APTSecurity Management

Level 1 or Level 2? How to Tell Which You Need

Cody D. Martin//Updated August 9, 2026

Your CMMC level depends on the government data you handle. Federal Contract Information alone points to Level 1 and its 15 requirements. Controlled Unclassified Information points to Level 2 and its 110 practices. The contract clauses tell you which, and DFARS 252.204-7012 is the clearest signal.

The level is not a choice and it does not scale with company size. It follows from the data you handle, which follows from your contract.

Read the clauses first

Clause present What it tells you
FAR 52.204-21 only FCI. Points to Level 1
DFARS 252.204-7012 CUI. Points to Level 2
DFARS 252.204-7019 / 7020 SPRS posting and assessment access, which accompany CUI
DFARS 252.204-7021 The CMMC clause, which names the level

7012 is the clearest signal in the whole framework. If it is in your contract, you handle CUI and Level 1 is not your path, regardless of what anyone told you verbally.

Check attachments and the statement of work, not just the cover page. And if you are a subcontractor, check what your prime flowed down to you rather than what the prime’s own obligations are. A prime handling CUI may or may not pass CUI to you, and the flow down governs.

What each level costs you

Level 1. Fifteen requirements from FAR 52.204-21. Access control, individual accounts, media sanitisation, physical protection, boundary protection, patching, antimalware. Annual self assessment. Most companies already do most of it and have never documented it.

Level 2. One hundred and ten practices aligned to NIST SP 800-171. A System Security Plan describing your actual boundary. A POA&M for anything unmet. An SPRS score. Annual affirmation. This is a program rather than a checklist, and first time scores are frequently negative.

The gap between them is large enough that the scoping question deserves real attention rather than an assumption.

The misclassification that costs most

A small shop makes parts for a defense prime. To make them it receives engineering drawings and specifications.

That technical data is almost always Controlled Technical Information, which is a CUI category. The company is Level 2 and often believes it is Level 1, sometimes for years, because nobody sent a document with a marking on it.

CUI is frequently unmarked. Marking practice across the defense industrial base is inconsistent, and the category decides, not the stamp.

What the July 2026 suspension changed

For Level 1, nothing at all.

For Level 2, only the assessment route. Third party assessment by a C3PAO is paused, and during the suspension a contract may specify Level 2 (Self) instead. The 110 practices, the SSP, the POA&M, the SPRS score and the annual affirmation all continue, because DFARS 252.204-7012 was not suspended.

So the answer to “which level am I” is unchanged by the suspension. What changed is who verifies it.

If you are between the two

Some companies could legitimately avoid CUI and choose to, declining work that would carry it. That is a real business decision and often a cheaper one than a Level 2 program built reluctantly.

If you take that path, say so to your primes in writing, and have a rule for what happens when a drawing arrives by email anyway. That moment is when your scope changes, and somebody should recognize it.

  • CMMC
  • FCI
  • CUI
  • DFARS
  • scoping

More on compliance