Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
LEVEL COMPARISON

CMMC Level 1 vs. Level 2 vs. Level 3: Full Comparison Table

CMMC Level 1 protects FCI, Level 2 protects CUI using the current Rev. 2 baseline, and Level 3 adds enhanced requirements for selected high-sensitivity programs.

The shortest comparison is: Level 1 is for FCI and basic safeguarding; Level 2 addresses CUI using the 110 NIST SP 800-171 Rev. 2 requirements under the current baseline; Level 3 builds on Level 2 with additional advanced requirements for selected high-sensitivity programs.

Status note: reviewed September 4, 2026. Phase II is suspended, Phase I remains in force, and the Department of War's CMMC Reform Task Force review is still open. Re-check the official CMMC page before publication if this article is published after that date.

The rule in plain English

Assessment path matters as much as control count. Level 1 uses self-assessment, Level 2 can use a self-assessment or C3PAO path depending on the solicitation or contract requirement, and Level 3 uses a government-led assessment path after Level 2 prerequisites.

As of September 4, 2026, Phase II is suspended, so rollout timing for mandatory Level 2 C3PAO requirements is under review even though the program structure and Phase I obligations remain.

Level 1 vs. Level 2 vs. Level 3 — comparison

Because the site's Guide schema does not include a table field, this comparison is expressed as structured bullets that can be rendered into a table in the page component if desired.

  • Level 1 — protects FCI; uses the 15 basic safeguarding requirements derived from FAR 52.204-21; assessment path is self-assessment with required affirmation under the CMMC program.
  • Level 2 — protects CUI; current baseline is the 110 NIST SP 800-171 Rev. 2 security requirements; the solicitation determines whether the required path is Level 2 Self or Level 2 C3PAO.
  • Level 3 — applies to selected highest-sensitivity CUI programs; builds on Level 2 with additional advanced requirements and uses a government-led assessment path.
  • Information driver — FCI generally points to Level 1; CUI generally points to Level 2 or, for selected programs, Level 3; always read the solicitation's stated CMMC requirement.
  • Assessment timing — Phase II mandatory C3PAO rollout is suspended as of September 4, 2026; do not reuse the former November 10, 2026 Phase II date as an active deadline.
  • Baseline version — Rev. 3 is published by NIST, but the current DoD class deviation keeps Rev. 2 as the contractual baseline for the relevant DFARS 252.204-7012/CMMC implementation until the acquisition framework changes.

How to implement it without overbuilding

For each opportunity, read the solicitation's CMMC notice and map the work to the information system that will handle FCI or CUI.

Do not pursue Level 2 or Level 3 solely as a marketing badge without understanding the system, contract, evidence, and ongoing maintenance obligations.

What evidence to keep

Keep the solicitation requirement, data classification, system scope, assessment/status records, affirmation dates, and any prerequisite records.

For comparison tables on the site, date-stamp the rollout-status row separately from the more stable level definitions.

Where teams get into trouble

The most common error is saying every CUI contract requires a C3PAO today. Another is calling Level 1 'no CUI, therefore no security'; Level 1 still includes basic safeguarding requirements for FCI.

Small-contractor walkthrough

A business owner asks which CMMC level to pursue. The answer starts with the solicitation and information type: FCI drives Level 1 treatment, CUI drives Level 2 treatment under the current Rev. 2 baseline, and Level 3 is reserved for selected higher-sensitivity programs with a different assessment path.

  • Identify FCI versus CUI.
  • Read the required level in the solicitation.
  • Map the system boundary.
  • Choose the applicable assessment path.

Correct level comparison: 15, 110, then enhanced requirements

Level 1 protects FCI using the 15 safeguarding requirements in FAR 52.204-21. Level 2 protects CUI using the 110 NIST SP 800-171 Rev. 2 requirements. Level 3 requires a Final Level 2 (C3PAO) status for the relevant scope and adds selected enhanced NIST SP 800-172 requirements for the most critical programs, assessed by DCMA DIBCAC.

Do not repeat the common '17 Level 1 practices' figure. Current 32 CFR 170.14 explicitly maps Level 1 to the fifteen FAR safeguards. Also do not say all Level 2 work is C3PAO assessed; the rule contains Level 2 (Self) and Level 2 (C3PAO) status types.

