The shortest comparison is: Level 1 is for FCI and basic safeguarding; Level 2 addresses CUI using the 110 NIST SP 800-171 Rev. 2 requirements under the current baseline; Level 3 builds on Level 2 with additional advanced requirements for selected high-sensitivity programs.
Status note: reviewed September 4, 2026. Phase II is suspended, Phase I remains in force, and the Department of War's CMMC Reform Task Force review is still open. Re-check the official CMMC page before publication if this article is published after that date.
The rule in plain English
Assessment path matters as much as control count. Level 1 uses self-assessment, Level 2 can use a self-assessment or C3PAO path depending on the solicitation or contract requirement, and Level 3 uses a government-led assessment path after Level 2 prerequisites.
As of September 4, 2026, Phase II is suspended, so rollout timing for mandatory Level 2 C3PAO requirements is under review even though the program structure and Phase I obligations remain.
Level 1 vs. Level 2 vs. Level 3 — comparison
Because the site's Guide schema does not include a table field, this comparison is expressed as structured bullets that can be rendered into a table in the page component if desired.
- Level 1 — protects FCI; uses the 15 basic safeguarding requirements derived from FAR 52.204-21; assessment path is self-assessment with required affirmation under the CMMC program.
- Level 2 — protects CUI; current baseline is the 110 NIST SP 800-171 Rev. 2 security requirements; the solicitation determines whether the required path is Level 2 Self or Level 2 C3PAO.
- Level 3 — applies to selected highest-sensitivity CUI programs; builds on Level 2 with additional advanced requirements and uses a government-led assessment path.
- Information driver — FCI generally points to Level 1; CUI generally points to Level 2 or, for selected programs, Level 3; always read the solicitation's stated CMMC requirement.
- Assessment timing — Phase II mandatory C3PAO rollout is suspended as of September 4, 2026; do not reuse the former November 10, 2026 Phase II date as an active deadline.
- Baseline version — Rev. 3 is published by NIST, but the current DoD class deviation keeps Rev. 2 as the contractual baseline for the relevant DFARS 252.204-7012/CMMC implementation until the acquisition framework changes.
How to implement it without overbuilding
For each opportunity, read the solicitation's CMMC notice and map the work to the information system that will handle FCI or CUI.
Do not pursue Level 2 or Level 3 solely as a marketing badge without understanding the system, contract, evidence, and ongoing maintenance obligations.
What evidence to keep
Keep the solicitation requirement, data classification, system scope, assessment/status records, affirmation dates, and any prerequisite records.
For comparison tables on the site, date-stamp the rollout-status row separately from the more stable level definitions.
Where teams get into trouble
The most common error is saying every CUI contract requires a C3PAO today. Another is calling Level 1 'no CUI, therefore no security'; Level 1 still includes basic safeguarding requirements for FCI.
Small-contractor walkthrough
A business owner asks which CMMC level to pursue. The answer starts with the solicitation and information type: FCI drives Level 1 treatment, CUI drives Level 2 treatment under the current Rev. 2 baseline, and Level 3 is reserved for selected higher-sensitivity programs with a different assessment path.
- Identify FCI versus CUI.
- Read the required level in the solicitation.
- Map the system boundary.
- Choose the applicable assessment path.
Correct level comparison: 15, 110, then enhanced requirements
Level 1 protects FCI using the 15 safeguarding requirements in FAR 52.204-21. Level 2 protects CUI using the 110 NIST SP 800-171 Rev. 2 requirements. Level 3 requires a Final Level 2 (C3PAO) status for the relevant scope and adds selected enhanced NIST SP 800-172 requirements for the most critical programs, assessed by DCMA DIBCAC.
Do not repeat the common '17 Level 1 practices' figure. Current 32 CFR 170.14 explicitly maps Level 1 to the fifteen FAR safeguards. Also do not say all Level 2 work is C3PAO assessed; the rule contains Level 2 (Self) and Level 2 (C3PAO) status types.
Assessment cycle and annual affirmation are separate concepts
Level 1 is self-assessed annually. Level 2 (Self) uses the rule's three-year self-assessment cycle with annual affirmation. Level 2 (C3PAO) uses a three-year certification assessment cycle with annual affirmation. Level 3 uses DIBCAC, has a Final Level 2 prerequisite, follows a three-year cycle, and also requires annual affirmation.
During the current Phase II suspension, the defined model still explains the status types, but do not imply that the old phased rollout automatically makes every certification-assessment path active on its original date.
Choose a level from data and contract, not company size
A five-person engineering firm can need Level 2 when its subcontract requires it to process CUI. A much larger company can have an FCI-only system with a Level 1 requirement. Level 3 is selected for the most critical programs and technologies; it is not a voluntary badge for companies that want to appear more mature.
Maintain a contract-to-system matrix with information type, required status, performance system/CMMC UID, assessment date, affirmation currency, and downstream flowdown. This prevents a company from citing status held by a different system.
- Level 1: FCI, 15 FAR safeguards, self-assessment.
- Level 2: CUI, 110 Rev. 2 requirements, Self or C3PAO path as required.
- Level 3: critical programs, Level 2 prerequisite plus selected 800-172 requirements, DIBCAC.
- Annual affirmation is distinct from assessment frequency.
A short working check
- ✓Identify FCI versus CUI.
- ✓Read the required level in the solicitation.
- ✓Map the system boundary.
- ✓Choose the applicable assessment path.
- ✓Track affirmation and status.
- ✓Re-check rollout status.
Common questions
How many requirements are in Level 2 today?
Under the current Rev. 2 baseline, Level 2 is based on 110 NIST SP 800-171 Rev. 2 security requirements.
Does Level 1 protect CUI?
Level 1 is designed around FCI and FAR basic safeguarding, not the Rev. 2 CUI baseline.
Is Level 3 common?
No. It is intended for a limited set of higher-sensitivity programs.
Is Level 2 C3PAO mandatory for everyone handling CUI right now?
No universal statement should be made during the Phase II suspension; read the current solicitation or contract and official status.
How many Level 1 safeguards are there?
Fifteen. Current 32 CFR 170.14 maps Level 1 to the 15 safeguards in FAR 52.204-21(b)(1)(i) through (xv).
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.


