Last updated: 2026-08-13 · Jurisdiction: United States (32 CFR Part 170, FAR 52.204-21)
CMMC Level 1 vs Level 2
CMMC Level 1 and Level 2 are different programs, not two sizes of the same one. Level 1 protects Federal Contract Information under FAR 52.204-21. Level 2 protects Controlled Unclassified Information under NIST SP 800-171 Revision 2. They use different assessors and different POA&M rules. Treating Level 1 as “baby Level 2” is how a contractor books the wrong assessment and fails the right contract.
The short version
If the system holds FCI and not CUI, you are in Level 1: 15 security requirements from FAR 52.204-21, an annual self-assessment, no POA&M, no C3PAO. If the system holds CUI, you are in Level 2: the 110 requirements of NIST SP 800-171 Revision 2 (not Revision 3), a C3PAO or a specified self-assessment, and the POA&M bars in 32 CFR 170.21. The contract assigns the status. Status note, checked 13 August 2026: on 13 July 2026 DoD suspended Phase II, so new designations are Level 1 (Self) or Level 2 (Self). Phase I self-assessments, DFARS 252.204-7012, and NIST 800-171 Rev. 2 remain in force. ISMS Copilot drafts the SSP and the POA&M. It is not FedRAMP authorized. Keep CUI out of chats.
Why “which level?” is the wrong first question
Teams ask for a level the way they ask for a t-shirt size. The CMMC Program at 32 CFR Part 170 does not work that way. The information on the system selects the program. The contract writes the required CMMC Status. The assessment machine (self, C3PAO, or, later, DIBCAC at Level 3) is a consequence, not a preference.
Level 3 is a third program (selected NIST SP 800-172 requirements, DCMA DIBCAC). It is not a larger Level 2, and it is not the decision this page is for. Most contractors choosing between Level 1 and Level 2 can ignore it until a solicitation names it.
Level 1 and Level 2, side by side
The useful comparison is not maturity. It is information, source document, assessor, cycle, and whether a POA&M is even legal.
| Dimension | Level 1 | Level 2 |
|---|---|---|
| Information | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Source document | FAR 52.204-21(b)(1)(i) through (xv) | NIST SP 800-171 Revision 2 (not Revision 3) |
| How many requirements | 15 security requirements from FAR 52.204-21 | 110 requirements in 14 families |
| Who assesses | The Organization Seeking Assessment, annually (32 CFR 170.15) | Self-assessment when the contract specifies 32 CFR 170.16, or a C3PAO when it specifies 32 CFR 170.17 |
| Cycle | Annual self-assessment and annual affirmation | Three-year assessment cycle and annual affirmation (32 CFR 170.22) |
| POA&M | Never permitted (32 CFR 170.21(a)(1)) | Conditional status only inside the 32 CFR 170.21 bars, closed in 180 days |
| What it is not | Not a starter kit for Level 2, and not a C3PAO event | Not 800-171 Revision 3, and not FedRAMP |
Version and jurisdiction stamp: the rows paraphrase 32 CFR 170.14 through 170.22 and FAR 52.204-21 as currently published. NIST SP 800-171 Revision 2 is cited by identifier only. Checked 2026-08-13.
How to tell which program you are in
- 1
Name the information first: FCI or CUI
The split is not “how mature is our security.” It is “what information sits on this system.” Federal Contract Information (FCI) is information not intended for public release that the Government provides, or that you generate, under a contract to develop or deliver a product or service to the Government (FAR 52.204-21). Controlled Unclassified Information (CUI) is unclassified information the Government creates or possesses, or that a contractor creates or possesses for the Government, that a law, regulation, or government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls (32 CFR Part 2002). Level 1 is the FCI program. Level 2 is the CUI program. If the contract never places CUI on your system, Level 2 is the wrong program. If it does, Level 1 is not a cheaper substitute.
- 2
Read the CMMC status the contract actually assigned
32 CFR Part 170 does not invite you to pick a level because it sounds serious. The solicitation and the resulting contract specify the required CMMC Statusfor the contractor information system that will process, store, or transmit the FCI or CUI. Flow-down under 32 CFR 170.23 can put a different status on a subcontractor than the prime holds, because the subcontractor only has to meet the level that matches the information it actually receives. Guessing from headcount, from a competitor's slide, or from a consultant who sells Level 2 to everyone is how teams book a C3PAO for an FCI-only contract, or self-attest a CUI program the contract already assigned to a certified third party.
