
CMMC Decision Guide · Reviewed August 2026
CMMC Level 1 vs Level 2:
Cost, Requirements, and the 2026 Decision
The expensive mistake is not simply choosing the wrong CMMC level. It is building a Level 2 environment before confirming that Controlled Unclassified Information actually enters your systems, or assuming Level 1 is enough because your company is small.
At a working level, the split is straightforward: Level 1 protects Federal Contract Information using 15 basic safeguards; Level 2 protects Controlled Unclassified Information using the 110 security requirements of NIST SP 800-171 Revision 2. Level 2 therefore creates a much larger technical, documentation, evidence, and assessment burden.
There is also an unusual 2026 wrinkle. The Department suspended the planned Phase II transition in July 2026. During the suspension, procurement requirements are limited to Level 1 self-assessment or Level 2 self-assessment rather than new Level 2 C3PAO or Level 3 designations. That makes contract reading, CUI identification, and scope control more important than buying an assessment too early.
Decision rule: classify the information first, define the system boundary second, and spend money third. 🔐
Snapshot
This guide is for defense contractors, subcontractors, founders, IT managers, and compliance owners deciding whether Level 1 or Level 2 applies, what each requires, and how much assessment readiness may cost. By the end, you should be able to identify the likely level, build a sensible budget, and know what to verify before hiring a consultant or assessment provider.
Table of Contents
- CMMC Level 1 vs Level 2: the quick verdict
- What changed in 2026?
- Level 1 vs Level 2 requirements
- How much does Level 1 vs Level 2 cost?
- What changes the real cost?
- Scope and evidence requirements
- DIY vs software vs professional help
- A practical readiness sequence
- How to evaluate a CMMC quote
- FAQ
- Your 15-minute next step

CMMC Level 1 vs Level 2: the quick verdict
CMMC Level 1 is the smaller requirement set. It is built around the 15 basic safeguarding requirements associated with FAR 52.204-21 and is intended for systems that process, store, or transmit Federal Contract Information, or FCI.
CMMC Level 2 is substantially more demanding. It uses all 110 security requirements in NIST SP 800-171 Revision 2 and applies to systems within the Level 2 assessment scope associated with Controlled Unclassified Information, or CUI. The CMMC regulation explicitly maps Level 1 to FAR safeguards and Level 2 to NIST SP 800-171 Rev. 2.
| Decision point | CMMC Level 1 | CMMC Level 2 |
|---|---|---|
| Information driver | FCI | CUI |
| Security requirements | 15 FAR-based safeguards | 110 NIST SP 800-171 Rev. 2 requirements |
| Typical complexity | Basic safeguarding | Formal CUI security program |
| Assessment cadence | Annual self-assessment | Self-assessment every 3 years under Level 2 (Self), plus annual affirmation |
| POA&M allowed? | No | Limited conditional status may be possible |
| SSP requirement | Not comparable to Level 2 | System Security Plan is required |
| Evidence burden | Lower | Substantially higher |
| Current 2026 procurement status | Self-assessment permitted | Level 2 Self permitted; new C3PAO designations suspended during review |
Key takeaway: company size does not determine your CMMC level. The information your contract requires you to process, store, or transmit is the more important starting point.
Before You Act
This guide is decision support, not individualized legal or contracting advice. Contract language, CUI categories, subcontract flowdowns, system architecture, cloud services, and current Department guidance can change the answer. Confirm material decisions against your solicitation, contract clauses, current CMMC guidance, and qualified contracting or compliance advisers where necessary.
What changed in 2026?
CMMC implementation took an important turn on July 13, 2026. The Department announced the immediate suspension of the planned Phase II requirements that had been scheduled for November 10, 2026. Phase I self-assessment requirements remain in place.
During the suspension, program managers and requiring activities are directed to use only CMMC Level 1 (Self) or CMMC Level 2 (Self) in procurement requirement documents. They may not designate Level 2 C3PAO or Level 3 DIBCAC assessments during the suspension period. The Department also directed amendments or modifications to remove those higher assessment designations from affected solicitations and contracts as applicable.
