Skip to content
Article

CMMC Level 1 or Level 2: Which One Applies to You?

Last updated — August 28, 2026

Almost every expensive wrong turn in CMMC starts in the same place: a contractor guessing at their level, then building toward it.

Guess high and you spend a year and a great deal of money implementing 110 requirements when 15 would have satisfied your contracts. Guess low and you sign an affirmation that is wrong, which is a considerably worse outcome than overspending.

The good news is that this is not a judgement call. Your level is not decided by your size, your revenue, your headcount, or how technical your work is. It is decided by one thing: what kind of government information you hold. And that is written down, in your contracts.

The four-step test

Step 1 — Pull every active contract and look for DFARS 252.204-7012

This is the clause that says you handle Controlled Unclassified Information. It can arrive from the Government directly, or be flowed down to you by a prime contractor.

Check the flow-down terms in your purchase orders, not just the top-level contract. This is where subcontractors are caught out constantly: the prime’s contract has the clause, the flow-down language incorporates it, and nobody at the supplier ever reads past page one of the PO.

Step 2 — If 252.204-7012 appears anywhere, you are at Level 2

That means all 110 NIST SP 800-171 Rev 2 requirements, 320 assessment objectives, a System Security Plan, a network diagram, and an SPRS score.

There is no partial version of this. You do not get a reduced set because you are small, because the CUI is incidental, or because it only appears on one contract out of forty.

Step 3 — If it does not appear, look for FAR 52.204-21

That clause covers Federal Contract Information: information not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service.

If you have FCI and no CUI clause, you are at Level 1: 15 practices and 59 assessment objectives. It is a genuinely achievable target for a small firm without outside help.

Step 4 — If neither clause appears anywhere, you are likely outside CMMC

Commercially available off-the-shelf items are generally excluded. Confirm with your contracting officer rather than assuming, and re-check whenever you win new work. Levels change when contracts change, not when you decide they have.

The two levels side by side

Level 1Level 2
Triggered byFAR 52.204-21DFARS 252.204-7012
Information typeFederal Contract Information (FCI)Controlled Unclassified Information (CUI)
Requirements15 practices110 requirements
Assessment objectives59320
Underlying standardFAR clause itselfNIST SP 800-171 Rev 2
System Security Plan requiredNoYes (3.12.4)
SPRS scoreAffirmation onlyNumeric score, −203 to 110
POA&M permittedNeverLimited — see below
Realistic effortWeeksMonths to a year

Four things people get wrong

Size is irrelevant. A six-person machine shop holding CUI is at Level 2, exactly like a 600-person firm. The requirements do not scale with headcount. This is the single most common and most expensive misconception in the defense industrial base, and it is why so many small suppliers discover their obligation late.

A Level 2 self-assessment satisfies Level 1 for the same scope. The 15 Level 1 practices map onto 17 of the Level 2 requirements. So Level 1 work is never wasted if you later find CUI in your environment — it is the foundation, not a detour.

No POA&Ms are permitted at Level 1. Every one of the 15 practices must reach MET or NOT APPLICABLE. There is no mechanism to defer a gap, at any time, for any reason. At Level 2 a POA&M is available but far more constrained than most people assume — it requires a score of at least 88, and most requirements are not eligible at all.

Certification is paused; self-assessment is not. The Phase 2 suspension of July 2026 paused third-party certification. It did not touch DFARS 252.204-7012, the self-assessment obligation, the SPRS submission, or the annual affirmation — which remains a signed certification to the United States government.

What to do once you know

If you land on Level 1, work through the 15 practices against the 59 objectives, gather the evidence, and submit. This is achievable in weeks with a structured workbook and no consultant.

If you land on Level 2, resist the urge to start implementing controls. Start with scope. Which assets handle CUI, which protect it, which are specialized, and which are genuinely out? Scope determines cost more than any other decision you will make, and an overscoped environment is the most expensive mistake available in this program. Only after scope is settled does the System Security Plan make sense to write.

Related reading


Work it out properly



Free download · 1 page · PDF

Do you need CMMC Level 1 or Level 2?

The same four steps as above, on one page you can hand to a colleague — plus the four things people most often get wrong.

Click here to download →

Once you know: the CMMC Level 1 Self-Assessment Workbook covers all 15 practices and 59 objectives with FCI scoping, evidence tracking and the SPRS affirmation. The CMMC Level 2 Readiness Kit covers all 110 requirements and 320 objectives, including the scoping workbook, System Security Plan template, 14 policies, evidence request list and POA&M.

Provided for general information. Not legal, audit or certification advice. Rules cited are current as at August 2026; the CMMC Program is under active review, so confirm the position before making contractual commitments.