CMMC Level Guide

Which CMMC Level Applies to You?

Use the plain-English guide below to self-identify which CMMC level applies to your organization.

Not sure which CMMC level applies to you? Use the guide below.

If your organization handles Federal Contract Information (FCI) but NOT Controlled Unclassified Information (CUI),
You need CMMC Level 1

15 basic safeguarding practices, annual self-assessment, applicable to most small contractors.

If your organization handles Controlled Unclassified Information (CUI) — e.g., technical specs, export-controlled data, sensitive program info,
You need CMMC Level 2

110 practices aligned to NIST SP 800-171, third-party assessment required for critical programs.

If your organization handles CUI on high-priority DoD programs and has been explicitly identified by your contracting officer as requiring Level 3,
You need CMMC Level 3

24 additional practices on top of Level 2, government-led assessment, reserved for the most sensitive programs.