If you do business with the Department of Defense, ‘what CMMC level do I need?’ is the first question worth answering — because it determines the size of the program you are about to run. The Cybersecurity Maturity Model Certification has three levels, and they are not incremental checkboxes; each maps to the sensitivity of the information you handle.

Level 1 — Foundational

Level 1 applies to contractors that handle Federal Contract Information (FCI) but not Controlled Unclassified Information (CUI). It covers 17 basic safeguarding practices drawn from FAR 52.204-21 — the security hygiene most organizations should already have. Level 1 is met with an annual self-assessment.

Level 2 — Advanced

Level 2 is where most of the defense industrial base lives. It applies when you store, process, or transmit CUI, and it aligns to the 110 security requirements of NIST SP 800-171 across 14 families. Depending on the contract, Level 2 is verified either by a self-assessment or by a third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO). The third-party path is the one that carries a formal certification.

Level 3 — Expert

Level 3 is for the highest-priority programs and the most sensitive CUI. It builds on Level 2 and adds a subset of the enhanced requirements in NIST SP 800-172, aimed at advanced persistent threats. Level 3 is assessed by the government, not a commercial C3PAO.

Which one applies to you?

Read the solicitation. The required level flows down through the contract, and it can differ across the primes and subcontractors on the same program. If you handle CUI, plan for Level 2 — and plan for it as an operating program, not a one-time project. The controls that trip teams up are the ones that require a recurring action and a record that you did it.

Not sure which level a contract requires, or what readiness looks like for yours? See how we help DIB contractors get ready for CMMC.