CMMC comes in three flavors of increasing maturity. Each one piles on more controls, more cost, and frankly more complexity. I'll break down what you actually need to do, what's going to hit your budget, and how long this will take.
Quick Overview: The Three CMMC Levels
Picture these as security maturity checkpoints — each one builds on the last:
- Level 1 (Foundational): Basic security hygiene for Federal Contract Information (FCI). 15 requirements (often counted as 17 practices). Self-assessed every year.
- Level 2 (Advanced): The 110 requirements of NIST SP 800-171 for Controlled Unclassified Information (CUI). Self-assessed or certified by a C3PAO — and while Phase 2 is paused, solicitations use the self-assessment; C3PAO certification is voluntary.
- Level 3 (Expert): Level 2 plus 24 enhanced requirements from NIST SP 800-172. Assessed by the government (DCMA's DIBCAC). Its rollout is on hold along with the rest of the schedule.
Each level builds on the previous one. You don't "jump" levels—you start at the foundation and move up as requirements increase.
CMMC Level 1: Foundational Cybersecurity Hygiene
What Is Level 1?
Level 1 is the bare minimum—who can log in, basic authentication, antivirus, patching, and physical security. It applies when you handle Federal Contract Information (FCI) but no CUI. Here's the reality: if you handle any CUI, Level 1 isn't your target — Level 2 is.
The Level 1 Requirements
Level 1 mirrors the 15 basic safeguarding requirements in FAR 52.204-21, which CMMC counts as 17 practices across six domains:
- Access Control (4 practices): Limit system access to authorized users, limit what they can do, control external connections, and control what gets posted publicly
- Identification & Authentication (2 practices): Identify users and devices, and authenticate them before granting access
- Media Protection (1 practice): Sanitize or destroy media containing FCI before disposal or reuse
- Physical Protection (4 practices): Limit physical access, escort visitors, keep access logs, and control keys and badges
- System & Communications Protection (2 practices): Protect your network boundary and separate public-facing systems
- System & Information Integrity (4 practices): Fix flaws promptly, run malware protection, keep it updated, and scan regularly
Example Level 1 practices:
- Give every user their own account and remove access when people leave
- Require authentication (passwords at minimum) before anyone gets into a system
- Keep systems patched with the latest security updates
- Install and maintain antivirus software on all computers
- Run a firewall at your network boundary
- Escort visitors and keep a visitor log
- Wipe or destroy drives before you throw them out
How Level 1 Is Assessed
You audit yourself — no third party needed — every year. You enter your results in SPRS and a senior company official affirms them. Cheap, but that comes with a catch: that affirmation is a representation to the government, and a false one is False Claims Act exposure.
Who Needs Level 1
- Contractors handling FCI but no CUI
- Contractors with specific contracts requiring only Level 1
- Companies building a foundation before moving to Level 2 (most CUI handlers go straight to Level 2)
Here's what I usually tell contractors: if you're handling real CUI, skip Level 1 entirely. Go straight to Level 2. Level 1 is fine if you handle FCI and no CUI—but check carefully before you assume that's you.
Level 1 Costs & Timeline
| Metric | Cost / Timeline |
|---|---|
| Implementation | 4–8 weeks |
| Total Cost | $4,000–$6,000 (mostly internal labor) |
| Assessment Cost | $0 (self-assessed) |
| Ongoing Annual Cost | $2,000–$5,000 (tools + labor) |
Level 1 Pros & Cons
Pros:
- Low cost to implement
- Self-assessed (no C3PAO required)
- Right fit for FCI-only environments
Cons:
- Insufficient for contractors handling CUI
- No documented processes or risk management
- Not enough if you handle any CUI
- Limited security controls
CMMC Level 2: Advanced (Most Common)
What Is Level 2?
Level 2 is where most of you live. You need documented processes, a System Security Plan, an honest assessment against all 110 requirements, and — yes — it costs real money. If you handle CUI on a DoD contract, this is almost certainly your level.
