" /> What is the difference between CMMC Level 1 and Level 2? | ITSecOps
Guide

What is the difference between CMMC Level 1 and Level 2?

Updated · Jul 2026 By ITSecOps.cloud Free · No signup

CMMC Level 1 covers companies handling only FCI: 15 basic safeguarding requirements from FAR 52.204-21, verified by annual self-assessment. Level 2 applies the moment you handle CUI: all 110 NIST SP 800-171 requirements, usually verified by a third-party (C3PAO) assessment every three years.

Practical differences

  • Scope: FCI = information not intended for public release under contract; CUI = controlled unclassified information marked by the government
  • Proof: L1 self-attests annually; most L2 contracts require certification by an accredited C3PAO
  • SPRS: L2 requires a submitted score; L1 self-assessments are also logged in SPRS
  • Cost: L1 is typically a few thousand in cleanup; L2 runs $40k-$150k+

Unsure which one your contracts trigger? The free CMMC planner classifies you from your data types, or read the full CMMC guide.

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation