The CMMC framework has three levels, and the one that applies to your business depends entirely on the data you handle and what your contract requires. Level 1 covers Federal Contract Information with basic safeguards. Level 2 covers Controlled Unclassified Information and aligns to NIST SP 800-171 Rev 2. Level 3 covers the highest-priority CUI and adds NIST SP 800-172 controls. Your next move: pull your active contracts, check for DFARS 252.204-7012 or CMMC clauses, and inventory where FCI or CUI actually lives in your systems.
TL;DR:
- Most small contractors handle FCI and can often meet Level 1 requirements through simple, annual self-assessments without external auditors.
- Handling CUI requires more controls, a thorough scope, and typically an assessment by a C3PAO, especially at Level 2 and above.
- Building a comprehensive System Security Plan and isolating CUI on a separate network reduces costs and simplifies the assessment process.
- Costs for Level 2 self-assessment are in the mid five figures over several years, while third-party certification can exceed six figures, with timelines lengthening at higher levels.
- Treating CMMC as ongoing cyber hygiene, rather than a one-time project, minimizes recertification stress and supports continuous compliance.
Table of Contents
- What Do the CMMC Levels Actually Require?
- Which Level Applies to Your Business?
- How to Prepare for Your Required CMMC Level
- What Will CMMC Readiness Cost, and How Long Does It Take?
- Why CMMC Is a Program, Not a Project
- How Total Cyber Solutions Helps You Reach Your CMMC Level
- Sources
- FAQ
What Do the CMMC Levels Actually Require?
Each level builds on the one below it, and the jump between them involves significantly more requirements and controls than many business owners anticipate.
Level 1 covers basic safeguarding of Federal Contract Information under FAR Clause 52.204-21. It requires basic safeguarding practices such as limiting system access, controlling media disposal, and restricting physical access to equipment. Businesses handle Level 1 through annual self-assessment without needing an external auditor.
Level 2 is where things get serious. It aligns to NIST SP 800-171 Rev 2, which spells out 110 controls across areas like access control, incident response, and system integrity. Depending on what your contract specifies, you’ll either self-assess or bring in a Certified Third-Party Assessment Organization, known as a C3PAO, for an outside review.
Level 3 exists for the smallest slice of contractors, the ones working with the most sensitive CUI on the DoD’s highest-priority programs. It layers enhanced controls from NIST SP 800-172 on top of everything in Level 2, and the government runs those assessments directly through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
All three levels draw from the same 14 control domains, just at different depths:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
A business rarely jumps straight to Level 2 without ever touching the Level 1 basics. The domains overlap, and the practices at Level 1 quietly become the floor for everything above it.
Which Level Applies to Your Business?
Most of the confusion here traces back to one root question: do you handle FCI, or do you handle CUI? FCI is information provided by or generated for the government under a contract that isn’t intended for public release, think basic contract details, delivery schedules, or invoicing data. CUI is more sensitive: technical drawings, unclassified military specifications, export-controlled data, or anything marked with a CUI designation by the prime contractor.
Here’s the decision path most SMBs should follow:
- Pull the contract and look for a DFARS or CMMC clause specifying your required level.
- Identify whether your systems touch FCI only, or CUI as well, since that alone usually separates Level 1 from Level 2.
- Confirm your assessment route: self-assessment or C3PAO, based on what the solicitation states.
- Check whether results need to post to the Supplier Performance Risk System (SPRS), where scores start at 110 and drop for every unmet control.
The pitfalls that trip up small contractors almost always fall into three buckets: CUI hiding in email attachments or shared drives nobody flagged, a mixed environment where CUI touches machines that were never scoped for it, and the mistaken belief that if your prime is Level 2, you automatically are too. Your level is defined by your own contract and your own data, not your prime’s certification status.
How to Prepare for Your Required CMMC Level
Readiness work follows a logical order, and skipping steps almost always costs more later.
- Scope your environment. Map every system, application, and supplier relationship that touches FCI or CUI. This is the step most businesses underestimate, and it’s usually where the surprises show up.
- Build your System Security Plan (SSP). Document your environment, then map each control to real evidence, policies, configurations, logs, screenshots, not just a checklist saying “done.”
- Lock down the technical baseline. Multifactor authentication, regular patching, endpoint protection, encryption for data at rest and in transit, and centralized logging cover a large share of the controls across every level.
- Set your operational baseline. Written incident response procedures, documented security awareness training, and a clear understanding of what a Plan of Action and Milestones (POA&M) can and cannot cover under current CMMC scoring rules.
- Get assessment-ready. Collect your evidence in one place, run a mock assessment against the actual control set, and if your contract requires a C3PAO, schedule early. Availability tightens as more contractors reach this stage at once.
Pro Tip: Isolate your CUI onto a separate, tightly controlled network segment instead of letting it spread across your whole environment. Reducing scope this way cuts both your assessment cost and your ongoing maintenance burden, often dramatically.
Free resources like Project Spectrum and DoD small-business bulletins can help with early-stage training and gap identification before you spend money on formal assessments.
What Will CMMC Readiness Cost, and How Long Does It Take?
Budget and timeline vary widely, but the pattern is consistent: cost rises fast once you move from self-assessment to third-party certification.
- Level 1 readiness typically takes a few weeks to a couple of months, with annualized support costs landing in the low thousands of dollars for a small business with modest IT infrastructure.
- Level 2 self-assessment path usually runs mid five figures across several years once you count documentation, remediation, and ongoing maintenance.
- Level 2 C3PAO certification path often exceeds six figures when readiness work and remediation are included, according to industry cost estimates.
- Level 3 timelines and costs run longest, since government-led DIBCAC assessments involve more coordination and stricter enhanced controls.
The businesses that blow past these ranges almost always share the same three problems: scope that was never properly defined, legacy systems that can’t support modern logging or encryption, and a remediation backlog that piles up because nobody tracked gaps early. A security posture assessment before you commit to a path can catch most of this before it becomes expensive.
Why CMMC Is a Program, Not a Project
Most businesses treat CMMC like a one-time hurdle: pass the assessment, file the paperwork, move on. That mindset creates the exact audit bottlenecks that DoD small-business guidance warns against. Controls decay. Employees change. Systems get added without anyone updating the SSP. Treat CMMC as continuous cyber hygiene instead, and the second audit becomes far less painful than the first.

