to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Three levels, and what each one actually asks of you

The level is set by the solicitation, not chosen by you. It decides which data the assessment covers, which standard applies, and who does the checking.

LevelRequirementsStandardData coveredWho assesses
Level 115 FAR requirements, assessed as 17 practicesFAR 52.204-21Federal contract information only. No CUI.Annual self-assessment, with an affirmation from a senior official in SPRS.
Level 2110 requirementsNIST SP 800-171 Rev. 2CUI, including covered defense information and controlled technical information.Either a self-assessment or a C3PAO assessment every three years, depending on what the contract specifies.
Level 3110 plus 24 selected requirements from 800-172NIST SP 800-171 Rev. 2 plus selected NIST SP 800-172CUI on programs judged to face advanced persistent threats.DIBCAC assessment, and Level 2 certification is a prerequisite.

The Level 1 practices

FAR 52.204-21 lists fifteen basic safeguarding requirements. CMMC assesses them as these seventeen practices drawn from NIST SP 800-171, which is why you will see both numbers. Every one of them is also part of Level 2.

  1. 3.1.1 Know who and what is allowed on your systems AC Level 1 5 pt
  2. 3.1.2 Limit what each person can do once inside AC Level 1 5 pt
  3. 3.1.20 Verify and limit outside systems AC Level 1 1 pt
  4. 3.1.22 Review what goes on public sites AC Level 1 1 pt
  5. 3.5.1 Give every user, process, and device an identity IA Level 1 5 pt
  6. 3.5.2 Prove those identities IA Level 1 5 pt
  7. 3.8.3 Destroy or wipe media properly MP Level 1 5 pt
  8. 3.10.1 Limit physical access PE Level 1 5 pt
  9. 3.10.3 Escort visitors PE Level 1 1 pt
  10. 3.10.4 Keep physical access logs PE Level 1 1 pt
  11. 3.10.5 Manage keys and badges PE Level 1 1 pt
  12. 3.13.1 Guard your boundaries SC Level 1 5 pt
  13. 3.13.5 Put public services in their own subnet SC Level 1 5 pt
  14. 3.14.1 Find and fix flaws on a clock SI Level 1 5 pt
  15. 3.14.2 Run malware protection SI Level 1 5 pt
  16. 3.14.4 Keep malware definitions current SI Level 1 5 pt
  17. 3.14.5 Scan on schedule and in real time SI Level 1 3 pt

A note on Level 3

Level 3 builds on a Level 2 certification and adds selected requirements from NIST SP 800-172. Those additional requirements are not reproduced on this site; only the 110 Rev. 2 requirements are.

For the rule that establishes the levels, see the crosswalk. For what the Phase 2 suspension changed about assessments, see the suspension page.