Assessment cycle and annual affirmation are separate concepts

Level 1 is self-assessed annually. Level 2 (Self) uses the rule's three-year self-assessment cycle with annual affirmation. Level 2 (C3PAO) uses a three-year certification assessment cycle with annual affirmation. Level 3 uses DIBCAC, has a Final Level 2 prerequisite, follows a three-year cycle, and also requires annual affirmation.

During the current Phase II suspension, the defined model still explains the status types, but do not imply that the old phased rollout automatically makes every certification-assessment path active on its original date.

Choose a level from data and contract, not company size

A five-person engineering firm can need Level 2 when its subcontract requires it to process CUI. A much larger company can have an FCI-only system with a Level 1 requirement. Level 3 is selected for the most critical programs and technologies; it is not a voluntary badge for companies that want to appear more mature.

Maintain a contract-to-system matrix with information type, required status, performance system/CMMC UID, assessment date, affirmation currency, and downstream flowdown. This prevents a company from citing status held by a different system.

  • Level 1: FCI, 15 FAR safeguards, self-assessment.
  • Level 2: CUI, 110 Rev. 2 requirements, Self or C3PAO path as required.
  • Level 3: critical programs, Level 2 prerequisite plus selected 800-172 requirements, DIBCAC.
  • Annual affirmation is distinct from assessment frequency.
WORKING CHECKLIST

A short working check

  • Identify FCI versus CUI.
  • Read the required level in the solicitation.
  • Map the system boundary.
  • Choose the applicable assessment path.
  • Track affirmation and status.
  • Re-check rollout status.

Common questions

How many requirements are in Level 2 today?

Under the current Rev. 2 baseline, Level 2 is based on 110 NIST SP 800-171 Rev. 2 security requirements.

Does Level 1 protect CUI?

Level 1 is designed around FCI and FAR basic safeguarding, not the Rev. 2 CUI baseline.

Is Level 3 common?

No. It is intended for a limited set of higher-sensitivity programs.

Is Level 2 C3PAO mandatory for everyone handling CUI right now?

No universal statement should be made during the Phase II suspension; read the current solicitation or contract and official status.

How many Level 1 safeguards are there?

Fifteen. Current 32 CFR 170.14 maps Level 1 to the 15 safeguards in FAR 52.204-21(b)(1)(i) through (xv).

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.

Federal RegisterCybersecurity Maturity Model Certification (CMMC) Program Final Rule — 32 CFR Part 170Final CMMC program rule, including assessment, affirmation, POA&M eligibility, scoring, and 180-day closeout requirements.Acquisition.govDFARS 252.204-7021 — Contractor Compliance with CMMC Level RequirementsCurrent CMMC contract clause, including current status, affirmations, POA&M closeout, and system UID concepts.Acquisition.govDFARS 252.204-7025 — Notice of CMMC Level RequirementsSolicitation provision describing required CMMC level and CMMC UIDs.Acquisition.govFAR 52.204-21 — Basic Safeguarding of Covered Contractor Information SystemsFifteen basic safeguarding requirements associated with CMMC Level 1.NISTNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsThe Rev. 2 security requirements used by current CMMC Level 2 assessments under 32 CFR Part 170 and the current DoD CMMC implementation baseline.U.S. Department of War CIOCybersecurity Maturity Model Certification — current program statusCurrent implementation status, assessment levels, affirmations, POA&M rules, and the July 2026 Phase II suspension.U.S. Department of Defense Chief Information OfficerCMMC Assessment Guide — Level 2, Version 2.13Used for Level 2 assessment mechanics, assessment objectives, and evidence methods such as examine, interview, and test.Electronic Code of Federal Regulations32 CFR § 170.14 — CMMC ModelCurrent rule text for Level 1, Level 2, and Level 3 security-requirement foundations.Electronic Code of Federal Regulations32 CFR § 170.17 — CMMC Level 2 certification assessment and affirmation requirementsPrimary rule text for Conditional/Final Level 2 C3PAO status, re-evaluation, POA&M closeout, and affirmation.Electronic Code of Federal Regulations32 CFR § 170.18 — CMMC Level 3 certification assessment and affirmation requirementsPrimary rule text for Level 3 DIBCAC assessment and the Final Level 2 prerequisite.