The single most important CMMC question for a small defense contractor is also the simplest: which level applies to me? The answer determines whether compliance is a few weeks of work or a months-long project — and the gap between the two is not a spectrum. Here’s the clear breakdown.
The deciding factor: FCI vs CUI
It comes down to what kind of government information your contracts involve:
- Federal Contract Information (FCI) only → Level 1
- Controlled Unclassified Information (CUI) → Level 2
If you’re not sure, your contract’s DFARS clauses and your contracting officer will tell you. Don’t guess — the level dictates everything downstream.
CMMC Level 1 at a glance
- Who: All DoD contractors handling FCI (but not CUI).
- Requirements: 17 basic cybersecurity practices (CMMCGap).
- Assessment: Annual self-assessment — no third party required.
- Timeline: Typically achievable in weeks.
- Status: Already phasing into contracts.
Level 1 is meaningful work, but it’s within reach for a small team, especially with good workforce training and documentation.
CMMC Level 2 at a glance
- Who: Contractors handling CUI.
- Requirements: All 110 security controls from NIST SP 800-171, across 14 control families — access control, audit and accountability, configuration management, incident response, system and communications protection, and more (Trinity Data Solutions).
- Assessment: For most prioritized acquisitions, a C3PAO (Certified Third-Party Assessment Organization) performs the audit. Some non-prioritized acquisitions allow a documented self-assessment — but the 110 controls still all apply (StealthTech).
- Certification: Valid 3 years, with an annual affirmation in SPRS.
- Timeline: Commonly 6–18 months to achieve — and C3PAO capacity is tight, with assessment scheduling running 6–9 months out (Theodosian).
The deadline that matters
Phase 2 enforcement begins November 10, 2026 — from that date, DoD can condition contract awards on Level 2 certification (Theodosian). Given 6–9 month assessment scheduling windows, the time to start Level 2 work is now, not next year.
Quick comparison
| Level 1 | Level 2 | |
|---|---|---|
| Triggered by | FCI only | CUI |
| Controls | 17 practices | 110 (NIST SP 800-171) |
| Assessment | Annual self-assessment | C3PAO (most CUI contracts) |
| Cert validity | Annual | 3 years + annual affirmation |
| Typical timeline | Weeks | 6–18 months |
Where to start — either level
Both levels lean heavily on workforce readiness: trained people, documented practices, and audit-ready evidence. That’s the fastest, most affordable place to begin — and it’s exactly what Readiness OS was built for, starting at $99/mo + $8/user.
See what your path costs before you commit: run the Cost of Compliance calculator.
General information, not compliance or legal advice — confirm your requirements with your contracting officer. Part of the CMMC for Small Contractors guide series.


Leave a comment