Audit

CMMC Level 1 vs Level 2: requirements, cost and which one you need

2 October 2026 · 9 min read · CertAssist

Which CMMC level your contract calls for, what each one asks you to implement, what the assessment costs, and what the July 2026 suspension changed.

CMMC Level 1 applies when your contract involves Federal Contract Information only. It asks for the 15 basic safeguarding requirements in FAR clause 52.204-21, confirmed by an annual self-assessment. CMMC Level 2 applies when you create, store, process or transmit Controlled Unclassified Information, and asks for all 110 security requirements in NIST SP 800-171, measured across 320 assessment objectives. Since 13 July 2026, new Department of War solicitations can designate only Level 1 (Self) or Level 2 (Self), because third-party Level 2 assessments are suspended pending a program review.

Side by side comparison of CMMC Level 1 and CMMC Level 2 showing Level 1 with 15 security requirements from FAR 52.204-21 protecting Federal Contract Information, and Level 2 with 110 security requirements from NIST SP 800-171 across 14 control families and 320 assessment objectives protecting Controlled Unclassified Information

What is the difference between CMMC Level 1 and CMMC Level 2?

The difference between CMMC Level 1 and CMMC Level 2 is the sensitivity of the information you hold, and everything else follows. CMMC Level 1 protects Federal Contract Information, which is information generated for or provided by the government under a contract and not intended for public release. CMMC Level 2 protects Controlled Unclassified Information, which carries specific safeguarding obligations under law, regulation or government-wide policy. Because CUI is more sensitive, CMMC Level 2 requires roughly seven times as many security requirements, formal documentation rather than informally performed practices, and a system security plan showing how each is met.

 CMMC Level 1CMMC Level 2
Information protectedFederal Contract Information (FCI)Controlled Unclassified Information (CUI)
Security requirements15, from FAR clause 52.204-21110, from NIST SP 800-171
Assessment objectivesThe NIST SP 800-171A objectives for those 15320
Control familiesA single FAR clause, not grouped14, from access control to system integrity
Documentation expectedPractices performed; no system security planSystem security plan, policies and procedures
Assessment route, October 2026Annual self-assessmentSelf-assessment; C3PAO route suspended
AffirmationAnnual, senior official, in SPRSAnnual, senior official, in SPRS
Plan of action permittedNo, every requirement must be metYes for a limited set, 180 days to close

What level of CMMC do I need?

You need CMMC Level 1 if the only government information on your systems is Federal Contract Information. You need CMMC Level 2 if Controlled Unclassified Information touches your systems at all, even if it arrives by email and is deleted the same day. The deciding question is the data, not the size of the company or the contract.

Three practical signals that CUI is in scope, and CMMC Level 2 applies:

If you cannot tell, ask the contracting officer and get the answer in writing. Guessing low is the expensive mistake, because a CMMC Level 2 programme started late is what delays an award. Guessing high spends money you may not need to.

What are the CMMC Level 1 requirements?

The CMMC Level 1 requirements are the 15 basic safeguarding requirements already in FAR clause 52.204-21, which has sat in standard federal contracts for years. They cover limiting access to authorised users and functions, controlling what gets posted publicly, sanitising media before disposal, limiting physical access, controlling network boundary connections, separating public-facing components onto their own subnetwork, correcting flaws, and protecting against malicious code.

Most organisations already do the substance of these. What CMMC Level 1 adds is the obligation to assess yourself against each one annually, record the result in the Supplier Performance Risk System, and have a senior company official affirm it. Every requirement must be met, because CMMC Level 1 allows no plan of action for anything outstanding.

What are the CMMC Level 2 requirements?

The CMMC Level 2 requirements are all 110 security requirements in NIST SP 800-171 Revision 2, grouped into 14 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

An assessor does not score those 110 requirements as a simple pass or fail. They are broken into 320 assessment objectives, each marked met, not met, or not applicable. That is why two companies can both claim multi-factor authentication and get different results: the objectives ask which accounts, which access types, and whether the evidence shows it.

CMMC Level 2 also expects documentation that CMMC Level 1 does not: a system security plan describing the boundary and how each requirement is met, policies and procedures across the 14 families, and evidence the practices run rather than merely exist on paper. A limited set of unmet requirements may sit on a plan of action and milestones, giving a conditional status and 180 days to close, as set out in 32 CFR 170.17.

Can CMMC Level 2 be self assessed?

Yes, and as at October 2026 self-assessment is the only CMMC Level 2 route being designated for new work. On 13 July 2026 the Department of War suspended Phase 2 of the CMMC program, due to begin on 10 November 2026, which would have required third-party assessments for CUI contracts. Program managers can no longer designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, and active solicitations carrying them are being amended.

What the suspension did not change matters just as much:

A CMMC Reform Task Force completed a 60 day review in September 2026, informed by a public request for information that drew more than 1,100 comments. Its recommendations had not been published when this guide was written, so treat the position as a pause rather than a repeal. A future rule is more likely to change how the requirements are verified than whether they apply.

How much does CMMC Level 1 and Level 2 cost?

