Which CMMC level your contract calls for, what each one asks you to implement, what the assessment costs, and what the July 2026 suspension changed.
CMMC Level 1 applies when your contract involves Federal Contract Information only. It asks for the 15 basic safeguarding requirements in FAR clause 52.204-21, confirmed by an annual self-assessment. CMMC Level 2 applies when you create, store, process or transmit Controlled Unclassified Information, and asks for all 110 security requirements in NIST SP 800-171, measured across 320 assessment objectives. Since 13 July 2026, new Department of War solicitations can designate only Level 1 (Self) or Level 2 (Self), because third-party Level 2 assessments are suspended pending a program review.
The difference between CMMC Level 1 and CMMC Level 2 is the sensitivity of the information you hold, and everything else follows. CMMC Level 1 protects Federal Contract Information, which is information generated for or provided by the government under a contract and not intended for public release. CMMC Level 2 protects Controlled Unclassified Information, which carries specific safeguarding obligations under law, regulation or government-wide policy. Because CUI is more sensitive, CMMC Level 2 requires roughly seven times as many security requirements, formal documentation rather than informally performed practices, and a system security plan showing how each is met.
| CMMC Level 1 | CMMC Level 2 | |
|---|---|---|
| Information protected | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Security requirements | 15, from FAR clause 52.204-21 | 110, from NIST SP 800-171 |
| Assessment objectives | The NIST SP 800-171A objectives for those 15 | 320 |
| Control families | A single FAR clause, not grouped | 14, from access control to system integrity |
| Documentation expected | Practices performed; no system security plan | System security plan, policies and procedures |
| Assessment route, October 2026 | Annual self-assessment | Self-assessment; C3PAO route suspended |
| Affirmation | Annual, senior official, in SPRS | Annual, senior official, in SPRS |
| Plan of action permitted | No, every requirement must be met | Yes for a limited set, 180 days to close |
You need CMMC Level 1 if the only government information on your systems is Federal Contract Information. You need CMMC Level 2 if Controlled Unclassified Information touches your systems at all, even if it arrives by email and is deleted the same day. The deciding question is the data, not the size of the company or the contract.
Three practical signals that CUI is in scope, and CMMC Level 2 applies:
If you cannot tell, ask the contracting officer and get the answer in writing. Guessing low is the expensive mistake, because a CMMC Level 2 programme started late is what delays an award. Guessing high spends money you may not need to.
The CMMC Level 1 requirements are the 15 basic safeguarding requirements already in FAR clause 52.204-21, which has sat in standard federal contracts for years. They cover limiting access to authorised users and functions, controlling what gets posted publicly, sanitising media before disposal, limiting physical access, controlling network boundary connections, separating public-facing components onto their own subnetwork, correcting flaws, and protecting against malicious code.
Most organisations already do the substance of these. What CMMC Level 1 adds is the obligation to assess yourself against each one annually, record the result in the Supplier Performance Risk System, and have a senior company official affirm it. Every requirement must be met, because CMMC Level 1 allows no plan of action for anything outstanding.
The CMMC Level 2 requirements are all 110 security requirements in NIST SP 800-171 Revision 2, grouped into 14 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
An assessor does not score those 110 requirements as a simple pass or fail. They are broken into 320 assessment objectives, each marked met, not met, or not applicable. That is why two companies can both claim multi-factor authentication and get different results: the objectives ask which accounts, which access types, and whether the evidence shows it.
CMMC Level 2 also expects documentation that CMMC Level 1 does not: a system security plan describing the boundary and how each requirement is met, policies and procedures across the 14 families, and evidence the practices run rather than merely exist on paper. A limited set of unmet requirements may sit on a plan of action and milestones, giving a conditional status and 180 days to close, as set out in 32 CFR 170.17.
Yes, and as at October 2026 self-assessment is the only CMMC Level 2 route being designated for new work. On 13 July 2026 the Department of War suspended Phase 2 of the CMMC program, due to begin on 10 November 2026, which would have required third-party assessments for CUI contracts. Program managers can no longer designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, and active solicitations carrying them are being amended.
What the suspension did not change matters just as much:
A CMMC Reform Task Force completed a 60 day review in September 2026, informed by a public request for information that drew more than 1,100 comments. Its recommendations had not been published when this guide was written, so treat the position as a pause rather than a repeal. A future rule is more likely to change how the requirements are verified than whether they apply.
