What is the difference between CMMC Level 1 and Level 2?
Level 1 covers Federal Contract Information and requires 15 practices verified by an annual self-assessment. Level 2 covers Controlled Unclassified Information and requires all 110 practices from NIST SP 800-171, verified every three years — by a C3PAO for most contracts, or by self-assessment only where a contract specifically permits it. The trigger is the data you handle, not your company size.
The practical consequence is that Level 2 is not Level 1 with more paperwork. It is a different assessment regime with an external assessor, a different evidence standard, and a scoring model where a single unmet practice can cost you points against a threshold.
If you are unsure which applies, the question to answer first is not 'what level do we want' but 'does CUI enter our environment, and where'. Scope follows the data. Organisations routinely over-scope by assuming every system is in the boundary, and under-scope by forgetting that email and file-sharing usually are.
Sources
- 32 CFR Part 170 — CMMC Program
- NIST SP 800-171 Rev 2
- CMMC Scoping Guide, Level 2
Drafted with the tools on this site, then checked against the sources above by a practitioner before publishing. Reviewed 2026-08-07. Found something wrong? It should be corrected — this page is only worth as much as its accuracy.