CMMC Level 1 vs Level 2: Which One Does Your Business Need?

The CMMC final rule went into effect December 16, 2024, and Phase 1 (self-assessments for Level 1) is live. However, on July 13, 2026, DoD suspended Phase 2, which would have required third-party C3PAO assessments for Level 2. The November 2026 deadline is gone, and DoD has not ruled out further changes after a 60-day review.

But here is what did not change: DFARS 252.204-7012 still requires contractors handling CUI to implement all 110 NIST SP 800-171 controls. The security requirements are the same. The certification timeline shifted.

The Short Version

CMMC Level 1 is for contractors who handle Federal Contract Information (FCI). 17 security practices from FAR 52.204-21. Self-assessment. Annual.

CMMC Level 2 is for contractors who handle Controlled Unclassified Information (CUI). 110 security controls from NIST SP 800-171. Third-party assessment by a C3PAO (when Phase 2 resumes). Every three years.

If you only touch FCI, you need Level 1. If you touch CUI at all, even a little, you need Level 2.

How to Figure Out Which Level You Need

Step 1: Check for DFARS 252.204-7012. If it’s in your contract, you need Level 2.

Step 2: Check for CUI markings like “ITAR,” “Export Controlled,” or CUI category banners.

Step 3: Ask your prime what flows down.

Step 4: Think about where CUI might hide. Emails, shared drives, Teams chats, personal laptops.

What Each Level Costs

Level 1 is manageable. Think thousands, not tens of thousands.

Level 2 is a significant investment. For a small contractor with 20-50 employees, preparation can run well into six figures over 12-18 months.

Common Misconceptions

“CMMC is suspended so I can stop worrying.” The certification program is paused. The security requirements are not. DFARS still requires all 110 controls. The DOJ is still enforcing false SPRS scores. When Phase 2 resumes, the contractors who kept preparing will be ready.

“I’m a small sub, so I only need Level 1.” Size doesn’t determine your level. Data does.

“My IT guy says we’re already compliant.” Unless someone has done a control-by-control mapping against NIST 800-171, you don’t actually know where you stand.

What to Do Next

Figure out your level. Then figure out your gaps. Then build a plan to close them.

We’ll review your SPRS score and help you figure out your CMMC level. Free. No obligation. Call 480-937-7021 or visit asteroidit.com.

Scroll to Top