This blog was originally published by Justice IT Consulting LLC here

CMMC Levels Explained: Level 1 vs. Level 2 vs. Level 3 (and FCI vs. CUI)

Quick answer: There are three CMMC levels. Level 1 applies if you handle Federal Contract Information (FCI) and requires 15 controls across roughly 57 assessment objectives, self-assessed annually. Level 2 applies if you store, process, or transmit Controlled Unclassified Information (CUI) and requires 110 controls across 320 assessment objectives, based on NIST 800-171 Revision 2. Level 3 applies to a very small subset of companies handling more sensitive information and requires Level 2 certification first, followed by a government-led (DIBCAC) assessment. Most companies that think they need Level 3 actually don’t.

What Determines Your Level: FCI vs. CUI

Your CMMC level isn’t a business decision. It’s determined entirely by what kind of information you handle.

Federal Contract Information (FCI) is any non-public information related to a government contract. A simple way to think about it: if you have to log in somewhere to access it, it’s likely FCI. If the same information is publicly available, like a company name or a general phone number, it’s not FCI. If your business handles FCI but no CUI, Level 1 is your requirement.

Controlled Unclassified Information (CUI) is a step up in sensitivity. It’s effectively a derivative of classified information: not top secret, but sensitive enough that its exposure matters. In practice, CUI often looks like drawings, technical specifications, or what’s specifically called Controlled Technical Information (CTI). CUI is also categorized as either basic or specified, where specified CUI carries additional dissemination instructions, such as export control restrictions or “no foreign” markings. If your business stores, processes, or transmits CUI, you need Level 2, whether through self-assessment or third-party (C3PAO) certification depending on what your specific contracts require.

Level 1: The FCI Baseline

Level 1 covers companies that handle FCI but not CUI. It requires 15 controls, broken down into roughly 57 assessment objectives, and is satisfied through an annual self-assessment. This is the lightest tier of CMMC, but it’s not optional if FCI is present in your environment.

Level 2: The Tier Most Companies Land In

Level 2 is where the majority of companies in the defense industrial base actually need to be. It’s built on NIST 800-171 Revision 2’s 110 controls, organized into 14 control families, which break down further into 320 specific assessment objectives. Those assessment objectives, not the controls themselves, are what you’re actually evaluated against.

Depending on what your specific contracts require, Level 2 compliance is demonstrated either through a self-assessment or through third-party certification performed by a Certified Third-Party Assessment Organization (C3PAO). Which one applies to you depends on what’s written into your contract, not on which one seems easier or less expensive.

Level 3: Rare, and Often Assumed Incorrectly

Level 3 covers a genuinely small subset of companies handling more sensitive categories of information, and it requires completing Level 2 certification first before a government-led DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) assessment can even begin.

Here’s a pattern worth knowing about: companies frequently assume they need Level 3 when they actually don’t. If someone tells you your business needs Level 3, it’s worth stepping back and specifically identifying what type of information you handle and why before accepting that at face value. Most companies that go through this exercise land back at Level 2.

Why the Old “Five Levels” Confuses People

If you’ve seen references to five CMMC levels, that’s from CMMC 1.0, the earlier version of this framework. The current model has only three levels. Roughly speaking, old Level 1 mapped to what’s now Level 1, old Level 3 mapped to what’s now Level 2, and old Level 5 mapped to what’s now Level 3. If you’re seeing outdated five-level references, especially in older vendor materials or old internal documentation, they don’t reflect the current framework.

Bottom Line

Your CMMC level comes down to one question: do you handle FCI only, or do you handle CUI? FCI alone puts you at Level 1. Any CUI exposure puts you at Level 2, which is where most companies in the defense supply chain actually land. Level 3 is reserved for a narrow set of companies handling especially sensitive information, and it’s worth confirming you actually need it before assuming that’s your requirement.

Published by Austin Justice, Justice IT Consulting LLC