Resource
CMMC Level 1 versus Level 2 explained
The level that applies follows from the data your contract requires you to handle, not from your size or sector. Getting that determination wrong in either direction is expensive, which makes it the first question to answer rather than the last.
The two levels most suppliers face
The gap between them is substantial in control count, cost and assessment burden.
| Aspect | Level 1 |
|---|---|
| Data handledControlled unclassified information | Federal contract information |
| Control count110 NIST SP 800-171 controls | 17 basic safeguarding practices |
| AssessmentThird party assessment for most | Annual self assessment |
| DocumentationSystem security plan and plan of action required | Limited |
| Typical timelineOften around a year from a commercial baseline | Weeks to months |
| Scoping importanceCritical, and it drives the entire cost | Moderate |
Establishing which applies
Five steps, in order, before spending anything.
- Ask your prime contractor or contracting officer in writing which data category your contract covers
- Identify every system where that data is created, stored, processed or transmitted
- Include backups, email and file sharing, since data travels further than people assume
- Decide whether to contain the data in an enclave or accept company wide scope
- Only then assess controls, because scope determines how many systems each control must cover
The enclave approach
For a small supplier, the most cost effective pattern is usually to stop controlled information spreading across the whole business and contain it in a defined enclave: a specific set of systems, accounts and storage locations, separated from general operations.
The controls then apply to that enclave rather than to every laptop in the building. The rest of the business is secured properly, because it should be, but it is not carrying assessment scope.
This requires discipline about where controlled material is allowed to travel. Email is the hardest part, because it is where controlled documents most often leak into general scope without anyone deciding they should.
Common questions
Answered before you ask.
We are a subcontractor. Does this still apply?
Frequently yes. Requirements flow down through the supply chain, so a subcontractor handling controlled unclassified information carries obligations without a direct government contract. The trigger is the data you handle rather than your position in the chain, which catches out a lot of smaller suppliers around Joint Base Lewis McChord.
What is an SPRS score?
A self assessment score against the NIST 800-171 controls, submitted to a government system. It starts at 110 and deducts weighted points for each control not implemented, so it can be negative. A low score is not automatically disqualifying, but it is visible to contracting officers and sits alongside a plan showing how and when gaps close.
How much does Level 2 readiness cost?
The range is wide and scope is the dominant variable, which is why scoping comes first. A business already running multi factor authentication, endpoint detection, logging and managed backup starts considerably further along than one starting from a basic commercial baseline. Anyone quoting a figure before understanding your scope is guessing.
Related
Read next.
CMMC and DFARS compliance
Level 1 and Level 2, NIST 800-171, SPRS scoring and assessment readiness.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Manufacturing
Shop floor networks, ERP, downtime cost
IT compliance for Washington State businesses
RCW 19.255 breach notification and the My Health My Data Act, which most national guidance misses.
What managed IT services cost in Tacoma
Per user pricing bands, what moves the number up, and how to read a quote.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.