RaptorGRC — Offline GRC

BLOG

CMMC 2.0 Levels Explained for Suppliers

Published 14 August 2026 · By P Larner

Frameworks & Standards#CMMC#NIST SP 800-171#DFARS#CUI#defence supply chain

CMMC 2.0 Levels Explained for Suppliers

Illustration for: CMMC 2.0 Levels Explained for Suppliers

Illustration for: CMMC 2.0 Levels Explained for Suppliers

The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense’s answer to a decade of contractors promising security and not delivering it. The final programme rule took effect in December 2024, and requirements are being phased into new DoD contracts over a three-year period. If you sell into a US defence supply chain, directly or three tiers down, one of the three levels will eventually apply to you.

Why the DoD created it

Since 2017, the DFARS 252.204-7012 clause has required contractors handling Controlled Unclassified Information (CUI) to implement the 110 security requirements of NIST SP 800-171. Compliance was self-attested, nobody checked, and the results were predictable. DoD assessments of contractors who had certified their own compliance routinely found large gaps, while adversaries extracted sensitive technical data from the supply chain, with the theft of F-35 related design data the best-known example.

CMMC replaces trust with verification. The original 2020 model had five levels and bespoke practices, and CMMC 2.0 cut this to three levels aligned to existing NIST publications, which was a sensible simplification. The core idea is that the sensitivity of the information you handle determines your level, and your level determines who has to check your work.

Three-tier pyramid of the CMMC 2.0 levels, from Level 1 with 15 requirements and annual self-assessment up to Level 3 with 110 plus 24 requirements and government DIBCAC assessment, with arrows showing information sensitivity and assessment rigour rising together

Three-tier pyramid of the CMMC 2.0 levels, from Level 1 with 15 requirements and annual self-assessment up to Level 3 with 110 plus 24 requirements and government DIBCAC assessment, with arrows showing information sensitivity and assessment rigour rising together

The three CMMC 2.0 levels, where the information gets more sensitive and the requirements and the scrutiny both climb.

The two kinds of information that drive everything

  • Federal Contract Information (FCI) is information provided by or generated for the government under contract, not intended for public release. Almost every defence contract involves FCI.
  • Controlled Unclassified Information (CUI) is unclassified information that US law or policy requires to be protected, such as export-controlled technical data or engineering drawings. Handling CUI is what pushes you from Level 1 to Level 2.

Work out which of these you actually hold before doing anything else. I have seen suppliers spend six figures preparing for Level 2 when their contracts only ever exposed them to FCI.

Decision flowchart from the information held under a contract to the applicable CMMC level, where neither FCI nor CUI means CMMC does not apply, FCI only means Level 1, CUI means Level 2, and a dotted extension reaches Level 3 only if the solicitation requires it

Decision flowchart from the information held under a contract to the applicable CMMC level, where neither FCI nor CUI means CMMC does not apply, FCI only means Level 1, CUI means Level 2, and a dotted extension reaches Level 3 only if the solicitation requires it

Work out what information you will actually hold, then confirm the answer with your customer in writing.

Level 1 covers basic hygiene for FCI

Level 1 applies when you handle FCI only. It requires the 15 basic safeguarding requirements of FAR clause 52.204-21, covering access control, identification and authentication, media handling, physical protection, basic boundary defence and malware protection. Nothing exotic, and a competently run IT environment meets most of it already.

Assessment is an annual self-assessment. You score yourself, record the result in the DoD’s Supplier Performance Risk System (SPRS), and a senior company official signs an annual affirmation of compliance. No third party is involved, but the affirmation has teeth, as covered below.

Level 2 means NIST SP 800-171 for CUI

Level 2 applies when you handle CUI and requires all 110 requirements of NIST SP 800-171, assessed against the DoD’s scoring methodology. This is where the real work sits, meaning FIPS-validated cryptography, multifactor authentication, incident response, audit logging, configuration management and a written System Security Plan covering the scope where CUI lives.

Assessment depends on the contract. Most Level 2 contracts will require a certification assessment every three years by a C3PAO (CMMC Third-Party Assessment Organization), accredited through the Cyber AB. A minority, where the DoD judges the CUI less critical, will allow triennial self-assessment. You do not get to choose, because the solicitation tells you.

Two practical points. Conditional certification is possible at 80 per cent of the maximum score, with a Plan of Action and Milestones (POA&M) to close the rest, but the POA&M must be closed within 180 days and the highest-value requirements are not eligible for it. And scoping is the biggest cost lever you have, because a segmented enclave that contains CUI to 30 machines is assessable, while trying to certify a flat 2,000-seat network is misery.

Side-by-side network diagram comparing a flat 2,000-seat network entirely inside a dashed assessment boundary with a segmented CUI enclave of about 30 machines behind a firewall, with assessment cost shown as high versus low

Side-by-side network diagram comparing a flat 2,000-seat network entirely inside a dashed assessment boundary with a segmented CUI enclave of about 30 machines behind a firewall, with assessment cost shown as high versus low

A contained CUI enclave turns an unassessable flat network into a small, affordable assessment boundary.

Level 3 is for hardened targets

Level 3 is for suppliers on the most sensitive programmes, those attractive to state-level attackers. It adds 24 selected requirements from NIST SP 800-172 on top of a completed Level 2 certification, including threat hunting, enhanced supply chain controls and resistance to advanced persistent threats. Assessment is conducted by the government itself, through DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center), every three years. Few suppliers will ever need this level, and those who do will know, because their contracting officer will tell them.

Level

Basis

Requirements

Assessed by

1

FAR 52.204-21

15

Annual self-assessment

2

NIST SP 800-171

110

C3PAO for most, or self-assessment, every 3 years

3

NIST SP 800-172 subset

110 plus 24

Government (DIBCAC), every 3 years

Self-assessment is not the soft option

Every level, including self-assessed ones, requires a named senior official to affirm compliance annually in SPRS. False affirmations expose the company to the US False Claims Act, and the Department of Justice has been actively pursuing cyber-related false claims cases since 2021, including multi-million dollar settlements with contractors who overstated their 800-171 compliance. Treat a self-assessment with the same rigour as an external one, which means evidence, scoring worksheets, and a defensible file. The affirmation is a legal statement, not a formality.

What non-US suppliers need to know

UK and European suppliers are not exempt. CMMC obligations flow down through the supply chain, so if your customer’s DoD contract carries a CMMC clause and you will handle FCI or CUI in performance of it, the requirement reaches you in Shropshire just as it reaches a machine shop in Ohio.

  • Cyber Essentials, Cyber Essentials Plus and ISO 27001 do not substitute for CMMC. Mappings exist, and an ISO 27001 programme gives you a head start, but the assessment must still happen against the CMMC requirements.
  • C3PAO capacity outside the US is thin. If you will need a Level 2 certification, start conversations early, because assessment slots are already a bottleneck.
  • Watch your data flows. CUI arriving into a shared European infrastructure creates scoping and export-control questions under ITAR and EAR that are far cheaper to answer before the data arrives.
  • Ask your prime, in writing, what level they expect you to hold and by when. Primes are mapping their supply chains now, and suppliers with credible plans keep their place on the bid.

Where to start this quarter

Identify whether you hold FCI, CUI, or neither, and get your customer to confirm it in writing. If CUI is in scope, run a gap assessment against NIST SP 800-171 using the DoD scoring methodology, and put your honest score in front of your board with a costed remediation plan. Certification timelines run twelve to eighteen months for most organisations starting cold, and the contracts will not wait for you.

Run your GRC programme in your own network.

RaptorGRC Community Edition is free — every module, offline licence activation, nothing phones home.

Register / Download Contact us
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.