Defense supply chain · self-guided
CMMC Level Map
Which level applies is decided by the kind of government information that lands in your systems — not by your size or the size of the contract. Answer three questions, then check yourself against Level 1. Nothing you enter leaves your browser.
Which level applies to you
Three questions · about 30 secondsLevel 1 self-check
The 15 requirements, in plain languageAn orientation, not an assessment — it tells you where you’d stand if you had to affirm today. Level 1 permits no plan of action, so a single honest “no” is the whole answer.
Answer the fifteen above to see where you stand.
Send it to me and let’s spend twenty minutes on it
Nothing you enter here reaches me — the page has no way to send it. If you want a second opinion on what you just answered, copy it across and I’ll read it before we talk.
- Book twenty minutes. That is the whole ask — no access to your systems, nothing installed, no one calling you afterward.
- Copy your answers with the button above. It includes your level result and every question you marked.
- Send them over first if you want me briefed before we talk, to — I’ll have read them and run a few checks on your domain from public records before we start.
Level 1 · Federal Contract Information
15 requirements- Source
- FAR 52.204-21 (b)(1)(i)–(xv) — basic safeguarding
- Assessment
- Self-assessment, repeated annually
- Affirmation
- A senior company official affirms in SPRS, annually
- POA&M
- Not permitted. Every requirement must be met at the time of assessment
- Cost to certify
- No third party, no fee — your time, and whatever you have to fix
No written security plan required, no encryption mandate, no multi-factor requirement, no continuous monitoring. Most of it is ordinary hygiene — which is why the affirmation, not the control set, carries the risk. A false affirmation is a False Claims Act exposure for the person who signs it.
Level 2 · Controlled Unclassified Information
110 requirements- Source
- NIST SP 800-171 Revision 2 — 110 requirements, 320 assessment objectives
- Assessment
- Self-assessment or a C3PAO certification assessment, depending on the contract — every three years
- Affirmation
- On conditional status, on final status, after POA&M closeout, and annually
- POA&M
- Allowed only if the score is at least 80% and no deferred item is on the excluded list
- Closeout
- 180 days from the conditional status date, or the status expires
| Family | Domain | Reqs |
|---|---|---|
| AC | Access Control | 22 |
| SC | System & Communications Protection | 16 |
| IA | Identification & Authentication | 11 |
| AU | Audit & Accountability | 9 |
| CM | Configuration Management | 9 |
| MP | Media Protection | 9 |
| SI | System & Information Integrity | 7 |
| MA | Maintenance | 6 |
| PE | Physical Protection | 6 |
| CA | Security Assessment | 4 |
| AT | Awareness & Training | 3 |
| IR | Incident Response | 3 |
| RA | Risk Assessment | 3 |
| PS | Personnel Security | 2 |
| Total | 110 |
Never eligible for a POA&M: external system connections (AC.L2-3.1.20), control of publicly posted information (AC.L2-3.1.22), the system security plan itself (CA.L2-3.12.4), and visitor escort, physical access logs and access device control (PE.L2-3.10.3, .4, .5). Unmet on assessment day means no conditional status to fall back on.
The expensive requirements are architectural, not procedural: a defined CUI boundary, FIPS-validated encryption, audit logging with retention, incident response with 72-hour reporting to DoD, periodic security assessment. Where CUI is stored is usually the first thing that has to change.
Level 3 · Advanced persistent threat protection
24 added requirements- Source
- 24 selected requirements from NIST SP 800-172, with DoD-assigned parameters
- Prerequisite
- Level 2 final certification for the same scope, first
- Assessment
- DIBCAC — the government assesses this one, not a C3PAO. Every three years
- POA&M
- Same 80% rule with its own exclusions, same 180-day closeout
Named in the contract for a small number of highest-priority programs. If nobody has told you this applies, it doesn’t.
How the Level 2 score works
A self-assessment produces a score out of 110 that gets posted to SPRS. Start at 110, subtract 1, 3 or 5 points per unmet requirement depending on weight. Primes look at that number long before any certificate exists.
Where the work actually sits
- Scoping comes first and decides the cost. A supplier who keeps CUI in one defined place has a small assessment. One who lets it spread across email, file shares and quoting has an expensive one.
- Implementation and assessment are different jobs. The firm that builds your controls cannot be the firm that certifies them. Readiness, documentation and remediation are ours; the certification assessment belongs to an authorized third party.
- Your service providers come with you. An IT provider whose tools protect in-scope systems is looked at as part of your assessment, whether or not any CUI passes through them.
- Level 1 is reachable this quarter. Fifteen practices, a self-assessment, an affirmation. For most small suppliers the gap is documentation and a handful of settings, not new equipment.
