CMMC Level 1 vs. Level 2: What's the Difference?
The biggest difference is usually not company size. It is the type of federal information your business handles and the cybersecurity requirements attached to that information.
CMMC Level 1 is generally associated with protecting Federal Contract Information (FCI), while CMMC Level 2 is generally associated with protecting Controlled Unclassified Information (CUI) and involves significantly more extensive cybersecurity requirements. The biggest difference is usually not company size. It is the type of federal information your business handles and the cybersecurity requirements attached to that information.
Your required CMMC level depends on applicable contract requirements and the information your organization handles. This page is general educational guidance, not legal advice or a certification determination. Verify current requirements against official DoD CMMC guidance and your applicable contracts.
The fastest way to understand the difference
| Area | CMMC Level 1 | CMMC Level 2 |
|---|---|---|
| Primary information type | FCI | CUI |
| Security basis | Basic safeguarding requirements (FAR 52.204-21) | NIST SP 800-171-based requirements under CMMC |
| Complexity | Foundational | Substantially more extensive |
| Documentation | More limited but still important | Significant documentation and evidence expectations |
| Assessment | Verify current official requirement (self-assessment with affirmation) | Self-assessment or C3PAO assessment depending on contract and requirement |
| Typical scope | Systems handling or protecting applicable FCI | Systems handling or protecting applicable CUI plus applicable security assets |
| Planning effort | Lower relative complexity | Higher relative complexity |
Do not hard-code practice counts or assessment frequencies without verifying them against current official CMMC sources, as these can change.
Level 1 starts with FCI
Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service, subject to the applicable federal definition. It commonly appears in contracts that include the standard FAR clause for safeguarding covered defense information.
Level 1 focuses on basic safeguarding of that information under FAR 52.204-21. Level 1 is less complex than Level 2, but it still requires organizations to actually implement and verify the applicable safeguards. It is not a formality to skip.
Level 2 starts with CUI
Controlled Unclassified Information (CUI) is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official CUI Registry of categories.
Handling CUI typically drives a substantially more extensive cybersecurity obligation because the requirements attach to the information itself, not to the size of the company. A small business that handles CUI may face Level 2 requirements regardless of its number of employees.
FCI vs. CUI
Federal Contract Information (FCI)
Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service, subject to the applicable federal definition. Level 1 focuses on basic safeguarding of that information under FAR 52.204-21.
Controlled Unclassified Information (CUI)
Controlled Unclassified Information (CUI) is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official CUI Registry of categories. Handling CUI typically drives a substantially more extensive cybersecurity obligation.
Do not determine your CMMC level based only on company size, revenue, or number of employees. The information and contract requirements matter more.
Why NIST SP 800-171 matters more at Level 2
Level 2 is closely tied to the requirements of NIST SP 800-171 under the applicable CMMC framework. NIST SP 800-171 is designed to protect CUI in nonfederal systems and organizations, and CMMC Level 2 assesses implementation of those applicable security requirements.
Documentation and evidence are important because an organization must be able to demonstrate that controls are actually implemented, not simply that a policy says they exist. A policy that says a control exists is not the same as evidence that the control actually operates.
Be careful about NIST revision references. Verify which revision of NIST SP 800-171 currently applies under the applicable CMMC and DoD rules before relying on any specific control wording. Do not mix revision 2 and revision 3 requirements without explicitly explaining applicability.
CMMC Level 2 aligns with NIST SP 800-171. The official NIST publication is the authoritative source for the underlying security requirements. Verify the current revision before acting on any specific control.
The assessment difference
For Level 1, describe the current self-assessment and affirmation requirements based on official DoD guidance. Under current CMMC rules, Level 1 involves an annual self-assessment with an annual affirmation by a company executive.
For Level 2, some organizations may be subject to self-assessment while others may require an authorized C3PAO assessment depending on the applicable contract and requirement. Not every Level 2 obligation requires a C3PAO assessment. Verify the current requirement for your specific situation against official DoD CMMC guidance.
Titan can help prepare a business for assessment, but Titan does not issue CMMC certifications. Unless an organization holds current official C3PAO authorization, it cannot perform official CMMC certification assessments.
Level 1 vs. Level 2 in the real world
Illustrative examples. Not actual Titan clients.
Example 1: Small DoD subcontractor handling FCI
A small subcontractor receives contract-related information but does not receive or process CUI. Applicable contract language may point the company toward Level 1 requirements. Do not definitively assign Level 1 without contract review. Confirm what information you actually handle before assuming a level.
Example 2: Engineering firm handling CUI
An engineering firm receives technical information identified as CUI and stores it electronically. This likely creates a more substantial NIST SP 800-171 and CMMC Level 2 compliance obligation depending on contract requirements. The company is small, but the information it handles drives the obligation. Do not use real company names.
Level 2 is not just Level 1 with more antivirus
Level 2 can involve significantly more mature controls across many areas of the technology environment. Avoid implying that technology products alone satisfy these areas.
Level 2 is a security program, not a software bundle.
Does Level 2 mean every device in the company?
