Why understanding the difference matters
If you’re going to work with the Department of War (DoW), you need CMMC Level 1. That’s not a negotiation. If your organization handles DoW Federal Contract Information (FCI) in any way, and nearly any organization holding a DoW contract does, Level 1 applies. Full stop. Level 2 works differently: whether it applies, and how you must prove it, is dictated by the contract and the type of CUI in scope.
Conflating the two is what creates expensive rework. Level 1 self-assessments are required annually, while, depending on contract requirements, Level 2 requires either a self-assessment or C3PAO assessment every three years, as well as annual self-attestations. Level 1 can be a great starting point if the Level 1 and Level 2 scopes are the same, e.g. the entire organization. However, when the scopes are different (Level 1 for the entire organization and Level 2 for a smaller enclave), the work completed for the Level 1 may be of little help for the Level 2 effort.
Agile IT insight: Level 1 isn’t a phase you pass through on the way to Level 2. It’s a standing requirement the moment FCI is present in your environment, regardless of whether CUI, and Level 2, ever enters the picture. Depending on where each boundary lands, the two can run as one certification effort or two entirely separate ones.
What determines which level applies
Level 1 and Level 2 don’t follow the same logic and treating them as two points on the same ladder is where scoping goes wrong.
Level 1 (Basic Safeguarding of FCI) is triggered by data type alone. If DoW Federal Contract Information is present anywhere in your environment, you should be prepared to address Level 1 requirements. The Department of War (DoW) defines FCI as “information, not intended for public release, that is provided by or generated for the Government under a contract… excluding information provided to the public or simple transactional information.”
Level 2 (Broad Protection of CUI) is triggered by the contract. Whether Level 2 applies, and which protection method it requires (self-assessment or C3PAO assessment), is specified by the contract, based on the type of Controlled Unclassified Information (CUI) involved. CUI is “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.”
- If FCI is the only DoW information in your environment, Level 1 likely applies. You must perform an annual self-assessment and affirm compliance with the 15 security requirements from FAR clause 52.204-21.
- If DoW CUI flows through your environment, Level 2 also applies on top of Level 1, not instead of it. Level 2 requires implementing all 110 security requirements from NIST SP 800-171 Rev 2 and either a self-assessment or independent C3PAO assessment every three years, as the contract specifies.
Defense contractors frequently hold both. A Level 2 assessment satisfies the Level 1 requirements within the same scope, but the scope itself isn’t guaranteed to match. Level 1 typically covers the whole business: contracting staff, executives, finance, and delivery teams alike. Level 2 is often certified against a narrower, purpose-built enclave. The two can be the same certification effort or two entirely different ones, and that distinction has to be decided before either assessment gets scheduled.
Level 3 builds on Level 2 with additional requirements from NIST SP 800-172. Level 3 is reserved for select contracts with sensitive technology-related CUI that need additional protection against Advanced Persistent Threat attacks. It applies to a narrower set of contracts than Level 1 or Level 2, but that doesn’t mean Level 1 and Level 2 cover the defense industrial base on their own. A meaningful share of DIB contractors, particularly those tied to national security programs, need Level 3. We’re covering it in its own piece soon. [Sign up for CMMC Now →]
Agile IT insight: The Level 2 requirement flows down to subcontractors when CUI flows to them, not automatically because the prime handles CUI. If CUI doesn’t reach the subcontractor’s environment as part of contract performance, Level 2 may not apply regardless of what the prime handles. Confirming whether CUI reaches your environment is the first question. Level 1 isn’t part of that question. It’s already answered the moment there’s a federal contract in place.
CMMC Level 1 explained
Level 1 (Basic Safeguarding of FCI) covers the basic safeguarding requirements specified in FAR 52.204‑21. Organizations must conduct an annual self-assessment, submit supporting evidence, and affirm compliance to the Supplier Performance Risk System (SPRS). Level 1 doesn’t require a C3PAO assessment, but self-assessment isn’t self-certifying from memory. The evidence still has to exist and hold up to review.
