Back to Blog
Compliance
4 min read

CMMC Level 1 vs Level 2: Which Applies and What It Demands

The dividing line is the type of information you handle. Getting it wrong in either direction is expensive, and most contractors guess.

GuardsArm Team

Security Experts

September 25, 2026

CMMC Level 1 compared with Level 2

Which CMMC level applies to you is not a choice. It is determined by the type of information your contracts involve, and the gap in effort between the levels is large enough that guessing is costly in both directions.

Information type decides
FCI means Level 1; CUI means Level 2
Self-assessment versus assessor
The step change between the levels
Enclave design sets the cost
Scattered CUI puts everything in scope

The dividing line is the information type

Federal Contract Information (FCI) is information provided by or generated for the government under a contract, not intended for public release. Most contractors handling any federal work touch FCI.

Controlled Unclassified Information (CUI) is information requiring safeguarding or dissemination controls under law, regulation or government-wide policy. Technical data, specifications, and a wide range of programme information fall under it.

You handleLevel
FCI onlyLevel 1
CUILevel 2
CUI on the most critical programmesLevel 3

The practical problem is that contractors frequently do not know which they hold. CUI arrives in an email attachment, in a drawing, in a specification — it is not always marked as clearly as it should be, and once it is in your environment the requirement follows it.


The effort gap

Relative programme effort by levelLevel 2 is not an increment on Level 1. It is a substantially larger programme with external assessment.Level 1 — FCI15Basic safeguarding, annual self-assessmentLevel 2 — CUI100NIST SP 800-171 aligned, third-party assessed
This gap is why misjudging which applies is expensive.

Level 1 is a set of basic safeguarding requirements, demonstrated by annual self-assessment with an affirmation. They are genuinely basic: limit access to authorised users, control what is posted publicly, sanitise media before disposal, use antivirus, control physical access.

Level 2 aligns with the NIST SP 800-171 requirement set — a substantially larger and more demanding body of controls, generally requiring assessment by a certified third-party organisation rather than self-attestation for most contracts.

That is not a marginal step up. It is a different programme, with a system security plan, a plan of action and milestones, and evidence that controls operate.


What Level 2 actually requires you to build

AreaTypical gap for a smaller contractor
Access controlShared accounts; no role-based model
Audit and accountabilityLogging not centralised, not retained
Configuration managementNo baselines, no change control
Identification and authenticationMFA incomplete, especially for remote access
Incident responseNo plan, never exercised
Media protectionRemovable media uncontrolled
System and communications protectionCUI not segregated from general IT
System and information integrityPatching ad hoc

Segregating CUI is the architectural decision that determines the size of the programme. If CUI is scattered across your general environment, the whole environment is in scope. Creating a defined enclave — a bounded environment where CUI lives — dramatically reduces what must be assessed.

That decision is worth making before remediation starts, because it changes what needs remediating. See NIST 800-53 tailoring for the related scoping logic.


The System Security Plan and the POA&M

Two documents carry the programme:

The System Security Plan describes your environment, its boundary, and how each requirement is met. An assessor reads it first and assesses against it, so a vague or inaccurate SSP makes everything harder.

The Plan of Action and Milestones records requirements not yet met, with owners and dates. Some requirements cannot be deferred to a POA&M at all, and there are limits on how long items may remain open — so a POA&M is not a way to postpone the difficult controls indefinitely.

The POA&M is not an indefinite deferral
Some requirements must be met outright and cannot sit on a plan of action, and those that can are subject to limits on how long they stay open. Treating the POA&M as a place to park the hard controls produces a programme that fails at assessment rather than one that is progressing.

Where contractors go wrong

  1. Assuming Level 1 because nobody has said the word CUI, without checking contract clauses or what actually arrives in the inbox
  2. Scoping the whole company instead of building an enclave
  3. Starting remediation before scoping, then redoing it
  4. Treating it as an IT project when it needs contract, legal and operations involvement
  5. Leaving it until a contract is at stake, when the timeline no longer permits a proper programme

Where to start

Determine what you actually hold. Check your contract clauses, and check what has arrived by email from prime contractors over the past year. That single question decides which level applies and therefore the size of everything that follows.

GuardsArm supports contractors through CMMC scoping, enclave design and readiness. See CMMC compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “CMMC Level 1 vs Level 2: Which Applies and What It Demands”

Talk to the GuardsArm team about how these services apply to your environment.