CMMC Levels Explained: Level 1 vs Level 2 vs Level 3

“Which CMMC level do I actually need?” is one of the first questions every defense contractor asks, and it’s also one of the most consequential, because the answer determines your assessment type, your timeline, your cost, and which contracts you’re even eligible to bid on.

The short answer: it depends entirely on what information your systems touch, not on your company’s size, revenue, or how long you’ve worked with the DoD. Here’s exactly what separates the three levels, who actually verifies your compliance, and how to determine which one applies to your organization.

The Core Distinction: What Information Are You Actually Handling?

Before anything else, your required CMMC level comes down to one question: does your organization handle Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or both?

FCI is information provided by or generated for the government under a contract that isn’t intended for public release. CUI is more sensitive, information that requires safeguarding under law, regulation, or government-wide policy, but that isn’t classified. If your systems only ever touch FCI, you’re looking at Level 1. If CUI flows through your environment at any point, you need Level 2 at minimum. Level 3 is reserved for a much smaller subset of organizations supporting the DoD’s most sensitive programs. GovTrack.us

Level 1: Foundational

Level 1 is the entry point, the floor every DoD contractor handling FCI has to meet, regardless of how small the contract is.

What it covers. CMMC Level 1 aligns with the 15 basic safeguards outlined in FAR 52.204-21, foundational cyber hygiene practices the federal government has required of contractors for years, now formalized under the CMMC structure. These cover basic access control, identification and authentication, media protection, and physical security at a fundamental level. Congress.gov

Assessment type. Level 1 is self-assessed annually, with results submitted to the Supplier Performance Risk System (SPRS). There’s no third-party assessment requirement, and critically, no POA&M is allowed, every one of the 15 practices must be fully implemented before you affirm compliance.

Who needs it. Any DoD contractor or subcontractor whose systems process, store, or transmit FCI, even if that’s the only government-related information your organization touches. This is a large population: many small and mid-sized subcontractors with no direct CUI exposure still fall under Level 1 simply by virtue of working anywhere in the DoD supply chain.

Level 2: Advanced

Level 2 is where the program’s real weight lives. It’s the most common level, and it’s where third-party verification enters the picture for most organizations. GovTrack.us

What it covers. CMMC Level 2 aligns with NIST 800-171’s 110 cybersecurity requirements, organized into 14 practice domains covering access control, audit and accountability, configuration management, incident response, risk assessment, and the rest of the control families that govern CUI protection. GovTrack.us

Assessment type. This is the critical fork. Depending on the specific contract requirement, organizations complete either a self-assessment or an independent assessment by an authorized C3PAO, conducted every three years, with results entered into SPRS, and organizations responsible for affirming their status annually or the certification lapses. Some Level 2 contracts permit self-assessment; others, particularly those involving CUI considered critical to national security, require the full third-party certification path. Congress.gov

Who needs it. Any organization whose systems process, store, or transmit CUI under a DoD contract. This is the level most defense contractors and subcontractors handling sensitive program data will need, and it’s the level around which most of the CMMC ecosystem, C3PAOs, RPOs, assessor training, is built.

Level 3: Expert

Level 3 sits at the top of the framework, and it’s deliberately narrow in scope.

What it covers. Level 3 is reserved for contractors supporting the most sensitive programs. It requires compliance with NIST SP 800-171 plus a subset of 24 NIST SP 800-172 controls designed to protect against Advanced Persistent Threats (APTs). Sources vary slightly on the resulting total practice count, generally cited as somewhere around 130 to 134 combined requirements, depending on how the count is structured, so confirm the precise current figure before publishing anything definitive. Congress.gov

Assessment type. Assessments are performed by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a government-led assessment, not a C3PAO engagement. Before pursuing Level 3, an organization must already hold Final Level 2 certification; there’s no path to Level 3 that skips Level 2 first. Congress.gov

Who needs it. A small, specific population: organizations supporting the DoD’s highest-priority programs where CUI requires protection against the most sophisticated, persistent adversaries. Most defense contractors will never need Level 3, it’s not a higher tier of “more secure,” it’s a different category of program risk entirely.

 

Who Actually Verifies Your Compliance: The Cyber AB Ecosystem

Understanding the levels only gets you halfway. Knowing who actually does the verifying, and why that distinction matters, is just as important.

The Cyber AB has defined two key roles for organizations that help OSCs (Organizations Seeking Certification) get certified: Registered Provider Organizations (RPOs), who advise, and C3PAOs, who assess. That separation is intentional and strictly enforced. A properly operating C3PAO does not consult for the firms it assesses, there’s a hard conflict-of-interest wall between advisory work and assessment work. 