A System Security Plan (SSP) requires documentation for the assessment, not an optional add-on. If a reviewer (a contracting officer or an assessor) finds no SSP on record, the result is a “No Score”: the assessment doesn’t get completed, and the award tied to it goes with it.
Agile IT insight: The 15 controls need to be implemented, documented, and evidenced before the self-assessment begins, not assembled in response to it. Organizations that can’t produce an SSP when asked, have attested to compliance they can’t support, which is a different and more serious problem than not having assessed at all.
CMMC Level 2 explained
Level 2 (Broad Protection of CUI) applies to contractors that process, store, or transmit CUI. The implementation scope, evidence requirements, and assessment structure are fundamentally different from Level 1. Organizations must implement all 110 security requirements from NIST SP 800‑171 Rev 2 and either complete a self-assessment or undergo an independent C3PAO assessment every three years, as the contract specifies. Contractors must also develop and maintain a System Security Plan, a Plan of Action and Milestones, evidence of ongoing monitoring, and submit an annual attestation.
The CMMC program allows Plans of Action and Milestones (POA&Ms) in a narrow set of circumstances: only for requirements worth a single point in the scoring methodology, and only when the control itself is already implemented but the supporting documentation is incomplete. Where a POA&M is permitted, open items must close within 180 days; missing that window terminates the conditional status and requires a new assessment.
Agile IT insight: A common assumption is that migrating workloads to Microsoft GCC High automatically satisfies Level 2. In reality, the platform is only the foundation. “Lift-and-shift” migrations frequently require policy rebuilds, logging configuration, and evidence creation, because the environment migration addressed hosting, not control. Without documented decisions and proof of control operation, the environment won’t hold under C3PAO review.
Side-by-side comparison

The full comparison, including evidence expectations, identity controls, incident response, and a three-step decision flow, is available as a downloadable reference.
Download the full comparison →
Common misconceptions about CMMC levels
- “We can start with Level 1 and move up later.” Level 1 isn’t a starting tier. It’s required the moment you hold a DoW contract with FCI in it, whether or not Level 2 ever applies. Organizations that anticipate CUI often pursue Level 1 and Level 2 together, but the two aren’t automatically the same project: Level 1 typically covers the whole business, Level 2 is often scoped to a narrower enclave. Skipping that scoping decision, not the Level 1 work itself, is what creates rework.
- “Using GCC High means we’re Level 2 ready.” GCC High provides the right hosting environment, but it doesn’t implement controls for you. A large share of the 110 requirements are governance and process controls (personnel screening, training, incident response planning) that have nothing to do with which platform you’re on. Even the technical controls you configure inside GCC High still need supporting policy and evidence behind them. None of that comes preloaded with the tenant.
- “Level 2 is just Level 1 plus a few controls.” Level 2 requires a comprehensive security program covering 110 requirements across 14 control families: Broad Protection of CUI, not Basic Safeguarding of FCI with extra steps. It demands policies, processes, technical controls, and governance, not merely additional tools.
- “NIST SP 800‑171 Rev 2 compliance equals Level 2.” SP 800-171 forms the basis of Level 2, but CMMC requires that controls are implemented, documented in a System Security Plan, and evidenced. Missing that documentation produces a “No Score,” and critical requirements can’t sit on a POA&M beyond 180 days regardless.
Agile IT insight: These misconceptions often surface during early sales conversations. Correcting them before compliance activities begin prevents restarts. Contract language, data flow mapping, and level confirmation are the starting point, not controls.
How Microsoft environments differ by level
At a high level, the platform you use must align with the data you handle. Level 1 contractors can generally operate in Microsoft 365 Commercial, provided they implement the 15 basic practices required for Basic Safeguarding of FCI. Level 2 contractors typically require a GCC High or equivalent enclave built on a FedRAMP Moderate baseline, which provides the isolation and control enforcement capabilities required for Broad Protection of CUI. Moving workloads to GCC High is a major undertaking: licensing changes, data migration, identity reconfiguration, and tool availability must be planned and validated.
