Skip to content

A Technology Innovation Partners Inc. company.

What CMMC Level Do You Actually Need?

August 7, 2026 · 7 min read · By Quantum Shield Secure

Compliance documentation for CMMC and NIST 800-171.

If your organization does business with the U.S. Department of Defense, the Cybersecurity Maturity Model Certification (CMMC) is moving from a talking point to a contract requirement. The good news: which level you need is usually determined by one thing — the kind of government information you handle.

The two levels most contractors face

CMMC has three levels, but the vast majority of contractors deal with the first two. Level 1 covers organizations that handle Federal Contract Information (FCI) — the non-public information you receive or generate under a contract. Level 2 covers organizations that handle Controlled Unclassified Information (CUI) — more sensitive information the government marks for protection. Level 3 is reserved for the highest-priority programs and a small number of contractors.

Start with one question: do you handle CUI?

The fastest way to find your level is to determine whether any contract requires you to store, process, or transmit CUI. If it does, you are almost certainly in Level 2 territory. If you only handle FCI, Level 1 likely applies. Your contracts and your contracting officer are the authoritative source — but knowing what to look for lets you plan before the requirement lands.

Where NIST 800-171 fits

People often treat CMMC and NIST 800-171 as competing acronyms. They are not. NIST 800-171 is the catalog of 110 security requirements for protecting CUI. CMMC Level 2 is the program that verifies you have actually implemented those 110 requirements. In other words, meeting NIST 800-171 is the work; CMMC Level 2 is the proof. If you prepare for one, you are preparing for the other.

What Level 1 preparation looks like

Level 1 maps to seventeen basic safeguarding practices — things like access control, boundary protection, and antivirus. For many organizations these are already partly in place. The effort is usually in documenting them and closing the handful of gaps, and Level 1 currently allows an annual self-assessment.

What Level 2 preparation looks like

Level 2 is a bigger lift. You will need a System Security Plan (SSP) that documents how you meet each of the 110 requirements, and a Plan of Action and Milestones (POA&M) for any you have not fully met yet. Depending on the contract, Level 2 may require a third-party assessment rather than a self-assessment, so the documentation and evidence have to hold up to outside review.

The practical path

Whatever your level, the sequence is the same. First, a gap assessment maps your current state against the requirements. Second, remediation closes the gaps, with quick wins separated from longer projects. Third, you produce the SSP, POA&M, and evidence that demonstrate compliance. Done well, this is not a fire drill — it is a few months of focused work that also makes your organization genuinely more secure.

Do not wait for the requirement to appear

The costliest way to approach CMMC is to discover it in a contract you are about to lose. Determining your likely level now, and starting the gap assessment early, turns a compliance scramble into a manageable project — and keeps you eligible for the contracts that matter.

« All Insights

Ready to Act on This?

Talk with our team about turning these ideas into a concrete plan for your organization.

Get Started