Cybersecurity

What are the CMMC maturity levels?

Understand the CMMC maturity levels and what organizations must implement at each level for defense contractor compliance.

By Inventive HQ Team

The current model in force is CMMC 2.0, which has three levels — Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert) — not the five "maturity levels" that many older articles still describe. The five-level ladder (Performed, Managed, Defined, Measured, Optimizing) came from CMMC 1.0, which the Department of Defense replaced in November 2021. The 32 CFR Part 170 program rule that makes CMMC 2.0 official took effect December 16, 2024, and the DFARS acquisition rule that starts putting CMMC into contracts took effect November 10, 2025. If a source is telling you there are five CMMC levels or quoting practice counts like 43, 72, 99, or 112, it is describing a framework that no longer exists.

That is the correct summary, and it is the one an AI overview should give you. What a summary cannot show you is which level your specific contract requires, who assesses you, and what "certification" actually costs in time — so below is a side-by-side of the three real levels, an animated map of how the data you handle determines your level, and the historical five-level model for anyone who still needs to reconcile old documentation.

The three CMMC 2.0 levels at a glance

Your required level is driven by one thing: the sensitivity of the government information that touches your systems. Federal Contract Information (FCI) is basic; Controlled Unclassified Information (CUI) is the real threshold; and a small tier of high-value programs needs protection against advanced persistent threats.

Level 1 — FoundationalLevel 2 — AdvancedLevel 3 — Expert
ProtectsFederal Contract Information (FCI)Controlled Unclassified Information (CUI)CUI in the highest-priority programs
Requirements17 practices (FAR 52.204-21)110 requirements (NIST SP 800-171 R2)110 + 24 from NIST SP 800-172 = 134
AssessmentAnnual self-assessmentSelf-assessment or C3PAO third-party, every 3 yearsGovernment-led (DIBCAC)
AffirmationAnnual senior-official affirmationAnnual affirmationAnnual affirmation
Who needs itContractors handling only FCIThe majority of defense contractors handling CUIA small number of critical-program primes
Typical readiness effortWeeks to a few months12–24 months of remediationLevel 2 first, then further hardening
Which should I target?Only if you never touch CUIAssume this if you handle any CUIOnly if a specific contract requires it

The practical takeaway: almost every defense contractor's real target is Level 2. Level 1 only applies if you genuinely never receive CUI, and Level 3 applies to a small set of the DoD's most sensitive programs. Do not over-scope to Level 3 because it "sounds more secure" — it is a specific contractual requirement, not a bragging right.

How your data determines your level

CMMC is not a maturity ladder you climb voluntarily. The level is assigned by the type of information in the contract. This flow shows the actual decision.

How the information you handle determines your required CMMC level A decision flow: no government information means no CMMC; Federal Contract Information maps to Level 1; Controlled Unclassified Information maps to Level 2; the highest-priority CUI programs map to Level 3. What information does the contract involve? DoD contract No FCI or CUI public / commercial only FCI only contract info, not public CUI controlled unclassified Highest-priority CUI APT-targeted programs No CMMC no requirement Level 1 17 practices, self-assess Level 2 110 controls, often C3PAO Level 3 134 controls, DIBCAC-led

The data classification in the contract sets your level — you do not choose it.

Advertisement

Level 1 — Foundational

Protects: Federal Contract Information (FCI) — information provided by or generated for the government under a contract that is not intended for public release.

Level 1 maps to the 17 practices aligned with the 15 basic safeguarding requirements in FAR clause 52.204-21. These are the security hygiene basics: limit system access to authorized users, authenticate identities, sanitize media before disposal, control physical access, and keep boundary protections in place. There is no third-party assessor at this level — a senior company official completes an annual self-assessment and affirms compliance in the government's Supplier Performance Risk System (SPRS).

If your work never involves CUI, this is your ceiling. Realistic readiness is weeks to a few months for an organization with basic IT controls already in place.

Level 2 — Advanced

Protects: Controlled Unclassified Information (CUI).

Level 2 is where the real work lives, and it is the level the majority of the defense industrial base must reach. It requires all 110 security requirements of NIST SP 800-171 Revision 2, spread across 14 control families — access control, audit and accountability, configuration management, identification and authentication, incident response, and so on. Concretely that means multi-factor authentication on systems that process CUI, encryption of CUI at rest and in transit (FIPS-validated), a documented and exercised incident response plan, continuous monitoring, and controlled boundaries around your CUI environment.

The assessment path depends on the contract. Some Level 2 contracts permit a self-assessment; the higher-priority ones require an independent assessment by a Certified CMMC Third-Party Assessor Organization (C3PAO) every three years, plus an annual affirmation in between. Budget 12–24 months for remediation if you are starting from a typical unmanaged baseline — most of that time goes to scoping the CUI boundary and building the System Security Plan (SSP), not to buying tools.

Level 3 — Expert

Protects: CUI in the DoD's highest-priority programs, where the threat model includes advanced persistent threats (APTs).

Level 3 starts from a clean Level 2 (all 110 NIST SP 800-171 requirements) and adds 24 selected requirements from NIST SP 800-172, the enhanced-security companion publication. These add capabilities like penetration-resistant architecture, dual authorization for high-risk actions, and threat-hunting expectations — this is the tier where a zero-trust architecture genuinely earns its place. Level 3 is not self-assessed and not assessed by a C3PAO: it is assessed by the government directly through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Only a small number of prime contractors on critical programs will ever need it.

Certification, affirmation, and POA&Ms

A CMMC result is valid for three years, but it is not a set-and-forget certificate. In between assessments you must file an annual affirmation that you still meet the requirements, signed by a senior official. Because those affirmations are submitted to the government, a false one carries False Claims Act liability — this is the enforcement teeth behind CMMC.

