Menu

CMMC 2.0 Levels Explained: Are You Ready for DoD Contract Compliance?

CMMC 2.0 Levels Explained: Are You Ready for DoD Contract Compliance?

Learn about CMMC 2.0 Levels 1, 2, and 3, certification requirements, compliance steps, assessment process, costs, and how to prepare for DoD contract eligibility.

For years, cybersecurity has been a growing concern across the U.S. defense industrial base. Defense contractors, subcontractors, and technology providers routinely handle sensitive government information, making them attractive targets for cybercriminals and nation-state attackers. A single security breach can expose valuable defense data, disrupt critical supply chains, and compromise national security.

Recognizing these risks, the U.S. Department of Defense (DoD) introduced the Cybersecurity Maturity Model Certification (CMMC) to establish consistent cybersecurity expectations for organizations working within the defense supply chain. The updated CMMC 2.0 model simplifies the original framework while maintaining a strong focus on protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

Today, understanding the CMMC 2.0 levels is no longer optional for organizations pursuing or maintaining DoD contracts. The certification level required depends on the sensitivity of the information an organization handles and the type of defense work it performs.

Whether you're a prime contractor, subcontractor, software provider, manufacturer, engineering firm, or managed service provider, meeting the applicable CMMC certification requirements is becoming an essential part of DoD contractor compliance.

In this article, we'll explain the three CMMC 2.0 levels, explore the requirements for each level, and discuss how organizations can prepare for certification while strengthening their cybersecurity posture.

Understanding the Three CMMC 2.0 Levels

One of the biggest changes introduced under CMMC 2.0 was the simplification of the maturity model. The original CMMC framework contained five maturity levels. Under CMMC 2.0, those five levels have been consolidated into three clearly defined certification levels. These CMMC Level 1 2 3 categories align cybersecurity expectations with the sensitivity of federal information processed by the organization.

Each level builds upon the previous one by introducing increasingly comprehensive cybersecurity practices and assessment requirements.

At a high level:

  • Level 1 protects Federal Contract Information (FCI).

  • Level 2 protects Controlled Unclassified Information (CUI).

  • Level 3 applies to organizations handling the most sensitive CUI associated with critical national security programs.

Rather than requiring every contractor to satisfy the highest level of cybersecurity, the DoD uses this risk-based approach to ensure that security expectations are proportionate to the information being protected. Selecting the appropriate level is determined by contract requirements rather than organizational preference.

Level 1 Compliance Requirements

CMMC Level 1 represents the foundational level of the framework. It applies primarily to organizations that process, store, or transmit Federal Contract Information (FCI) but do not handle Controlled Unclassified Information. Federal Contract Information refers to information provided by or generated for the government under a contract that is not intended for public release. Although Level 1 represents the entry point into the framework, it still requires organizations to establish basic cybersecurity practices capable of protecting government information.

What Are the CMMC Certification Requirements for Level 1?

Level 1 is based on the cybersecurity requirements contained in FAR 52.204-21, consisting of 15 fundamental security practices. These practices address basic cyber hygiene across areas such as:

  • Access control

  • User authentication

  • Physical security

  • Device protection

  • Information handling

  • System maintenance

Examples include limiting access to authorized users, controlling physical access to systems, updating software, protecting devices from unauthorized use, and safeguarding information during transmission. Unlike the higher levels, Level 1 organizations generally perform an annual self-assessment and submit compliance affirmations rather than undergoing mandatory third-party certification. However, organizations must still maintain documented evidence demonstrating that required security practices are consistently applied.

Who Typically Needs Level 1?

Organizations commonly requiring Level 1 include:

  • Small subcontractors

  • Product suppliers

  • Manufacturers providing commercial products

  • Service providers handling limited federal information

  • Vendors supporting low-risk defense contracts

Although the requirements are comparatively straightforward, establishing strong cybersecurity fundamentals creates a solid foundation for future maturity if business opportunities later require higher CMMC 2.0 levels.

Level 2 Compliance Requirements

CMMC Level 2 is expected to become the most common certification level across the Defense Industrial Base. It applies to organizations that create, process, store, or transmit Controlled Unclassified Information (CUI). CUI includes sensitive government information that requires safeguarding but is not classified.

Examples may include:

  • Engineering drawings

  • Technical specifications

  • Procurement information

  • Manufacturing data

  • Defense research

  • Controlled technical information

Because CUI presents greater cybersecurity risks than FCI, organizations pursuing Level 2 must establish significantly more comprehensive security controls.

CMMC Certification Requirements for Level 2

Level 2 aligns directly with NIST SP 800-171. Organizations are expected to satisfy all 110 security requirements contained within that standard. These controls cover numerous cybersecurity domains, including:

  • Access control

  • Awareness and training

  • Audit and accountability

  • Configuration management

  • Identification and authentication

  • Incident response

  • Maintenance

  • Media protection

  • Personnel security

  • Physical protection

  • Risk assessment

  • Security assessment

  • System and communications protection

  • System integrity

Unlike Level 1, many Level 2 organizations will require an independent assessment conducted by a Certified Third-Party Assessment Organization (C3PAO), depending on contract requirements. Organizations should also maintain comprehensive documentation demonstrating that cybersecurity controls operate effectively in practice rather than existing solely as written policies.

