CMMC
What Is the Difference Between CMMC Level 1 and Level 2?
The information you handle decides it. Level 1 applies to Federal Contract Information (FCI) and is the 15 basic safeguarding requirements of FAR 52.204-21, self-assessed every year with no plan of action allowed. Level 2 applies to Controlled Unclassified Information (CUI) and is the 110 security requirements of NIST SP 800-171 Rev 2, assessed at least every three years, with a limited plan of action allowed.
Capital Cyber. Sources are listed at the end of the article.
Level 1: Federal Contract Information
Level 1 is the 15 requirements of FAR 52.204-21(b)(1)(i) through (xv): limit system access to authorized users, limit what they can do, verify and control external connections, control public information, identify and authenticate users, sanitize media before disposal, limit and escort physical access, monitor and protect the boundary, separate public-facing systems, and identify, report and fix flaws, protect against malicious code, update that protection and scan for it.
Every requirement must be met. 32 CFR 170.15 says "No POA&Ms are permitted for CMMC Level 1." The company self-assesses annually, posts the result in SPRS and a senior official affirms it.
Level 2: Controlled Unclassified Information
Level 2 is the 110 security requirements of NIST SP 800-171 Rev 2, the version 32 CFR Part 170 incorporates by reference, assessed against the objectives in NIST SP 800-171A. It covers access control, awareness and training, audit, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
A Level 2 self-assessment is repeated at least every three years and affirmed annually (32 CFR 170.16 and 170.22). A limited Plan of Action and Milestones is allowed, closed within 180 days (32 CFR 170.21).
How to Tell Which One You Need
Read the contract and the data it gives you. If you only receive information that is not intended for public release and is provided by or generated for the government under a contract, that is FCI and Level 1. If the contract includes DFARS 252.204-7012 and you receive information marked as CUI, plan for Level 2. A Level 2 self-assessment also satisfies Level 1 for the same scope (32 CFR 170.16(a)).
Frequently Asked Questions
4 QUESTIONSHow many requirements are in CMMC Level 1?
Fifteen: the basic safeguarding requirements of FAR 52.204-21(b)(1)(i) through (xv), per 32 CFR 170.15.
How many requirements are in CMMC Level 2?
110, the security requirements of NIST SP 800-171 Rev 2.
Can I have a POA&M at Level 1?
No. 32 CFR 170.15 and 170.21(a)(1) do not permit a POA&M for Level 1 at any time.
How often is each level assessed?
Level 1 is self-assessed annually. A Level 2 self-assessment is repeated at least every three years, with an annual affirmation in between (32 CFR 170.15, 170.16 and 170.22).
Sources
READ 2026-10-08- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov)
- 32 CFR 170.15, CMMC Level 1 self-assessment and affirmation (eCFR)
- 32 CFR 170.16, CMMC Level 2 self-assessment and affirmation (eCFR)
- 32 CFR 170.21, Plan of Action and Milestones requirements (eCFR)
- NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (csrc.nist.gov)
This article explains the regulations and is not legal advice.
Talk it through in 30 minutes.
A call is a conversation, not a pitch. Tell us how your business runs and we will tell you what we would manage.
Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.
