CMMC Assessment Checklist
Download our CMMC assessment checklist!
Quick answer: CMMC Level 2 applies to the vast majority of Department of Defense contractors handling Controlled Unclassified Information (CUI) and requires 110 security controls from NIST SP 800-171. CMMC Level 3 applies to roughly 1% of contractors working with highly sensitive CUI facing advanced persistent threats, adding 24 enhanced controls from NIST SP 800-172 for a total of 134. Level 2 certification is a mandatory prerequisite for Level 3.
Choosing the wrong CMMC path costs contractors real money and real time. Overshoot your requirement, and you're pouring resources into security operations centers and threat-hunting capabilities your contract never demanded. Undershoot it, and you risk losing contract eligibility altogether when a Defense Contract Management Agency (DCMA) assessment reveals the gap.
For contractors trying to map their obligations to the correct certification path, the distinction between CMMC Level 2 and CMMC Level 3 comes down to three factors: the type of information involved, the number of security controls required, and who conducts the assessment. Understanding each helps you determine where your organization falls before a solicitation forces the question.
CMMC Level 2, officially termed "Advanced," protects Controlled Unclassified Information and requires implementation of all 110 security requirements found in NIST SP 800-171 Revision 2. Most Department of Defense contractors that touch CUI will need CMMC Level 2, whether through self-attestation or a Certified Third-Party Assessment Organization (C3PAO) assessment, depending on what the contract specifies.
CMMC Level 3, officially termed "Expert," builds directly on top of Level 2. Contractors seeking CMMC Level 3 must meet all 110 NIST SP 800-171 requirements plus 24 additional enhanced requirements from NIST SP 800-172, bringing the total to 134 controls. According to the Department of Defense's own estimate published in the Federal Register, only about 1% of the Defense Industrial Base will require CMMC Level 3 certification.
Critically, CMMC Level 3 is not a standalone track. An organization must first hold a Final CMMC Level 2 (C3PAO) certification for the identical scope before it can even request a Level 3 assessment. You cannot pursue both levels simultaneously, and you cannot skip Level 2 to go straight to Level 3.
Your contract solicitation will tell you exactly which level applies. Contracting officers are required to state, "The CMMC level required by this solicitation is ___," filling in one of four options: Level 1 self-attestation, Level 2 self-attestation, Level 2 C3PAO assessment, or Level 3 assessment by the government.
CMMC Level 2 covers standard handling of CUI across the vast majority of defense contracts—research documents, technical drawings, and program-related data that require protection but don't rise to the level of national security risk if compromised through ordinary means.
CMMC Level 3 is reserved for three specific scenarios, according to the Department of Defense's January 2025 implementation memo:
The Department of Defense has explicitly cautioned program managers against overusing the CMMC Level 3 requirement, wanting to preserve it for cases where the added protection is genuinely warranted. That said, some agencies expect meaningful Level 3 volume. The Defense Logistics Agency, for instance, anticipates that 10% of its CMMC-requiring service contracts will call for Level 3.
The 24 additional controls required for CMMC Level 3 span 10 control families and target Advanced Persistent Threats (APTs)—the sophisticated, well-funded, and sustained attacks typically associated with nation-state actors. These enhancements include:
Choose CMMC Level 2 if your organization handles standard CUI without one of the three triggering scenarios above. Choose CMMC Level 3—or prepare to—if your contract explicitly names it, or if you're competing for programs involving emerging technology, aggregated CUI at scale, or infrastructure that other contractors depend on.
CMMC Level 3 also imposes stricter Organization-Defined Parameters (ODPs). At Level 2, organizations set their own values for things like login attempt limits, based on their risk tolerance. At Level 3, the Department of Defense specifies these values directly, removing that flexibility to ensure uniform security posture across every Level 3 contractor.
CMMC Level 2 assessments are conducted by a C3PAO, an independent organization certified to evaluate compliance. These assessments can involve spot-checking certain controls rather than exhaustively inspecting every system, and four asset categories are considered in scope, though Contractor Risk Managed Assets can avoid full assessment if properly documented in a System Security Plan.
CMMC Level 3 assessments are conducted directly by DIBCAC, the DCMA's Defense Industrial Base Cybersecurity Assessment Center—not by a third party. This is often called a "High Confidence Assessment" because DIBCAC examines systems in far greater depth than a typical C3PAO review. At Level 3, only three asset categories apply, because Contractor Risk Managed Assets are reclassified as CUI Assets and must be fully assessed against every Level 3 requirement.
Scoring also diverges. CMMC Level 2 uses a weighted Supplier Performance Risk System (SPRS) score, where controls are worth 1, 3, or 5 points, ranging from -203 to 110. CMMC Level 3 assigns equal weight to every control—1 point each, for a maximum of 24—leaving far less room for partial compliance.
Both levels allow conditional status through a Plan of Action and Milestones (POA&M) for certain unmet requirements, provided they aren't on the prohibited list. However, before any CMMC Level 3 assessment can even begin, all Level 2 POA&M items must be fully closed out with a perfect SPRS score of 110.
Start with the solicitation language itself—it will state the required level explicitly. From there, ask three questions: Does this contract involve CUI at all? If so, does it involve breakthrough technology, a large aggregation of CUI, or infrastructure other contractors rely on? And has DIBCAC or a program office specifically flagged Level 3 requirements for this work?
If the answer to the second and third questions is no, CMMC Level 2 is almost certainly your target. If either applies, begin planning for CMMC Level 3 now, since achieving Final Level 2 certification first, then scheduling a DIBCAC assessment, takes considerable time and cannot be shortcut.
Certification timelines don't bend for procurement deadlines. Contractors that wait until a solicitation names CMMC Level 3 to start preparing will find themselves locked out of bidding, since Level 2 certification alone can take months to achieve and Level 3 adds further preparation and assessment time on top of it.
Review your current and anticipated contracts against the criteria above, confirm which level applies to each, and start closing any gaps in your NIST SP 800-171 or NIST SP 800-172 controls well ahead of your next bid cycle.
Yes. A Final CMMC Level 2 (C3PAO) certification for the identical scope is mandatory before an organization can request a CMMC Level 3 assessment from DIBCAC. You cannot pursue both levels at once or skip directly to Level 3.
CMMC Level 3 is substantially more expensive. Beyond the cost of the prerequisite Level 2 C3PAO certification, the Department of Defense estimates Level 3 nonrecurring engineering costs alone at roughly $2.7 million for small entities and $21.1 million for large entities, plus ongoing recurring and assessment costs.
CMMC Level 2 covers standard Controlled Unclassified Information (CUI). CMMC Level 3 applies when that CUI involves breakthrough technology, is aggregated in large volumes within a single system, or resides on infrastructure that other Defense Industrial Base contractors rely on.
CMMC Level 2 is assessed by a Certified Third-Party Assessment Organization (C3PAO). CMMC Level 3 is assessed directly by the DCMA's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a government body, in what's known as a High Confidence Assessment.
The Department of Defense estimates that only about 1% of the Defense Industrial Base will require CMMC Level 3 certification, reserving it for contracts involving the most sensitive technology and information.