The controls worth prioritizing first are the ones with the widest blast radius if ignored: multi-factor authentication, centralized logging, and disciplined patching. These show up across nearly every domain in the maturity model, and they’re usually the fastest wins for a business trying to close gaps without blowing the budget. Isolating CUI early, rather than scrambling to segment it later, saves both money and stress.
The gap between businesses that sail through recertification and those that scramble every time isn’t talent or budget. It’s whether someone owns the evidence operation year round instead of resurrecting it every assessment cycle.
— Alden
How Total Cyber Solutions Helps You Reach Your CMMC Level
Some cybersecurity providers offer a unified approach to CMMC readiness by managing assessment, documentation, remediation, and ongoing monitoring as a coordinated service, reducing the need for clients to manage multiple vendors.

Total Cyber Solutions offers readiness assessments to identify your gaps before an assessor does, SSP and evidence creation so your documentation actually reflects your environment, remediation projects to close technical gaps, and managed cybersecurity services to keep your controls operational between assessment cycles. If you need ongoing security leadership without a full-time hire, our vCSO advisory covers that too, alongside workforce training that satisfies your awareness-training requirements.
Whether you need a short-term readiness project or a long-term managed security partnership, the first step is the same. Book a free readiness consult and find out exactly where your business stands before your next contract deadline forces the question.

Sources
These are the primary documents worth bookmarking, since CMMC guidance updates periodically and secondhand summaries drift out of date fast.
- CMMC Model Overview v2.0 (DoD)
- CMMC for Small Defense Contractors: 2026 Cost & Levels (Defense Compliance Report)
FAQ
What Is the Difference Between CMMC Level 1 and Level 2?
Level 1 covers basic safeguarding of FCI under 15 practices from FAR 52.204-21 with annual self-assessment. Level 2 covers CUI under 110 controls from NIST SP 800-171 Rev 2 and may require a C3PAO assessment.
Do I Need a C3PAO for Level 1?
No. Level 1 only requires an annual self-assessment; C3PAO involvement applies to certain Level 2 contracts and none of the Level 1 requirements.
What Happens If I Have Open Items on My POA&M?
A Plan of Action and Milestones lets you document unmet controls with a remediation timeline, but current CMMC rules limit which controls can appear on a POA&M and for how long, so most gaps still need closing before certification.
Where Do CMMC Assessment Results Get Reported?
Self-assessment scores and many third-party results are entered into the Supplier Performance Risk System (SPRS), where organizations start at a maximum score of 110.
Does My Level Change if My Prime Contractor Has a Higher Level?
No. Your CMMC level is determined by your own contract and the data your business handles, not by the certification level of your prime contractor.
Can Total Cyber Solutions Help Me Figure Out My Level?
Yes. Total Cyber Solutions offers readiness assessments that identify your data types, map them to contract requirements, and outline the assessment path that applies to your business.