The 110 Level 2 Requirements
Level 2 covers all 110 requirements of NIST SP 800-171 Rev 2 (the Level 1 basics are included) across 14 families:
- Access Control: Fine-grained access controls, least privilege, remote access
- Awareness & Training: Role-specific security training programs
- Audit & Accountability: Logging, log review, and protecting audit records
- Configuration Management: System baselines and change management
- Identification & Authentication: MFA, account and password management
- Incident Response: IR procedures, testing, and reporting
- Maintenance: Controlled system maintenance and maintenance tools
- Media Protection: Protecting, marking, and sanitizing media with CUI
- Personnel Security: Screening people and handling terminations and transfers
- Physical Protection: Facility access and monitoring
- Risk Assessment: Risk assessments and vulnerability scanning
- Security Assessment: System Security Plan, control assessments, POA&M
- System & Communications Protection: Encryption, boundary protection, network segmentation
- System & Information Integrity: Patch management, malware detection, monitoring
Example Level 2 practices beyond Level 1:
- Implement multi-factor authentication (MFA) for all users accessing CUI
- Conduct monthly vulnerability scanning and remediation
- Encrypt CUI both at rest (on disk) and in transit (over networks)
- Implement network segmentation to isolate CUI systems
- Deploy EDR (endpoint detection & response) on all computers
- Implement SIEM for centralized logging and threat detection
- Conduct annual risk assessments and create remediation plans
- Document all security policies and procedures
- Conduct incident response drills and testing
- Implement privileged access management (PAM) for sensitive accounts
How Level 2 Is Assessed
There are two ways. Level 2 (Self): you assess yourself against all 110 requirements, post the score in SPRS, and affirm it — every 3 years, with annual affirmations. That's what solicitations call for right now. Level 2 (C3PAO): an authorized third-party firm reviews your documentation, talks to your staff, and pokes around your systems. Figure on 3–5 days on-site if you're mid-sized. Pass and you're certified for 3 years. C3PAO certification was due to become mandatory on applicable contracts under Phase 2; with Phase 2 suspended since July 13, 2026, it's voluntary for now — but still available, sometimes requested by primes, and likely to return in some form.
Who Needs Level 2
- Most defense contractors handling CUI
- Subcontractors working for prime contractors
- Companies with DoD contracts requiring CMMC
Call your prime contractor right now and ask: "What CMMC level does our contract require — and do you expect a C3PAO certificate?" If you handle CUI, the answer to the first question will almost always be Level 2.
Level 2 Costs & Timeline
| Metric | Cost / Timeline |
|---|---|
| Gap Analysis | 2–4 weeks, $10K–$30K |
| Technical Implementation | 3–6 months, $30K–$150K |
| Documentation & SSP | 2–4 weeks, $3K–$15K |
| C3PAO Assessment (voluntary for now) | 3–5 months wait + 3–5 days on-site, $105K–$118K |
| Total Year 1 Cost | $150K–$300K (depending on company size) |
| Total Timeline | 6–12 months from start to certification |
| Ongoing Annual Cost | $10K–$50K/year |
Level 2 Pros & Cons
Pros:
- Covers what most DoD contracts involving CUI require
- Documented processes reduce security risk
- Optional third-party validation (C3PAO) adds credibility, and positions you if the requirement returns
- Comprehensive but achievable for mid-size contractors
Cons:
- Significant cost ($150K–$300K first year)
- 6–12 month implementation timeline
- Requires skilled IT and compliance staff
- Ongoing compliance obligations
CMMC Level 3: Expert
What Is Level 3?
Level 3 is the elite tier — advanced threat detection, continuous monitoring, the whole security infrastructure. You only need this if DoD designates it for a program you're on, typically the most sensitive ones. Honestly? Only a small fraction of contractors will ever see it. And Level 3 requirements were slated to start with Phase 3 (originally November 2027), which is on hold pending the reform review.
The Level 3 Requirements
Level 3 includes all 110 Level 2 requirements plus 24 enhanced requirements selected from NIST SP 800-172, covering areas like:
- Continuous monitoring: Real-time automated threat detection
- Advanced incident response: Forensics, threat hunting, APT response
- Threat modeling: Identify and mitigate advanced threats
- Supply chain risk: Vendor security assessment and management
- Advanced access control: Zero-trust network access, behavioral analytics
- Security architecture: Advanced system design and isolation
Example Level 3 practices beyond Level 2:
- Implement continuous automated monitoring with behavioral analytics
- Conduct threat modeling for high-value systems
- Implement advanced incident response capabilities including forensics
- Perform supply chain risk assessments of all critical vendors
- Implement zero-trust network access model
- Conduct security architecture reviews for all new systems
How Level 3 Is Assessed
Government assessment by DCMA's DIBCAC, not a C3PAO. You first need a Level 2 C3PAO certification for the same scope; DIBCAC then assesses the 24 enhanced requirements.
Who Needs Level 3
- Contractors on programs where DoD specifies Level 3 in the solicitation
- Typically, work on the highest-priority programs and technologies, where advanced persistent threats are the concern
Real talk: if you're unsure whether you need Level 3, you don't. Call your prime contractor and ask them straight up. They'll know.
