Back to Blog

CMMC Level 1 vs Level 2: How a DoD Contractor Knows Which Applies

BomberJacket Networks
6 min read
CMMC Level 1 vs Level 2: How a DoD Contractor Knows Which Applies

CMMC Level 1 and Level 2 are not badges a contractor chooses based on company size, revenue, or how mature the IT department feels. They are driven by the information your organization stores, processes, or transmits for a DoD contract.

The practical question is simple: are you handling only Federal Contract Information, or are you handling Controlled Unclassified Information? That answer usually determines whether Level 1 or Level 2 applies.

What CMMC Level 1 is for

CMMC Level 1 is for contractors that handle Federal Contract Information, often shortened to FCI, but do not handle Controlled Unclassified Information. FCI is information provided by or generated for the government under a contract that is not intended for public release.

Common examples include contract documents, basic project communications, schedules, order details, and other non-public contract information that does not carry a CUI marking or require the stronger protection requirements tied to CUI.

Level 1 focuses on basic safeguarding. It maps to 15 requirements from FAR 52.204-21. These are foundational security practices such as limiting system access to authorized users, controlling physical access, sanitizing media before disposal or reuse, and protecting information systems from malicious code.

For many small subcontractors, Level 1 is still real work. It is not a paperwork-only exercise. If your staff uses Microsoft 365, shared drives, personal devices, unmanaged email forwarding, or consumer file sharing to handle contract information, those practices still have to be brought under control.

What CMMC Level 2 is for

CMMC Level 2 is for contractors that handle CUI. CUI is information that requires safeguarding under federal law, regulation, or government-wide policy. In the defense industrial base, that often includes technical data, drawings, specifications, export-controlled information, certain engineering files, test data, maintenance data, and other information called out by the contract or program.

Level 2 is built around the 110 security requirements in NIST SP 800-171. That is a very different lift than Level 1. It covers access control, audit logging, incident response, configuration management, multifactor authentication, system and communications protection, risk assessment, security assessment, media protection, and more.

This is also where assessment expectations change. Some Level 2 programs may allow self-assessment, but many DoD contracts involving CUI will require a third-party CMMC assessment by an authorized C3PAO. That distinction matters early, because a C3PAO assessment is not something to prepare for in the final few weeks before an award decision.

The fastest way to tell which level applies

Start with the contract language and the data. Do not start with the level you hope applies.

Look for DFARS 252.204-7012, CUI markings, distribution statements, export control language, DD Form 254 references, program security instructions, or flowdown language from a prime contractor. Ask what information your team actually receives, creates, stores, transmits, or has access to while performing the work.

If the work only involves FCI, Level 1 may apply. If the work involves CUI, Level 2 is the right planning assumption until the contract and data review proves otherwise.

Prime contractor flowdowns are another common source of confusion. A subcontractor may not receive CUI directly from the DoD, but may receive it from a prime as part of the work package. The source does not make it less important. If CUI lands in your environment, your environment is in scope.

Size of company does not decide the level

A 12-person machine shop can have Level 2 obligations if it receives CUI. A larger services company may only need Level 1 if it handles FCI and no CUI. CMMC is not assigned by headcount.

The same is true for job title or department. If engineering receives CUI but accounting, purchasing, or operations can access the same shared storage, the scope may be wider than leadership expects. If employees download CUI to laptops, forward it through email, or store it in a general cloud file share, those systems may become part of the CMMC boundary.

That is where many contractors lose time. They assume CMMC is an IT checklist, then discover the real issue is data flow. Before you decide on Level 1 or Level 2, map where FCI and CUI enter the business, where they are stored, who can access them, and which systems support the work.

What a contractor should do before bidding or accepting a flowdown

Before you accept contract language, respond to a prime, or commit to a delivery schedule, answer these questions:

  1. Does the work involve FCI only, or does it involve CUI?
  2. Where will that information be stored, processed, or transmitted?
  3. Are any personal devices, unmanaged cloud tools, or non-compliant email paths involved?
  4. Does the contract or prime flowdown require Level 2 self-assessment or a C3PAO assessment?
  5. Is the current environment built to meet FAR 52.204-21 or NIST SP 800-171?

If those answers are unclear, the safe move is to slow down and review the contract, the data, and the system boundary before making promises to a prime or contracting officer.

How BomberJacket Networks helps

BomberJacket Networks brings more than 25 years in IT, cybersecurity, and defense contractor environments, and we operate as an authorized C3PAO, so we know exactly what an assessor looks for. We put that same lens to work on the readiness side: helping contractors determine whether Level 1 or Level 2 applies, map where FCI and CUI actually live, and close control gaps against FAR 52.204-21 or NIST SP 800-171 before a deadline forces the issue.

There is one step contractors underestimate. For Level 1 and many Level 2 contracts, you still have to score your own environment and enter that number into SPRS yourself. That score is a legal statement. If it is overstated, the DoJ's Civil Cyber-Fraud Initiative can pursue it under the False Claims Act. Before you submit, it is worth having expert eyes confirm your environment actually supports the number you are about to attest to.

If you are not sure which level applies, or you want your SPRS score reviewed and defensible before you submit it, reach out and we will help you get it right.

Related Resources

Free Ebooks & Guides

View All
Ransomware Survival Guide

Ransomware Survival Guide

Essential strategies and best practices to protect your business from ransomware attacks and recover quickly if compromised.

Download Free
All Businesses Should Adopt MFA. Now

All Businesses Should Adopt MFA. Now

Learn why multi-factor authentication is essential for business security and how to implement it across your organization to prevent account takeovers.

Download Free
Inside Threat

Inside Threat

Understand and mitigate insider threats with strategies to protect your business from malicious employees, contractors, and accidental data breaches.

Download Free

Visual Guides & Infographics

View All
Cybersecurity Checklist for Data Security and Privacy

Cybersecurity Checklist for Data Security and Privacy

A comprehensive checklist to help protect your organization's sensitive data and maintain robust privacy practices.

Download Free
Beware of Business Email Compromise

Beware of Business Email Compromise

Learn how to identify and prevent business email compromise attacks that target your organization's financial transactions and sensitive communications.

Download Free
Encryption: Facts & Figures

Encryption: Facts & Figures

Essential facts and statistics about encryption technology and its critical role in protecting your organization's sensitive data.

Download Free

Need Help with Cybersecurity?

BomberJacket Networks is a Minnesota MSP with 25 years of expertise. Protect your business with 24/7 threat monitoring, managed detection and response, and comprehensive security services.

Continue Reading