CMMC Level 1 vs Level 2: Which Does Your Company Actually Need?
The level question is usually the first one a shop asks and the easiest to answer badly. Here’s the honest decision test.
What’s the one-question test?
Does controlled technical data — drawings, models, specs for defense parts — ever enter your shop? If yes, you’re a Level 2 shop. If genuinely no, and you only touch contract information like POs and schedules, you’re Level 1. That’s 90% of the determination; the rest is confirming it against your actual POs and clauses (here’s how).
What does Level 1 actually involve?
The 15 basic safeguarding requirements of FAR 52.204-21 — access control, identification and authentication, media handling, physical protection, boundary protection, and basic system hygiene — plus an annual self-assessment and affirmation in SPRS. For a small shop with sane IT, this is weeks of focused work, not months. No SSP required, no third-party assessment.
What does Level 2 actually involve?
The full NIST SP 800-171 set: 110 requirements across 14 families, a System Security Plan documenting how each is met, a POA&M for gaps (with closeout rules), and a SPRS score from the DoD scoring methodology (-203 to 110). Under the current phased rollout, Level 2 appears in solicitations as a self-assessment requirement; third-party certification requirements were part of Phase 2, which is suspended pending DoD’s program review. Independent of CMMC entirely, DFARS 252.204-7012 already obligates CUI-handling shops to 800-171 — that clause has been in POs for years.
How different is the effort, really?
| Level 1 | Level 2 | |
|---|---|---|
| Requirements | 15 | 110 |
| Documentation | Minimal | SSP + POA&M + evidence |
| Score | Affirmation | SPRS score, visible to primes |
| Typical shop timeline | Weeks | 3–9 months |
| Scoping leverage | Low (small footprint anyway) | Huge — enclave design can shrink cost dramatically |
What are the traps?
- Under-calling it. Doing Level 1 while controlled drawings sit on the quoting PC doesn’t reduce your obligations; it just documents that you missed them.
- Over-building it. Some shops genuinely are Level 1 — machining commercial parts with one federal PO for standard hardware. Don’t buy a GCC High migration you don’t need.
- Level shopping by budget. Your level is a fact about your data, not a menu choice. Budget belongs in the scoping conversation, where an enclave can legitimately shrink a Level 2 project.
- Waiting for the Task Force. The review may change assessment mechanics; it won’t change whether your drawings are CUI.
What’s the next step?
Trace your data, confirm your clauses, pick your track, then scope hard before you spend. That’s the first two weeks of our onboarding — site walk, dump-in, gap snapshot, work plan. Start here.
Quick answers
How many requirements does each level have?
Level 1 covers the 15 basic safeguarding requirements of FAR 52.204-21 with an annual self-assessment. Level 2 covers the 110 security requirements of NIST SP 800-171, with an SSP, POA&M, and a SPRS score.
Can I just do Level 1 to be safe?
Only if you truly never touch CUI. If your primes send controlled drawings or tech data, Level 1 doesn't cover your obligations — DFARS 252.204-7012 already requires NIST SP 800-171 for CUI regardless of CMMC assessments.
Does the Phase 2 suspension change which level I need?
No. The suspension paused third-party certification rollout, not the level determination. Your level is set by the data you handle and your contract clauses, both unchanged.