The Department of Defense published its own cost estimates alongside the CMMC rule in 32 CFR Part 170. For a small entity they are roughly US$5,977 for a CMMC Level 1 self-assessment, US$37,196 over three years for a CMMC Level 2 self-assessment, and US$104,670 over three years for a CMMC Level 2 certification through a C3PAO. These are assessment costs, not programme costs.
| Assessment path | DoD estimate, small entity | Period | What the figure covers |
|---|---|---|---|
| CMMC Level 1 self-assessment | About US$5,977 | Annual | Internal effort to assess the 15 requirements, submit to SPRS and affirm |
| CMMC Level 2 self-assessment | US$37,196 | Three year cycle | The triennial self-assessment plus two annual affirmations at about US$1,459 each |
| CMMC Level 2 certification by a C3PAO | US$104,670 | Three year cycle | Planning, conduct, reporting, the C3PAO engagement and affirmations |
What those figures exclude is where real CMMC budgets go: closing the gaps the assessment finds. Remediation, a CUI enclave if your environment cannot hold CUI, logging and endpoint tooling, the system security plan and policy set, training, and the staff time to run it. Published practitioner ranges for a full CMMC Level 2 programme commonly run from the low tens of thousands to well over US$100,000, depending on how much of the 110 you already meet. CertAssist covers the documentation and evidence side for a flat US$225 per month as at October 2026, and does not cover the tooling, the enclave or the assessor. For a fuller breakdown, see the CertAssist guide to CMMC Level 2 cost in 2026.
CMMC Level 2 commonly takes 6 to 18 months from a standing start, and the variable is not paperwork speed, it is how much of NIST SP 800-171 your environment already satisfies. A company already running centralised identity, enforced MFA, managed endpoints and retained logs is doing a documentation exercise. A company that must first move CUI into a separate enclave is doing an infrastructure project with a compliance deliverable at the end. CMMC Level 1, by contrast, usually takes days or weeks, because the 15 requirements are mostly things an organisation already does.
A reasonable sequence for CMMC Level 2: scope the CUI boundary, run a gap assessment against all 110 requirements, remediate with the heaviest SPRS deductions first, write the system security plan as you go, then self-assess and affirm. If you are also weighing NIST SP 800-171 against the broader federal catalogue, the CertAssist note on NIST 800-171 vs 800-53 explains which applies to contractors.
CertAssist lays out the 110 CMMC Level 2 practices as a board, gives you editable policy and evidence templates against each one, and lets an assessor or prime review the evidence read-only. CertAssist connects to nothing, by design, so there is no cloud or identity provider access to grant.
That design has limits worth stating plainly. CertAssist does not scan your environment, so it cannot tell you whether multi-factor authentication is genuinely enforced on every account, and it cannot generate technical evidence you have not produced. CertAssist is not a CUI enclave and should not hold CUI itself. CertAssist is not a C3PAO and cannot assess or certify anyone, and no software product removes the need for an independent assessment where one is required. If you need continuous technical monitoring across a large estate, a platform with deep integrations will serve you better.
CertAssist lays out every CMMC Level 2 practice with editable policy and evidence templates, and gives your assessor read-only access, for a flat $225 a month. No integrations, so nothing to connect.
See pricing FrameworksHow many CMMC levels are there?
There are three CMMC levels. Level 1 covers Federal Contract Information with 15 requirements from FAR 52.204-21. Level 2 covers Controlled Unclassified Information with all 110 requirements from NIST SP 800-171. Level 3 adds enhanced requirements for the most sensitive programs and is assessed by the government rather than a commercial assessor.
Who needs CMMC Level 1?
CMMC Level 1 applies to any Department of War contractor or subcontractor whose systems hold Federal Contract Information but no Controlled Unclassified Information. That describes a large share of the defense industrial base, including many suppliers of commercial items and services. If CUI is in scope at all, CMMC Level 2 applies instead.
Does CMMC Level 2 require an audit?
Not for new solicitations as at October 2026. Third-party CMMC Level 2 assessments by a C3PAO were suspended on 13 July 2026, so Level 2 is designated as a self-assessment. A senior company official must still affirm the result annually in SPRS, and that affirmation carries legal weight even with no external assessor.
Is CMMC Level 2 still required?
The CMMC Level 2 security requirements still apply, but third-party verification of them is suspended. DFARS 252.204-7012 and NIST SP 800-171 implementation remain in force, and Level 2 (Self) can still be designated in new contracts. The CMMC Reform Task Force reported in September 2026 and its recommendations were unpublished at the time of writing.
How many CMMC Level 2 controls are there?
CMMC Level 2 has 110 security requirements, taken directly from NIST SP 800-171, across 14 control families. Those 110 requirements break down into 320 assessment objectives, and an assessment is scored against the objectives rather than the requirements, which is why 320 is the number that matters in practice.
Flat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.