If your organization works with the U.S. Department of Defense (DoD) or plans to bid on defense contracts, understanding CMMC Level 1 vs Level 2 is essential. Choosing the correct certification level isn’t just about meeting compliance requirements, it can determine whether you’re eligible to win contracts and protect sensitive government information.
Many contractors assume they need the highest CMMC level available, while others underestimate their requirements and risk failing an assessment. The reality is that the right level depends on the type of information your organization handles, specifically whether you work with Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
In this blog, we’ll explain the key differences between CMMC Level 1 vs Level 2, compare their requirements, identify which level your organization needs, and share best practices to prepare for compliance in 2026.
Key Takeaways
- CMMC Level 1 is designed for organizations that handle only Federal Contract Information (FCI).
- CMMC Level 2 is required for organizations that store, process, or transmit Controlled Unclassified Information (CUI).
- Level 1 requires 15 foundational cybersecurity practices, while Level 2 requires 110 security requirements aligned with NIST SP 800-171 Rev. 2.
- Level 1 uses an annual self-assessment, whereas Level 2 may require a Certified Third-Party Assessment Organization (C3PAO) assessment depending on contract requirements.
- If your organization handles CUI, you will most likely need CMMC Level 2.
- Building a continuous compliance program makes maintaining CMMC certification significantly easier than preparing only when an assessment is due.
CMMC Level 1 vs Level 2 at a Glance
|
Feature |
CMMC Level 1 |
CMMC Level 2 |
|
Purpose |
Protect Federal Contract Information (FCI) |
Protect Controlled Unclassified Information (CUI) |
|
Security Requirements |
15 practices |
110 security requirements |
|
Standard |
FAR 52.204-21 |
NIST SP 800-171 Rev. 2 |
|
Assessment |
Annual Self-Assessment |
Self-Assessment or C3PAO Assessment (depending on contract) |
|
Documentation |
Basic |
Comprehensive |
|
Cybersecurity Maturity |
Foundational |
Advanced |
|
Typical Organizations |
Small subcontractors |
Prime contractors and suppliers handling CUI |
Which CMMC Level Does Your Organization Need?
Use this quick decision guide.
|
If your organization… |
Recommended Level |
|
Handles only Federal Contract Information (FCI) |
CMMC Level 1 |
|
Stores or processes Controlled Unclassified Information (CUI) |
CMMC Level 2 |
|
Is a DoD prime contractor working with CUI |
Usually Level 2 |
|
Is a subcontractor receiving only FCI |
Usually Level 1 |
|
Must comply with NIST SP 800-171 |
Level 2 |
If you’re still unsure, review your DoD contract requirements. The contract will specify the required CMMC level.
What Is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the cybersecurity framework developed by the U.S. Department of Defense (DoD) to strengthen the security of the Defense Industrial Base (DIB).
Its primary objective is to ensure contractors implement cybersecurity controls that protect sensitive government information from cyber threats, data breaches, and supply chain attacks.
CMMC 2.0 consists of three certification levels, but for most organizations, the decision is between Level 1 and Level 2.
Understanding CMMC Level 1
CMMC Level 1 is the foundational level of the certification model. It applies to organizations that handle only Federal Contract Information (FCI) and do not store, process, or transmit Controlled Unclassified Information (CUI).
The focus is on implementing basic cybersecurity practices that reduce common risks and establish minimum security standards.
CMMC Level 1 Requirements
Organizations must implement 15 cybersecurity practices based on FAR 52.204-21.
These include:
- Limiting system access to authorized users
- Using unique user identities
- Securing physical access to systems
- Protecting organizational information
- Monitoring user activity
- Performing routine system maintenance
- Sanitizing media before disposal
- Identifying and authenticating users
Although these controls are considered foundational, they provide an essential cybersecurity baseline for organizations entering the defense supply chain.
Who Needs CMMC Level 1?