Why Level 2 Is So Important

For many defense contractors, achieving Level 2 represents a significant business milestone. Without demonstrating compliance with applicable CMMC certification requirements, organizations may become ineligible to compete for contracts involving Controlled Unclassified Information. As a result, Level 2 has become a central focus of DoD contractor compliance strategies across the defense supply chain.

Comparing CMMC Level 1 and Level 2

Although both certification levels strengthen an organization's cybersecurity posture, they differ significantly in their scope, requirements, and intended purpose.

  • CMMC Level 1

CMMC Level 1 focuses on establishing basic cyber hygiene practices to protect Federal Contract Information (FCI). It is intended for organizations that handle FCI but do not process Controlled Unclassified Information (CUI). The requirements are relatively straightforward and emphasize the implementation of fundamental cybersecurity controls.

  • CMMC Level 2

CMMC Level 2 is designed for organizations that store, process, or transmit Controlled Unclassified Information (CUI). It requires a more mature cybersecurity program aligned with NIST SP 800-171, with greater emphasis on governance, risk management, documentation, and the consistent operation of security controls.

  • Key Differences

Compared to Level 1, CMMC Level 2 requires organizations to implement more advanced cybersecurity practices, including formal risk management, security monitoring, incident response planning, multi-factor authentication, continuous improvement, documented policies, governance processes, and ongoing security awareness initiatives. As a result, achieving Level 2 generally requires a greater investment of time, resources, and organizational commitment.

  • Choosing the Right Level

Organizations should determine the appropriate certification level based on their contractual obligations and the type of government information they handle. Understanding where they fit within the CMMC Level 1, 2, and 3 model enables them to allocate resources effectively and develop a structured CMMC compliance checklist that aligns with applicable DoD requirements.

Level 3 Compliance Requirements

CMMC Level 3 represents the highest of the three CMMC 2.0 levels and is intended for organizations that support the U.S. Department of Defense's most sensitive programs. It applies to contractors handling high-value Controlled Unclassified Information (CUI) where the risk of sophisticated cyber threats is significantly greater.

Unlike Level 2, which aligns with the security requirements of NIST SP 800-171, Level 3 introduces additional cybersecurity measures derived from NIST SP 800-172. These enhanced requirements are designed to strengthen an organization's ability to defend against Advanced Persistent Threats (APTs) and other highly capable adversaries. Organizations operating at this level are expected to demonstrate mature cybersecurity governance across both technical and operational areas.

Key focus areas include:

  • Advanced threat detection

  • Enhanced access control

  • Security architecture

  • Continuous monitoring

  • Incident response capabilities

  • Supply chain risk management

  • Cyber resilience

  • Configuration management

  • Vulnerability management

Unlike Level 1 self-assessments and many Level 2 third-party assessments, Level 3 assessments are conducted by the U.S. Department of Defense or organizations specifically authorized by the DoD. Because of the additional security expectations, Level 3 generally requires the greatest investment in people, technology, and governance. Fortunately, only a relatively small portion of the Defense Industrial Base is expected to require this certification level.

Benefits of CMMC Compliance

Although many organizations initially pursue certification because it is required for federal contracts, the value of CMMC extends well beyond contract eligibility. Meeting the applicable CMMC certification requirements often strengthens cybersecurity across the entire organization while improving operational resilience and customer confidence.

  • Improved Eligibility for DoD Contracts

Maintaining the appropriate CMMC certification level is essential for organizations that wish to compete for current and future Department of Defense (DoD) contracts. As CMMC requirements become integrated into DoD procurement processes, contractors without the required certification may no longer qualify to bid on projects involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). For many organizations, achieving compliance is becoming a fundamental business requirement rather than simply a competitive advantage.

  • Stronger Cybersecurity

CMMC encourages organizations to implement a structured and comprehensive cybersecurity program. By strengthening areas such as access control, risk assessment, incident response, vulnerability management, and continuous security monitoring, organizations can reduce their exposure to cyber threats and improve their ability to detect, respond to, and recover from security incidents.

  • Increased Customer Confidence

A mature cybersecurity program demonstrates an organization's commitment to protecting sensitive information. While CMMC is designed for the defense sector, the practices it promotes can also strengthen relationships with commercial customers, many of whom now assess suppliers based on their cybersecurity maturity. Certification helps reinforce trust and provides greater assurance that information is being managed securely.

  • Better Risk Management

CMMC promotes a proactive approach to cybersecurity by encouraging organizations to identify, assess, and address risks before they lead to security incidents. Establishing consistent governance, risk management, and monitoring processes enables organizations to respond more effectively to emerging threats while supporting long-term operational resilience.

  • Competitive Differentiation

Organizations that achieve CMMC compliance can demonstrate a higher level of cybersecurity maturity within the defense supply chain. This can position them as more reliable and trusted partners for prime contractors and government agencies, strengthening business relationships and improving opportunities to participate in future defense programs.

