CMMC Level 1 vs Level 2: Which Do You Need?

CMMC Level 1 vs Level 2 explained — Readiness OS

The single most important CMMC question for a small defense contractor is also the simplest: which level applies to me? The answer determines whether compliance is a few weeks of work or a months-long project — and the gap between the two is not a spectrum. Here’s the clear breakdown.

The deciding factor: FCI vs CUI

It comes down to what kind of government information your contracts involve:

  • Federal Contract Information (FCI) only → Level 1
  • Controlled Unclassified Information (CUI)Level 2

If you’re not sure, your contract’s DFARS clauses and your contracting officer will tell you. Don’t guess — the level dictates everything downstream.

CMMC Level 1 at a glance

  • Who: All DoD contractors handling FCI (but not CUI).
  • Requirements: 17 basic cybersecurity practices (CMMCGap).
  • Assessment: Annual self-assessment — no third party required.
  • Timeline: Typically achievable in weeks.
  • Status: Already phasing into contracts.

Level 1 is meaningful work, but it’s within reach for a small team, especially with good workforce training and documentation.

CMMC Level 2 at a glance

  • Who: Contractors handling CUI.
  • Requirements: All 110 security controls from NIST SP 800-171, across 14 control families — access control, audit and accountability, configuration management, incident response, system and communications protection, and more (Trinity Data Solutions).
  • Assessment: For most prioritized acquisitions, a C3PAO (Certified Third-Party Assessment Organization) performs the audit. Some non-prioritized acquisitions allow a documented self-assessment — but the 110 controls still all apply (StealthTech).
  • Certification: Valid 3 years, with an annual affirmation in SPRS.
  • Timeline: Commonly 6–18 months to achieve — and C3PAO capacity is tight, with assessment scheduling running 6–9 months out (Theodosian).

The deadline that matters

Phase 2 enforcement begins November 10, 2026 — from that date, DoD can condition contract awards on Level 2 certification (Theodosian). Given 6–9 month assessment scheduling windows, the time to start Level 2 work is now, not next year.

Quick comparison

Level 1Level 2
Triggered byFCI onlyCUI
Controls17 practices110 (NIST SP 800-171)
AssessmentAnnual self-assessmentC3PAO (most CUI contracts)
Cert validityAnnual3 years + annual affirmation
Typical timelineWeeks6–18 months

Where to start — either level

Both levels lean heavily on workforce readiness: trained people, documented practices, and audit-ready evidence. That’s the fastest, most affordable place to begin — and it’s exactly what Readiness OS was built for, starting at $99/mo + $8/user.

See what your path costs before you commit: run the Cost of Compliance calculator.


General information, not compliance or legal advice — confirm your requirements with your contracting officer. Part of the CMMC for Small Contractors guide series.

Leave a comment