Level 1 is typically suitable for organizations that:
- Handle only Federal Contract Information (FCI)
- Do not work with Controlled Unclassified Information (CUI)
- Support defense contractors as subcontractors
- Need to demonstrate basic cybersecurity hygiene
- Have contracts specifically requiring Level 1 compliance
Understanding CMMC Level 2
CMMC Level 2 is designed for organizations that store, process, or transmit Controlled Unclassified Information (CUI).
Since CUI is more sensitive than FCI, stronger cybersecurity measures are required to protect it against increasingly sophisticated cyber threats.
Unlike Level 1, Level 2 requires organizations to establish a structured cybersecurity program supported by governance, documentation, continuous monitoring, and risk management.
CMMC Level 2 Requirements
Level 2 aligns directly with the 110 security requirements defined in NIST SP 800-171 Rev. 2. These requirements cover 14 control families, including:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
Organizations must demonstrate that these controls are not only implemented but also operating effectively through policies, procedures, and audit evidence.
Who Needs CMMC Level 2?
Organizations generally require Level 2 if they:
- Handle Controlled Unclassified Information (CUI)
- Develop software for the DoD
- Provide managed services to defense agencies
- Process engineering or technical defense data
- Must comply with NIST SP 800-171
- Receive contracts specifying Level 2 certification
CMMC Level 1 vs Level 2: The Key Differences
1. Information Being Protected
The most significant difference is the type of information involved.
- Level 1 protects Federal Contract Information (FCI).
- Level 2 protects Controlled Unclassified Information (CUI), which requires stronger safeguards and greater oversight.
2. Security Requirements
- Level 1 includes 15 foundational cybersecurity practices.
- Level 2 expands to 110 security requirements, covering governance, technical safeguards, risk management, documentation, and continuous security monitoring.
3. Assessment Process
Organizations seeking Level 1 perform an annual self-assessment.
For Level 2, the assessment method depends on contract requirements:
- Annual self-assessment for selected contracts.
- Independent assessment by a Certified Third-Party Assessment Organization (C3PAO) for contracts involving higher-risk information.
4. Documentation
Documentation expectations increase significantly from Level 1 to Level 2.
Level 2 organizations typically maintain:
- Information security policies
- Risk assessments
- Asset inventories
- Incident response plans
- User access reviews
- Vulnerability reports
- Security awareness records
- Configuration baselines
- Continuous monitoring reports
- Audit evidence
5. Cybersecurity Maturity
Level 1 demonstrates basic cyber hygiene.
Level 2 demonstrates an organization can manage cybersecurity risks through repeatable, documented, and continuously monitored security practices.
Common Misconceptions About CMMC Levels
“Every defense contractor needs Level 2.”
Not true. Many subcontractors handling only FCI require only Level 1.
“Small businesses only need Level 1.”
Incorrect. Company size does not determine the required level. A small contractor handling CUI must still meet Level 2 requirements.
“Level 2 is just Level 1 with more controls.”
Only partially. Level 2 also introduces stronger governance, formal documentation, continuous monitoring, risk management, and assessment expectations.
How to Determine Your Required CMMC Level
Ask yourself these questions:
Do you store or process Controlled Unclassified Information (CUI)?
If yes, you likely require Level 2.
Do you only receive Federal Contract Information (FCI)?
If yes, Level 1 is usually appropriate.
Does your DoD contract specify a certification level?
Always follow the contract requirements.
Are you already complying with NIST SP 800-171?
If so, you’re already aligned with the foundation of Level 2.
Best Practices for Achieving CMMC Compliance
Regardless of which level you need, following these best practices can simplify your compliance journey.
Understand Your Compliance Scope
Identify the systems, users, applications, cloud services, and data included within your CMMC environment.
Perform a Gap Assessment
Compare your existing controls against the applicable CMMC requirements to identify missing safeguards.
Strengthen Identity and Access Management
Implement least privilege, role-based access control, multi-factor authentication (MFA), and regular user access reviews.
