If you’re a defense contractor or subcontractor, chances are you’ve been hearing more and more about the Cybersecurity Maturity Model Certification, or CMMC. It’s the Department of Defense’s (DoD) framework for making sure every company in the Defense Industrial Base (DIB) protects government data at the level it deserves.
Here’s the problem: between acronyms like FCI, CUI, NIST 800-171, and C3PAO assessments, it’s easy to get lost in the jargon. The question we hear most often from clients sums it up perfectly:
“What CMMC level do we actually need?”
The answer isn’t one-size-fits-all. It depends on two things—the type of information you handle and what your contract says. Let’s walk through how to figure that out.
Step One: Know What Kind of Data You Handle
CMMC requirements start with two categories of data: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
FCI is information that’s provided by or generated for the government under a contract but isn’t meant for public release. Think of it as the everyday details of doing business with the DoD—project timelines, internal correspondence, schedules, and so on. The handling of FCI is covered under FAR 52.204-21.
CUI, on the other hand, involves more sensitive material. Laws, regulations, or government-wide policies require it to be protected with added safeguards. That might include technical drawings, specifications, or export-controlled data. You can find the official definition in 32 CFR § 2002.4(h) and the DoD’s CUI guidance.
If your organization works only with FCI, you’ll most likely fall under CMMC Level 1. Handling CUI? That moves you into Level 2, or for the rare, highly sensitive programs, Level 3.
Keep in mind: CMMC requirements flow down to subcontractors. If your prime contractor shares CUI with you, you have to meet the same level they do. It’s not optional.
The Current CMMC Framework: Three Levels
When CMMC first rolled out, it included five levels. The current version, CMMC 2.0, streamlined that to three, making the model easier to understand and apply.
| Level | What It Covers | Assessment Type | Core Standard | Typical Use Case |
| Level 1 – Foundational | Basic safeguarding of FCI | Annual self-assessment and affirmation | FAR 52.204-21 | Contractors handling only FCI |
| Level 2 – Advanced | Protection of CUI | Self-assessment or third-party certification by a C3PAO, depending on the contract | NIST SP 800-171 | Most defense contractors and subcontractors |
| Level 3 – Expert | Enhanced protection for critical programs | DoD-led DIBCAC assessment | NIST SP 800-172 | Select, high-sensitivity contracts |
Level 1 covers 17 basic practices. Level 2 expands to all 110 controls in NIST SP 800-171. Level 3 adds a handful of the more advanced requirements from NIST SP 800-172. (DoD CIO, CMMC Model Overview v2.0, Dec 2021)
How to Match Your Situation to a Level
A practical way to think about CMMC levels is by asking what kind of data lives in your systems:
- Level 1: You deal with FCI only. You’ll perform an annual self-assessment, upload the score to the Supplier Performance Risk System (SPRS), and affirm compliance each year.
- Level 2: You handle CUI. Your contract will say whether you can self-assess or need a C3PAO (CMMC Third-Party Assessment Organization) certification. Assessments typically recur every three years.
- Level 3: You’re supporting a critical national security program, so the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) will perform the assessment directly.
When in doubt, read your clauses.
- DFARS 252.204-7012 indicates you’re working with CUI and must follow NIST SP 800-171.
- DFARS 252.204-7021 establishes which CMMC level is required for award eligibility.
Before You Bid: A Quick Readiness Check
Before spending time and money preparing a proposal, take an honest look at your current posture:
- Does the solicitation include DFARS 252.204-7021? If so, CMMC applies.
- Does it reference CUI or “covered defense information”? That points to Level 2 or higher.
- Have you already submitted a NIST SP 800-171 score in SPRS? (That’s now required for most DoD contracts.)
- Does the solicitation specify Level 2 (self) or Level 2 (C3PAO required)?
- Do your subcontractors handle FCI or CUI? Their systems must meet the same standard.
- Can you clearly define where CUI resides? Sometimes setting up a separate, secure enclave is more practical than locking down your entire enterprise network.
Getting this clarity early helps avoid compliance gaps that can derail a bid. DoD contracting officers increasingly check SPRS scores and CMMC status before awarding or extending contracts.
Building a Realistic Roadmap
Once you’ve identified your level, you can start mapping out next steps.
- Classify your data. Confirm whether you handle FCI, CUI, or both.
- Confirm the required level and assessment type. The solicitation will tell you.
- Run a gap assessment. Compare your systems to the controls in NIST SP 800-171 or FAR 52.204-21.
- Document your findings. Develop a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) for anything not yet complete.
- Post your score. Level 2 organizations must submit their SPRS score before award.
- Close the gaps. If you’ve received conditional approval, you usually have 180 days to resolve remaining items.
- Plan for recurring assessments. Expect annual affirmations and triennial reassessments depending on your level.
Treating CMMC like a phased project with owners, milestones, and documentation keeps it manageable and prevents last-minute scrambles.
When It’s Time to Ask for Help
Many contractors eventually realize they need outside support. Bringing in a CMMC consultant can make a world of difference if:
- You’re not sure whether specific data counts as CUI.
- Your SPRS score is low and you need to prioritize fixes.
- You’re facing a C3PAO audit or preparing for DIBCAC review.
- You’d rather build a secure enclave than harden every system.
- You rely on multiple subcontractors or cloud providers that also handle CUI.
A qualified cybersecurity partner will start with a gap review, outline a readiness plan, and guide you through remediation so you can focus on running your business instead of deciphering compliance jargon.
Final Thoughts
CMMC isn’t just another government checkbox. It’s about keeping the information that supports our national defense safe and keeping your organization eligible to compete.
By understanding the kind of data you manage, reading your contracts carefully, and building a realistic action plan, you can move through CMMC confidently and position your company for long-term success in the DoD supply chain.
🟢 Need help figuring out which level applies to your business or how to get ready for your assessment? Book a consult to map your scope, score your readiness, and plan your next steps.
FAQs
- Does my industry determine my CMMC level?
- No. Your contract language and the type of data you handle determine your level—not your industry category.
- How often do we need to reassess?
- Level 1 requires an annual self-attestation.
- Level 2 requires a triennial assessment (self or C3PAO) with yearly affirmations.
- Level 3 involves a DoD-led review every three years.
- What if we’re almost compliant but not quite there?
- The DoD may allow a temporary or “conditional” status with an approved POA&M, but all open items must be closed within 180 days to maintain eligibility.
🟢 For more detail on CMMC preparation, visit our CMMC Compliance Services page.