A C3PAO, CMMC Third-Party Assessor Organization, is an organization authorized by the Cyber AB to conduct and deliver CMMC assessments after entering a contract with an OSC. The C3PAO doesn’t directly issue the certification itself, they submit the assessment results to the Cyber AB, which reviews the report and, based on that review, officially grants certification. The White House

Becoming a C3PAO is itself a rigorous, regulated process. Within 27 months of authorization, C3PAOs must achieve ISO 17020 accreditation, the international standard for inspection bodies, and DIBCAC conducts its own assessments of C3PAOs every three years to verify they can protect the sensitive information they encounter during client assessments. The assessors themselves carry individual credentials too: CMMC Certified Assessors (CCAs) must meet baseline certification requirements under DoD 8140.03 Work Role 612, and as of April 2026, ISACA administers the CCP, CCA, and LCCA certifications as the designated CMMC Assessor & Instructor Certification Organization. 

The Assessor Capacity Problem You Need to Plan Around

This is the part of the CMMC ecosystem that doesn’t get enough attention in most explainer content, and it directly affects your timeline regardless of which level you need.

Fewer than 100 authorized C3PAOs currently serve an ecosystem of more than 80,000 Defense Industrial Base contractors who may eventually need Level 2 certification. The Cyber AB’s own CEO noted in December 2025 that approximately 600 certified CMMC assessors exist currently, with about half eligible to lead assessment teams, while the program needs between 2,000 and 3,000 assessors to handle the anticipated assessment volume. 

That gap between supply and demand is not a minor scheduling inconvenience. If your organization needs a C3PAO certification assessment and you wait until your contract deadline is close to start that process, you may simply be unable to book an assessor in time, regardless of how ready your environment actually is. This is one of the strongest practical arguments for starting readiness work well before your specific contract or solicitation requires it.

How to Determine Which Level Actually Applies to You

The honest starting point isn’t “what level do we want”, it’s an honest inventory of what your systems actually touch.

Map every system, application, and environment in your organization against the information types flowing through it. If FCI is the only government-related information your systems handle, you’re a Level 1 organization. If CUI flows through any part of your environment, even one system, even one contract, you need Level 2 for that environment at minimum.

From there, check your specific contract or solicitation language. Some Level 2 contracts permit self-assessment; others require the full C3PAO certification path. The contract, not your own preference, determines which assessment type applies. And unless your organization is explicitly supporting one of the DoD’s highest-sensitivity programs, Level 3 almost certainly does not apply to you; it’s a narrow, government-assessed tier built for a specific category of risk, not a “more advanced” version of Level 2 that ambitious organizations should aspire to.

Where RSI Security Fits

RSI Security is an authorized C3PAO. We conduct CMMC Level 2 certification assessments directly, and we also help organizations prepare for them.

Because the Cyber AB requires a hard separation between advisory and assessment to avoid conflicts of interest, our assessment team operates independently from our readiness and remediation teams. If your organization works with us on readiness — gap assessment, SSP development, remediation support — your formal certification assessment will be conducted by an independent team within our C3PAO practice, walled off from the advisory engagement, consistent with Cyber AB rules.

If you’re not sure which CMMC level applies to your organization, want help preparing for assessment, or are ready to schedule your certification directly with our C3PAO team, [schedule a CMMC readiness consultation] to find the right starting point.

Frequently Asked Questions

What are the differences between CMMC Level 1, Level 2, and Level 3?
Level 1 covers 15 basic safeguarding practices for organizations handling Federal Contract Information, verified through annual self-assessment with no third-party review. Level 2 aligns with all 110 NIST SP 800-171 Rev. 2 requirements for organizations handling Controlled Unclassified Information, verified through either self-assessment or third-party C3PAO certification depending on the contract. Level 3 adds a subset of NIST SP 800-172 controls for organizations supporting the DoD’s most sensitive programs, assessed directly by the government through DIBCAC.

How do I know which CMMC level my organization needs?
Your required level depends on what information your systems handle, not your organization’s size. If your systems only process Federal Contract Information, you need Level 1. If Controlled Unclassified Information flows through any part of your environment, you need Level 2 at minimum. Level 3 applies only to a small subset of organizations explicitly supporting the DoD’s highest-sensitivity programs, and it always requires holding Level 2 certification first.

What is a C3PAO and how is it different from an RPO?
A C3PAO (Certified Third-Party Assessor Organization) is authorized by the Cyber AB to conduct formal CMMC assessments and is the only type of entity that can issue a Level 2 certification recommendation. A Registered Provider Organization (RPO) provides advisory and readiness support to help an organization prepare for assessment but cannot conduct the formal assessment itself. The separation between these roles is strictly enforced to avoid conflicts of interest.

Can a C3PAO also help my organization prepare for its own assessment?
No. A properly operating C3PAO does not provide consulting or advisory services to organizations it assesses, and Cyber AB rules are designed to maintain a strict separation between advisory and assessment roles. Organizations typically work with an RPO or advisory partner to prepare, then engage a separate, independent C3PAO to conduct the formal certification assessment.

How long does it take to get CMMC certified?
Timelines vary significantly based on your current security posture, required level, and assessor availability. Given that fewer than 100 authorized C3PAOs currently serve an ecosystem of more than 80,000 Defense Industrial Base contractors, scheduling a certification assessment can itself take significant lead time, independent of how long your internal remediation work takes. Organizations should begin readiness work well before their contract deadline requires certification.