Back to Blog
A stairwell sign marked 01, in a navy duotone.

CMMC Level 1

CMMC Level 1 or Level 2? Which Does Your Contract Need

The difference between CMMC Level 1 and Level 2, what triggers each, and how to read your own contract, without anyone guessing your level for you.


A prime sends a letter, or a clause shows up in a solicitation, and the instruction is vague. Be CMMC compliant. Nobody says which level, and the two are very different in scope and cost. This is the most common question small suppliers ask, and the good news is that the answer is written down. It is in the type of information you handle and in the clauses in your contract.

The short version. Level 1 protects Federal Contract Information (FCI) and has 15 requirements from FAR 52.204-21. Level 2 protects Controlled Unclassified Information (CUI) and has 110 controls from NIST SP 800-171, triggered by the clause DFARS 252.204-7012. The kind of data your contract involves is what points to the level. That determination is yours to make, and this guide gives you the facts it turns on.

The Real Difference Is the Data

CMMC levels are not a difficulty setting you pick. They follow the sensitivity of the government information you handle.

  • Level 1 is about FCI. Federal Contract Information is non-public information provided by or generated for the government under a contract to deliver a product or service. Think purchase orders, delivery schedules, and non-public contract communications. Level 1 is the foundational tier of basic safeguarding.
  • Level 2 is about CUI. Controlled Unclassified Information is more sensitive, for example controlled technical drawings, specifications, and other information the government marks or specifies as CUI. It carries the full weight of NIST SP 800-171 and 110 controls.

If a contract only ever involves FCI, it points to Level 1. If it involves CUI, it points to Level 2. That is the fact the whole question turns on.

Read the Clauses, Not the Rumor

Two clauses do most of the signaling. Finding them in your own contract is the most reliable step you can take.

  • FAR 52.204-21 is the basic safeguarding clause tied to FCI. It is the source of the 15 Level 1 requirements.
  • DFARS 252.204-7012 is the clause tied to CUI and NIST SP 800-171. Where it applies, Level 2 is in view.

A common and expensive mistake circulates in the community. Someone hears that any defense work means the full 110 controls, or an IT provider assumes Level 2 without checking the data. Handling FCI only does not mean 110 controls. That is the Level 2 world. Reading your actual contract language beats acting on a rumor every time.

Why This Is Your Call, Not Ours

Here is a boundary we take seriously. We will not tell you that your specific contract or system is Level 1 or Level 2. That is a determination about your own environment and your own contracts, and it carries real consequences, so it stays with you and your contracting officer or counsel.

What a good system can do is lay out the facts the decision turns on and keep your reasoning and evidence organized once you have made the call. It names the rule. You make the determination. The free readiness check helps you think through where your information lives without deciding for you.

When You Only Handle FCI

If your work involves FCI and not CUI, Level 1 is the path in view, and it is genuinely self-serviceable. It is a self-assessment against 15 requirements and 59 objectives, affirmed annually by a senior official in SPRS, with no third-party assessor and no numeric score. That is the whole point of AssessrLog. It is the system of record where a Level 1 self-assessment lives, so you can work it at your own pace and hand your official a clean, defensible package.

Frequently Asked Questions

What is the main difference between CMMC Level 1 and Level 2? Level 1 protects FCI with 15 requirements from FAR 52.204-21. Level 2 protects the more sensitive CUI with 110 controls from NIST SP 800-171. The data type drives the level.

Does handling FCI mean I need all 110 controls? FCI maps to the 15 Level 1 requirements. The 110 controls belong to Level 2 and CUI. A provider telling you otherwise for FCI-only work is mixing up the two.

Which clause tells me my level? FAR 52.204-21 is the basic safeguarding clause for FCI, tied to Level 1. DFARS 252.204-7012 is tied to CUI and NIST SP 800-171, tied to Level 2. Check your contract for both.

Can a contract require a higher level than my data suggests? The government can specify requirements in a contract. This is why reading your actual contract language, and confirming with your contracting officer when it is unclear, matters more than any general rule.

Can AssessrLog tell me which level I need? No. That is a determination about your contracts and environment, and it stays with you. AssessrLog helps you organize the facts and, for FCI, run the Level 1 self-assessment itself.

Filed Under
  • CMMC Level 1
  • Level 2
  • FCI
Start Today

Know Exactly Where Your Assessment Stands.

Work your CMMC Level 1 self-assessment a little at a time, with every determination and its evidence in one place.