What information triggers it
Level 1 — FCI. Federal Contract Information: generated for or provided
under a federal contract, not intended for public release.
Level 2 — CUI. Controlled Unclassified Information: categories the
government requires be safeguarded, flowed down by a prime or contracting officer.
How many practices
Level 1 — 15 practices drawn from FAR 52.204-21 basic safeguarding.
Level 2 — 110 practices from NIST SP 800-171, each with
assessment objectives that have to be evidenced individually.
Who verifies it
Level 1 — self-assessment, annually, with an affirmation by a company
official.
Level 2 — a C3PAO in the common CUI case, on a three-year cycle.
C3PAO assessment preparation →
What a POA&M can carry
Level 1 — nothing. All 15 practices must be met; there is no deferral.
Level 2 — a limited set, conditionally, with a closeout clock. Not every
practice is eligible, and the ineligible ones are exactly the ones teams try to defer.
What it costs you in scope
Level 1 rarely forces an architecture change.
Level 2 makes every system that touches CUI part of the assessed
boundary — which is why narrowing where CUI lives is the highest-leverage decision available.
How a CUI enclave narrows scope →
How long preparation takes
Level 1 is usually measured in weeks of tidying and documentation.
Level 2 is measured in quarters, because evidence has to accumulate over
time and implementation cannot be compressed at the end.