Technically Acceptable
ENTRY 02.10 / DO YOU EVEN NEED CMMC, AND AT WHAT LEVEL
READ 8 MIN
STATUS IN PROGRESS
UTC--:--:--Z
CMMC: Lesson 10

Do you even need CMMC, and at what level

Before you spend a dollar or hire anyone, work out whether these rules apply to you at all, and at which of three levels. The answer is mostly sitting in your contract.

The short version

CMMC, the Cybersecurity Maturity Model Certification, is how the Department of Defense checks that the companies in its supply chain actually protect the government information they handle. If you do business with the DoD, or you subcontract to someone who does, it can apply to you. It is not about classified material. It is about two specific categories of unclassified information: Federal Contract Information and Controlled Unclassified Information.

Your required level depends entirely on which of those two you touch. Handle only Federal Contract Information and you are looking at Level 1. Handle Controlled Unclassified Information and you are at Level 2, or for a small number of high-stakes programs, Level 3. You do not get to pick. The contract sets the level, and the requirement flows down from the prime to the subcontractors who touch the data.

So the first job is not buying tools or hiring a consultant. It is reading your contracts to find out which information you handle and what the solicitation actually asks for.

FCI vs CUI

Federal Contract Information (FCI) is information provided by or generated for the government under a contract to develop or deliver a product or service, that is not intended for public release. Think of the routine non-public details of doing the work: delivery schedules, basic specifications, internal correspondence about the contract. Almost anyone with a federal contract handles some FCI.

Controlled Unclassified Information (CUI) is a step up. It is information the government, or a contractor acting on the government’s behalf, creates or possesses that a law, regulation, or government-wide policy says must be safeguarded. Controlled technical data, certain export-controlled information, and many engineering and program details fall here. CUI is usually marked, and it usually arrives with a contract clause telling you to protect it.

The practical test: FCI is the baseline almost every contractor has. CUI is specific, often marked, and triggered by the nature of the data plus the clauses in your contract. If you only ever see FCI, you are a Level 1 shop. The moment CUI enters your environment, you are in Level 2 territory.

Level 1 vs Level 2, and where Level 3 sits

Level 1 protects FCI. It maps to the 15 basic safeguarding requirements in FAR 52.204-21. These are foundational practices: control who has access, authenticate your users, protect your boundaries. You assess yourself once a year and a company official affirms it.

Level 2 protects CUI. It maps to the 110 security requirements in NIST Special Publication 800-171. This is a serious jump in scope and effort over Level 1. Depending on the contract, Level 2 is either a self-assessment or an assessment by an outside certified assessor, repeated every three years, with an annual affirmation in between.

Level 3 is for the most sensitive programs. It builds on the 110 Level 2 requirements and adds a subset of the enhanced requirements from NIST SP 800-172. Level 3 assessments are run by the government itself, not a commercial assessor. Most contractors will never see Level 3, and if you are at it you generally know, because the program is unusual.

Reading your level off the contract

You do not have to guess. The signals are in the contract and the solicitation.

Look for three clauses. FAR 52.204-21 is the basic safeguarding clause that travels with FCI and Level 1. DFARS 252.204-7012 is the clause that requires protection of CUI under NIST 800-171, and its presence is a strong sign you are in Level 2 land. DFARS 252.204-7021 is the CMMC clause itself, and the solicitation will name the CMMC level the contract requires.

Then look at the data. What does the government actually send you, and what do you generate for them? If any of it is marked CUI, or the clauses above require 800-171 protection, you are at Level 2 no matter how small your shop is.

Self-assessment vs C3PAO

Who checks your work depends on your level and your contract.

Level 1 is always a self-assessment. You evaluate yourself against the 15 requirements, a company official affirms it annually, and you record it in the government’s Supplier Performance Risk System.

Level 2 splits. Some Level 2 contracts allow a self-assessment. Others require an assessment by a Certified Third-Party Assessment Organization, a C3PAO, accredited under the CMMC ecosystem. A C3PAO assessment happens every three years, with an annual affirmation in the years between. Which path you are on is set by the contract, not by you, so do not bank on the cheaper self-assessment route until the solicitation confirms it.

Level 3 is assessed by the government’s own assessors, not a commercial C3PAO.

Common ways people get the level wrong

A few traps catch contractors over and over.

Assuming “we do not touch classified, so we are fine.” CMMC is not about classified information. It is about FCI and CUI, both of which are unclassified.

Assuming it only hits primes. The requirement flows down. If you are a subcontractor who handles FCI or CUI, it reaches you.

Confusing FCI with CUI, in both directions. Some shops assume Level 1 while CUI is quietly flowing down to them, which leaves them under-protected and out of compliance. Others assume they have CUI when they only ever see FCI, and they over-scope and overspend on a Level 2 program they never needed.

Treating it as one and done. Affirmations are annual and assessments recur. A clean assessment is not a permanent badge.

Waiting until award to find out. The level is in the solicitation. By the time you win the work, you should already know what you signed up for.

What to do next

Start with paper, not products.

Pull your current contracts and live solicitations and search for FAR 52.204-21, DFARS 252.204-7012, and DFARS 252.204-7021. Write down what you find.

Sort your data. List what the government sends you and what you produce for them, and label each piece as FCI or CUI based on its markings and the clauses above.

Set your level from that. FCI only means Level 1. CUI means Level 2, and the contract tells you whether that is a self-assessment or a C3PAO assessment.

Only then think about scope, gaps, and outside help. The next guide covers the first thirty days: scoping your environment, running a gap assessment, and computing your SPRS score, all before you hire anyone.