Not necessarily. Scope matters. The importance is in identifying:
Properly designed segmentation or an enclave may potentially reduce unnecessary scope, but only where the technical architecture and actual data flows support it. Do not promise scope reduction without validating the boundary against your actual environment and applicable scoping guidance.
Can a company be Level 1 today and need Level 2 later?
Yes, potentially. A business's obligations can change as new contracts are awarded, the company begins handling CUI, subcontracting requirements change, customers impose new contractual requirements, or new systems are introduced.
This is why growing defense contractors should avoid building a technology environment that will be impossible to mature later. A foundation that is easy to mature is worth more than a quick fix that creates structural debt.
What does Level 2 usually require more of?
Level 1
- Basic safeguarding
- Limited scope relative to Level 2
- Simpler documentation environment
Level 2
- More extensive technical controls
- More evidence
- More formal documentation
- More security monitoring
- More process maturity
- Greater assessment rigor
Keep these comparisons qualitative unless official sources support more specific claims.
SSP, POA&M and evidence
System Security Plan (SSP)
The SSP documents the relevant system environment and how applicable security requirements are implemented. It is more prominent in Level 2 readiness because the documentation requirements are substantially more extensive.
Plan of Action and Milestones (POA&M)
A POA&M describes how the organization plans to address requirements not yet fully implemented. Current CMMC rules may limit how POA&Ms can be used. Not every missing requirement can simply be placed on a POA&M. Verify current DoD requirements before relying on a POA&M strategy.
A policy that says a control exists is not the same as evidence that the control actually operates.
Microsoft 365: Level 1 vs. Level 2
Cloud decisions become more important when CUI is involved. This can involve Microsoft 365 Commercial, government-oriented Microsoft cloud environments, identity, MFA, email, SharePoint, OneDrive, Teams, logging, and data handling.
Do not say CMMC Level 2 always requires GCC High. The appropriate Microsoft environment depends on the organization's contract requirements, the type of CUI, export-controlled data, service requirements, and applicable federal obligations. Use official Microsoft and DoD sources for cloud compliance claims.
How much more expensive is Level 2?
There is no invented multiplier or generic project cost. Level 2 is usually more expensive and time-consuming because of greater control complexity, documentation, scope, logging and security monitoring, identity requirements, remediation, cloud architecture, professional services, and assessment requirements.
A small, well-scoped environment may be substantially easier to manage than an unnecessarily broad environment.
The cheapest way to approach CMMC is not to skip requirements. It is to understand your scope before you start buying solutions.
How do I know which level I need?
Review your contracts and flow-down requirements
Identify the cybersecurity clauses and requirements in your DoD contracts and any flow-down requirements from primes.
Identify whether you handle FCI
Determine whether your contracts involve Federal Contract Information.
Identify whether you handle CUI
Determine whether your contracts involve Controlled Unclassified Information, using the National Archives CUI Registry as the authoritative reference.
Map where that data goes
Trace where the information enters, lives, and travels within your environment.
Determine applicable CMMC requirements
Based on the information you handle and your contract requirements, determine the applicable CMMC level.
Confirm with appropriate contractual, legal, or compliance resources where necessary
Titan can assist with the technical scoping and readiness portion, but should not replace legal interpretation of contract obligations.
Titan can assist with the technical scoping and readiness portion, but should not replace legal interpretation of contract obligations.
Level 1 or Level 2: where should I start?
This educational tool helps you think through where you are in the CMMC process. It cannot determine your contractual obligations.
Do you perform work for the DoD or a DoD prime contractor?
Do your contracts include FAR 52.204-21?
Do your contracts include DFARS 252.204-7012 or related clauses?
Do you handle Federal Contract Information (FCI)?
Do you handle Controlled Unclassified Information (CUI)?
Do you know where FCI or CUI is stored?
Do you know which employees can access it?
Do you have a documented system scope?
Do you have a current SSP where applicable?
Answer all 9 questions to see your starting-point summary.
Level 1 to Level 2 readiness roadmap
A conceptual progression, not an officially mandated sequence.
Identify FCI and CUI
Understand what information your business actually handles.
Map data flows
Determine where that information enters, lives, and travels.
Define scope
Identify applicable users, devices, systems, and service providers.
Establish baseline security
Implement foundational controls across the in-scope environment.
Perform gap assessment
Compare current controls with applicable requirements.
Remediate technical gaps
Correct technical and operational gaps.
Build documentation
Develop SSP, policies, procedures, and evidence as applicable.
Validate evidence
Verify that documentation and technical reality match.
Prepare for applicable assessment
Complete the required self-assessment or authorized assessment based on the CMMC requirement.
A CMMC technical readiness and scoping partner
Titan IT Management helps organizations understand what they actually have, what information they are protecting, which systems are in scope, what technical gaps exist, and what needs to happen before an assessment.
Titan can assist organizations with scoping, FCI and CUI data flow review, NIST SP 800-171 technical gap analysis, Microsoft 365 and security architecture, endpoint security, MFA and identity, logging and monitoring, backup and recovery, network and security architecture, remediation, and documentation support.
