Skip to content

Resource

CMMC Level 1 versus Level 2 explained

The level that applies follows from the data your contract requires you to handle, not from your size or sector. Getting that determination wrong in either direction is expensive, which makes it the first question to answer rather than the last.

The two levels most suppliers face

The gap between them is substantial in control count, cost and assessment burden.

CMMC Level 1 and Level 2 compared
AspectLevel 1
Data handledControlled unclassified informationFederal contract information
Control count110 NIST SP 800-171 controls17 basic safeguarding practices
AssessmentThird party assessment for mostAnnual self assessment
DocumentationSystem security plan and plan of action requiredLimited
Typical timelineOften around a year from a commercial baselineWeeks to months
Scoping importanceCritical, and it drives the entire costModerate

Establishing which applies

Five steps, in order, before spending anything.

  • Ask your prime contractor or contracting officer in writing which data category your contract covers
  • Identify every system where that data is created, stored, processed or transmitted
  • Include backups, email and file sharing, since data travels further than people assume
  • Decide whether to contain the data in an enclave or accept company wide scope
  • Only then assess controls, because scope determines how many systems each control must cover

The enclave approach

For a small supplier, the most cost effective pattern is usually to stop controlled information spreading across the whole business and contain it in a defined enclave: a specific set of systems, accounts and storage locations, separated from general operations.

The controls then apply to that enclave rather than to every laptop in the building. The rest of the business is secured properly, because it should be, but it is not carrying assessment scope.

This requires discipline about where controlled material is allowed to travel. Email is the hardest part, because it is where controlled documents most often leak into general scope without anyone deciding they should.

Common questions

Answered before you ask.

We are a subcontractor. Does this still apply?

Frequently yes. Requirements flow down through the supply chain, so a subcontractor handling controlled unclassified information carries obligations without a direct government contract. The trigger is the data you handle rather than your position in the chain, which catches out a lot of smaller suppliers around Joint Base Lewis McChord.

What is an SPRS score?

A self assessment score against the NIST 800-171 controls, submitted to a government system. It starts at 110 and deducts weighted points for each control not implemented, so it can be negative. A low score is not automatically disqualifying, but it is visible to contracting officers and sits alongside a plan showing how and when gaps close.

How much does Level 2 readiness cost?

The range is wide and scope is the dominant variable, which is why scoping comes first. A business already running multi factor authentication, endpoint detection, logging and managed backup starts considerably further along than one starting from a basic commercial baseline. Anyone quoting a figure before understanding your scope is guessing.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment