One question

What does your business handle?

Your CMMC level is not a choice or a tier. It is set by the data your contracts put on your systems. Pick the line that describes you and land on the right path. As your contracts grow, your work here carries forward to the next level.

Federal Contract Information only

Contract documents, invoices, delivery schedules, the emails and orders for a job. Nothing marked CUI.

Level 1. 15 safeguarding requirements from FAR 52.204-21, the same basic safeguards every federal contractor has owed since 2016. You self assess once a year and your senior official affirms the result in SPRS. It is binary, MET or NOT MET, and there is no score at Level 1.

See the Level 1 track

Controlled Unclassified Information

Controlled drawings, specs, and technical data marked CUI in your contracts, usually alongside DFARS 252.204-7012.

Level 2. 110 requirements from NIST SP 800-171, scored out of 110 under 32 CFR 170.24. The 15 Level 1 safeguards are assessed inside the 110. Some contracts allow a self assessment, most require certification by an accredited third party assessor (a C3PAO), and your solicitation sets the track. Valid three years with an annual affirmation.

See the Level 2 track

CUI on the highest priority programs

Programs the DoD designates as highest priority or exposed to advanced persistent threats.

Level 3. 24 enhanced requirements from NIST SP 800-172, on top of everything Level 2 asks for. Assessed by the government's own DIBCAC team, and it requires a Final Level 2 certification first. Levels 1 and 2 are the prerequisites, not alternatives.

Build the prerequisites

Not sure what you handle? Take the free eight question check and we will place you from your answers.