The current model in force is CMMC 2.0, which has three levels — Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert) — not the five "maturity levels" that many older articles still describe. The five-level ladder (Performed, Managed, Defined, Measured, Optimizing) came from CMMC 1.0, which the Department of Defense replaced in November 2021. The 32 CFR Part 170 program rule that makes CMMC 2.0 official took effect December 16, 2024, and the DFARS acquisition rule that starts putting CMMC into contracts took effect November 10, 2025. If a source is telling you there are five CMMC levels or quoting practice counts like 43, 72, 99, or 112, it is describing a framework that no longer exists.
That is the correct summary, and it is the one an AI overview should give you. What a summary cannot show you is which level your specific contract requires, who assesses you, and what "certification" actually costs in time — so below is a side-by-side of the three real levels, an animated map of how the data you handle determines your level, and the historical five-level model for anyone who still needs to reconcile old documentation.
The three CMMC 2.0 levels at a glance
Your required level is driven by one thing: the sensitivity of the government information that touches your systems. Federal Contract Information (FCI) is basic; Controlled Unclassified Information (CUI) is the real threshold; and a small tier of high-value programs needs protection against advanced persistent threats.
| Level 1 — Foundational | Level 2 — Advanced | Level 3 — Expert | |
|---|---|---|---|
| Protects | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | CUI in the highest-priority programs |
| Requirements | 17 practices (FAR 52.204-21) | 110 requirements (NIST SP 800-171 R2) | 110 + 24 from NIST SP 800-172 = 134 |
| Assessment | Annual self-assessment | Self-assessment or C3PAO third-party, every 3 years | Government-led (DIBCAC) |
| Affirmation | Annual senior-official affirmation | Annual affirmation | Annual affirmation |
| Who needs it | Contractors handling only FCI | The majority of defense contractors handling CUI | A small number of critical-program primes |
| Typical readiness effort | Weeks to a few months | 12–24 months of remediation | Level 2 first, then further hardening |
| Which should I target? | Only if you never touch CUI | Assume this if you handle any CUI | Only if a specific contract requires it |
The practical takeaway: almost every defense contractor's real target is Level 2. Level 1 only applies if you genuinely never receive CUI, and Level 3 applies to a small set of the DoD's most sensitive programs. Do not over-scope to Level 3 because it "sounds more secure" — it is a specific contractual requirement, not a bragging right.
How your data determines your level
CMMC is not a maturity ladder you climb voluntarily. The level is assigned by the type of information in the contract. This flow shows the actual decision.
Level 1 — Foundational
Protects: Federal Contract Information (FCI) — information provided by or generated for the government under a contract that is not intended for public release.
Level 1 maps to the 17 practices aligned with the 15 basic safeguarding requirements in FAR clause 52.204-21. These are the security hygiene basics: limit system access to authorized users, authenticate identities, sanitize media before disposal, control physical access, and keep boundary protections in place. There is no third-party assessor at this level — a senior company official completes an annual self-assessment and affirms compliance in the government's Supplier Performance Risk System (SPRS).
If your work never involves CUI, this is your ceiling. Realistic readiness is weeks to a few months for an organization with basic IT controls already in place.
Level 2 — Advanced
Protects: Controlled Unclassified Information (CUI).
Level 2 is where the real work lives, and it is the level the majority of the defense industrial base must reach. It requires all 110 security requirements of NIST SP 800-171 Revision 2, spread across 14 control families — access control, audit and accountability, configuration management, identification and authentication, incident response, and so on. Concretely that means multi-factor authentication on systems that process CUI, encryption of CUI at rest and in transit (FIPS-validated), a documented and exercised incident response plan, continuous monitoring, and controlled boundaries around your CUI environment.
