CMMC Level Map

Defense supply chain · self-guided

CMMC Level Map

Which level applies is decided by the kind of government information that lands in your systems — not by your size or the size of the contract. Answer three questions, then check yourself against Level 1. Nothing you enter leaves your browser.

Which level applies to you

Three questions · about 30 seconds
Question 1 of 3

Level 1 self-check

The 15 requirements, in plain language

An orientation, not an assessment — it tells you where you’d stand if you had to affirm today. Level 1 permits no plan of action, so a single honest “no” is the whole answer.

0in place
0gaps
0not sure

Answer the fifteen above to see where you stand.

Send it to me and let’s spend twenty minutes on it

Nothing you enter here reaches me — the page has no way to send it. If you want a second opinion on what you just answered, copy it across and I’ll read it before we talk.

  1. Book twenty minutes. That is the whole ask — no access to your systems, nothing installed, no one calling you afterward.
  2. Copy your answers with the button above. It includes your level result and every question you marked.
  3. Send them over first if you want me briefed before we talk, to — I’ll have read them and run a few checks on your domain from public records before we start.
Book the 20 minutes

Level 1 · Federal Contract Information

15 requirements
Source
FAR 52.204-21 (b)(1)(i)–(xv) — basic safeguarding
Assessment
Self-assessment, repeated annually
Affirmation
A senior company official affirms in SPRS, annually
POA&M
Not permitted. Every requirement must be met at the time of assessment
Cost to certify
No third party, no fee — your time, and whatever you have to fix

No written security plan required, no encryption mandate, no multi-factor requirement, no continuous monitoring. Most of it is ordinary hygiene — which is why the affirmation, not the control set, carries the risk. A false affirmation is a False Claims Act exposure for the person who signs it.

Level 2 · Controlled Unclassified Information

110 requirements
Source
NIST SP 800-171 Revision 2 — 110 requirements, 320 assessment objectives
Assessment
Self-assessment or a C3PAO certification assessment, depending on the contract — every three years
Affirmation
On conditional status, on final status, after POA&M closeout, and annually
POA&M
Allowed only if the score is at least 80% and no deferred item is on the excluded list
Closeout
180 days from the conditional status date, or the status expires
FamilyDomainReqs
ACAccess Control22
SCSystem & Communications Protection16
IAIdentification & Authentication11
AUAudit & Accountability9
CMConfiguration Management9
MPMedia Protection9
SISystem & Information Integrity7
MAMaintenance6
PEPhysical Protection6
CASecurity Assessment4
ATAwareness & Training3
IRIncident Response3
RARisk Assessment3
PSPersonnel Security2
Total110

Never eligible for a POA&M: external system connections (AC.L2-3.1.20), control of publicly posted information (AC.L2-3.1.22), the system security plan itself (CA.L2-3.12.4), and visitor escort, physical access logs and access device control (PE.L2-3.10.3, .4, .5). Unmet on assessment day means no conditional status to fall back on.

The expensive requirements are architectural, not procedural: a defined CUI boundary, FIPS-validated encryption, audit logging with retention, incident response with 72-hour reporting to DoD, periodic security assessment. Where CUI is stored is usually the first thing that has to change.

Level 3 · Advanced persistent threat protection

24 added requirements
Source
24 selected requirements from NIST SP 800-172, with DoD-assigned parameters
Prerequisite
Level 2 final certification for the same scope, first
Assessment
DIBCAC — the government assesses this one, not a C3PAO. Every three years
POA&M
Same 80% rule with its own exclusions, same 180-day closeout

Named in the contract for a small number of highest-priority programs. If nobody has told you this applies, it doesn’t.

How the Level 2 score works

A self-assessment produces a score out of 110 that gets posted to SPRS. Start at 110, subtract 1, 3 or 5 points per unmet requirement depending on weight. Primes look at that number long before any certificate exists.

110
Perfect score — every requirement met
88
80% — the floor for conditional status with a POA&M
−5
Worst single deduction, on the requirements that matter most
180
Days to close the POA&M before conditional status expires

Where the work actually sits

  • Scoping comes first and decides the cost. A supplier who keeps CUI in one defined place has a small assessment. One who lets it spread across email, file shares and quoting has an expensive one.
  • Implementation and assessment are different jobs. The firm that builds your controls cannot be the firm that certifies them. Readiness, documentation and remediation are ours; the certification assessment belongs to an authorized third party.
  • Your service providers come with you. An IT provider whose tools protect in-scope systems is looked at as part of your assessment, whether or not any CUI passes through them.
  • Level 1 is reachable this quarter. Fifteen practices, a self-assessment, an affirmation. For most small suppliers the gap is documentation and a handful of settings, not new equipment.

Sources: 32 CFR Part 170 (the CMMC Program rule), FAR 52.204-21, NIST SP 800-171 Rev. 2, NIST SP 800-172. Verified 23 September 2026.

Nothing entered on this page is transmitted or stored — it runs entirely in your browser.

Prepared by Cybertitans · cybertitans.net · Woodbury, Minnesota. Reference material, not legal advice — the contract clause governs.