How to Prepare for CMMC 2.0 Certification

Preparing for CMMC 2.0 certification requires more than implementing technical security controls. Organizations must integrate cybersecurity into governance, operational processes, and day-to-day decision-making. A structured CMMC compliance checklist provides a practical framework for organizing preparation activities and ensuring readiness for assessment.

  • Determine Your Required CMMC Level

The first step is identifying which CMMC level applies to your organization based on the type of government information you handle. Organizations that process only Federal Contract Information (FCI) may require a different certification level than those handling Controlled Unclassified Information (CUI). Determining the appropriate level early enables organizations to allocate resources effectively, prioritize cybersecurity investments, and build a compliance strategy aligned with their contractual obligations.

  • Define the Assessment Scope

A clearly defined assessment scope helps organizations focus their compliance efforts while avoiding unnecessary complexity during certification. The scope should include systems that process or store Federal Contract Information (FCI), systems handling Controlled Unclassified Information (CUI), supporting infrastructure, cloud environments, third-party service providers, and all relevant users and administrative accounts. Establishing these boundaries early ensures that all applicable assets are included in the assessment without unnecessarily expanding its scope.

  • Evaluate Existing Security Controls

Before pursuing certification, organizations should conduct a comprehensive review of their existing cybersecurity program against the applicable CMMC requirements. This evaluation should cover areas such as access management, multi-factor authentication (MFA), security policies, incident response capabilities, asset inventories, configuration management, risk assessments, security monitoring, and employee training programs. Identifying gaps at this stage allows organizations to strengthen their security posture and address deficiencies before the formal assessment begins.

  • Prepare Documentation

Documentation is a critical component of the certification process because assessors rely on objective evidence to verify that cybersecurity practices are implemented consistently. Organizations should maintain accurate and up-to-date records, including information security policies, risk assessments, asset inventories, incident response procedures, configuration management records, training records, audit logs, and change management documentation. Well-organized documentation not only simplifies the assessment process but also demonstrates the maturity and effectiveness of the organization's cybersecurity program.

  • Promote Security Awareness

Technology alone cannot protect sensitive government information without informed and responsible employees. Organizations should provide regular security awareness training that helps personnel understand their cybersecurity responsibilities, follow strong password management practices, recognize phishing and other social engineering attacks, report security incidents promptly, and handle sensitive government information appropriately. Building a strong security culture reduces human-related risks while reinforcing compliance across everyday business operations.

  • Plan for Long-Term Compliance

CMMC certification should be viewed as the beginning of an ongoing cybersecurity journey rather than a one-time milestone. As cyber threats continue to evolve, organizations should establish processes for continuous monitoring, vulnerability management, periodic policy reviews, internal assessments, and continual improvement. Embedding cybersecurity into everyday operations helps maintain compliance over time, supports future reassessments, and strengthens the organization's overall resilience against emerging threats.

Understanding CMMC Certification Cost

One of the most common questions organizations ask when planning for compliance is how much CMMC certification will cost. There is no fixed certification fee because the overall investment varies significantly from one organization to another. Factors such as the required CMMC level, organizational size, number of employees, complexity of IT systems, existing cybersecurity maturity, assessment scope, third-party assessment requirements, technology upgrades, and the quality of existing documentation all influence the total cost of certification.

For many organizations, the largest expense is not the certification assessment itself but the effort required to strengthen cybersecurity controls and address compliance gaps before the assessment takes place. Investments may include implementing new security technologies, updating policies and procedures, improving documentation, enhancing employee training, and remediating identified vulnerabilities to meet the applicable CMMC certification requirements.

Rather than viewing CMMC certification solely as a compliance cost, many defense contractors consider it a long-term strategic investment. Beyond maintaining eligibility for Department of Defense contracts, certification helps improve cybersecurity resilience, reduce operational and regulatory risks, build customer confidence, and strengthen an organization's position within the defense industrial base. Over time, these benefits can deliver value that extends well beyond the initial investment required to achieve certification.

Securing Defense Supply Chains with CMMC 2.0 

The CMMC 2.0 levels provide a structured framework that aligns cybersecurity expectations with the sensitivity of the information contractors handle, ensuring that security measures are proportionate to operational risk.

Whether your organization requires CMMC Level 1 2 3, understanding the applicable CMMC certification requirements, developing a practical CMMC compliance checklist, and strengthening overall DoD contractor compliance are essential steps toward maintaining eligibility for future defense contracts. While the CMMC certification cost varies depending on organizational complexity and assessment scope, investing in mature cybersecurity governance delivers long-term value far beyond regulatory compliance.

For organizations seeking independent certification against internationally recognized management system and cybersecurity standards, INTERCERT provides accredited certification services across information security, privacy, quality, environmental, and governance frameworks. Through impartial certification activities, organizations can demonstrate conformity with globally recognized standards, reinforcing confidence among customers, regulators, defense partners, and other stakeholders while strengthening long-term organizational resilience.

Read More:
CMMC Phase 2: What Defense Contractors Need to Know
What Is CMMC 2.0? A Guide to CMMC Compliance Requirements for Defense Contractors

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved