Resource Guide

CMMC Level 1 vs. Level 2: What's the Difference?

The biggest difference is usually not company size. It is the type of federal information your business handles and the cybersecurity requirements attached to that information.

In plain English

CMMC Level 1 is generally associated with protecting Federal Contract Information (FCI), while CMMC Level 2 is generally associated with protecting Controlled Unclassified Information (CUI) and involves significantly more extensive cybersecurity requirements. The biggest difference is usually not company size. It is the type of federal information your business handles and the cybersecurity requirements attached to that information.

Your required CMMC level depends on applicable contract requirements and the information your organization handles. This page is general educational guidance, not legal advice or a certification determination. Verify current requirements against official DoD CMMC guidance and your applicable contracts.

Side by Side

The fastest way to understand the difference

AreaCMMC Level 1CMMC Level 2
Primary information typeFCICUI
Security basisBasic safeguarding requirements (FAR 52.204-21)NIST SP 800-171-based requirements under CMMC
ComplexityFoundationalSubstantially more extensive
DocumentationMore limited but still importantSignificant documentation and evidence expectations
AssessmentVerify current official requirement (self-assessment with affirmation)Self-assessment or C3PAO assessment depending on contract and requirement
Typical scopeSystems handling or protecting applicable FCISystems handling or protecting applicable CUI plus applicable security assets
Planning effortLower relative complexityHigher relative complexity

Do not hard-code practice counts or assessment frequencies without verifying them against current official CMMC sources, as these can change.

Level 1

Level 1 starts with FCI

Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service, subject to the applicable federal definition. It commonly appears in contracts that include the standard FAR clause for safeguarding covered defense information.

Level 1 focuses on basic safeguarding of that information under FAR 52.204-21. Level 1 is less complex than Level 2, but it still requires organizations to actually implement and verify the applicable safeguards. It is not a formality to skip.

Level 2

Level 2 starts with CUI

Controlled Unclassified Information (CUI) is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official CUI Registry of categories.

Handling CUI typically drives a substantially more extensive cybersecurity obligation because the requirements attach to the information itself, not to the size of the company. A small business that handles CUI may face Level 2 requirements regardless of its number of employees.

Read the Full CMMC Guide
The Distinction

FCI vs. CUI

Federal Contract Information (FCI)

Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service, subject to the applicable federal definition. Level 1 focuses on basic safeguarding of that information under FAR 52.204-21.

Typically associated with CMMC Level 1

Controlled Unclassified Information (CUI)

Controlled Unclassified Information (CUI) is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official CUI Registry of categories. Handling CUI typically drives a substantially more extensive cybersecurity obligation.

Typically associated with CMMC Level 2

Do not determine your CMMC level based only on company size, revenue, or number of employees. The information and contract requirements matter more.

The Foundation

Why NIST SP 800-171 matters more at Level 2

Level 2 is closely tied to the requirements of NIST SP 800-171 under the applicable CMMC framework. NIST SP 800-171 is designed to protect CUI in nonfederal systems and organizations, and CMMC Level 2 assesses implementation of those applicable security requirements.

Documentation and evidence are important because an organization must be able to demonstrate that controls are actually implemented, not simply that a policy says they exist. A policy that says a control exists is not the same as evidence that the control actually operates.

Be careful about NIST revision references. Verify which revision of NIST SP 800-171 currently applies under the applicable CMMC and DoD rules before relying on any specific control wording. Do not mix revision 2 and revision 3 requirements without explicitly explaining applicability.

CMMC Level 2 aligns with NIST SP 800-171. The official NIST publication is the authoritative source for the underlying security requirements. Verify the current revision before acting on any specific control.

Assessment

The assessment difference

For Level 1, describe the current self-assessment and affirmation requirements based on official DoD guidance. Under current CMMC rules, Level 1 involves an annual self-assessment with an annual affirmation by a company executive.