- 3
Treat Level 1 as FAR 52.204-21, not as a small Level 2
Level 1 is the basic safeguarding program already sitting in FAR 52.204-21. The CMMC Model takes the 15 paragraphs at 52.204-21(b)(1)(i) through (xv) and expresses them as 15 security requirements (32 CFR 170.14(c)(2)). Assessment is an annual self-assessment and affirmation under 32 CFR 170.15. Results go in SPRS. A Plan of Action and Milestones is not permitted at any time (32 CFR 170.21(a)(1)). There is no C3PAO at Level 1. There is no 110-requirement catalogue hiding underneath, and there is no Conditional status to buy time. Either the 15 security requirements are MET, or you do not have Level 1 status.
- 4
Treat Level 2 as NIST SP 800-171 Revision 2, not Revision 3
Level 2 security requirements are identical to NIST SP 800-171 Revision 2: 110 requirements in 14 families (32 CFR 170.14(c)(3)). The CMMC Program incorporates Revision 2 by reference at 32 CFR 170.2. NIST has published Revision 3. That is a different document. It is not what a Level 2 assessment measures. Mapping to Revision 3, or buying a vendor product that has already moved its catalogue to r3, is a different program of work than the one 32 CFR Part 170 assesses. Do the Revision 2 implementation. Track Revision 3 as a future change, not as this year's score.
- 5
Pick the Level 2 assessment path the contract specified
Level 2 has two assessment machines, and they are not the same product. 32 CFR 170.16 is a Level 2 self-assessment and affirmation, used when the contract specifies that path (typically for CUI that DoD has not designated as requiring a certified third party). 32 CFR 170.17 is a Level 2 certification assessment by an authorized or accredited C3PAO, used when the contract specifies that path. Both sit on a three-year cycle with an annual affirmation under 32 CFR 170.22. They are not interchangeable. A thorough self-assessment does not become a certification, and a C3PAO engagement is wasted money on a contract that only asked for 170.16. Read the clause. Then book the matching machine.
- 6
Apply the 32 CFR 170.21 POA&M bars before you write a POA&M
This is the mechanic people import from a generic 800-171 program and then fail. Level 1 never gets a POA&M. Level 2 can reach Conditionalstatus with a POA&M only if every condition in 32 CFR 170.21(a)(2) is met: the assessment score divided by 110 is at least 0.8; no leftover requirement is worth more than one point under 32 CFR 170.24 (with a narrow exception for SC.L2-3.13.11 when encryption is employed but is not FIPS-validated); and none of six named requirements is on the list: AC.L2-3.1.20 (external connections), AC.L2-3.1.22 (control public information), CA.L2-3.12.4 (system security plan), PE.L2-3.10.3 (escort visitors), PE.L2-3.10.4 (physical access logs), and PE.L2-3.10.5(manage physical access). Conditional status expires in 180 days if the closeout assessment does not land (32 CFR 170.21(b)). A POA&M is not a parking lot.
Draft the pack. Do not put CUI in the chat.
ISMS Copilot drafts System Security Plans, POA&M language, and implementation statements against FAR 52.204-21 and NIST SP 800-171 Revision 2. It is not FedRAMP authorized and it does not issue a CMMC Status. Keep CUI, CDI, and export-controlled technical data out of chats. The assessment still belongs to you, to a C3PAO, or to DCMA DIBCAC.
Five mistakes that collapse the two programs into one
Treating Level 1 as a smaller Level 2
Different information, different source document, different assessor, different POA&M rule. Padding a Level 1 program with extra policies does not produce a Level 2 status, and skipping Level 1 practices because 'we are going for Level 2 anyway' fails the FCI contract you already have.
Assessing Level 2 against NIST 800-171 Revision 3
32 CFR 170.14(c)(3) is explicit: Level 2 is identical to Revision 2. Revision 3 is a published NIST document and a future change, not this assessment.
Booking a C3PAO because it feels more official
32 CFR 170.16 and 170.17 are assigned by the contract. A self-assessment contract does not become a certification because you paid a C3PAO. A certification contract is not satisfied by a thorough SPRS entry.
Writing a POA&M the way a generic 800-171 program allows
Level 1 never gets one. Level 2 gets Conditional status only if the score is at least 80 percent, high-value leftovers stay off the list, and the six named requirements are already MET. The 180-day closeout is a deadline, not a target.
Putting CUI in a tool that is not authorized to hold it
Drafting an SSP is not the same as processing CUI. ISMS Copilot is not FedRAMP authorized. Keep CUI, CDI, and export-controlled technical data out of chats. The documentation can live here. The information cannot.
