CMMC levels

Level 1 or Level 2? The data you hold decides.

The two levels are not degrees of the same requirement — they answer to different information, different control sets, and different verification. Level 1 is 15 practices you attest to yourself. Level 2 is 110 practices assessed by a C3PAO. Getting the answer wrong is expensive in both directions: over-scoping buys controls no contract asked for, and under-scoping is discovered at assessment.

CMMC Level 1 is a self-assessment, and Cyberneza covers it end to end for a published fixed fee. See federal pricing →

Side by side

The differences that change what you do.

What information triggers it

Level 1 — FCI. Federal Contract Information: generated for or provided under a federal contract, not intended for public release.

Level 2 — CUI. Controlled Unclassified Information: categories the government requires be safeguarded, flowed down by a prime or contracting officer.

How many practices

Level 1 — 15 practices drawn from FAR 52.204-21 basic safeguarding.

Level 2 — 110 practices from NIST SP 800-171, each with assessment objectives that have to be evidenced individually.

Who verifies it

Level 1 — self-assessment, annually, with an affirmation by a company official.

Level 2 — a C3PAO in the common CUI case, on a three-year cycle. C3PAO assessment preparation →

What a POA&M can carry

Level 1 — nothing. All 15 practices must be met; there is no deferral.

Level 2 — a limited set, conditionally, with a closeout clock. Not every practice is eligible, and the ineligible ones are exactly the ones teams try to defer.

What it costs you in scope

Level 1 rarely forces an architecture change.

Level 2 makes every system that touches CUI part of the assessed boundary — which is why narrowing where CUI lives is the highest-leverage decision available. How a CUI enclave narrows scope →

How long preparation takes

Level 1 is usually measured in weeks of tidying and documentation.

Level 2 is measured in quarters, because evidence has to accumulate over time and implementation cannot be compressed at the end.

How to actually determine yours

  • Read the clauses, not the summary. DFARS 252.204-7012 / 7019 / 7020 / 7021 and FAR 52.204-21 are where the obligation is stated.
  • Follow the data, not the org chart. Trace where information from the contract actually arrives, rests, and gets forwarded — inboxes and shared drives included.
  • Ask the prime in writing. If a flow-down is ambiguous about whether what you receive is CUI, that ambiguity is theirs to resolve and yours to record.
  • Assume nothing from your size. Level is set by the information you handle, not by headcount or contract value.

Two mistakes worth avoiding

  • Buying Level 2 tooling before settling scope. The boundary determines what the tooling has to cover; reversing that order buys coverage for systems you could have excluded.
  • Treating Level 1 as a stepping stone. It is a different obligation, not the first 15 of 110. Meeting it does not put you meaningfully closer to Level 2.
  • Declaring a level to a prime before verifying it. A stated level becomes a commitment other people plan around.

CMMC & NIST 800-171 readiness → · Federal cybersecurity support →

Not sure which one your contracts require?

Tell us what you receive and from whom. You will get back a written view of which level your contracts point to, where the data that drives it actually lives, and what the readiness path looks like for that level.