What this means for a contractor today
- Do not assume a November 2026 C3PAO deadline still applies to you.
- Read the actual solicitation and any amendment before commissioning a certification assessment.
- Do not treat the suspension as permission to stop protecting FCI or CUI.
- Continue to address contractual cybersecurity obligations such as DFARS 252.204-7012 when they apply.
- Keep Level 2 readiness moving if you handle CUI, because the underlying security requirements have not evaporated.
The Department’s suspension notice specifically states that contractual protection of covered defense information remains in effect and that NIST SP 800-171 Rev. 2 compliance will continue to be enforced through self-assessments and selected government-led assessments during the interim period.
2026 planning rule: treat C3PAO certification cost as a future-planning variable, not an automatic current procurement expense. Verify the contract before signing an assessment engagement.

Level 1 vs Level 2 requirements: what actually gets harder?
Level 1: 15 basic safeguards for FCI
Level 1 centers on basic safeguarding. FAR 52.204-21 covers areas such as limiting system access, controlling external connections, authenticating users, protecting physical access, patching flaws, protecting against malicious code, and performing system scans.
You can review the complete official safeguard language in FAR 52.204-21 on Acquisition.gov.
The important operational detail is unforgiving: all Level 1 requirements must be fully implemented. CMMC does not permit a Plan of Action and Milestones to carry unfinished Level 1 safeguards.
Level 2: 110 requirements for CUI
Level 2 expands the job from basic cyber hygiene into a documented CUI protection program. The 110 requirements span areas including access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system integrity.
An organization also needs an up-to-date System Security Plan for each information system in the assessment scope. Under the CMMC scoring methodology, absence of an adequate SSP prevents the assessment from being completed as a normal passing assessment.
Multi-factor authentication becomes one of the controls that can materially affect the Level 2 score and implementation plan. If MFA deployment is still unfinished, the practical implementation sequence in the MFA rollout guide can help separate the technology purchase from the rollout work.
Conditional Level 2 is not a permission slip for a long backlog
Level 2 can allow a limited POA&M path to Conditional status, but the rules are narrow. The assessment score must be at least 80% of the maximum, which corresponds to 88 out of 110, and most higher-value deficiencies cannot be placed on the POA&M. Several specifically named requirements are also excluded. Remaining items must be closed within 180 days.
The Technical Detail That Matters
NIST has superseded SP 800-171 Rev. 2 with Rev. 3 for general NIST publication purposes. CMMC, however, currently incorporates Revision 2 in 32 CFR Part 170, and the July 2026 suspension guidance also refers to Rev. 2. Do not silently substitute Rev. 3 for your current CMMC assessment basis simply because it is the newer NIST publication.
How much does CMMC Level 1 vs Level 2 cost?
There is no universal CMMC price. A tiny FCI-only contractor using a straightforward managed environment and a CUI-heavy manufacturer with dozens of endpoints, engineering systems, cloud services, and external providers are buying very different amounts of work.
For a defensible benchmark, the 2024 CMMC final rule contains official economic estimates for assessment and affirmation effort. These numbers are useful as planning references, but they are not vendor price lists and not complete implementation budgets. Most importantly, the government’s estimates assume the underlying security requirements are already implemented.
| Assessment path | Small-entity government estimate | Other-than-small estimate | Cadence / status |
|---|---|---|---|
| Level 1 Self + initial affirmation | $5,977 | $4,042 | Annual self-assessment |
| Level 2 Self + initial affirmation | $34,277 | $43,403 | Assessment every 3 years, annual affirmation |
| Level 2 Self, modeled 3-year total | $37,196 | $48,827 | Includes additional annual affirmations |
| Level 2 C3PAO + initial affirmation | $101,752 | $112,345 | Useful planning reference; new C3PAO designations are suspended as of Aug. 2026 |
| Level 2 C3PAO, modeled 3-year total | $104,670 | $117,768 | Historical regulatory cost model, not a current quote |
The small-entity Level 1 estimate includes outside-service-provider time in the government’s model, which helps explain why it is higher than the model for larger organizations using internal staff. Likewise, the Level 2 certification estimate includes both internal effort and modeled C3PAO activity.
