CMMC Levels at a Glance: Foundational, Advanced, and Expert
A fast reference for CMMC 2.0’s three certification levels — what data each one covers, how many controls it requires, how it’s assessed, and who needs it. For a full explanation of how the levels relate to each other and what the jump between them actually involves, see our CMMC Level 2 guide.
Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Level 1 self-assessment and Level 2 self-assessment (where applicable) remain in force. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

The Three Levels, at a Glance
| Level 1 — Foundational | Level 2 — Advanced | Level 3 — Expert | |
|---|---|---|---|
| Data protected | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | CUI on the highest-priority programs |
| Control count | 17 basic safeguarding practices | 110 controls (NIST SP 800-171) | 134 controls (110 from NIST SP 800-171 + 24 from NIST SP 800-172) |
| What’s new at this level | Basic cyber hygiene: user identification, physical access limits, controlling public-facing information — no encryption, audit logging, or incident response requirements yet | Everything in Level 1, plus encryption (FIPS-validated), audit logging tied to individual users, formal incident response, documented risk assessment, and 10 additional control domains Level 1 doesn’t touch at all | Everything in Level 2, plus enhanced requirements aimed at advanced persistent threats: deeper supply chain risk management, advanced threat hunting capability, and stronger insider threat protections |
| Prerequisite for this level | None — this is the entry point | No formal prerequisite, but organizations already meeting Level 1 have a head start, since Level 2 encompasses Level 1’s practices | No formal prerequisite, but Level 3 assumes full Level 2 implementation is already in place and functioning — it is not a starting point for an organization new to CMMC |
| Assessment type | Annual self-assessment | Self-assessment or C3PAO third-party certification, depending on program criticality | Triennial government-led assessment (DIBCAC) |
| POA&Ms allowed? | No | Yes, for a limited subset of controls with a defined timeline | Yes, under the same limited framework as Level 2 |
| Who typically needs it | Contractors handling only FCI, not CUI | Contractors and subcontractors handling CUI — the largest share of the DIB | Contractors on the most sensitive national security programs, facing advanced persistent threats |
| Go deeper | CMMC Level 1 guide | CMMC Level 2 guide | CMMC Level 3 guide |
How to Use This Table
Find your row by the type of data your organization handles — that’s the determining factor, not company size or revenue. If you handle only FCI, you’re looking at Level 1. If you handle CUI, you’re at Level 2, and your specific contract will specify whether self-assessment or C3PAO certification applies. Level 3 applies to a small subset of the DIB working on the most sensitive national security programs, and it’s specified directly in the relevant contract — it’s not a level an organization chooses to pursue independently.
The levels are additive: Level 2 encompasses Level 1’s requirements and adds substantially more; Level 3 encompasses Level 2’s full baseline and adds enhanced controls on top. An organization certified at a higher level has, in effect, already satisfied the levels below it.
How to Determine Which Level Your Organization Actually Needs
Most organizations don’t get to choose their CMMC level — it’s determined by the data they handle and specified in the contract itself. But figuring out exactly what that means for your organization takes a few concrete steps.
Key Steps to Determine Your CMMC Level
- Start with your contract language, not your own assumption.
The solicitation or contract will typically specify the required CMMC level directly, or reference the type of information involved in terms that map to a level (FCI vs. CUI). If you’re a subcontractor, check your prime contractor’s flow-down requirements — the level that applies to you is tied to what you specifically handle, which may differ from what the prime handles.
- Identify exactly what data flows through your organization, not just what you assume flows through it.
This is where organizations most often misjudge their own level. A company that believes it only handles FCI may discover, on closer inspection, that a subset of technical drawings, export-controlled specifications, or other CUI passes through email, file sharing, or a subcontractor relationship without anyone having formally classified it as such. Since CUI triggers Level 2 regardless of how small the volume is, an inventory of actual data flows — not a general impression of “the kind of work we do” — is the only reliable way to confirm your level.
- If you’re at Level 2, confirm whether your specific program requires self-assessment or third-party certification.
Not all Level 2 contracts carry the same assessment burden. Programs involving the most critical national security information require C3PAO certification; others permit self-assessment. This distinction significantly affects your compliance timeline and cost, and it’s worth confirming directly rather than assuming the more demanding path applies by default — or, just as risky, assuming the lighter path applies without checking.
- Don’t over-invest in Level 3 controls you don’t need, and don’t under-invest in Level 2 controls you do.
