Framework guide
CMMC 2.0 compliance, level by level
Which level do you need?
| Level | Data | Controls | Assessment | Renewal |
|---|---|---|---|---|
| Level 1 (Foundational) | FCI | 15 safeguards from FAR 52.204-21 | Annual self-assessment with executive affirmation | Annually |
| Level 2 (Advanced) | CUI | 110 controls, NIST SP 800-171 Rev 2 | C3PAO third-party assessment for most contracts; self-assessment for a limited set | Every three years, annual affirmation |
| Level 3 (Expert) | CUI on critical programmes | Level 2 plus 24 controls from NIST SP 800-172 | Government-led (DIBCAC) | Every three years |
What Level 2 actually asks for
How assessment works
Timeline and cost
Weeks 1 to 2
Scope the CUI boundary
Weeks 2 to 4
SSP and gap plan
Weeks 4 to 12
Implement and evidence
Weeks 12 to 16
Assessment
Reusing SOC 2 or ISO 27001 work
Go deeper
Start here
Related frameworks
CMMC questions we hear most
Is CMMC mandatory yet?
Yes, in phases. The CMMC programme rule took effect in late 2024 and the contract clause is being phased into new DoD solicitations from 2025, with Level 2 C3PAO assessments required for most CUI contracts as the phases progress. Primes are already flowing the requirement down.
Can we self-assess for Level 2?
Only for a limited set of contracts the DoD designates. Assume a C3PAO assessment unless your contracting officer confirms otherwise.
Do we need a FedRAMP cloud?
If you store or process CUI in a cloud service, that service must meet FedRAMP Moderate or equivalent. Commercial cloud regions can qualify; check the provider’s attestation for the specific services you use.
Does a SOC 2 report count?
Not as a certificate, but the controls and evidence carry over. Certifyi maps SOC 2 and ISO 27001 controls onto NIST SP 800-171 so the CMMC gap is the CUI-specific remainder.
What is the difference between CMMC and NIST SP 800-171?
NIST SP 800-171 is the control set. CMMC is the DoD programme that verifies you meet it, through self-assessment or third-party assessment, and records the result.