Level 3 Costs & Timeline
| Metric | Cost / Timeline |
|---|---|
| Gap Analysis | 4–6 weeks, $30K–$50K |
| Technical Implementation | 6–12 months, $150K–$400K+ |
| Documentation & SSP | 4–8 weeks, $10K–$30K |
| Assessments | Level 2 C3PAO certification first ($105K–$118K), then the DIBCAC Level 3 assessment |
| Total Year 1 Cost | $300K–$600K+ (can exceed $1M for very large orgs) |
| Total Timeline | 12–18 months from start to certification |
| Ongoing Annual Cost | $50K–$150K/year |
Level 3 Pros & Cons
Pros:
- Meets requirements for DoD's most sensitive programs
- Continuous monitoring and automation reduce incident response time
- Advanced controls reduce risk from sophisticated threats
- Demonstrates leadership in security maturity
Cons:
- Very high cost ($300K–$600K+ first year)
- 12–18 month implementation timeline
- Requires specialized security expertise
- Complex tool integration and management
- Continuous compliance burden and costs
Level 1 vs. Level 2 vs. Level 3: Side-by-Side Comparison
| Attribute | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Requirements | 15 (17 practices) | 110 | 110 + 24 |
| Assessment Type | Self-assessed | Self-assessed or C3PAO (C3PAO voluntary while Phase 2 is paused) | DIBCAC (government), after Level 2 C3PAO |
| Who Needs It | FCI only, no CUI | Most contractors handling CUI | DoD-designated programs only |
| Year 1 Cost | $4K–$6K | $150K–$300K | $300K–$600K+ |
| Timeline | 4–8 weeks | 6–12 months | 12–18 months |
| Annual Ongoing | $2K–$5K | $10K–$50K | $50K–$150K |
| Assessment Cycle | Every year (self-assessment + affirmation) | Every 3 years, with annual affirmations | Every 3 years, with annual affirmations |
| Key Processes | None documented | SSP, policies, risk mgmt | All L2 + advanced monitoring |
| Tools Required | Basic (antivirus) | EDR, SIEM, scanning, MFA | All L2 + advanced SIEM, threat modeling |
Which Level Do I Need? Decision Framework
Stop guessing. Walk through these questions in order and you'll know:
- Do I have any DoD contracts that mention CMMC?
- No: You don't need CMMC (yet). Stop here.
- Yes: Go to question 2.
- Does my contract explicitly state a CMMC level requirement?
- Yes, Level 1: You need Level 1. Stop here.
- Yes, Level 2: You need Level 2. Stop here.
- Yes, Level 3: You need Level 3. Stop here.
- No, or unclear: Go to question 3.
- How much CUI do I handle?
- None (FCI only): Level 1 is your requirement.
- Any CUI at all: You need Level 2.
- CUI on DoD's most sensitive programs: Go to question 4.
- Has DoD designated Level 3 for my program?
- No: You need Level 2.
- Yes or unsure: Confirm with the contracting officer. Level 3 is set by DoD, not chosen by you.
Bottom line: if you handle CUI and you're on the fence, assume Level 2. That covers the vast majority of you. Level 3 is for the outliers. Level 1 is for companies that only touch FCI. And remember: while Phase 2 is paused, your solicitation will call for Level 1 (Self) or Level 2 (Self) — but the level you need to actually meet doesn't change.
How CMMC Relates to NIST 800-171 and DFARS
NIST SP 800-171 is the Department of Commerce security standard. CMMC is based on NIST 800-171 but adds maturity levels and assessment rigor.
DFARS (Defense Federal Acquisition Regulation Supplement) is where the contract requirements live: DFARS 252.204-7012 (safeguard CUI and report incidents within 72 hours), 252.204-7019/-7020 (post your NIST 800-171 score in SPRS), and 252.204-7021 (CMMC). The CMMC Phase 2 pause didn't change 7012 or 7019/7020 — they still apply.
The relationship: DFARS says "protect CUI to NIST 800-171 and, where the contract says so, meet a CMMC level" → CMMC says "here's how that gets assessed at your level" → You implement the NIST 800-171 requirements and prove it.
FAQ: CMMC Levels
Can I downgrade from Level 2 to Level 1?
Technically yes, but it's a bad idea. If you've already achieved Level 2, the DoD and your prime contractor expect you to maintain it. Downgrading signals weakness in your security posture.
If I achieve Level 2, do I ever need to upgrade to Level 3?
Only if your contracts change or the DoD increases requirements. If your business stays the same (handling CUI but not critical information), Level 2 is sufficient long-term.
How often do I need to recertify?
Level 1: Self-assessment and affirmation every year
Level 2: Every 3 years (self-assessment or C3PAO), with annual affirmations
Level 3: Every 3 years by DIBCAC, with annual affirmations
Do I still need a C3PAO for Level 2 now that Phase 2 is paused?
Not to meet current solicitations — since July 13, 2026, contracting officers use only Level 1 (Self) or Level 2 (Self), and no new date for C3PAO certification has been set. But C3PAO certification is still available voluntarily, some primes still ask for it, and it's strong evidence if the requirement returns. Either way, the 110 NIST 800-171 requirements, your SPRS score, and DFARS 7012 still apply.
Can I combine Level 2 and Level 3 requirements?
No. You pursue one level. You can't "partially" do Level 3. If your contract requires Level 3, you must meet all 110 Level 2 requirements plus the 24 Level 3 requirements. If it requires Level 2, you must meet the 110 requirements (and can't be audited on Level 3 requirements).
What if my contract changes mid-implementation?
If you're 6 months into a Level 2 implementation and your contract suddenly requires Level 3, you'll need to extend your implementation and assessment timelines. This is rare but possible. Stay in close communication with your prime contractor.