For Level 2, some organizations may be subject to self-assessment while others may require an authorized C3PAO assessment depending on the applicable contract and requirement. Not every Level 2 obligation requires a C3PAO assessment. Verify the current requirement for your specific situation against official DoD CMMC guidance.

Titan can help prepare a business for assessment, but Titan does not issue CMMC certifications. Unless an organization holds current official C3PAO authorization, it cannot perform official CMMC certification assessments.

Learn About C3PAOs in the Full CMMC Guide
Illustrative Examples

Level 1 vs. Level 2 in the real world

Illustrative examples. Not actual Titan clients.

Example 1: Small DoD subcontractor handling FCI

A small subcontractor receives contract-related information but does not receive or process CUI. Applicable contract language may point the company toward Level 1 requirements. Do not definitively assign Level 1 without contract review. Confirm what information you actually handle before assuming a level.

Example 2: Engineering firm handling CUI

An engineering firm receives technical information identified as CUI and stores it electronically. This likely creates a more substantial NIST SP 800-171 and CMMC Level 2 compliance obligation depending on contract requirements. The company is small, but the information it handles drives the obligation. Do not use real company names.

The Reality

Level 2 is not just Level 1 with more antivirus

Level 2 can involve significantly more mature controls across many areas of the technology environment. Avoid implying that technology products alone satisfy these areas.

Access controlIdentityMFAAudit and loggingConfiguration managementIncident responseMedia protectionPersonnel securityRisk assessmentSecurity assessmentSystem and communications protectionSystem integrityVulnerability managementDocumentationPolicies and procedures

Level 2 is a security program, not a software bundle.

Scope

Does Level 2 mean every device in the company?

Not necessarily. Scope matters. The importance is in identifying:

Where CUI is stored
Where CUI is processed
Where CUI is transmitted
Which users access it
Which systems protect it
Which external service providers are involved

Properly designed segmentation or an enclave may potentially reduce unnecessary scope, but only where the technical architecture and actual data flows support it. Do not promise scope reduction without validating the boundary against your actual environment and applicable scoping guidance.

Growth

Can a company be Level 1 today and need Level 2 later?

Yes, potentially. A business's obligations can change as new contracts are awarded, the company begins handling CUI, subcontracting requirements change, customers impose new contractual requirements, or new systems are introduced.

This is why growing defense contractors should avoid building a technology environment that will be impossible to mature later. A foundation that is easy to mature is worth more than a quick fix that creates structural debt.

Comparison

What does Level 2 usually require more of?

Level 1

  • Basic safeguarding
  • Limited scope relative to Level 2
  • Simpler documentation environment

Level 2

  • More extensive technical controls
  • More evidence
  • More formal documentation
  • More security monitoring
  • More process maturity
  • Greater assessment rigor

Keep these comparisons qualitative unless official sources support more specific claims.

Documentation

SSP, POA&M and evidence

System Security Plan (SSP)

The SSP documents the relevant system environment and how applicable security requirements are implemented. It is more prominent in Level 2 readiness because the documentation requirements are substantially more extensive.

Plan of Action and Milestones (POA&M)

A POA&M describes how the organization plans to address requirements not yet fully implemented. Current CMMC rules may limit how POA&Ms can be used. Not every missing requirement can simply be placed on a POA&M. Verify current DoD requirements before relying on a POA&M strategy.

A policy that says a control exists is not the same as evidence that the control actually operates.

Microsoft 365

Microsoft 365: Level 1 vs. Level 2

Cloud decisions become more important when CUI is involved. This can involve Microsoft 365 Commercial, government-oriented Microsoft cloud environments, identity, MFA, email, SharePoint, OneDrive, Teams, logging, and data handling.

Do not say CMMC Level 2 always requires GCC High. The appropriate Microsoft environment depends on the organization's contract requirements, the type of CUI, export-controlled data, service requirements, and applicable federal obligations. Use official Microsoft and DoD sources for cloud compliance claims.

