CMMC Level 1 vs Level 2: Which Does Your Company Actually Need?
A practical guide to choosing between CMMC Level 1 (15 requirements, FCI) and Level 2 (110 requirements, CUI) — with the decision test, effort comparison, and common traps.
We implement, track and maintain CMMC Level 1 and Level 2 for defense suppliers — inside one live portal for onboarding, evidence, tickets, alerts, and everything still left to do.
New DoD solicitations require CMMC Level 1 or Level 2 self-assessments at award, with annual affirmations recorded in SPRS.
Legal requirementDoD suspended the Phase 2 rollout — which would have required C3PAO third-party certification in many awards — and opened a program review. A Reform Task Force report is expected around mid-September 2026.
Legal requirementSafeguarding covered defense information under NIST SP 800-171, plus incident reporting. Unaffected by the Phase 2 suspension.
Legal requirementDFARS 252.204-7019/7020 require a current self-assessment score in SPRS. Primes can and do check it.
Legal requirementCyber incidents affecting covered defense information must be reported to DoD within 72 hours of discovery.
Legal requirementAn affirming official must confirm continued compliance each year. Inaccurate affirmations carry False Claims Act exposure.
Legal requirementPick the one that sounds like your week. We will show you what actually comes next.
This is the most common reason shops call us, and it is usually the fastest to resolve.
We prepare and support the submission. The affirming official inside your company is the one who signs it.
A clause landed in a solicitation or a flowdown and you need to know what it commits you to.
We read clauses to determine technical scope. Contract interpretation questions belong with your counsel or contracting officer.
Unsure is the most common honest answer, and getting it wrong is expensive in both directions.
We do not unilaterally designate data as CUI. The determination follows your contract and the government or prime that owns the data.
Federal Contract Information only — no controlled technical data in your environment.
Level 1 is a self-assessment. One controlled drawing changes the answer, so we re-check the determination each year.
Controlled Unclassified Information is in play, so the full NIST SP 800-171 set applies.
We prepare you for assessment. We are not a C3PAO and cannot assess or certify you.
If covered defense information may be affected, the reporting clock is short.
The reporting obligation sits with your company, not with us. We support containment, evidence and documentation for clients; we are not a 24/7 emergency response retainer.
Every engagement runs inside the portal — the same one your assigned technician uses. You always know what is done, what is open, and whose turn it is.
Live Partly live Preview
Open tickets, remaining onboarding tasks, completion percentage and active alerts, scoped to your organisation by row-level security.
Illustrative layout — no real client data is shown anywhere on this site.
The task plan, owners and completion tracking are live. The guided intake wizard and bulk user import are still being built.
Core of this module is live today; the parts noted above are still in build.
Illustrative layout — no real client data is shown anywhere on this site.
Create, comment, prioritise and resolve tickets with a full event history. Internal notes stay internal — enforced server-side, not hidden in the UI.
Illustrative layout — no real client data is shown anywhere on this site.
Inventory and scope flags are live. Automated syncs from endpoint and identity tooling are configured but not yet publishing.
Core of this module is live today; the parts noted above are still in build.
Illustrative layout — no real client data is shown anywhere on this site.
The alert feed, deduplication and triage actions are live. Provider integrations are staged and awaiting activation.
Core of this module is live today; the parts noted above are still in build.
Illustrative layout — no real client data is shown anywhere on this site.
Per-requirement status, evidence linkage and POA&M tracking against the Level 1 and Level 2 catalogues. Designed, not yet shipped.
Designed and specified, not yet shipped. Shown so you can see where this is going.
Illustrative layout — no real client data is shown anywhere on this site.
Versioned evidence artefacts with freshness tracking and review dates. Designed, not yet shipped.
Designed and specified, not yet shipped. Shown so you can see where this is going.
Illustrative layout — no real client data is shown anywhere on this site.
Three questions. About twenty seconds. No email required.
Preliminary only. This is a starting point for a conversation, not a scoping determination — your contract clauses and what your primes actually send you decide it.
Seven stages, with both sides of the line named so nothing sits waiting on "someone".
CMMC911Review contracts, clauses and data flows.
YouShare clauses, primes and known obligations.
CMMC911Physical inventory of systems, network and access.
YouGive us a couple of hours and floor access.
CMMC911Import identities, endpoints and network devices.
YouConfirm the people list is accurate.
CMMC911Assess against the applicable requirement set.
YouReview findings and confirm priorities.
CMMC911Implement controls, segmentation and tooling.
YouApprove changes and maintenance windows.
CMMC911Capture and version artefacts per requirement.
YouSign off on policies and procedures.
CMMC911Monitor drift, refresh evidence, prep the assessment.
YouAffirm — the signature is always yours.
When your prime asks, your assessment changes, or something breaks, you know exactly where to go.
Portal, email or phone — every request becomes a tracked ticket.
Priority set against response and resolution targets.
A named technician, not a queue.
Severity or a stalled clock moves it up.
Artefacts attach to the ticket and to the requirement they satisfy.
Every status change and comment kept, in order, permanently.
A practical guide to choosing between CMMC Level 1 (15 requirements, FCI) and Level 2 (110 requirements, CUI) — with the decision test, effort comparison, and common traps.
DoD suspended CMMC Phase 2 on July 13, 2026. Here's what's still required for defense contractors — self-assessments, SPRS, NIST 800-171 — and why pausing now is the worst move.
The FCI vs CUI determination decides whether you need CMMC Level 1 or Level 2. A plain-English guide to classifying purchase orders, drawings, and tech data.
Yes. DoD suspended Phase 2 (third-party certification requirements) in July 2026 while it reviews the program, but Phase 1 remains in force: Level 1 and Level 2 self-assessments, SPRS score submissions, and annual affirmations are still required, and NIST SP 800-171 obligations under DFARS 252.204-7012 never paused.
If you only handle Federal Contract Information (FCI) — basic contract data — Level 1 applies. If you receive Controlled Unclassified Information (CUI) like controlled drawings, specs, or technical data from a prime, Level 2 applies. Most companies doing DoD work handle CUI.
No — and be wary of anyone who says they can. Certification assessments are done by authorized third parties. We do everything before and after: implement the requirements, prepare your self-assessment, maintain your compliance, and support your organization day to day.
We start with a site walk of your facility, load your users, assets, and network details into your portal, generate your gap snapshot and work plan, then start executing. You watch progress live in the portal and always know exactly what is left.
No guessing, no consultant fog, no surprise when the prime asks.
Start the assessment Talk to the support desk
CMMC911 is an independent compliance support provider. We are not a C3PAO and do not conduct certification assessments.