CMMC Level 1 requires 17 practices focused on basic cybersecurity hygiene to protect Federal Contract Information (FCI), while Level 2 requires 110 practices aligned with NIST SP 800-171 to protect Controlled Unclassified Information (CUI). The level you need depends entirely on what type of data flows through your contract: if you only handle FCI, Level 1 suffices; if you handle CUI—which includes technical data, export-controlled information, or anything marked CUI—you need Level 2. Most DoD subcontractors working on defense programs will need Level 2.
This distinction matters more than ever in October 2026, as DoD contract language increasingly mandates CMMC certification before contract award or option renewal. Understanding which level applies to your organization—and what's actually required—determines your compliance timeline, budget, and operational readiness.
What Data Type Determines Your CMMC Level
The single biggest factor is the data classification in your contract. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn't intended for public release—think contract documents, invoices, delivery schedules. Controlled Unclassified Information (CUI) is more sensitive: technical drawings, specifications, personally identifiable information, export-controlled data, or anything bearing a CUI marking.
Check your contract's DD Form 254 (for classified contracts) or the contract data requirements list. If the contract explicitly states you'll handle CUI or includes a DFARS 7012 clause, you need Level 2. If it only mentions FCI and basic safeguarding, Level 1 may suffice—but many prime contractors now require Level 2 across their entire supply chain as a risk management measure, even when the subcontract technically only involves FCI.
CMMC Level 1: The 17 Basic Practices
Level 1 maps to the 17 practices in FAR 52.204-21, covering foundational cybersecurity. These practices span access control (limit system access to authorized users), identification and authentication (verify user identities), media protection (sanitize or destroy media containing FCI), physical protection (limit physical access to systems), system and communications protection (monitor and control communications at external boundaries), and system and information integrity (identify and manage information system flaws).
Level 1 assessments are annual self-assessments—you document your compliance, affirm it in writing, and maintain evidence. No third-party assessor is required. The cost is essentially internal labor: documenting policies, implementing basic controls like password requirements and antivirus software, and maintaining an assessment record. Most small businesses can achieve Level 1 in 30-90 days with focused effort and minimal outside help.
Common gaps at Level 1 include inconsistent access reviews, lack of media sanitization procedures for disposed equipment, and missing physical access logs. The practices are straightforward, but documentation discipline is essential.
CMMC Level 2: The 110 NIST SP 800-171 Practices
Level 2 implements all 110 security requirements from NIST SP 800-171 Rev 2, organized into 14 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
This is a comprehensive information security program. You'll need written policies and procedures for each family, technical controls like multifactor authentication (MFA) for all users, encryption for CUI at rest and in transit, network segmentation to isolate CUI systems, continuous monitoring and logging, incident response plans with defined roles and contact information, personnel security screening, regular vulnerability scanning and remediation, configuration management baselines, annual security assessments, and formal risk assessments.
Level 2 requires a third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO). The C3PAO conducts interviews, reviews documentation, and performs technical testing to validate your implementation. Assessments are valid for three years. Costs vary widely: expect $15,000-$50,000 for the C3PAO assessment itself, plus $50,000-$200,000+ in preparation costs depending on your current security posture, IT complexity, and whether you need outside consulting, tooling, or infrastructure upgrades.
Timeline from kickoff to certification typically runs 6-12 months for organizations starting from scratch, or 3-6 months if you already have a mature security program.
Key Differences Between Level 1 and Level 2
Scope and complexity: Level 1 is basic hygiene; Level 2 is a full security program. Level 1 has 17 practices; Level 2 has 110.
Assessment rigor: Level 1 is self-assessed annually; Level 2 requires third-party assessment every three years.
Technical requirements: Level 1 can often be met with existing business IT practices. Level 2 mandates MFA, encryption, network segmentation, SIEM or log aggregation, vulnerability management, and formal change control—technical capabilities many small businesses lack.
Documentation burden: Level 1 requires basic documentation. Level 2 requires a System Security Plan (SSP), policies and procedures for all 14 families, an incident response plan, a risk assessment, and continuous evidence collection.
Cost: Level 1 costs are mostly internal labor. Level 2 involves significant external spend for tools, consulting, and assessors.
Common Mistakes DoD Subcontractors Make
Assuming you only need Level 1 without checking contract language or consulting with the prime contractor. Many primes impose Level 2 as a flow-down requirement regardless of technical necessity.
Delaying preparation until contract award is imminent. CMMC certification can take months; starting late risks contract delays or loss.
Treating CMMC as a paperwork exercise. Assessors test technical controls. If your documentation says you encrypt CUI but systems aren't actually encrypted, you'll fail.
Failing to scope the assessment boundary correctly. You don't need to secure your entire enterprise—only the systems that process, store, or transmit CUI. Proper network segmentation and scoping can dramatically reduce cost and complexity.
Neglecting the Plan of Action and Milestones (POA&M) process. CMMC allows up to a $3 million contract threshold with a POA&M for up to 180 days to remediate gaps—but only if you document them properly and demonstrate progress.
How to Prepare for CMMC Certification
Step 1: Identify your required level by reviewing all active and anticipated DoD contracts. Consult with prime contractors to confirm their flow-down requirements.
Step 2: Conduct a gap assessment. For Level 1, map your current practices against the 17 requirements. For Level 2, conduct a full NIST SP 800-171 assessment. Many organizations discover 20-40 gaps on first assessment.
Step 3: Develop a remediation roadmap. Prioritize high-impact gaps like MFA, encryption, and incident response. Budget for tools, infrastructure changes, and consulting if needed.
Step 4: Implement controls and document everything. Policies, procedures, configuration baselines, evidence of implementation. Assessors will ask to see all of it.
Step 5: For Level 2, engage a C3PAO when you're confident you've closed all gaps. Schedule a readiness review first—most C3PAOs offer pre-assessment services to identify remaining issues before the formal assessment.
Step 6: Maintain your program. CMMC isn't one-and-done. Continuous monitoring, annual training, regular vulnerability scans, and periodic reviews are required to stay compliant.
Why This Matters in October 2026
The threat landscape makes CMMC more critical than ever. This week alone, CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog—including flaws in ISC BIND, Apache Struts, and ProFTPD dating back to 2015 and 2016, all exploited by the China-linked Flax Typhoon threat group. These aren't new zero-days; they're old vulnerabilities in unpatched systems. CMMC Level 2's configuration management and vulnerability management practices are designed to prevent exactly this scenario.
Meanwhile, supply chain attacks continue to escalate. Researchers disclosed this week that credential-stealing GitHub Actions workflows have been planted in tens of thousands of repositories after compromising high-profile maintainer accounts. DoD subcontractors often use open-source tools and libraries; CMMC's software integrity and supply chain risk management practices provide a framework to vet and monitor these dependencies.
The lesson: adversaries are patient, sophisticated, and targeting the defense industrial base. CMMC isn't bureaucratic overhead—it's a baseline defense posture that addresses real threats.
Getting Expert Help
Many DoD subcontractors lack in-house security expertise to navigate CMMC on their own. Engaging a firm experienced in CMMC preparation, gap assessments, and remediation can accelerate your timeline and reduce costly missteps. Vici Tech Solutions helps DoD contractors assess their current security posture, implement required controls, and prepare for successful CMMC certification—reach out if you need a roadmap tailored to your contract requirements and IT environment.