Check My Microsoft 365 Security
Budgeting

How much more expensive is Level 2?

There is no invented multiplier or generic project cost. Level 2 is usually more expensive and time-consuming because of greater control complexity, documentation, scope, logging and security monitoring, identity requirements, remediation, cloud architecture, professional services, and assessment requirements.

Greater control complexity
Documentation
Scope
Logging and security monitoring
Identity requirements
Remediation
Cloud architecture
Professional services
Assessment requirements

A small, well-scoped environment may be substantially easier to manage than an unnecessarily broad environment.

The cheapest way to approach CMMC is not to skip requirements. It is to understand your scope before you start buying solutions.

Decision Framework

How do I know which level I need?

1

Review your contracts and flow-down requirements

Identify the cybersecurity clauses and requirements in your DoD contracts and any flow-down requirements from primes.

2

Identify whether you handle FCI

Determine whether your contracts involve Federal Contract Information.

3

Identify whether you handle CUI

Determine whether your contracts involve Controlled Unclassified Information, using the National Archives CUI Registry as the authoritative reference.

4

Map where that data goes

Trace where the information enters, lives, and travels within your environment.

5

Determine applicable CMMC requirements

Based on the information you handle and your contract requirements, determine the applicable CMMC level.

6

Confirm with appropriate contractual, legal, or compliance resources where necessary

Titan can assist with the technical scoping and readiness portion, but should not replace legal interpretation of contract obligations.

Titan can assist with the technical scoping and readiness portion, but should not replace legal interpretation of contract obligations.

Interactive Tool

Level 1 or Level 2: where should I start?

This educational tool helps you think through where you are in the CMMC process. It cannot determine your contractual obligations.

Do you perform work for the DoD or a DoD prime contractor?

Do your contracts include FAR 52.204-21?

Do your contracts include DFARS 252.204-7012 or related clauses?

Do you handle Federal Contract Information (FCI)?

Do you handle Controlled Unclassified Information (CUI)?

Do you know where FCI or CUI is stored?

Do you know which employees can access it?

Do you have a documented system scope?

Do you have a current SSP where applicable?

Answer all 9 questions to see your starting-point summary.

The Path

Level 1 to Level 2 readiness roadmap

A conceptual progression, not an officially mandated sequence.

1

Identify FCI and CUI

Understand what information your business actually handles.

2

Map data flows

Determine where that information enters, lives, and travels.

3

Define scope

Identify applicable users, devices, systems, and service providers.

4

Establish baseline security

Implement foundational controls across the in-scope environment.

5

Perform gap assessment

Compare current controls with applicable requirements.

6

Remediate technical gaps

Correct technical and operational gaps.

7

Build documentation

Develop SSP, policies, procedures, and evidence as applicable.

8

Validate evidence

Verify that documentation and technical reality match.

9

Prepare for applicable assessment

Complete the required self-assessment or authorized assessment based on the CMMC requirement.

About Titan

A CMMC technical readiness and scoping partner

Titan IT Management helps organizations understand what they actually have, what information they are protecting, which systems are in scope, what technical gaps exist, and what needs to happen before an assessment.

Titan can assist organizations with scoping, FCI and CUI data flow review, NIST SP 800-171 technical gap analysis, Microsoft 365 and security architecture, endpoint security, MFA and identity, logging and monitoring, backup and recovery, network and security architecture, remediation, and documentation support.

Our philosophy is simple: compliance must come before claim. We will not promise instant certification, and we will not pretend a product purchase replaces the work of scoping, implementing, and documenting a real security environment.

Titan serves businesses across Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce, and can support organizations with DoD contracting requirements throughout the region.