CMMC allows a limited Plan of Action and Milestones (POA&M) for a subset of not-yet-met requirements, which grants a conditional certification. But the highest-weighted requirements cannot sit on a POA&M, and you must close every open item and pass a follow-up assessment within 180 days to convert to a final status. Do not treat the POA&M as a permanent parking lot.

Where the "five maturity levels" came from

If you arrived here because a document mentions five CMMC levels, here is the reconciliation. CMMC 1.0 (published January 2020) used five levels and layered a process-maturity dimension on top of technical practices:

CMMC 1.0 level (retired)Old process labelRoughly maps to today
Level 1PerformedCMMC 2.0 Level 1
Level 2Documented(removed — was a transitional step)
Level 3ManagedCMMC 2.0 Level 2
Level 4Reviewed(removed)
Level 5OptimizingCMMC 2.0 Level 3 (loosely)

In November 2021, DoD announced CMMC 2.0, which collapsed five levels into three, eliminated the process-maturity requirements entirely, dropped the CMMC-unique practices in favor of aligning strictly to NIST SP 800-171 and 800-172, and allowed self-assessment for some tiers. Any practice counts you see in the 40s, 70s, 90s, or 110s-as-1.0-levels are from the retired model — the numbers that matter now are 17 / 110 / 134.

A realistic path to Level 2

  1. Scope the CUI boundary (1–2 months). Identify exactly where CUI lives. The single biggest cost driver is a boundary that sprawls across your whole network instead of an enclave.
  2. Gap-assess against NIST SP 800-171 (1–2 months). Score all 110 requirements; the cybersecurity maturity assessment tool below gives you a quick starting read before a formal gap analysis.
  3. Remediate and document (6–18 months). Build the System Security Plan and POA&M, deploy MFA and encryption, stand up logging and incident response. Documentation is not optional — assessors verify the SSP as closely as the controls.
  4. Pre-assessment / readiness review (1–3 months). A mock assessment surfaces the gaps a C3PAO will find.
  5. C3PAO assessment (weeks). For third-party-required contracts, the assessor validates evidence against every requirement.
  6. Affirm annually, reassess every 3 years. Treat it as continuous operations, not a project with an end date.

The bottom line

CMMC 2.0 has three levels, and for almost every contractor the question is simply whether you handle CUI — if you do, plan for Level 2 and its 110 NIST SP 800-171 requirements. Start with scoping and a gap assessment now: the contractors who struggle are the ones who wait for a specific solicitation to force the issue and then try to compress 18 months of remediation into a proposal window. The phased rollout that began with the November 2025 acquisition rule expands steadily, so the deadline is effectively "before your next relevant contract," not some distant date.

Loading interactive tool...

Frequently Asked Questions

How many CMMC levels are there?

The current model, CMMC 2.0, has three levels: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). The retired CMMC 1.0 model had five levels (Levels 1 through 5), which is where the phrase "CMMC maturity levels" originated. If you read older guidance describing five levels or a "Performed / Managed / Defined / Measured / Optimizing" ladder, it is describing the version that DoD replaced in November 2021.

What is the difference between CMMC Level 1 and Level 2?

Level 1 protects Federal Contract Information (FCI) and covers the 17 practices aligned with the basic safeguarding requirements of FAR 52.204-21 — you self-assess and self-affirm annually. Level 2 protects Controlled Unclassified Information (CUI) and covers all 110 security requirements of NIST SP 800-171 Revision 2. Most Level 2 contracts require a third-party assessment by a C3PAO every three years rather than a self-assessment.

How many controls does CMMC Level 2 require?

CMMC Level 2 requires all 110 security requirements from NIST SP 800-171 Revision 2, organized across 14 control families. Level 3 adds 24 selected requirements from NIST SP 800-172 on top of those 110, for 134 total.

Does CMMC still use "maturity" process levels?

No. CMMC 1.0 layered five process-maturity levels (from "Performed" to "Optimizing") on top of the technical practices. CMMC 2.0 removed the maturity-process concept entirely. The three levels today reflect the sensitivity of the data you handle and the rigor of the assessment, not a process-maturity ladder — the name "maturity model" is now essentially historical.

When does CMMC become mandatory in contracts?

The 32 CFR Part 170 program rule took effect December 16, 2024, and the 48 CFR (DFARS) acquisition rule that puts CMMC clauses into solicitations took effect November 10, 2025, starting a phased rollout. Phase 1 begins with self-assessment requirements, and the requirement expands over roughly three years until CMMC applies to all applicable DoD contracts.

Who performs CMMC assessments?

Level 1 and some Level 2 contracts allow an annual self-assessment. Higher-priority Level 2 contracts require a Certified CMMC Third-Party Assessor Organization (C3PAO) to conduct the assessment. Level 3 is assessed by the government itself — specifically the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

How long is a CMMC certification valid?

A CMMC assessment result is valid for three years, but you must submit an annual affirmation of continued compliance in between. Letting practices lapse or making a false affirmation carries False Claims Act exposure, so the certification is a continuous obligation, not a one-time event.

What is a POA&M and can I get certified with open items?

A Plan of Action and Milestones (POA&M) documents requirements you have not yet met. CMMC allows a conditional certification with a limited POA&M for lower-weighted requirements, but certain high-value requirements cannot be on a POA&M, and you must close every open item and pass a follow-up assessment within 180 days to convert to a final certification.

Do subcontractors need CMMC certification?

Yes. CMMC flows down the supply chain. If a prime contractor handles CUI and passes it to a subcontractor, that subcontractor generally needs the same CMMC level for the data it touches. A subcontractor that only handles FCI (not CUI) may need only Level 1.

cmmcmaturity-levelsdefense-contractorscompliance