CMMC Levels Explained: 3 Tiers, Requirements & Assessments

What Is the CMMC Model?

The Cybersecurity Maturity Model Certification (CMMC) is a framework established by the U.S. Department of Defense (DoD) to enhance the protection of sensitive unclassified information within the Defense Industrial Base (DIB). The model introduces a set of cybersecurity standards that contractors and subcontractors must meet to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

The CMMC framework features three cumulative compliance levels: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). Each tier aligns security controls with the sensitivity of the defense information handled by a contractor.

Level 1: Foundational:

  • Data protected: Federal Contract Information (FCI) only.
  • Requirements: 15 basic cyber hygiene practices based on FAR clause 52.204-21.
  • Assessment type: Annual self-assessment and yearly affirmation submitted via the Supplier Performance Risk System (SPRS).

Level 2: Advanced:

  • Data protected: Controlled Unclassified Information (CUI).
  • Requirements: 110 security controls specified in NIST SP 800-171 Rev. 2.
  • Assessment type: Triennial third-party assessment by a C3PAO for critical programs, or an annual self-assessment for select lower-risk contracts.

Level 3: Expert:

  • Data protected: Highly sensitive CUI for critical national security programs.
  • Requirements: 110 practices from Level 2 plus an enhanced subset of requirements from NIST SP 800-172.
  • Assessment type: Triennial government-led assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

This is part of a series of articles about cyber risk management.

In this article:

Understanding the CMMC Levels

CMMC Level 1: Foundational

CMMC Level 1 is the entry point of the model, focusing on basic safeguarding of Federal Contract Information (FCI). The requirements align with FAR 52.204-21 and consist of 17 cybersecurity practices. These practices include measures such as limiting physical access, updating antivirus software, and enforcing secure password policies. The intent is to establish basic cyber hygiene that protects FCI from common threats.

Organizations seeking Level 1 certification are typically required to perform annual self-assessments and attest to the implementation of these practices. At this level, there is no requirement for extensive documentation or process maturity. The emphasis is on consistent execution of straightforward security activities that form the baseline for further cybersecurity improvements.

CMMC Level 2: Advanced

CMMC Level 2 increases requirements and targets organizations that handle Controlled Unclassified Information (CUI). At this level, organizations must comply with all 17 Level 1 practices and implement an additional 93 practices, many of which align with NIST SP 800-171. The focus shifts from basic cyber hygiene to protecting CUI against more sophisticated threats, such as advanced persistent threats (APTs).

Unlike Level 1, Level 2 requires organizations to document their practices and processes, demonstrating that security controls are institutionalized and repeatable. Third-party assessments are required to achieve certification, providing independent validation that the controls are implemented and maintained. This level marks a transition from foundational security to a managed approach to cybersecurity.

CMMC Level 3: Expert

CMMC Level 3 is the highest tier, reserved for organizations with critical roles in the defense supply chain. This level builds on the requirements of Levels 1 and 2 by adding 35 more practices, for a total of 128. The additional controls counter advanced persistent threats and draw from NIST SP 800-172.

To achieve Level 3 certification, organizations must demonstrate implementation of all required practices and advanced process maturity. This includes continuous monitoring, proactive threat hunting, and the ability to respond to emerging threats. Assessments at this level are conducted by government-led teams, reflecting the risk and sensitivity associated with Level 3 environments.

CMMC Level 1 Requirements

CMMC Level 1 requirements are based on the 17 security requirements defined in FAR 52.204-21. These controls focus on basic cybersecurity practices that help protect Federal Contract Information (FCI) from unauthorized access and disclosure. The requirements cover areas such as access control, identification and authentication, media protection, physical security, system integrity, and limiting access to authorized users and devices.

Examples of Level 1 controls include:

  • Restricting system access to authorized users
  • Verifying user identities before granting access
  • Protecting devices that store FCI
  • Regularly updating antivirus software

Organizations are also expected to protect information during transmission, dispose of media securely, and monitor systems for signs of compromise. These practices establish a security baseline that reduces exposure to common cyber threats.