The number most buyers miss: remediation cost
The regulatory estimates above deliberately separate assessment burden from the cost of becoming compliant. That distinction matters. If you need to replace unsupported systems, redesign identity, implement centralized logging, restrict CUI, revise cloud architecture, deploy MFA, improve backups, document procedures, or create an SSP, remediation can dwarf the assessment itself.
For a broader model covering assessment, remediation, tools, consulting, and recurring operations, use the site’s CMMC compliance cost guide. This comparison page is intentionally narrower: it helps you decide which level creates the cost in the first place.
Cost insight: an assessment quote answers “what does verification cost?” It does not necessarily answer “what will it cost us to become ready?” Keep those budgets separate.
What changes the real CMMC cost?
Five variables usually move the budget far more than employee count alone.
| Cost driver | Lower-cost condition | Higher-cost condition |
|---|---|---|
| CUI footprint | Small dedicated enclave | CUI spread across normal business systems |
| Existing controls | Modern identity, endpoint security, logging, patching already deployed | Large technical remediation backlog |
| Cloud and providers | Clearly documented compliant services | Multiple CSPs/ESPs with unclear responsibility boundaries |
| Documentation | Current SSP, policies, diagrams, inventories, evidence | Controls exist but cannot be demonstrated |
| Asset count | Limited CUI assets | Broad endpoint, server, SaaS, plant, remote-user scope |
| Internal capability | Staff understand NIST 800-171 evidence | Heavy dependence on consultants for interpretation and remediation |
A simple cost model
A more useful budget formula is:
Current-state assessment + remediation + documentation + technology changes + external-provider changes + formal assessment effort + annual operating burden + contingency = realistic CMMC budget.
The recurring technology portion can be modeled separately using a security stack worksheet such as the security tool stack cost calculator. That prevents one-time consultant fees from becoming tangled with annual licensing costs.
The CMMC cost chain
FCI or CUI?
Which assets touch it?
What is not implemented?
Can you prove it?
Self or required validation path
The expensive shortcut is jumping directly to Step 5. Assessment readiness is mostly created in Steps 1 through 4.
Scope and evidence: where Level 2 becomes expensive
CMMC cost follows scope surprisingly closely. Every asset admitted into the CUI environment can add configuration work, evidence, ownership questions, monitoring, provider dependencies, and recurring maintenance.
Level 1 scope
For Level 1, organizational systems that process, store, or transmit FCI are in scope. The rule also tells organizations to consider the people, technology, facilities, and external service providers involved with that FCI.
Level 2 scope
Level 2 distinguishes several asset categories, including CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. CUI Assets must be documented in the asset inventory, SSP, and network diagram and prepared for assessment against the applicable Level 2 requirements.
External services deserve special attention. A cloud or managed service touching CUI or Security Protection Data can affect the assessment scope and evidence model. The regulation also requires the relationship and responsibilities of relevant external providers to be documented, including through service descriptions and customer responsibility information where applicable.
Why an enclave can change the economics
Suppose a 40-person engineering company lets CUI move through ordinary email, shared drives, employee laptops, collaboration tools, printers, and support platforms. The Level 2 boundary may become broad and operationally awkward.
If the same company can lawfully and operationally restrict CUI to a properly designed smaller environment, the number of CUI assets may shrink. That does not remove the security requirements, but it can reduce the number of places where those requirements must be implemented and evidenced.
Scope reduction is therefore not a paperwork trick. It is architecture. Done badly, it merely creates a diagram that reality refuses to obey.
Common mistake: buying a “CMMC-ready” software bundle before mapping where CUI actually flows. Tools cannot compensate for a boundary nobody understands.
