· CMMC · 6 min read
CMMC Level 1 vs Level 2 vs Level 3: Choosing the Right Maturity Target
Pick your CMMC target by contract and data type, not preference; FCI points to Level 1, CUI drives Level 2, and only select programs require Level 3 with added 800-172 safeguards and a DCMA DIBCAC government assessment.

CMMC targets follow the data and the contract. Federal Contract Information (FCI) work points you to Level 1. Controlled Unclassified Information (CUI) work drives Level 2 against NIST SP 800-171. Only select programs need Level 3 with added NIST SP 800-172 safeguards and a government assessment by DCMA DIBCAC.
CMMC level coverage
DoD defines three levels with distinct scopes and assessment expectations.
Level 1 addresses FCI. DoD maps Level 1 to 15 safeguards drawn from FAR 52.204-21. These practices focus on basic access control, device hardening, and physical protections that a small environment can implement without a full CUI program.
Level 2 addresses CUI. DoD maps Level 2 to the 110 requirements in NIST SP 800-171 Rev. 2. That baseline spans access control, audit and accountability, configuration management, identification and authentication, incident response, media protection, physical protection, personnel security, risk assessment, security assessment, system and information integrity, and system and communications protection. Assessors and primes expect a living system security plan, objective evidence, and repeatable processes across the CUI boundary.
Level 3 applies to the most sensitive programs. DoD requires Level 2 status before Level 3. DCMA DIBCAC conducts the government assessment. DoD also directs the contractor to affirm a selected set of 24 NIST SP 800-172 requirements each year, which extend the defense against advanced threats.
DoD codified the CMMC final rule in 32 CFR Part 170. Contract clauses and rollout still flow through DFARS rulemaking. Treat 32 CFR Part 170 as the program rule, and read your solicitations and clauses for the acquisition direction you must follow.
Selecting a target level
The contract tells you what to build. Read your awarded contracts and active solicitations first, then trace the information flows.
- Information types in scope. If you handle FCI alone, target Level 1. If you handle CUI, plan for Level 2 against the NIST SP 800-171 baseline. If a program office names Level 3, expect 800-172 safeguards on top of 800-171 with a government assessment.
- Solicitation and flowdown language. DFARS terms set expectations for incident reporting, media handling, and cloud boundaries. Prime contractors often pass those requirements to you. See our DFARS primer for context: DFARS 252.204-7012 requirements.
Now draw the boundary. Define where CUI enters, where it resides, and where it exits. A clear boundary drives scope, control selection, and tool choice. If you need a starting point, use our scoping overview: CMMC scoping and the CUI boundary.
Level selection also ties to your operating model. A subcontractor that never touches CUI and feeds deliverables to a prime may stay at Level 1 if the prime enclaves CUI. A design shop that receives export-controlled drawings from a DoD program office must plan for Level 2.
Assessment differences by level
Assessment mechanics vary. The Cyber AB describes the assessment process in the CAP v2.0. DoD supplements that with level-specific guides.
Level 1 relies on the 15 FAR 52.204-21 practices for FCI protection. DoD uses supplier affirmation at Level 1. Keep evidence for each practice and be ready to show how your team enforces it.
Level 2 assessments align to NIST SP 800-171. DoD can require either a self-assessment or a C3PAO-conducted assessment, based on the solicitation. The DoD CIO Level 2 Assessment Guide explains objective evidence, methods, and scoring. Teams should expect interviews, demonstrations, and artifact reviews mapped to each control.
Level 3 builds on Level 2. DoD requires a government assessment performed by DCMA DIBCAC. The contractor then affirms the selected 800-172 safeguards each year. Plan for higher assurance on monitoring, detection, response, and data-at-rest and data-in-transit protections that resist advanced threat techniques.
Scoring and internal readiness still matter outside a formal assessment. Many teams track NIST SP 800-171 performance in SPRS. If you need a guide for that work, see SPRS scoring for NIST 800-171.
Microsoft 365 cloud fit by level
Your cloud choice should follow your data and the contract. Microsoft publishes CMMC applicability statements for its clouds.
Microsoft states that Microsoft 365 for Enterprise supports organizations in meeting Level 1 requirements. Environments that handle FCI alone can often operate on commercial Microsoft 365 for Enterprise with correct hardening and administrative controls.
Microsoft states that Microsoft 365 GCC High supports organizations in meeting Level 2 and Level 3 requirements with proper configuration. GCC High brings sovereign identity, US-only support and operations, and alignment with government boundary expectations that many CUI programs expect. Microsoft 365 GCC also exists, and Microsoft positions it for FedRAMP High and related government work, but not for the most sensitive defense programs.
Treat the Microsoft Product Placemat as a planning aid, not as authorization. Microsoft labels it as a preview resource and does not present it as a guarantee. Always map the required controls to your tenant configuration, your boundary, and your evidence.
Cloud fit depends on the CUI boundary you draw, your DFARS 7012 obligations, your enclave design, and your customer. If you face a cloud choice, review our decision framework: GCC High migration decision framework.
Control focus areas that swing the level
Teams often anchor on a few controls that force a higher maturity target once CUI enters the picture.
Assessors test NIST SP 800-171 controls with IDs that tie back to the CMMC model. AC.L2-3.1.1 and IA.L2-3.5.1 drive identity, device, and session enforcement in the CUI enclave. IR.L2-3.6.1 and RA.L2-3.11.1 drive incident handling and risk processes that must exist before you accept CUI. These controls require documented procedures, trained responders, and monitoring that produces evidence on demand.
At Level 1, the parallel access control concept, AC.L1-3.1.1, still matters. You still need to limit access to authorized users and devices, even in an FCI-only shop. The difference sits in depth, formality, and evidence volume once you move into Level 2.
If you need a control-by-control mapping, we maintain a practitioner view here: NIST 800-171 to CMMC Level 2 mapping. Build your system security plan around that baseline. Use your plan as the single source for boundaries, roles, inheritance, and methods. If you need a plan starter, see System security plan for NIST 800-171.
Frequent decision errors
- Picking a level based on a sales deck. The solicitation and the data types drive the target. Bring the program office, the prime, and counsel into that call.
- Assuming a cloud label equals authorization. Microsoft helps with platform capabilities, but your controls, your boundary, and your evidence determine assessment outcomes.
Practical next steps
- Confirm the information types and the acquisition language you face. Read the clauses. Ask the KO or the prime for a plain statement on FCI versus CUI, and on the required CMMC level.
- Define the CUI boundary and stand up the core governance artifacts. Write the system security plan, the incident response plan, and the access control policy. Tie each control to methods and evidence you can produce on request.
Teams that track these steps hit fewer surprises during readiness. You avoid over-build for FCI-only work, and you avoid control shortfalls when CUI flows start.
Sources
Office of the DoD CIO: About CMMC (DoD CIO)
32 CFR Part 170 Cybersecurity Maturity Model Certification (eCFR)
CMMC Assessment Process v2.0 (The Cyber AB)
CMMC Level 2 Assessment Guide (DoD CIO)
CMMC resources and documentation (DoD CIO)
Microsoft cloud support for CMMC (Microsoft Learn)
Product Placemat for CMMC, October 2024 update (Microsoft Tech Community)
NIST SP 800-171 Rev. 2 Access Control family (NIST)
NIST SP 800-171 Rev. 2 Identification and Authentication family (NIST)
Want a structured starting point?
Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.



