
CMMC Level 1 vs Level 2: Which Applies and What It Demands
The dividing line is the type of information you handle. Getting it wrong in either direction is expensive, and most contractors guess.
GuardsArm Team
Security Experts

Which CMMC level applies to you is not a choice. It is determined by the type of information your contracts involve, and the gap in effort between the levels is large enough that guessing is costly in both directions.
The dividing line is the information type
Federal Contract Information (FCI) is information provided by or generated for the government under a contract, not intended for public release. Most contractors handling any federal work touch FCI.
Controlled Unclassified Information (CUI) is information requiring safeguarding or dissemination controls under law, regulation or government-wide policy. Technical data, specifications, and a wide range of programme information fall under it.
| You handle | Level |
|---|---|
| FCI only | Level 1 |
| CUI | Level 2 |
| CUI on the most critical programmes | Level 3 |
The practical problem is that contractors frequently do not know which they hold. CUI arrives in an email attachment, in a drawing, in a specification — it is not always marked as clearly as it should be, and once it is in your environment the requirement follows it.
The effort gap
Level 1 is a set of basic safeguarding requirements, demonstrated by annual self-assessment with an affirmation. They are genuinely basic: limit access to authorised users, control what is posted publicly, sanitise media before disposal, use antivirus, control physical access.
Level 2 aligns with the NIST SP 800-171 requirement set — a substantially larger and more demanding body of controls, generally requiring assessment by a certified third-party organisation rather than self-attestation for most contracts.
That is not a marginal step up. It is a different programme, with a system security plan, a plan of action and milestones, and evidence that controls operate.
What Level 2 actually requires you to build
| Area | Typical gap for a smaller contractor |
|---|---|
| Access control | Shared accounts; no role-based model |
| Audit and accountability | Logging not centralised, not retained |
| Configuration management | No baselines, no change control |
| Identification and authentication | MFA incomplete, especially for remote access |
| Incident response | No plan, never exercised |
| Media protection | Removable media uncontrolled |
| System and communications protection | CUI not segregated from general IT |
| System and information integrity | Patching ad hoc |
Segregating CUI is the architectural decision that determines the size of the programme. If CUI is scattered across your general environment, the whole environment is in scope. Creating a defined enclave — a bounded environment where CUI lives — dramatically reduces what must be assessed.
That decision is worth making before remediation starts, because it changes what needs remediating. See NIST 800-53 tailoring for the related scoping logic.
The System Security Plan and the POA&M
Two documents carry the programme:
The System Security Plan describes your environment, its boundary, and how each requirement is met. An assessor reads it first and assesses against it, so a vague or inaccurate SSP makes everything harder.
The Plan of Action and Milestones records requirements not yet met, with owners and dates. Some requirements cannot be deferred to a POA&M at all, and there are limits on how long items may remain open — so a POA&M is not a way to postpone the difficult controls indefinitely.
Where contractors go wrong
- Assuming Level 1 because nobody has said the word CUI, without checking contract clauses or what actually arrives in the inbox
- Scoping the whole company instead of building an enclave
- Starting remediation before scoping, then redoing it
- Treating it as an IT project when it needs contract, legal and operations involvement
- Leaving it until a contract is at stake, when the timeline no longer permits a proper programme
Where to start
Determine what you actually hold. Check your contract clauses, and check what has arrived by email from prime contractors over the past year. That single question decides which level applies and therefore the size of everything that follows.
GuardsArm supports contractors through CMMC scoping, enclave design and readiness. See CMMC compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “CMMC Level 1 vs Level 2: Which Applies and What It Demands”
Talk to the GuardsArm team about how these services apply to your environment.