When DIY, software, or professional help makes sense
| Approach | Good fit | Where it stops being enough |
|---|---|---|
| DIY | Small Level 1 scope, strong internal IT knowledge, clear contract/data flow | You cannot confidently map requirements to evidence or interpret CUI scope |
| Software | Evidence tracking, asset inventories, policy workflow, control ownership, recurring checks | The organization expects software to make architectural or contractual decisions |
| Professional readiness help | Complex Level 2 scope, weak documentation, major remediation, unusual cloud/ESP relationships | The provider mainly generates templates without validating implementation |
| Independent assessment provider | When the applicable contract and current program rules require independent certification | Do not buy certification merely because a salesperson predicts a future mandate |
Do it free or mostly DIY when…
- You have a small, well-understood Level 1 environment.
- Your staff can map the 15 safeguards to implemented controls.
- You can responsibly perform the self-assessment and affirmation.
- You are not trying to outsource accountability to a consultant.
Pay for software when…
Software earns its keep when it reduces repeated evidence work, tracks asset and control ownership, organizes policies, connects technical evidence to requirements, or helps a larger team maintain readiness over time. It should reduce operational friction, not merely decorate a dashboard with green circles.
Pay for professional help when…
Professional assistance becomes more defensible when the CUI boundary is uncertain, the SSP is weak, multiple external providers are involved, the technical backlog is large, or management needs an independent readiness view before making a contract commitment.
During the current 2026 suspension, however, distinguish readiness consulting from a formal C3PAO certification assessment. They solve different problems, and the latter should not be purchased simply because it was part of the pre-suspension implementation schedule.
A practical CMMC readiness sequence that avoids buying twice
- Read the contract and solicitation. Identify the CMMC language, DFARS clauses, amendments, flowdowns, and the information you are expected to receive or create.
- Separate FCI from CUI. Do not label ordinary company data as CUI merely to be cautious. Do not downgrade actual CUI because Level 2 looks expensive.
- Map the data flow. Include endpoints, servers, SaaS, cloud storage, email, support tools, administrators, facilities, and external providers.
- Define the smallest defensible assessment scope. Document what is in scope and why other assets are genuinely outside it.
- Run a requirement-by-requirement gap review. Distinguish fully implemented, partially implemented, not implemented, and not applicable.
- Fix architecture before polishing paperwork. Identity, access, logging, configuration, encryption, endpoint management, and provider choices may require longer lead times.
- Build the evidence set. Policies without implementation evidence are weak; technology without approved documentation can also fail to demonstrate the requirement.
- Perform the applicable self-assessment. Use the CMMC scoring rules and retain required Level 2 artifacts.
- Complete the affirmation and required SPRS activity. Treat affirmation as an accountability step, not a ceremonial click.
- Monitor current CMMC policy before purchasing certification services. The 2026 suspension makes this step unusually important.
Level 2 assessment artifacts used as evidence must be retained for six years from the CMMC Status Date. Level 2 Self assessments are performed every three years, with affirmation required at the assessment and annually thereafter.
Real-world example: two small contractors, two very different budgets
A 12-person parts supplier receives ordinary nonpublic contract information but no CUI. Its systems are modern, endpoint protection is managed, access is restricted, and FCI resides in a modest business environment. Its likely problem is demonstrating Level 1 safeguards consistently, not building a Level 2 enclave.
A 25-person engineering subcontractor receives controlled technical information, stores drawings in cloud services, collaborates remotely, and relies on an MSP. Its headcount is still small, but the decision changes completely. It must understand Level 2 scope, NIST 800-171 requirements, the MSP’s role, cloud responsibilities, SSP content, evidence, and remediation.
The lesson is useful beyond CMMC: small business does not necessarily mean small compliance scope. Data architecture beats employee count as a budgeting clue.
