Skip to content
    August 16, 2026| Top Floor Team| 10 min read

    What CMMC Level Do You Need? A Decision Tree by Data Type

    Your required CMMC level is determined by the information the contract puts in your hands. If you handle only Federal Contract Information (FCI), you need Level 1: the 15 basic safeguarding requirements from FAR 52.204-21, assessed annually by yourself. If you handle Controlled Unclassified Information (CUI), you need Level 2: the 110 security requirements of NIST SP 800-171 Rev 2. Level 3 applies to a small set of contractors on the highest-priority programs, it adds selected enhancements from NIST SP 800-172, and the Department designates it in the solicitation rather than leaving it to you to work out. Your revenue, your headcount, and your prime's own certification level do not enter into it.

    That is the rule. Almost all of the difficulty in applying it comes from one question, which is what data you actually hold, so the rest of this walks the decision and then the four edge cases where the answer is not obvious.

    Key takeaways

    • Your level is set by the information the contract puts in your hands, not by contract value, headcount, or your prime's own certification level.
    • Federal Contract Information only means Level 1. Controlled Unclassified Information means Level 2. Level 3 is designated by the Department in the solicitation and is not something a contractor elects into.
    • Meeting a level is three artifacts plus an ongoing obligation: a System Security Plan, a score in the Supplier Performance Risk System, and an affirmation from a senior company official, repeated annually.
    • The most common way a Level 1 organization becomes a Level 2 organization is that someone emails a drawing. Markings are frequently missing or wrong.
    • Scoping is what stops Level 2 from swallowing your whole environment. If CUI from one contract sits on the same file server as everything else, your assessment boundary just did too.
    LevelWhat triggers itRequirementsAssessment
    Level 1Federal Contract Information only15 basic safeguarding requirements from FAR 52.204-21Annual self-assessment with a senior official affirmation. No POA&M permitted at any time
    Level 2Controlled Unclassified InformationThe 110 security requirements of NIST SP 800-171 Rev 2, across 14 familiesSelf-assessment under Phase 1, with program offices holding discretion to require a certification assessment; the Phase 2 trigger is suspended
    Level 3Designated by the Department in the solicitation, for the highest-priority programsLevel 2 plus a selected subset of NIST SP 800-172 enhancementsGovernment-led rather than commercial

    The decision, in the order the questions matter

    Do you hold a federal contract or subcontract at all? If no, CMMC does not reach you. Vendor emails about CMMC readiness are sent by list, not by contract.

    Does any contract deliverable, drawing, specification, or system involve CUI? If yes, Level 2, and the rest of the tree is irrelevant. CUI drags the whole assessment scope with it.

    If not CUI, is any of the information non-public and provided by or generated for the government under the contract? That is FCI, and it means Level 1. Almost every federal contractor holds FCI somewhere, because a delivery schedule or an unpublished statement of work qualifies.

    Does the solicitation name Level 3? Then it is Level 3, and you will know because it is written down. Level 3 is not something a contractor elects into, and it involves a government-led assessment rather than a commercial one.

    Note what is missing from that list. Nothing asks how big you are. A three-person machine shop that receives a CUI-marked drawing is a Level 2 organization. A 400-person logistics contractor that receives only schedules and invoices is a Level 1 organization. The information is the trigger.

    Level 1: 15 requirements, self-assessed, annual

    Level 1 maps to the basic safeguarding requirements in FAR 52.204-21: limiting system access to authorized users, controlling what is posted publicly, sanitizing media before disposal, keeping systems patched, running malware protection, and so on. They are the practices most functioning IT environments already have in some form.

    Two things about Level 1 catch people out. The assessment is annual, not one-time, and it comes with an affirmation from a senior company official. And a POA&M is not permitted at Level 1 at any time, which 32 CFR 170.21 states plainly. There is no partial credit and no deferral: you either meet the 15 requirements or you do not have a Level 1 self-assessment.

    Level 2: 110 requirements, and the assessment path depends on the contract

    Level 2 is NIST SP 800-171 Rev 2 in full: 110 security requirements across 14 families, from access control and audit logging through incident response, media protection, and system and communications protection.

    The assessment path is the part in motion. Under Phase 1, which began November 10, 2025, Level 2 self-assessment is what applicable solicitations have been requiring, with program offices holding discretion to require a certification assessment in some procurements. The Phase 2 trigger that would have made third-party C3PAO certification assessments the norm was suspended on July 13, 2026 pending a reform task force review, so the honest answer about which path you will face is that Level 2 is the requirement and the assessment mechanism is under review. Our piece on what the suspension did and did not change works through that in detail.

    What has not moved is the substance. Whether you self-assess or an assessor assesses you, the 110 requirements are the same 110 requirements, and DFARS 252.204-7012 has obliged their implementation on covered systems for years.

    Level 3: designated, not elected

    Level 3 adds a selected subset of NIST SP 800-172 enhancements on top of the Level 2 baseline, is aimed at contractors supporting the most sensitive programs, and is assessed by the government rather than by a commercial assessor. If you are wondering whether you are Level 3, you are almost certainly not. Contractors in scope for it find out through the solicitation and through their program office, and they generally have a Level 2 certification behind them already.