Our philosophy is simple: compliance must come before claim. We will not promise instant certification, and we will not pretend a product purchase replaces the work of scoping, implementing, and documenting a real security environment.
Titan serves businesses across Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce, and can support organizations with DoD contracting requirements throughout the region.
What Titan can help with
- CMMC readiness support
- Technical scoping
- FCI and CUI data flow review
- NIST SP 800-171 technical gap analysis
- Microsoft 365 and security architecture
- Endpoint security
- MFA and identity
- Logging and monitoring
- Backup and recovery
- Network and security architecture
- Remediation
- Documentation support
Titan does not perform official CMMC certification assessments. Unless an organization holds current official C3PAO authorization, it cannot issue CMMC certifications. Titan is a technical readiness partner, not an authorized certifier.
CMMC Level 1 vs. Level 2 questions, answered
What is the main difference between CMMC Level 1 and Level 2?+
CMMC Level 1 is generally associated with protecting Federal Contract Information (FCI) and incorporates the basic safeguarding requirements in FAR 52.204-21. Level 2 is generally associated with protecting Controlled Unclassified Information (CUI) and aligns with the more extensive security requirements of NIST SP 800-171 under applicable CMMC rules. The difference is driven primarily by the type of information you handle and your contract requirements, not by company size.
Does Level 1 protect FCI or CUI?+
Level 1 is associated with protecting FCI. Level 2 is associated with protecting CUI. Do not assume your level based on company size, revenue, or number of employees. Review your contracts and the information you actually handle.
Does CMMC Level 2 require NIST SP 800-171?+
CMMC Level 2 aligns with the security requirements of NIST SP 800-171, subject to current CMMC rules. NIST SP 800-171 is designed to protect CUI in nonfederal systems and organizations. Verify which revision of NIST 800-171 currently applies under the applicable CMMC and DoD rules before relying on any specific control wording.
Does every DoD contractor need Level 2?+
No. The required level depends on the information you handle and your contract requirements. Organizations handling only FCI may have different requirements than those handling CUI. Do not assume every DoD contractor automatically needs Level 2. Determine what information you actually handle and review applicable contract clauses.
Can a small business need CMMC Level 2?+
Yes. CMMC level is not determined by company size. A small business that handles CUI under a DoD contract may need Level 2 regardless of its number of employees. The information you handle and your contract requirements drive the obligation, not the size of your organization.
Does Level 2 require a C3PAO assessment?+
Depending on the applicable contract and requirement, Level 2 may involve either a self-assessment with affirmation or an assessment by an authorized C3PAO. Not every Level 2 obligation requires a C3PAO assessment. Verify the current requirement for your specific situation against official DoD CMMC guidance.
Can a company move from Level 1 to Level 2?+
Yes. A business's obligations can change as new contracts are awarded, the company begins handling CUI, subcontracting requirements change, or customers impose new contractual requirements. This is why growing defense contractors should avoid building a technology environment that will be impossible to mature later.
Does CMMC Level 2 require GCC High?+
Not automatically. The appropriate Microsoft environment depends on your contract requirements, the type of CUI, export-controlled data considerations, and applicable federal obligations. Do not assume Level 2 always requires GCC, GCC High, or any specific Microsoft environment without evaluating your contracts and applicable requirements. Use official Microsoft and DoD sources for cloud compliance claims.
Official sources and further reading
Primary government and standards sources for the regulatory claims on this page. Verify all current requirements against official DoD CMMC guidance before acting.
U.S. Department of Defense
- Cybersecurity Maturity Model Certification (CMMC) Program (2024)
The official DoD CMMC Program page, including the CMMC 2.0 final rule (32 CFR Part 170) establishing the three-level framework, assessment requirements, and implementation timelines. This is the primary authority for current CMMC requirements.
NIST
- NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (2024)
The security requirements that underpin CMMC Level 2. Verify which revision currently applies under applicable CMMC and DoD rules, as requirements can differ between revisions.
Acquisition.gov / FAR / DFARS
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (2016)
The Federal Acquisition Regulation clause containing the basic safeguarding requirements that underpin CMMC Level 1 protection of FCI.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (2016)
The Defense FAR Supplement clause requiring contractors to implement NIST SP 800-171 security requirements for protecting CUI and report cyber incidents.
National Archives CUI Program
- CUI Registry (2024)
The official registry of Controlled Unclassified Information categories and markings maintained by the National Archives and Records Administration, the authoritative source for what constitutes CUI.
Cyber AB
- The Cyber AB (CMMC Accreditation Body) (2024)
The authorized accreditation body for the CMMC ecosystem, including information on C3PAOs, Certified Assessors, and the CMMC assessment process.
Microsoft
- Microsoft 365 compliance and GCC High documentation (2025)
Microsoft documentation covering cloud environments relevant to CUI and CMMC, including GCC, GCC High, and data residency considerations. Do not assume any Microsoft environment is automatically appropriate for every CMMC use case without evaluating your contracts and applicable requirements.
Ready to understand your scope before you buy solutions?
Whether you are determining whether Level 1 applies or preparing for Level 2, Titan can help you understand your environment, map your data, identify gaps, and prepare for an assessment the right way.
