CMMC Level 1 · GuideSEC / GDE

Guide

What is the difference between CMMC Level 1 and Level 2?

Short Answer

Level 1 protects Federal Contract Information with fifteen requirements and an annual self-assessment. Level 2 protects Controlled Unclassified Information with far more requirements and, in many cases, a third-party assessment. Which one applies depends on the information a contract involves.

Level 1

Level 1 covers FCI. It is fifteen requirements and fifty-nine assessment objectives, self-assessed each year and affirmed in SPRS. There is no score and no POA&M.

Level 2

Level 2 covers CUI. It is the 110-control NIST SP 800-171 set, with a numeric score, and it can require a third-party assessment by a C3PAO. It is a substantially larger effort than Level 1.

How the level is decided

The level is driven by the information a specific contract involves and the CMMC requirement stated in that contract. This reference center covers Level 1. Deciding which level applies to a given contract is a boundary decision the customer makes.

Primary Sources

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.