How to evaluate a CMMC consultant or assessment quote
A good quote should make the boundary between advisory work, remediation, software, and formal assessment painfully clear. Foggy proposals have a habit of producing surprisingly solid invoices.
| Question to ask | Why it matters |
|---|---|
| Is this readiness consulting, remediation, a self-assessment support engagement, or a formal assessment? | Prevents you from paying assessment-level prices for advisory work. |
| What exact assessment scope is assumed? | Asset and provider count can change effort substantially. |
| Is evidence collection included? | A low quote may assume your evidence is already organized. |
| Does the price include SSP, diagrams, inventory, and policy work? | These may be separate projects. |
| Are remediation hours included? | Finding a gap and fixing it are different services. |
| Which external providers must participate? | MSP, MSSP, cloud, and SaaS dependencies can add work. |
| What happens if scope expands? | Ask for change-order pricing before the expansion occurs. |
| Who owns the final documents and evidence repository? | You need operational continuity after the consultant leaves. |
| How does the July 2026 suspension affect the service being proposed? | A provider should be able to separate present requirements from future planning. |
Red flags worth walking away from
- “Every defense contractor needs Level 2.”
- “Buy our platform and you will be CMMC compliant.”
- A quote that never asks what FCI or CUI you handle.
- No written assessment scope.
- No distinction between implementation and assessment fees.
- A promise of certification before reviewing your environment.
- Pressure to purchase a C3PAO engagement without checking the current solicitation and 2026 suspension.
Buyer rule: the best proposal is not necessarily the cheapest or the most comprehensive. It is the one whose scope matches your actual contract, information flow, and readiness gap.

FAQ
Can a company choose Level 1 instead of Level 2 to save money?
Not simply as a budgeting choice. The applicable contract requirement, information type, and system scope determine the required status. If your performance requires handling CUI within the relevant systems, reducing cost means controlling the CUI scope or architecture appropriately, not declaring the environment Level 1.
Does Level 2 automatically require a C3PAO assessment in 2026?
No. As reviewed in August 2026, the Department has suspended the Phase II transition and directed procurement requirements during the suspension to Level 1 Self or Level 2 Self. New Level 2 C3PAO and Level 3 designations are not to be used during the suspension period. Check current official guidance and the actual solicitation because the review can produce further changes.
Is NIST SP 800-171 Revision 3 now the CMMC Level 2 standard?
Not under the current CMMC regulation reviewed here. NIST itself has superseded Revision 2 with Revision 3, but 32 CFR Part 170 still incorporates NIST SP 800-171 Revision 2 for CMMC Level 2, and the July 2026 suspension guidance likewise refers to Revision 2.
Can Level 1 use a POA&M for unfinished controls?
No. Level 1 requires all applicable Level 1 security requirements to be met. The CMMC rule does not permit a POA&M for Level 1 self-assessments.
Can Level 2 pass with some requirements unfinished?
Only under the restricted Conditional Level 2 rules. The organization must meet the minimum score threshold, only certain deficiencies are eligible for the POA&M, and successful closeout must occur within 180 days. A Final Level 2 status requires the applicable security requirements to be met.
Why can a small Level 2 contractor spend more than a much larger Level 1 contractor?
Because the level is driven by information and scope, not payroll size. A small company handling CUI may need an SSP, CUI boundary, stronger identity controls, logging, encryption, provider documentation, evidence retention, technical remediation, and a 110-requirement assessment. A larger FCI-only organization may face a much narrower Level 1 problem.
Should we hire a consultant before knowing whether we have CUI?
Usually, first gather the contract, data-flow information, CUI markings or contract requirements, and system architecture. If determining CUI applicability itself is uncertain, targeted contracting or compliance expertise may be valuable. Avoid commissioning a large implementation project while the basic scope question remains unanswered.
Your 15-minute next step: make a one-page CMMC scope note
Do not begin with a vendor demo. Open the solicitation, contract, or subcontract and write down three things:
- The CMMC status or cybersecurity clauses actually named in the document.
- Whether you receive, create, store, or transmit FCI, CUI, or both.
- The systems and external providers where that information currently travels.
That one-page note gives you the first defensible answer to the Level 1 versus Level 2 question. It also gives a consultant something concrete to review and prevents your budget from being built on an assumption.
Because the CMMC program is under active review in August 2026, check the official program page again before committing to a certification engagement or relying on an older rollout calendar. The security work may remain necessary even when the assessment timetable changes. That distinction is where a sensible CMMC budget begins.
Last reviewed: 2026-09