Skip to content

CMMC for Noobs Part 5: What’s the Difference Between CMMC Level 1, 2, and 3???

By now, you know that CMMC certification is a must if you want to do business with the Department of Defense (DoD). But not every company needs the same level of security. That’s where the three levels of CMMC 2.0 come in.

So, what’s the difference between Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert)? Let’s break it down in plain English.

CMMC Level 1: The Basics

CMMC Level 1 is like locking your front door – it keeps casual threats out, but it’s not Fort Knox.

Who Needs It?

If your company only handles Federal Contract Information (FCI) – which is general info related to DoD contracts but not sensitive military data – then Level 1 is probably enough.

Think of a janitorial service cleaning a military office or a company supplying office furniture to a base. They don’t deal with sensitive information, but they still need basic cybersecurity.

What’s Required?

Level 1 follows 17 security practices, like:

  • Using strong passwords
  • Limiting access to sensitive data
  • Training employees on security best practices

The best part? You can self-assess – no outside auditor needed.

CMMC Level 2: Stronger Security for Sensitive Data

Level 2 is a big step up. If Level 1 is locking your front door, Level 2 is installing a security system with cameras and motion detectors.

Who Needs It?

If your business handles Controlled Unclassified Information (CUI) – which is sensitive but not classified – you need Level 2.

Example? A small aerospace supplier making parts for fighter jets. Their designs aren’t classified, but they’re still important to national security.

What’s Required?

Level 2 follows 110 security controls from NIST 800-171 (a government cybersecurity standard). That means stronger protections like:

  • Encrypting sensitive data
  • Multi-Factor Authentication (MFA)
  • Monitoring your network for suspicious activity

Unlike Level 1, Level 2 requires a third-party assessment (unless you’re working on purely commercial contracts). You’ll need a Certified Third-Party Assessor Organization (C3PAO) to verify your security measures.

CMMC Level 3: The Highest Level of Security

Level 3 is Fort Knox. It’s designed for companies handling the most sensitive CUI – the kind of information that foreign adversaries would love to steal.

Who Needs It?

If your business supports top-tier defense projects – like advanced weapons systems or cybersecurity solutions for the military – you need Level 3.

Think of a cybersecurity firm protecting DoD networks or a contractor working on missile defense technology.

What’s Required?

Level 3 builds on Level 2’s 110 controls and adds even more protections. The full requirements aren’t public yet, but expect additional security measures based on NIST 800-172, which covers:

  • Advanced threat detection
  • Stronger data encryption
  • Continuous monitoring for cyber threats

And, of course, Level 3 requires a government-led audit – no self-assessments here!

Which Level Do You Need?

Here’s the quick summary:

  • Level 1 → Only FCI? Basic security. Self-assess.
  • Level 2 → Handling CUI? Stronger security. Third-party audit required.
  • Level 3 → High-risk CUI? Top security. Government audit required.

If you’re not sure which level applies to your business, it’s worth figuring that out before you get too deep into compliance.

Next up in CMMC for Noobs: Who’s Who in the CMMC Ecosystem?

Recent Posts

Cybersecurity in 2026: Are You Ready for AI-Powered Threats?
January 19, 2026

Cybersecurity in 2026: Are You Ready for AI-Powered Threats?

AI-driven attacks are evolving fast – deepfakes, autonomous malware, and social engineering are now everyday risks. At Argus Cybersecurity Partners,…

Cybersecurity in the Crosshairs: How the Israel-Iran Conflict Elevates Risk for the U.S. Defense Industrial Base
June 21, 2025

Cybersecurity in the Crosshairs: How the Israel-Iran Conflict Elevates Risk for the U.S. Defense Industrial Base

Executive Summary The intensifying conflict between Israel and Iran is reshaping the global cyber threat landscape. For the U.S. Defense…

Back To Top