Level 3 is reserved for a small population of the most sensitive programs and is explicitly specified when it applies — an organization won’t accidentally need Level 3 without a contract telling them so. The more common and more costly mistake runs the other direction: organizations that assume Level 1 is sufficient because they don’t think of their work as “sensitive,” when in fact CUI is already moving through their systems and Level 2 is the real requirement.
- When genuinely uncertain, ask the contracting officer or your prime directly.
The required level is a fact about the contract, not a matter of interpretation — and getting it wrong in either direction carries real cost, whether that’s an under-prepared bid getting disqualified or an over-built compliance program spending budget on requirements that don’t apply.
Current Program Status
Level 1 self-assessment and Level 2 self-assessment (for contracts not requiring third-party certification) remain fully in force. The Level 2 C3PAO certification requirement for the most critical programs — originally scheduled to expand under Phase 2 starting November 2026 — is currently suspended pending the Department of War’s Reform Task Force review, expected to report around mid-September 2026. Kiteworks’ own survey of 273 DIB organizations found the pause didn’t slow compliance activity broadly — 98% of respondents took at least one concrete action in response. See State of CMMC 2.0 Preparedness in the DIB for the full findings.
How Kiteworks Supports Every CMMC Level
Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box, with a unified Data Policy Engine, AES-256 encryption using FIPS 140-3 validated cryptographic modules, and a single, consolidated, immutable audit trail across secure email, secure file sharing, managed file transfer, and SFTP — the same foundation that supports Level 1’s basic safeguarding requirements and contributes toward Level 3’s enhanced control set. Kiteworks also holds FedRAMP Moderate Authorization, independently assessed since June 2017.
To see how Kiteworks supports your organization’s specific CMMC level, schedule a custom demo.
Frequently Asked Questions
The level required depends on the type of data your organization handles, and it’s typically specified directly in your contract or your prime contractor’s flow-down requirements. Organizations handling only Federal Contract Information need Level 1. Organizations handling Controlled Unclassified Information need Level 2. Level 3 applies only to a small subset of the most sensitive national security programs and is specified in the relevant contract, not chosen independently.
Assuming Level 1 is sufficient without actually inventorying what data flows through the organization. A company may believe it handles only Federal Contract Information, when in fact CUI — technical drawings, export-controlled specifications, or other sensitive data — passes through email, file sharing, or a subcontractor relationship without having been formally identified as such. Since any amount of CUI triggers Level 2 regardless of volume, the only reliable way to confirm a level is a genuine data flow inventory, not a general impression of the kind of work the organization does. The opposite mistake — over-investing in Level 3 controls that aren’t required — is less common, since Level 3 is always explicitly specified in a contract rather than something an organization could mistakenly assume applies.
Level 1 requires 17 basic safeguarding practices. Level 2 requires 110 controls drawn from NIST SP 800-171. Level 3 requires 134 controls — the full 110 from Level 2 plus 24 additional enhanced controls from NIST SP 800-172. Each level is additive, meaning a Level 3 organization has, in effect, already satisfied Levels 1 and 2 as a subset of its broader control set.
Moving from Level 1 to Level 2 means adding entire categories of requirement that Level 1 doesn’t touch at all — encryption using FIPS-validated cryptography, audit logging that traces individual user actions, a formal incident response capability, documented ongoing risk assessment, and coverage across 10 additional NIST SP 800-171 control domains beyond what Level 1’s 17 practices address. It’s a substantial jump in both scope and rigor, not an incremental add-on. Moving from Level 2 to Level 3 means adding a further, narrower set of enhanced requirements from NIST SP 800-172, aimed specifically at defending against advanced persistent threats — deeper supply chain risk management, advanced threat hunting capability, and stronger insider threat protections — on top of a full Level 2 implementation that’s assumed to already be in place and working.
Level 1 is always verified through annual self-assessment — there is no third-party requirement at this level. Level 2 depends on program criticality: contracts involving the most critical national security information require C3PAO third-party certification, while other Level 2 contracts may permit self-assessment. Level 3 requires a government-led triennial assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not a C3PAO.
No. Level 1 does not permit POA&Ms — all 17 practices must be fully implemented before certification. Level 2 and Level 3 both permit a POA&M for a limited subset of controls, with a defined remediation timeline, giving organizations a documented path to close specific gaps without requiring complete implementation on day one.

