home / frameworks / cmmc / levels-and-assessments

// CMMC hub

CMMC levels and assessment types

What each CMMC level requires, who assesses it, and how scoring and POA&Ms work.

How CMMC levels map to information

CMMC ties the level to the type of information on the contractor's systems. Federal Contract Information, which is information not intended for public release that's provided or generated under a contract, needs Level 1. Controlled Unclassified Information (CUI) needs Level 2. Level 3 is for CUI on programs that face advanced persistent threats, and the Department decides when it applies.

The program office or requiring activity picks the level and assessment type for each solicitation. Contractors don't choose their level. They need to know which systems, cloud services, and external service providers handle FCI or CUI, and they must scope their assessment to cover all of those assets.

Level 1 (Self)

Level 1 covers the 15 security requirements in FAR 52.204-21. They include limiting access to authorized users, authenticating users, sanitizing media, controlling physical access, protecting system boundaries, and keeping malware protection and patches current.

The contractor self-assesses every year and enters the result in SPRS, and an affirming official, usually a senior executive, also confirms compliance each year. All 15 requirements must be met. There is no plan of action option at this level.

Level 2 (Self) and Level 2 (C3PAO)

Level 2 uses the 110 requirements of NIST SP 800-171 Rev. 2, grouped into 14 domains, and assesses them with the procedures in SP 800-171A. The rule allows 2 assessment types. A Level 2 (Self) assessment is done by the contractor. A Level 2 (C3PAO) certification assessment is done by an authorized third-party assessment organization and recorded in the Department's CMMC eMASS system.

Both run on a 3-year cycle. Scoring follows the DoD assessment methodology, in which each requirement is worth 1, 3, or 5 points and a perfect score is 110. The contracting officer sees the status in SPRS but not the details of the assessment.

Level 3 (DIBCAC)

Level 3 goes further. Its 24 requirements come from SP 800-172 and include a security operations centre, a cyber incident response team, threat-informed risk assessment, supply chain risk plans, and penetration testing. A contractor must hold a final Level 2 (C3PAO) status on the same scope before DCMA's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) will conduct the Level 3 assessment.

Level 3 also runs on a 3-year cycle with annual affirmations. Few contractors will need it, since the Department expects to reserve it for a small share of programs.

Conditional status and POA&Ms

A contractor that falls a little short can reach a conditional status with a POA&M, but only under strict rules in 32 CFR 170.21. At Level 2, the score must be at least 80 percent of the requirements, and only requirements worth 1 point can be deferred, with a narrow exception for encryption that isn't FIPS-validated. Some can never be deferred. Six requirements are barred from a POA&M, including the system security plan, external connections, control of public information, and 3 physical access requirements.

Every POA&M must be closed within 180 days of the conditional status date, confirmed by a closeout assessment. Otherwise the status expires. Level 3 has its own list of requirements that can't be deferred, including the security operations centre and incident response team.

  • Level 1: 15 requirements, annual self-assessment, no POA&M
  • Level 2: 110 requirements, self or C3PAO, every 3 years
  • Level 3: 24 added requirements, DIBCAC, every 3 years
  • All levels: annual affirmation by a senior official

Resources

All CMMC resources

References

  1. 32 CFR part 170, Cybersecurity Maturity Model Certification (CMMC) Program, Electronic Code of Federal Regulations
  2. CMMC Program final rule, 89 FR 83092 (October 15, 2024), Federal Register via govinfo.gov
  3. NIST SP 800-172, Enhanced Security Requirements for Protecting CUI, NIST