One of the most common questions from businesses entering the defense market is: "Which CMMC level do I need?" The answer depends on the type of information you'll handle and the contracts you're pursuing. This guide breaks down the differences and helps you make the right choice.
CMMC Overview
The Cybersecurity Maturity Model Certification (CMMC) 2.0 has three levels:
Level 1 (Foundational) — Basic cyber hygieneLevel 2 (Advanced) — Aligned with NIST SP 800-171Level 3 (Expert) — Enhanced security for critical programs
Most small businesses will need Level 1 or Level 2. Level 3 is reserved for contractors working on the most sensitive defense programs.
Level 1: Foundational
Who Needs It
Any company that handles Federal Contract Information (FCI) — which is essentially any company with a federal contract.
FCI includes:
Contract documents and correspondenceTechnical specifications provided by the governmentPricing and cost dataDelivery schedules and logistics information
Requirements
17 security practices — based on FAR 52.204-21Annual self-assessment — (no third-party audit required)SPRS score submission — to the Supplier Performance Risk System
Key Practices
Limit system access to authorized usersLimit system access to authorized transaction typesVerify and control connections to external systemsControl information posted on publicly accessible systemsIdentify system users and processesAuthenticate user identitiesSanitize or destroy media containing FCILimit physical access to systemsEscort visitors and monitor activityMaintain audit logs of physical accessMonitor and control communications at boundariesImplement subnetworks for public systemsIdentify and fix system flaws timelyProvide malicious code protectionUpdate malicious code mechanismsPerform periodic system scansMonitor system security alerts
Cost and Timeline
Implementation cost: — $5,000-$25,000Timeline: — 4-12 weeksAnnual maintenance: — $2,000-$10,000
Level 2: Advanced
Who Needs It
Any company that handles Controlled Unclassified Information (CUI) — sensitive but unclassified defense information.
CUI includes:
Technical drawings and specifications marked as CUIExport-controlled information (ITAR/EAR)Critical infrastructure informationProprietary defense dataPersonally identifiable information in defense contexts
Requirements
110 security practices — aligned with NIST SP 800-171 Rev 2Third-party assessment — by a C3PAO for critical programsSelf-assessment — for non-critical programsPlan of Action and Milestones (POA&M) — allowed for up to 1 year
Additional Practices Beyond Level 1
Level 2 adds 93 practices across 14 domains:
| Domain | Level 1 Practices | Level 2 Practices |
|--------|------------------|-------------------|
| Access Control | 4 | 22 |
| Awareness & Training | 0 | 3 |
| Audit & Accountability | 0 | 9 |
| Configuration Management | 0 | 9 |
| Identification & Authentication | 2 | 11 |
| Incident Response | 0 | 3 |
| Maintenance | 0 | 6 |
| Media Protection | 1 | 9 |
| Personnel Security | 0 | 2 |
| Physical Protection | 4 | 6 |
| Risk Assessment | 0 | 3 |
| Security Assessment | 0 | 4 |
| System & Comm Protection | 2 | 16 |
| System & Info Integrity | 4 | 7 |
Cost and Timeline
Implementation cost: — $50,000-$250,000Third-party assessment: — $30,000-$75,000Timeline: — 6-18 monthsAnnual maintenance: — $15,000-$50,000
Decision Framework
Choose Level 1 If:
You only handle FCI (not CUI)Your contracts don't involve sensitive technical dataYou're a general supplier of commercial itemsYou're just entering the defense marketYour contracts are below the simplified acquisition threshold
Choose Level 2 If:
Your contracts involve CUIYou handle technical drawings or specificationsYou work with export-controlled informationYou're a subcontractor to a prime handling CUIYour contract includes DFARS 252.204-7012 clause
Not Sure? Ask These Questions:
Does your contract include the DFARS 252.204-7012 clause?Are you handling any information marked as CUI?Do you receive technical data packages from the government?Are you working on a program involving classified or sensitive information?Has your prime contractor told you CUI flows down to your level?
If you answered "yes" to any of these, you likely need Level 2.
The Transition Path: Level 1 to Level 2
Many businesses start with Level 1 and progress to Level 2 as they pursue larger contracts. Here's a smart transition strategy:
Phase 1: Achieve Level 1 (Months 1-3)
Implement 17 basic practicesComplete self-assessmentSubmit SPRS scoreBegin pursuing FCI-only contracts
Phase 2: Prepare for Level 2 (Months 4-9)
Conduct NIST 800-171 gap assessmentDevelop System Security PlanBegin implementing additional controlsInvest in required technology
Phase 3: Achieve Level 2 (Months 10-18)
Complete implementation of 110 practicesConduct internal assessmentEngage C3PAO for third-party assessmentAddress any findings and achieve certification
Conclusion
The right CMMC level depends on your business model, the contracts you pursue, and the information you handle. Start with Level 1 to enter the market quickly, then progress to Level 2 as your defense business grows. The important thing is to start now.
Ready to Take the Next Step?
Whether you're a small manufacturer seeking defense contracts, a government buyer looking for qualified suppliers, or a business owner pursuing CMMC certification, KDM & Associates and the V+KDM Consortium are here to help.
Join the KDM Consortium Platform today:
Schedule a free introductory session to learn how we can accelerate your path to government contracting success.
Whether you're a small manufacturer seeking defense contracts, a government buyer looking for qualified suppliers, or a business owner pursuing CMMC certification, KDM & Associates and the V+KDM Consortium are here to help.
Join the KDM Consortium Platform today:
[Register as a Supplier (SME)](/register?type=sme) — Get matched with government contract opportunities, access capacity-building resources, and connect with prime contractors.[Register as a Government Buyer](/register?type=buyer) — Discover qualified, defense-ready small businesses and streamline your procurement process.
*Schedule a free introductory session to learn how we can accelerate your path to government contracting success.*