Comparison · CMMC Guide

CMMC Level 1 vs Level 2: Which Does Your Contract Require?

The whole decision comes down to one question: does your contract involve CUI, or only FCI?

ComparisonCMMC Levels

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 19, 2026 · 5 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

The distinction between CMMC Level 1 and Level 2 comes down to one question: does your contract involve Controlled Unclassified Information (CUI), or only Federal Contract Information (FCI)? Get this wrong and you either overspend on unnecessary compliance or underprepare and lose contract eligibility.

The fundamental difference: FCI vs CUI

Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. It is the baseline category: contract terms, delivery schedules, and general project communications that are not publicly available but are not sensitive in a national security context.

Controlled Unclassified Information (CUI) requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy. CUI includes technical data, engineering drawings, test results, vulnerability information, and export-controlled data: information that, while not classified, could damage national security if compromised. CUI carries specific markings defined by the National Archives CUI Registry.

If your contract only involves FCI, you need CMMC Level 1. If your contract involves CUI in any capacity, whether you create it, receive it, store it, process it, or transmit it, you need CMMC Level 2. There is no middle ground.

CMMC Level 1: the basics

Level 1 requires the 15 basic safeguarding requirements derived from FAR 52.204-21. These are fundamental cybersecurity hygiene requirements that any business should implement regardless of government contracting. They cover access control basics, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.

The assessment model for Level 1 is self-assessment. You evaluate your own compliance, submit your score to the Supplier Performance Risk System (SPRS), and affirm compliance annually through a senior leadership affirmation. There is no third-party assessment required for Level 1, which significantly reduces both cost and timeline.

CMMC Level 2: the full standard

Level 2 requires compliance with all 110 security requirements in NIST SP 800-171, organized across 14 control families ranging from Access Control and Audit and Accountability to System and Communications Protection and System and Information Integrity.

The assessment model depends on the type of CUI and the contract's priority level. For contracts involving CUI on prioritized acquisitions, a C3PAO third-party assessment is required. For non-prioritized acquisitions, self-assessment may be acceptable, though this distinction is subject to ongoing DoD guidance and phased implementation. Understanding whether your contracts fall into the prioritized or non-prioritized category is critical for planning your approach and budget. See CMMC self-assessment vs C3PAO for the full breakdown.

Not sure whether you are looking at a 15-requirement Level 1 lift or the full 110-control Level 2 standard? A free 2-minute gap check gives you a directional self-assessment (not an official SPRS score).

Run the free gap check →

What the two levels actually cost

Cost claims for CMMC are all over the internet. The figures below come directly from the DoD's published Regulatory Impact Analysis, expressed as three-year totals so you can compare apples to apples. Most of the cost is preparation and documentation, which is the work AI can compress.

Path (3-year total)Small entityLarger entity
Level 1 self-assessment$5,977$4,042
Level 2 self-assessment$37,196$48,827
Level 2 certification (C3PAO)$104,670$117,768

The C3PAO assessor engagement alone runs about $31,234 for a small entity and $52,056 for a larger one within that certification total. The gap between Level 1 and Level 2 is large, which is exactly why correctly identifying your required level matters before you commit budget. For a deeper breakdown, see our CMMC Level 2 certification cost guide.

Source: DoD CMMC Program Regulatory Impact Analysis (DOD-2023-OS-0063-0003), pp. 12-26.

How to determine which level applies to you

Check your contract. The required CMMC level is specified in the DFARS CMMC clause when it appears in solicitations (confirm the current clause number, which DoD has updated through rulemaking). If you are unsure, look for these indicators.

Your contract likely requires Level 1 if it references FAR 52.204-21 only, you handle FCI but no technical data, no CUI markings appear on anything you receive or generate, and your contracting officer has confirmed no CUI is involved.

Your contract likely requires Level 2 if it references the DFARS safeguarding and CMMC clauses with Level 2 specified, you receive or generate technical data, engineering drawings, or test results, any information you handle carries CUI markings, or your prime has identified CUI flow-down in your subcontract.

If you hold multiple contracts, you may need different levels for different work. Your overall certification should target the highest level required by any active or anticipated contract.

The subcontractor trap

Subcontractors often assume they only need Level 1 because they are not the prime. This is frequently wrong. If CUI flows down to you from the prime, or if you generate CUI as part of your subcontracted work, you need Level 2 regardless of your position in the supply chain. The CUI flow-down requirements apply to subcontractors at all tiers who handle CUI.

Primes are increasingly requiring Level 2 compliance from subcontractors as a condition of doing business, because the prime is responsible for CUI protection throughout its supply chain. Even if your current contracts only require Level 1, building toward Level 2 readiness positions you to compete for higher-value subcontracts.

What about Level 3?

CMMC Level 3 exists for contractors handling the most sensitive CUI associated with critical programs. Level 3 adds requirements from NIST SP 800-172 on top of the 110 Level 2 requirements, focused on enhanced measures such as penetration-resistant architecture and advanced incident response. Level 3 assessments are conducted by the government rather than C3PAOs (confirm the current assessment authority). If you need Level 3, your contracting officer has told you so explicitly.

Making the right choice with AaaS

Whether you need Level 1 or Level 2, an AI-as-a-Service (AaaS) platform helps you implement exactly the right controls without over-engineering or under-building. AI agents map your contract requirements to the applicable controls and guide implementation at the appropriate level, giving your team operational leverage while the authorizing official approves every output. For companies managing multiple contracts at different levels, AaaS provides a single platform to track compliance across all of them without duplicating effort.

The platform also adds clarity when the Level 1 vs Level 2 determination is ambiguous, mapping your actual information flows against CUI definitions so your level decision rests on analysis rather than guesswork. Start with the free gap check, then move to the $799 CMMC Readiness Snapshot.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read in about 2 minutes. The CMMC Readiness Snapshot measures your environment against all 110 NIST 800-171 controls and returns a PDF within minutes of intake, for $799 one time. Month-to-month plans available, no long-term contract.

Run the free 2-minute gap check See the $799 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures are the DoD's published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ builds AI-driven CMMC Level 1 and Level 2 readiness software. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee CMMC certification, only an authorized C3PAO can. The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.