CMMC Level 1 vs. Level 2: Which Does a DoD Subcontractor Need?

Start with the information your systems will handle and the assessment type assigned to the subcontract—not with a generic assumption that every DoD supplier needs the same level.

CMMC Level 1 and Level 2 are not simply “basic” and “advanced” badges. They protect different categories of federal information and use different security requirement sets. For a subcontractor, the right level starts with what FCI or CUI will actually be processed, stored, or transmitted on the systems used to perform the subcontract.

Level 1: FCI and basic safeguarding

CMMC Level 1 uses the safeguarding requirements from FAR 52.204-21. Under 32 CFR 170.14, the Level 1 security requirements are the basic safeguarding requirements in that FAR clause. Under the subcontractor flowdown rule in 32 CFR 170.23, a subcontractor that will process, store, or transmit FCI—but not CUI—needs CMMC Level 1 (Self).

Level 1 is a self-assessment path, but “self” does not mean informal. The CMMC rule establishes assessment and affirmation requirements, and the contractor must maintain the required current status for the relevant systems.

Regulatory sources: 32 CFR 170.14 and 32 CFR 170.23.

Level 2: CUI and NIST SP 800-171

CMMC Level 2 uses the security requirements in NIST SP 800-171 Revision 2. If a subcontractor will process, store, or transmit CUI, 32 CFR 170.23 makes Level 2 (Self) the minimum subcontractor requirement. The required assessment type can be higher depending on the associated prime contract.

If the prime contract requires Level 2 (C3PAO), a subcontractor handling CUI needs Level 2 (C3PAO) at minimum. If the prime contract requires Level 3 (DIBCAC), a subcontractor handling CUI generally needs at least Level 2 (C3PAO), subject to any specific DoD guidance for that subcontract.

Level 2 does not always mean a C3PAO assessment

The current DFARS solicitation provision at 252.204-7025 allows the contracting officer to identify the required CMMC level as Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). That means a subcontractor should verify both the level and the assessment type instead of treating “Level 2” as one universal certification path.

The provision also ties award eligibility to current CMMC status in SPRS for the contractor information systems that will process, store, or transmit FCI or CUI during performance, together with a current affirmation of continuous compliance.

Official source: DFARS 252.204-7025.

A practical decision sequence

  1. Confirm whether the solicitation or subcontract includes a CMMC requirement.
  2. Map the FCI and CUI that your scope will actually require.
  3. Identify every contractor information system that will process, store, or transmit that information.
  4. Confirm the CMMC level and assessment type assigned to your subcontract.
  5. Check whether your current SPRS status and affirmation satisfy the pre-award requirement for those systems.
  6. Determine what must be flowed to any lower-tier supplier receiving FCI or CUI.

If you are not sure whether the information is FCI or CUI, start with FCI vs. CUI for DoD subcontractors. If you use lower tiers, continue to CMMC flowdown to lower-tier subcontractors.

Check Before You Price Compliance

SubPreCheck can surface the CMMC clause, assessment requirement, FCI/CUI references, lower-tier language, and missing cyber attachments so you can identify the questions before committing resources.

View Sample ReportSee Review Plans

General educational information only. CMMC applicability, system scope, status, and assessment type must be confirmed against the current solicitation, contract, subcontract, and DoD rules.