Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

CMMC and NIST 800-171

CMMC Level 1 or Level 2: How to Tell Which One Applies to You

The requirements for defense contractors and subcontractors shifted with the introduction of distinct CMMC Levels tied to the kind of federal data you manage. Now, whether you deal with Controlled Unclassified Information for the Department of Defense or just handle Federal Contract Information determines which Level applies to you. Your choice directly affects your compliance responsibilities, the amount of documentation you need, and your exposure to False Claims Act risk.

What is the key difference between CMMC Level 1 and CMMC Level 2?

The single most important question is whether your company handles CUI. If you do, CMMC Level 2 applies. If you do not, and you only handle FCI, you are subject to Level 1.

Federal Contract Information (FCI) is information not intended for public release, provided by or generated for the government under a contract to develop or deliver a product or service.

Controlled Unclassified Information (CUI) is information the government creates or possesses, or that a contractor receives, which requires safeguarding or dissemination controls according to law, regulation, or government policy.

If your contracts or statements of work mention CUI, or if you receive data labeled as CUI, you must meet CMMC Level 2 requirements. Sometimes, your contract or the government customer will explicitly tell you that you handle CUI. If you are not sure, ask your contracting officer for clarification. If you only handle FCI, Level 1 applies.

How many controls are required for CMMC Level 2?

CMMC Level 2 requires you to implement all 110 controls from NIST SP 800-171 Revision 2. This is a major step up from Level 1, which only requires 17 practices. Each of the 110 controls is broken down into specific assessment objectives in NIST SP 800-171A, and every objective must be met for the control to be considered satisfied.

These 110 controls are grouped into 14 families:

  • Access Control (22 controls)
  • Awareness and Training (3)
  • Audit and Accountability (9)
  • Configuration Management (9)
  • Identification and Authentication (11)
  • Incident Response (3)
  • Maintenance (6)
  • Media Protection (9)
  • Physical Protection (6)
  • Personnel Security (2)
  • Risk Assessment (3)
  • Security Assessment (4)
  • System and Communications Protection (16)
  • System and Information Integrity (7)

For the full list and details, see NIST SP 800-171 Rev 2.

Does the CMMC Level 2 third party certification requirement still apply?

As of July 13, 2026, the Department of War suspended the CMMC Phase II third party certification requirement. This means you do not need a C3PAO to certify your compliance before contract award, at least until the government completes its 60-day strategic review. However, all other requirements remain in force:

  • DFARS 252.204-7012 is still active.
  • You must perform self-assessments at Level 1 or Level 2, as applicable.
  • You are required to post your assessment score in the Supplier Performance Risk System (SPRS).
  • Your senior official must affirm the assessment every year.

The government may still conduct its own assessments and will continue to enforce compliance through these mechanisms. The signature of your senior official on the self-assessment is now the main assurance, which means any false claims carry significant risk under the False Claims Act. The absence of a third party assessor does not reduce your responsibility. In fact, it increases the risk if you overstate your score.

What assets are in scope for a CMMC Level 2 assessment?

For CMMC Level 2, the scope is defined in 32 CFR 170.19(c)(1) Table 3, and includes:

  • CUI Assets: These must meet all 110 controls.
  • Security Protection Assets: These are assessed against controls relevant to their function.
  • Contractor Risk Managed Assets: These require review of your System Security Plan (SSP) and may be spot-checked.
  • Specialized Assets: Items like government furnished equipment and IoT devices are reviewed in your SSP, but not fully assessed.
  • Out of Scope Assets: These are excluded from assessment, but you must justify their separation.

You will be expected to provide four key artifacts during an assessment: a CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and an Authorized User List.

What if you only handle FCI and not CUI?

If you only handle FCI, you are required to implement 17 practices under CMMC Level 1. These are aligned with the basic safeguarding requirements in FAR 52.204-21. The assessment is a self-assessment, with the results posted to SPRS and affirmed annually by a senior official. You are not required to implement the full set of 110 controls or to meet the more detailed documentation and evidence requirements of Level 2.

What are the real-world consequences of getting this wrong?

If you certify that you meet CMMC Level 2 or NIST SP 800-171 requirements and do not, the consequences can be severe. Recent False Claims Act cases have named contractors and their private equity owners, more than for missing controls, but for failing to document their compliance or using non-compliant systems. For example, Health Net Federal Services certified compliance but failed to scan and remediate known vulnerabilities. MORSECORP lacked required documentation and used non-FedRAMP email. Aero Turbine shared defense data with an unauthorized foreign entity, and the private equity owner was included in the settlement.

The law allows whistleblowers to file actions on the government's behalf. Liability can extend to primes, subcontractors, affiliates and investors. The government continues to enforce these requirements through self-assessments and government-led reviews.

How do you prepare for a CMMC Level 2 self-assessment?

Preparation for CMMC Level 2 means more than checking boxes. You need:

  • Documented policies (what you intend to do)
  • Detailed procedures (how you do it)
  • Evidence (timestamped, system-generated artifacts proving execution)
  • A complete System Security Plan (SSP)
  • A Plan of Actions and Milestones (POA&M) if any controls are not fully implemented

Every one of the 320 assessment objectives in NIST SP 800-171A must be met for a perfect SPRS score of 110. Partial implementation is not enough. Documentation alone is not proof, real evidence is required.

Most mid-sized defense contractors spend significant time and resources achieving Level 2 readiness, including gap assessments, remediation, documentation and ongoing consulting. The CMMC Scoping and Assessment Guides Level 2 v2.13, and NIST SP 800-171A, are essential references.

Common questions

How do I know if I handle CUI? Check your contract, statement of work or data markings. If you are unsure, ask your contracting officer. Only companies with CUI are subject to CMMC Level 2.

What is the current status of CMMC Level 2 certification? The requirement for a third party C3PAO assessment is suspended as of July 13, 2026, pending a strategic review. All other requirements, including self-assessment, SPRS posting and annual affirmation, remain in force.

What is the required SPRS score for CMMC Level 2? A perfect SPRS score is 110, meaning you have implemented all 110 controls from NIST SP 800-171 Rev 2.

Checklist for Achieving CMMC Level 2 Compliance

If you handle CUI, you must meet all 110 controls from NIST SP 800-171 Rev 2, post your self-assessment score in SPRS and have your senior official affirm compliance each year. If you need help identifying gaps, the Cyber Grants Alliance CMMC Gap Assessment Grant provides an in kind gap assessment delivered as services, covering all 110 controls for qualifying defense contractors. This can help you prepare accurate, defensible documentation and reduce your False Claims Act risk. If you only handle FCI, focus on the 17 Level 1 practices and be sure your documentation and evidence are in order.

At a glance

The five CMMC asset categories and how each is assessedThe five asset categories, 32 CFR 170.19(c)(1)CUI AssetsProcess, store or transmit CUIAssessed against all 110 controlsSecurity Protection AssetsProvide security functionsAssessed against relevant controlsContractor Risk ManagedCould but should not touch CUISSP review plus limited spot checkSpecialized AssetsGFE, IoT, OT, test equipmentSSP review onlyOut of ScopeCannot touch or protect CUINo assessment, separation must be justified
The five CMMC asset categories and how each is assessed
The three CMMC levels
The three CMMC levels

More on CMMC