Agile IT insight: Level 1 contractors that migrate to GCC High unnecessarily increase cost without reducing risk. Level 2 contractors that stay on commercial tenants miss critical controls, audit logging retention being one of the first gaps to surface. The environment decision made early is the one that’s hardest to undo later.
How to tell which level you’re likely headed toward
- Examine your contracts for CUI. Solicitations should specify whether CUI is involved and which Level 2 protection method (self-assessment or C3PAO) is required. Level 1 applies when the contract contains a FAR 52-204-21 clause.
- Consider the data you handle. If you process drawings, specifications, or test results that the government marks as CUI, you will need Level 2. If you handle only administrative data (purchase orders or schedules) categorized as FCI, Level 1 may suffice on its own.
- Ask your prime contractor whether CUI will flow to you as part of contract performance. Flowdown clauses require Level 2 when CUI reaches the subcontractor’s environment, not automatically because the prime handles CUI. If CUI doesn’t reach your environment, Level 2 may not apply. If it does, the level follows.
- Engage a CMMC-registered practitioner early. An experienced advisor can help you interpret contract language, map data flows, and scope your environment correctly.
Agile IT insight: The CUI contractors hold is frequently underestimated. Engineering drawings, supplier specifications, and test data carry CUI designation even when contracts don’t state it explicitly. A data-mapping exercise early in the capture process is where that exposure surfaces, before it becomes a compliance gap.
What this means for planning and budgeting
Identifying the required level early is what makes an accurate timeline possible. Level 1 is significantly less resource-intensive than Level 2 in scope, timeline, and cost. Level 2 requires more time and investment: implementing 110 controls, migrating to an appropriate Microsoft environment, developing policies and evidence, and scheduling a C3PAO assessment. The timeline for Level 2 preparation depends on starting environment and scope clarity. Organizations migrating from commercial to GCC High while implementing 110 controls face a longer floor than those already operating in GCC High. Plan accordingly: environment, scope, and evidence work all have fixed minimums that effort alone can’t compress.
Agile IT insight: Level 2 projects stall when leadership underestimates the resource commitment. The cost isn’t just tools. It’s the people and processes behind incident response testing, change management, and evidence collection. The timeline starts when CUI is confirmed in scope, not when preparation formally begins.
Next steps for each type of contractor
If you’re likely Level 1
Level 1 applies as soon as a DoW contract with FCI is in place. That part isn’t in question. What needs confirming is whether CUI is also present, since that determines whether Level 2 applies on top of it. Contracts and data flows get reviewed for that reason, not to decide whether Level 1 itself is required.
From there, the 15 basic requirements from FAR 52.204-21 need to be implemented, documented, and evidenced, including a System Security Plan, to support the annual self-assessment and SPRS affirmation. Migrating to GCC High or building toward Level 2 controls without a contract requirement increases cost without reducing risk.
If contract language or data classification creates uncertainty about which level applies, a strategy session is where that gets resolved, before preparation begins in the wrong direction. Connect with us here for a strategy session
If you’re likely Level 2
Level 2 preparation starts with scope: where CUI resides, who accesses it, and how it flows across the environment. That boundary determines the environment requirements, the evidence standard, and the assessment timeline.
From there, all 110 NIST SP 800-171 Rev 2 requirements need to be evaluated against the current state, with gaps documented in a Plan of Action and Milestones, limited to the single-point requirements eligible for one. POA&M items must close within 180 days of conditional certification, and that clock starts at the assessment result, not at the gap analysis. Environment selection, scope definition, evidence structure, and control implementation all have fixed minimums that run in sequence.
Speak with our CMMC team to determine the right next step based on where you are: whether that’s a gap analysis, environment design, or pressure-testing what’s already in place.