Organizations must implement each required practice and perform annual self-assessments to confirm compliance. They must also provide an annual affirmation that the controls remain in place. Although formal process documentation is limited at this level, organizations still need evidence that the practices are consistently applied during normal operations. Maintaining records of implemented controls, employee training, and system configurations can help demonstrate compliance during reviews.

CMMC Level 2 Requirements

CMMC Level 2 requirements align with the 110 security requirements in NIST SP 800-171 Rev. 2. These controls are intended to protect Controlled Unclassified Information (CUI) and cover 14 security domains, including access control, audit and accountability, configuration management, incident response, risk assessment, security awareness, and system and communications protection.

Compared to Level 1, Level 2 requires a more structured and risk-based approach to cybersecurity. Organizations must implement technical, administrative, and operational controls that protect CUI throughout its lifecycle. This often includes:

  • Enforcing multi-factor authentication
  • Encrypting sensitive information
  • Managing vulnerabilities through regular patching
  • Maintaining audit logs
  • Establishing formal incident response and recovery procedures

In addition to implementing the required controls, organizations must maintain supporting documentation such as a system security plan (SSP) and plans of action and milestones (POA&M), where permitted. Most organizations handling CUI must successfully complete an assessment by a Certified Third-Party Assessment Organization (C3PAO), while a limited number of lower-risk contracts may allow annual self-assessments when specified by the DoD. Because Level 2 assessments evaluate both technical controls and supporting evidence, organizations often spend significant time preparing documentation, validating configurations, and addressing security gaps before the assessment.

CMMC Level 3 Requirements

CMMC Level 3 builds on all Level 2 requirements by adding selected security requirements from NIST SP 800-172. These additional controls strengthen an organization’s ability to detect, resist, and recover from advanced persistent threats. The requirements emphasize enhanced monitoring, threat-informed security operations, stronger access protections, and improved incident response capabilities.

At this level, organizations are expected to operate a mature cybersecurity program that goes beyond implementing security controls. They must:

  • Demonstrate the ability to identify sophisticated attack techniques
  • Continuously monitor critical systems
  • Respond to evolving threats

Security operations become more proactive, with greater emphasis on analyzing attacker behavior, protecting high-value assets, and minimizing the impact of potential breaches. Organizations pursuing Level 3 must first achieve Level 2 certification before undergoing a government-led assessment for the additional Level 3 requirements.

Maintaining compliance requires continuous operation of security controls, regular reviews of the cybersecurity program, and the ability to demonstrate that defensive measures are effective against evolving threats. Since Level 3 is intended for organizations supporting sensitive defense programs, ongoing security improvement and operational resilience are required to meet certification requirements.

How Do You Determine Which CMMC Level You Need?

1. Identify Whether You Handle FCI or CUI

The first step in determining your required CMMC level is to classify the data you process. Federal Contract Information (FCI) refers to information provided by or generated for the government under contract that is not intended for public release. Controlled Unclassified Information (CUI) refers to sensitive information that requires safeguarding under federal laws and regulations. Handling CUI typically triggers the need for a higher CMMC level.

Review your contracts, workflows, and data repositories to identify whether you handle FCI, CUI, or both. If your organization only processes FCI, Level 1 certification is usually sufficient. However, if you access, store, or transmit CUI, you will need to meet the requirements of Level 2 or, in rare cases, Level 3. Accurate classification at this stage prevents unnecessary compliance burdens and ensures alignment with DoD expectations.

2. Review the Solicitation and Contract Requirements

Solicitation documents and contract language specify the CMMC level required for a given project or engagement. These documents often outline the types of information you will handle and the expected security posture. Carefully reviewing these requirements helps avoid misunderstandings and ensures your organization is prepared for the appropriate level of assessment and certification.

Failure to align with contractual requirements can result in disqualification from bidding or termination of existing contracts. Engage with your contracting officer or legal team to clarify ambiguities in the solicitation. Early identification of CMMC requirements in the contract lifecycle allows for planning, budgeting, and timely implementation of required security controls, reducing the risk of noncompliance.

3. Determine Your Role in the Supply Chain

Your position within the Defense Industrial Base (DIB) also affects the CMMC level you need. Prime contractors are responsible for meeting the certification requirements specified in their contracts, but subcontractors must also comply if they receive or process FCI or CUI as part of their work. The required level depends on the information that flows to your organization, not simply your status as a prime or subcontractor.