What Titan can help with

  • CMMC readiness support
  • Technical scoping
  • FCI and CUI data flow review
  • NIST SP 800-171 technical gap analysis
  • Microsoft 365 and security architecture
  • Endpoint security
  • MFA and identity
  • Logging and monitoring
  • Backup and recovery
  • Network and security architecture
  • Remediation
  • Documentation support

Titan does not perform official CMMC certification assessments. Unless an organization holds current official C3PAO authorization, it cannot issue CMMC certifications. Titan is a technical readiness partner, not an authorized certifier.

Frequently Asked Questions

CMMC Level 1 vs. Level 2 questions, answered

What is the main difference between CMMC Level 1 and Level 2?+

CMMC Level 1 is generally associated with protecting Federal Contract Information (FCI) and incorporates the basic safeguarding requirements in FAR 52.204-21. Level 2 is generally associated with protecting Controlled Unclassified Information (CUI) and aligns with the more extensive security requirements of NIST SP 800-171 under applicable CMMC rules. The difference is driven primarily by the type of information you handle and your contract requirements, not by company size.

Does Level 1 protect FCI or CUI?+

Level 1 is associated with protecting FCI. Level 2 is associated with protecting CUI. Do not assume your level based on company size, revenue, or number of employees. Review your contracts and the information you actually handle.

Does CMMC Level 2 require NIST SP 800-171?+

CMMC Level 2 aligns with the security requirements of NIST SP 800-171, subject to current CMMC rules. NIST SP 800-171 is designed to protect CUI in nonfederal systems and organizations. Verify which revision of NIST 800-171 currently applies under the applicable CMMC and DoD rules before relying on any specific control wording.

Does every DoD contractor need Level 2?+

No. The required level depends on the information you handle and your contract requirements. Organizations handling only FCI may have different requirements than those handling CUI. Do not assume every DoD contractor automatically needs Level 2. Determine what information you actually handle and review applicable contract clauses.

Can a small business need CMMC Level 2?+

Yes. CMMC level is not determined by company size. A small business that handles CUI under a DoD contract may need Level 2 regardless of its number of employees. The information you handle and your contract requirements drive the obligation, not the size of your organization.

Does Level 2 require a C3PAO assessment?+

Depending on the applicable contract and requirement, Level 2 may involve either a self-assessment with affirmation or an assessment by an authorized C3PAO. Not every Level 2 obligation requires a C3PAO assessment. Verify the current requirement for your specific situation against official DoD CMMC guidance.

Can a company move from Level 1 to Level 2?+

Yes. A business's obligations can change as new contracts are awarded, the company begins handling CUI, subcontracting requirements change, or customers impose new contractual requirements. This is why growing defense contractors should avoid building a technology environment that will be impossible to mature later.

Does CMMC Level 2 require GCC High?+

Not automatically. The appropriate Microsoft environment depends on your contract requirements, the type of CUI, export-controlled data considerations, and applicable federal obligations. Do not assume Level 2 always requires GCC, GCC High, or any specific Microsoft environment without evaluating your contracts and applicable requirements. Use official Microsoft and DoD sources for cloud compliance claims.

References

Official sources and further reading

Primary government and standards sources for the regulatory claims on this page. Verify all current requirements against official DoD CMMC guidance before acting.

U.S. Department of Defense

NIST

Acquisition.gov / FAR / DFARS

National Archives CUI Program

  • CUI Registry (2024)

    The official registry of Controlled Unclassified Information categories and markings maintained by the National Archives and Records Administration, the authoritative source for what constitutes CUI.

Cyber AB

Microsoft

  • Microsoft 365 compliance and GCC High documentation (2025)

    Microsoft documentation covering cloud environments relevant to CUI and CMMC, including GCC, GCC High, and data residency considerations. Do not assume any Microsoft environment is automatically appropriate for every CMMC use case without evaluating your contracts and applicable requirements.

Ready to understand your scope before you buy solutions?

Whether you are determining whether Level 1 applies or preparing for Level 2, Titan can help you understand your environment, map your data, identify gaps, and prepare for an assessment the right way.