The Department of Defense published its own cost estimates alongside the CMMC rule in 32 CFR Part 170. For a small entity they are roughly US$5,977 for a CMMC Level 1 self-assessment, US$37,196 over three years for a CMMC Level 2 self-assessment, and US$104,670 over three years for a CMMC Level 2 certification through a C3PAO. These are assessment costs, not programme costs.

Bar chart of the Department of Defense published CMMC assessment cost estimates for a small entity, showing about US$5,977 for a Level 1 self-assessment, US$37,196 over three years for a Level 2 self-assessment, and US$104,670 over three years for a Level 2 certification assessment by a C3PAO
Assessment pathDoD estimate, small entityPeriodWhat the figure covers
CMMC Level 1 self-assessmentAbout US$5,977AnnualInternal effort to assess the 15 requirements, submit to SPRS and affirm
CMMC Level 2 self-assessmentUS$37,196Three year cycleThe triennial self-assessment plus two annual affirmations at about US$1,459 each
CMMC Level 2 certification by a C3PAOUS$104,670Three year cyclePlanning, conduct, reporting, the C3PAO engagement and affirmations

What those figures exclude is where real CMMC budgets go: closing the gaps the assessment finds. Remediation, a CUI enclave if your environment cannot hold CUI, logging and endpoint tooling, the system security plan and policy set, training, and the staff time to run it. Published practitioner ranges for a full CMMC Level 2 programme commonly run from the low tens of thousands to well over US$100,000, depending on how much of the 110 you already meet. CertAssist covers the documentation and evidence side for a flat US$225 per month as at October 2026, and does not cover the tooling, the enclave or the assessor. For a fuller breakdown, see the CertAssist guide to CMMC Level 2 cost in 2026.

How long does CMMC Level 2 take?

CMMC Level 2 commonly takes 6 to 18 months from a standing start, and the variable is not paperwork speed, it is how much of NIST SP 800-171 your environment already satisfies. A company already running centralised identity, enforced MFA, managed endpoints and retained logs is doing a documentation exercise. A company that must first move CUI into a separate enclave is doing an infrastructure project with a compliance deliverable at the end. CMMC Level 1, by contrast, usually takes days or weeks, because the 15 requirements are mostly things an organisation already does.

A reasonable sequence for CMMC Level 2: scope the CUI boundary, run a gap assessment against all 110 requirements, remediate with the heaviest SPRS deductions first, write the system security plan as you go, then self-assess and affirm. If you are also weighing NIST SP 800-171 against the broader federal catalogue, the CertAssist note on NIST 800-171 vs 800-53 explains which applies to contractors.

When CertAssist is the wrong tool for CMMC

CertAssist lays out the 110 CMMC Level 2 practices as a board, gives you editable policy and evidence templates against each one, and lets an assessor or prime review the evidence read-only. CertAssist connects to nothing, by design, so there is no cloud or identity provider access to grant.

That design has limits worth stating plainly. CertAssist does not scan your environment, so it cannot tell you whether multi-factor authentication is genuinely enforced on every account, and it cannot generate technical evidence you have not produced. CertAssist is not a CUI enclave and should not hold CUI itself. CertAssist is not a C3PAO and cannot assess or certify anyone, and no software product removes the need for an independent assessment where one is required. If you need continuous technical monitoring across a large estate, a platform with deep integrations will serve you better.

Work through all 110 CMMC Level 2 practices in one place

CertAssist lays out every CMMC Level 2 practice with editable policy and evidence templates, and gives your assessor read-only access, for a flat $225 a month. No integrations, so nothing to connect.

See pricing Frameworks

Frequently asked questions about CMMC Level 1 and Level 2

How many CMMC levels are there?
There are three CMMC levels. Level 1 covers Federal Contract Information with 15 requirements from FAR 52.204-21. Level 2 covers Controlled Unclassified Information with all 110 requirements from NIST SP 800-171. Level 3 adds enhanced requirements for the most sensitive programs and is assessed by the government rather than a commercial assessor.

Who needs CMMC Level 1?
CMMC Level 1 applies to any Department of War contractor or subcontractor whose systems hold Federal Contract Information but no Controlled Unclassified Information. That describes a large share of the defense industrial base, including many suppliers of commercial items and services. If CUI is in scope at all, CMMC Level 2 applies instead.

Does CMMC Level 2 require an audit?
Not for new solicitations as at October 2026. Third-party CMMC Level 2 assessments by a C3PAO were suspended on 13 July 2026, so Level 2 is designated as a self-assessment. A senior company official must still affirm the result annually in SPRS, and that affirmation carries legal weight even with no external assessor.

Is CMMC Level 2 still required?
The CMMC Level 2 security requirements still apply, but third-party verification of them is suspended. DFARS 252.204-7012 and NIST SP 800-171 implementation remain in force, and Level 2 (Self) can still be designated in new contracts. The CMMC Reform Task Force reported in September 2026 and its recommendations were unpublished at the time of writing.

How many CMMC Level 2 controls are there?
CMMC Level 2 has 110 security requirements, taken directly from NIST SP 800-171, across 14 control families. Those 110 requirements break down into 320 assessment objectives, and an assessment is scored against the objectives rather than the requirements, which is why 320 is the number that matters in practice.

← Back to the blog

Powerful in its simplicity.

Flat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.