The assessment path depends on the contract. Some Level 2 contracts permit a self-assessment; the higher-priority ones require an independent assessment by a Certified CMMC Third-Party Assessor Organization (C3PAO) every three years, plus an annual affirmation in between. Budget 12–24 months for remediation if you are starting from a typical unmanaged baseline — most of that time goes to scoping the CUI boundary and building the System Security Plan (SSP), not to buying tools.
Level 3 — Expert
Protects: CUI in the DoD's highest-priority programs, where the threat model includes advanced persistent threats (APTs).
Level 3 starts from a clean Level 2 (all 110 NIST SP 800-171 requirements) and adds 24 selected requirements from NIST SP 800-172, the enhanced-security companion publication. These add capabilities like penetration-resistant architecture, dual authorization for high-risk actions, and threat-hunting expectations — this is the tier where a zero-trust architecture genuinely earns its place. Level 3 is not self-assessed and not assessed by a C3PAO: it is assessed by the government directly through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Only a small number of prime contractors on critical programs will ever need it.
Certification, affirmation, and POA&Ms
A CMMC result is valid for three years, but it is not a set-and-forget certificate. In between assessments you must file an annual affirmation that you still meet the requirements, signed by a senior official. Because those affirmations are submitted to the government, a false one carries False Claims Act liability — this is the enforcement teeth behind CMMC.
CMMC allows a limited Plan of Action and Milestones (POA&M) for a subset of not-yet-met requirements, which grants a conditional certification. But the highest-weighted requirements cannot sit on a POA&M, and you must close every open item and pass a follow-up assessment within 180 days to convert to a final status. Do not treat the POA&M as a permanent parking lot.
Where the "five maturity levels" came from
If you arrived here because a document mentions five CMMC levels, here is the reconciliation. CMMC 1.0 (published January 2020) used five levels and layered a process-maturity dimension on top of technical practices:
| CMMC 1.0 level (retired) | Old process label | Roughly maps to today |
|---|---|---|
| Level 1 | Performed | CMMC 2.0 Level 1 |
| Level 2 | Documented | (removed — was a transitional step) |
| Level 3 | Managed | CMMC 2.0 Level 2 |
| Level 4 | Reviewed | (removed) |
| Level 5 | Optimizing | CMMC 2.0 Level 3 (loosely) |
In November 2021, DoD announced CMMC 2.0, which collapsed five levels into three, eliminated the process-maturity requirements entirely, dropped the CMMC-unique practices in favor of aligning strictly to NIST SP 800-171 and 800-172, and allowed self-assessment for some tiers. Any practice counts you see in the 40s, 70s, 90s, or 110s-as-1.0-levels are from the retired model — the numbers that matter now are 17 / 110 / 134.
A realistic path to Level 2
- Scope the CUI boundary (1–2 months). Identify exactly where CUI lives. The single biggest cost driver is a boundary that sprawls across your whole network instead of an enclave.
- Gap-assess against NIST SP 800-171 (1–2 months). Score all 110 requirements; the cybersecurity maturity assessment tool below gives you a quick starting read before a formal gap analysis.
- Remediate and document (6–18 months). Build the System Security Plan and POA&M, deploy MFA and encryption, stand up logging and incident response. Documentation is not optional — assessors verify the SSP as closely as the controls.
- Pre-assessment / readiness review (1–3 months). A mock assessment surfaces the gaps a C3PAO will find.
- C3PAO assessment (weeks). For third-party-required contracts, the assessor validates evidence against every requirement.
- Affirm annually, reassess every 3 years. Treat it as continuous operations, not a project with an end date.
The bottom line
CMMC 2.0 has three levels, and for almost every contractor the question is simply whether you handle CUI — if you do, plan for Level 2 and its 110 NIST SP 800-171 requirements. Start with scoping and a gap assessment now: the contractors who struggle are the ones who wait for a specific solicitation to force the issue and then try to compress 18 months of remediation into a proposal window. The phased rollout that began with the November 2025 acquisition rule expands steadily, so the deadline is effectively "before your next relevant contract," not some distant date.