CMMC has three levels. The original model published in 2020 had five. When the Department restructured the programme into what became known as CMMC 2.0, levels 2 and 4 of the old model were removed and the remaining tiers renumbered.
That is why searches for CMMC level 4 or level 5 requirements return confusing results. Those tiers exist only in documentation that has been superseded.
Level 1: Foundational
Applies when you handle Federal Contract Information but no Controlled Unclassified Information. Almost any federal contract creates FCI.
Requires 17 practices, aligned to the basic safeguarding requirements of FAR 52.204-21. These are genuinely foundational: limit system access to authorised users, control who can post to publicly accessible systems, sanitise media before disposal, use antivirus, apply updates.
Assessment is an annual self-assessment with an affirmation.
Most organisations that believe they are Level 1 should double-check. Marking of CUI is inconsistent in practice, and what decides your tier is the contract language and the nature of the information, not whether a document arrived stamped.
Level 2: Advanced
Applies when you handle Controlled Unclassified Information. This covers most subcontractors on DoD programmes.
Requires all 110 controls of NIST SP 800-171 Rev 2, across fourteen control families. Our walkthrough of the requirements covers what each family means in practice and what evidence looks like.
Assessment is where the current pause matters. Under the suspended Phase 2, many Level 2 contracts would have required a third-party C3PAO assessment. That mandate is on hold; self-assessment and affirmation obligations continue. See what still applies.
Level 3: Expert
Applies to a small minority of contractors working on the most sensitive programmes, where the concern is advanced persistent threats rather than general safeguarding.
Requires everything in Level 2 plus a selected subset of NIST SP 800-172 enhanced requirements. Those are qualitatively different in character — they assume a capable adversary already inside the boundary and focus on detection, deception, resilience and recovery rather than perimeter controls.
Assessment at Level 3 is government-led rather than conducted by a third party.
If you are unsure whether Level 3 applies to you, it almost certainly does not. Level 3 arrives through explicit contract language on specific programmes, not by inference.
Why levels 4 and 5 disappeared
The original five-level model was widely criticised as unworkable for the small and midsize contractors who make up most of the defence industrial base. The restructure removed the two intermediate and top tiers, eliminated most of the process-maturity requirements that sat above the technical controls, and aligned the remaining levels directly to existing NIST publications rather than a bespoke control set.
Practically, that means the model now maps to standards most contractors were already contractually obliged to meet under DFARS 252.204-7012.
- Three levels, not five. Levels 4 and 5 were eliminated in the restructure.
- Level 1 is FCI and 17 practices. Level 2 is CUI and all 110 NIST 800-171 controls.
- Level 3 adds selected NIST SP 800-172 requirements and is government-assessed.
- If you are not certain Level 3 applies, it does not. It comes by explicit contract language.
Working out which level you are
- Read the contract, not the markings. Look for CUI clauses, DFARS 252.204-7012, and any reference to specific CUI categories.
- Ask the prime directly. If you subcontract, the prime knows what they are flowing down. Get it in writing.
- Inventory what you actually receive. Technical drawings, specifications and export-controlled data are CUI whether or not anyone labelled them.
- Assume Level 2 if you are genuinely unsure and handle DoD work. Scoping down later is cheaper than discovering you were under-scoped during an audit.
If you are hiring help with this, our guide to choosing a CMMC consultant covers what to verify. Virginia contractors should also read the regional picture.
Frequently asked questions
How many CMMC levels are there?
Three: Level 1 Foundational, Level 2 Advanced and Level 3 Expert. The original model published in 2020 had five levels, but the restructure known as CMMC 2.0 removed two of them and renumbered the rest. Searches for level 4 or level 5 requirements return superseded documentation.
What is the difference between CMMC Level 1 and Level 2?
Level 1 applies when you handle Federal Contract Information only and requires 17 practices aligned to FAR 52.204-21, with annual self-assessment. Level 2 applies when you handle Controlled Unclassified Information and requires all 110 controls of NIST SP 800-171 Rev 2. The jump is not incremental and the cost difference is substantial.
What does CMMC Level 3 require?
Everything in Level 2 plus a selected subset of NIST SP 800-172 enhanced requirements, which assume a capable adversary already inside the boundary and focus on detection, resilience and recovery. Level 3 assessment is government-led. It applies to a small minority of contractors and arrives through explicit contract language.
Do CMMC levels 4 and 5 still exist?
No. The original five-level model was restructured because it was widely considered unworkable for small and midsize contractors. Two tiers were eliminated, most process-maturity requirements above the technical controls were removed, and the remaining levels were aligned directly to existing NIST publications.
Keep exploring
- CMMC requirements explained
- Is CMMC still required in 2026?
- How to choose a CMMC consultant
- CMMC compliance services
Ready for a clear path forward?
Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.
Start with a Clarity Conversation