannot tell from the clause list which level applies, send us the clause list and the data description and we will walk the determination with you on a free 30-minute call with Rick.

Book a Free Call with Rick

Frequently Asked Questions

How do I know if I handle CUI or only FCI?

Inventory what the Government and your primes actually send you and what you generate under the statement of work. CUI on DoD contracts typically appears as controlled technical information, export controlled data, or documents carrying a distribution statement, and it should be marked, though marking failures are common. If DFARS 252.204-7012 is in your contract, the Government has already signaled that it anticipates CUI.

Can I be Level 1 on one contract and Level 2 on another?

Yes. The level attaches to the contract and to the information involved, not to the company. Many contractors legitimately maintain a Level 1 posture across the general environment and a Level 2 enclave for the specific contracts where CUI flows, which is often the most economical structure.

Does Level 2 require a C3PAO assessment in every case?

No. 32 CFR 170.16 provides for Level 2 self-assessment and 32 CFR 170.17 provides for Level 2 certification assessment by an authorized C3PAO. The requiring activity determines which applies based on the sensitivity of the CUI, and it is specified in the solicitation rather than chosen by the contractor.

If I only handle FCI, do I need a system security plan?

Not as a CMMC Level 1 requirement. Level 1 draws from FAR 52.204-21(b)(1) and does not include the security assessment domain or a system security plan obligation. A written scope definition and evidence of each practice is still strongly advisable, because your annual self-assessment and affirmation need something to rest on.

Does the Phase 2 suspension mean I can stop work?

No. The suspension affects the certification rollout mechanics, and it is not settled when or in what form it resumes. Obligations under DFARS 252.204-7012, 252.204-7019 and 252.204-7020 continue where those clauses are in your contracts, and any affirmation you have already submitted needs to be accurate today.

What happens if my contract has no CMMC clause but I am receiving CUI?

Raise it with the contracting officer in writing. Receiving CUI without the corresponding safeguarding clause is a contract administration problem, not a free pass, and you carry the practical risk of holding the data either way. Document the request and the response.

Sources

  • 32 CFR Part 170, CMMC Program final rule (sections 170.15, 170.16, 170.17, 170.19, 170.21) (ecfr.gov)
  • FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov)
  • DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021
  • NIST SP 800-171 and NIST SP 800-171A
  • 32 CFR Part 2002, Controlled Unclassified Information
  • Inside Defense, “CMMC assessment firms face cuts, delayed audits as defense contractors await potential program changes,” Sara Friedman, September 8, 2026