Maintain Strong Documentation
Policies, procedures, asset inventories, incident response plans, and training records should be updated regularly and readily available.
Continuously Monitor Security Controls
Security controls should be monitored year-round rather than only before an assessment.
Automate Compliance Activities
Compliance automation platforms help organizations:
- Collect audit evidence automatically
- Monitor security controls continuously
- Map controls to CMMC requirements
- Track remediation activities
- Generate audit-ready reports
- Reduce manual compliance work
Automation is becoming one of the most effective ways to maintain continuous compliance and simplify CMMC assessments.
Related Compliance Standards
Organizations pursuing CMMC compliance often also align with:
- NIST SP 800-171
- DFARS 252.204-7012
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001
- NIST SP 800-53 (for certain government environments)
Understanding how these frameworks complement CMMC can reduce duplicated effort and streamline compliance programs.
Final Thoughts
Choosing between CMMC Level 1 vs Level 2 ultimately comes down to one question: What type of Department of Defense information does your organization handle?
If your organization works only with Federal Contract Information (FCI), CMMC Level 1 provides the foundational cybersecurity practices needed to meet DoD requirements. However, if you store, process, or transmit Controlled Unclassified Information (CUI), you’ll likely need CMMC Level 2, which requires a more comprehensive cybersecurity program aligned with NIST SP 800-171.
Regardless of the level you pursue, treating CMMC as an ongoing cybersecurity strategy, not a one-time certification project, will deliver long-term benefits. Continuous monitoring, regular risk assessments, well-maintained documentation, and automated evidence collection help reduce compliance overhead while strengthening your organization’s security posture.
Security, AI Risk Management, and Compliance with Akitra!
In the competitive landscape of SaaS businesses, trust is paramount amidst data breaches and privacy concerns. Akitra addresses this need with its leading Agentic AI-powered Compliance Automation platform. Our platform empowers customers to prevent sensitive data disclosure and mitigate risks, meeting the expectations of customers and partners in the rapidly evolving landscape of data security and compliance. Through automated evidence collection and continuous monitoring, paired with customizable policies, Akitra ensures organizations are compliance-ready for various frameworks such as SOC 1, SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 9001, ISO 13485, ISO 42001, NIST 800-53, NIST 800-171, NIST AI RMF, FedRAMP, CCPA, CMMC, SOX ITGC, and more such as CIS AWS Foundations Benchmark, Australian ISM and Essential Eight etc. In addition, companies can use Akitra’s Risk Management product for overall risk management using quantitative methodologies such as Factorial Analysis of Information Risks (FAIR) and qualitative methods, including NIST-based for your company, Vulnerability Assessment and Pen Testing services, Third Party Vendor Risk Management, Trust Center, and AI-based Automated Questionnaire Response product to streamline and expedite security questionnaire response processes, delivering huge cost savings. Our compliance and security experts provide customized guidance to navigate the end-to-end compliance process confidently. Last but not least, we have also developed a resource hub called Akitra Academy, which offers easy-to-learn short video courses on security, compliance, and related topics of immense significance for today’s fast-growing companies.
Our solution offers substantial time and cost savings, including discounted audit fees, enabling fast and cost-effective compliance certification. Customers achieve continuous compliance as they grow, becoming certified under multiple frameworks through a single automation platform.
Build customer trust. Choose Akitra TODAY!To book your FREE DEMO, contact us right here.
FAQ’S
Does every defense contractor need CMMC Level 2?
No. Organizations that handle only FCI generally require Level 1, while those handling CUI typically need Level 2.
Can you skip Level 1 and go directly to Level 2?
Yes. If your contracts require Level 2 because you handle CUI, there is no requirement to achieve Level 1 first.
Is CMMC Level 2 based on NIST SP 800-171?
Yes. Level 2 aligns directly with all 110 security requirements in NIST SP 800-171 Rev. 2.
Can small businesses achieve CMMC Level 2?
Absolutely. The required CMMC level depends on the information you handle—not the size of your organization.