Where this page sits in the CMMC cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Separate Level 1 from Level 2 so a person (or an AI answer) stops treating them as sizes | Long-form how-to |
| CMMC framework page | Product-oriented overview of CMMC documentation with ISMS Copilot. Not FedRAMP. No CUI in chats. | Framework hub |
| NIST 800-171 framework page | The 110-requirement catalogue Level 2 assesses, plus SSP and POA&M drafting | Framework hub |
| US federal contractors | How DIB teams use the product for documentation, never for the CUI itself | Audience page |
| US region hub | SOC 2, HIPAA, NIST, CMMC, and CCPA as the US work | Region hub |
Frequently asked questions
Is CMMC Level 2 just a bigger CMMC Level 1?
No. They protect different information, cite different source documents, use different assessment machinery, and treat POA&Ms differently. Level 1 is FCI and FAR 52.204-21 (15 security requirements, annual self-assessment, no POA&M). Level 2 is CUI and NIST SP 800-171 Revision 2 (110 requirements, C3PAO or a specified self-assessment, Conditional status only inside the 32 CFR 170.21 bars). Adding more policies to a Level 1 program does not produce a Level 2 status.
Does CMMC Level 2 assess NIST 800-171 Revision 3?
No. 32 CFR 170.14(c)(3) states that Level 2 security requirements are identical to NIST SP 800-171 Revision 2, which 32 CFR 170.2 incorporates by reference. Revision 3 is a published NIST document. It is not the CMMC Level 2 assessment baseline. Do not let a vendor catalogue that has moved to r3 set this year's score.
When is a Level 2 self-assessment enough, and when do I need a C3PAO?
When the contract says so. 32 CFR 170.16 is the self-assessment path. 32 CFR 170.17 is the C3PAO certification path. DoD assigns the path in the solicitation based on the CUI and the program. They are not interchangeable, and a detailed self-assessment does not become a 170.17 certification.
Which Level 2 requirements can never go on a POA&M?
Under 32 CFR 170.21(a)(2)(iii): AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. Level 1 never gets a POA&M. Open Level 2 POA&M items must close within 180 days or Conditional status expires.
Where does Level 3 fit?
Level 3 is a third program, not a larger Level 2. It adds selected requirements from NIST SP 800-172 (February 2021), with DoD-assigned organization-defined parameters, and it is assessed by DCMA DIBCAC (32 CFR 170.14(c)(4) and 170.18). Most contractors who are choosing between Level 1 and Level 2 are not in that program yet.
Will ISMS Copilot store CUI or get us a CMMC status?
No. ISMS Copilot drafts System Security Plans, POA&Ms, and implementation statements. It is not FedRAMP authorized and it is not on a DoD CC SRG approved list. Do not paste CUI, CDI, or export-controlled technical data into chats. A C3PAO or the Organization Seeking Assessment still performs the assessment. See /for/us-federal-contractors and /frameworks/cmmc.
Primary sources
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR, current): the CMMC Model at 170.14, Level 1 self-assessment at 170.15, Level 2 self-assessment at 170.16, Level 2 certification assessment at 170.17, scoping at 170.19, POA&M rules at 170.21, affirmation at 170.22, and subcontractor flow-down at 170.23. www.ecfr.gov (checked 2026-08-13).
- 32 CFR 170.21, Plan of Action and Milestones requirements: no POA&M at Level 1, Conditional Level 2 score and named-barred requirements, 180-day closeout. www.ecfr.gov (checked 2026-08-13).
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (48 CFR 52.204-21): the 15 basic safeguarding requirements at (b)(1)(i) through (xv) that 32 CFR 170.14(c)(2) adopts as CMMC Level 1, and the definition of Federal Contract Information. www.ecfr.gov (checked 2026-08-13).
- NIST SP 800-171 Revision 2 (updated 28 January 2021), Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations: the 110-requirement catalogue that 32 CFR 170.14(c)(3) makes identical to CMMC Level 2. Official identifiers and abstract only; NIST text is not reproduced here. csrc.nist.gov (checked 2026-08-13).
- Department of Defense, CMMC Program final rule, 89 FR 83092 (15 October 2024), the rule that established 32 CFR Part 170. www.federalregister.gov (checked 2026-08-13).
Written and maintained by the ISMS Copilot team. Last reviewed 2026-08-13.
This page paraphrases the structure of 32 CFR Part 170 and FAR 52.204-21 (public US regulatory text) in original wording. NIST SP 800-171 Revision 2 is cited by identifier only; official NIST publication text is not reproduced. It is educational content, not legal advice and not a CMMC assessment. ISMS Copilot drafts SSPs and POA&Ms. It is not FedRAMP authorized and it is not a place to store CUI.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