    What "meeting the level" actually involves

    Knowing your level is the easy half. Meeting it is three artifacts and an ongoing obligation, and they are the same three at Level 1 and Level 2 with different weight behind them.

    A System Security Plan. A written description of your boundary and of how each applicable requirement is implemented. At Level 2 this is CA.L2-3.12.4, and it is one of the requirements that can never be deferred to a plan of action under 32 CFR 170.21. An assessment without an SSP is not a hard assessment, it is an impossible one, because there is nothing to assess against.

    A score in the Supplier Performance Risk System. At Level 2 that means the NIST SP 800-171 self-assessment result, calculated the way the scoring rules require. At Level 1 it is the self-assessment against the 15 FAR 52.204-21 requirements.

    An affirmation from a senior company official. Someone with authority signs that the organization complies, and continues to comply. That signature is a representation to the government, which is why the accuracy of the two artifacts above stops being an internal-quality question and becomes a legal one.

    The ongoing part is the word "annual". Level 1 self-assessments are annual, and affirmations recur. A level is not something you achieve and file away; it is a state you assert repeatedly, and each assertion has to be true on the day it is made.

    The practical consequence for planning: budget for the maintenance, not just the project. Most organizations that struggle here did the implementation work once and then let the SSP drift away from the environment it describes.

    The four edge cases that actually cause the confusion

    Your prime told you their level, and you assumed it is yours. A prime cannot make you Level 2 by being Level 2. What the prime can do is share CUI with you, and that is what sets your level. This is common enough that we wrote it up separately in CMMC flow-down. If a prime is demanding a level, ask what data they intend to send you and get the answer in writing.

    Mixed contracts. You can hold a Level 1 contract and a Level 2 contract at once. The obligations attach per contract, but your systems do not: if CUI from one contract sits on the same file server as everything else, your Level 2 scope has quietly become your whole environment. Scoping is what prevents that, and scoping is a design decision made early or an expensive discovery made late.

    CUI you did not expect. The most common way a Level 1 organization becomes a Level 2 organization is that someone emails a drawing. Markings are frequently missing or wrong, which is why identifying CUI is its own problem and why we treat it separately in FCI vs CUI.

    Export-controlled data. ITAR and EAR obligations run in parallel and do not care about your CMMC level. Technical data subject to export control is normally CUI as well, so it pulls you to Level 2, but meeting Level 2 does not discharge an export-control obligation. They are two regimes over one dataset.

    When you should not be doing any of this yet

    If you have no federal contract, no subcontract, and no realistic pipeline into one, the correct level is none, and the readiness proposal in your inbox is speculative spending. We have watched companies build a CUI enclave for a prime relationship that never produced an award.

    If you hold only FCI, be skeptical of anyone selling you a Level 2 program. Fifteen self-assessed requirements is a genuinely small project, and the gap between that and a 110-requirement program is the difference between a quarter and a year.

    And if you are unsure whether you handle CUI, the cheapest next step is an email to your contracting officer, not an engagement with us.

    Where Top Floor fits

    Most of what our CMMC practice does at this stage is scoping: establishing what data you receive, where it lands, and how small the assessment boundary can honestly be. That determination drives every cost in the program, and it is the one decision that is hard to reverse later.

    For organizations without a security leader to own the program across contracts, a virtual CISO engagement is usually the cheaper structure than hiring for it, particularly when defense work is a minority of revenue.

    How to decide this week

    Ask your contracting officer or prime, in writing, whether the contract involves CUI, and keep the answer.

    Search your own mail and file shares for CUI markings, and for the document types that usually carry them: drawings, specifications, test data, and anything export-controlled.

    Then write down one sentence per active contract: the contract, the data it involves, and the level that follows. If you cannot write that sentence for a contract, that is the contract to investigate first.

    Frequently asked questions

    Does my CMMC level depend on my contract value?

    No. The level is set by the type of information you handle under the contract. Federal Contract Information means Level 1, Controlled Unclassified Information means Level 2, and Level 3 applies only where the Department designates it in the solicitation for the highest-priority programs. A large contract that involves no CUI does not raise your level, and a very small one that involves CUI does not lower it.

    Can a prime require me to be Level 2 when I only handle FCI?

    Not by regulation. The level that applies to a subcontractor follows the information the prime actually shares, so a flow-down of CUI means at least Level 2 and a flow-down of FCI only means Level 1. A prime can still ask for more by contract, and some do, but that is a commercial negotiation rather than a regulatory obligation. Before agreeing, confirm in writing what data you will receive.

    How many requirements are in CMMC Level 2?

    110. They are the security requirements of NIST SP 800-171 Rev 2, organized into 14 families. The 171 in the document title is a publication number and not a count of anything, which is a common misreading in vendor content. Level 1 is 15 requirements drawn from FAR 52.204-21, and Level 3 adds a selected subset of NIST SP 800-172 enhancements on top of Level 2.

    What if I handle both FCI and CUI?

    Then you are a Level 2 organization for the CUI, and the practical question becomes scoping. CUI pulls every system that stores, processes, or transmits it into the assessment boundary, along with anything that provides security protection to those systems. Keeping FCI-only work outside that boundary is possible and usually worth engineering deliberately, because the boundary is what determines how much of your environment has to meet 110 requirements.

    Share Share on LinkedIn

    Related Services

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.