Map the flow of contract information between your organization, customers, and suppliers to determine where FCI and CUI are stored, processed, or transmitted. If your organization never receives CUI, a lower certification level may be appropriate. However, if CUI is shared with your systems or personnel, you must meet the CMMC requirements associated with that information before performing the work.

4. Define the CMMC Assessment Scope

After identifying the required certification level, define the scope of the assessment by determining which systems, users, applications, and locations handle FCI or CUI. A clearly defined scope helps ensure that relevant assets are protected while avoiding the cost and complexity of including systems unrelated to the contract.

Document the boundaries of the CMMC environment and identify connections to external systems or service providers. Many organizations reduce the assessment scope by isolating CUI into dedicated environments and limiting access to authorized personnel. Before the assessment, validate that in-scope assets, documentation, and security controls are complete and accurately reflect the environment to be evaluated.

Best Practices for Meeting Your Required CMMC Level

Organizations should consider the following best practices to ensure they meet their CMMC requirements.

1. Minimize the Systems That Handle FCI and CUI

Reducing the number of systems that store, process, or transmit FCI and CUI makes the CMMC environment easier to secure and assess. A smaller scope means fewer devices, applications, and users require security controls.

Review business processes to identify where sensitive information is used and eliminate unnecessary copies or transfers. Segment networks, use dedicated systems for sensitive workloads where practical, and restrict access to employees who need it. Limiting the spread of FCI and CUI reduces the attack surface and the effort required during assessments.

Key actions:

  • Isolate FCI and CUI in dedicated systems where practical.
  • Restrict access to authorized users only.
  • Eliminate unnecessary copies and data transfers.
  • Segment networks to reduce the assessment scope.

2. Maintain an Accurate Inventory of Executed Software

Keeping an up-to-date inventory of software helps organizations understand what is running in their environment and identify unauthorized or outdated applications. Without accurate visibility, it is difficult to manage vulnerabilities, investigate incidents, or demonstrate that only approved software is in use.

Maintain a centralized inventory that includes operating systems, installed applications, versions, publishers, and the systems where they are deployed. Regularly compare the inventory against approved software lists and remove applications that are no longer needed. Continuous inventory management also supports patch management and vulnerability remediation required by higher CMMC levels.

Key actions:

  • Maintain a centralized inventory of approved software.
  • Identify and remove unauthorized or outdated applications.
  • Track software versions, publishers, and installation locations.
  • Review the inventory regularly to keep it current.

Related content: Read our guide to browser hijacking

3. Apply Granular Application Control Policies

Application control limits which programs can run on organizational systems, reducing the risk of malware, ransomware, and unauthorized software. Instead of relying only on antivirus tools, organizations can allow trusted applications while preventing unknown or unapproved executables from running.

Define application control policies based on trusted publishers, digital signatures, file paths, or cryptographic hashes, depending on operational requirements. Review exceptions regularly and test policy changes before broad deployment to avoid disrupting business applications. Well-managed application control adds a layer of defense against common attack techniques.

Key actions:

  • Allow only approved applications to execute.
  • Create policies based on trusted publishers, signatures, or hashes.
  • Review and remove outdated policy exceptions.
  • Test policy changes before broad deployment.

4. Restrict Unauthorized Scripts and Executable Content

Attackers often use scripts, macros, and command-line tools to execute malicious code after gaining initial access. Restricting these technologies reduces opportunities for attackers to move laterally, establish persistence, or execute payloads within the environment.

Limit script execution to approved administrators and trusted automation tools, and disable unnecessary scripting features where possible. Apply controls to PowerShell, Windows Script Host, macros, and similar technologies, and monitor attempts to execute blocked content.

Key actions:

  • Limit script execution to approved administrators and tools.
  • Disable unnecessary scripting features and macros.
  • Block unapproved executable content by default.
  • Monitor and investigate blocked execution attempts.

Related content: Read our guide to ransomware protection

5. Collect Evidence Continuously

Preparing for a CMMC assessment is easier when evidence is collected throughout the year instead of immediately before the assessment. Continuous evidence collection demonstrates that security controls operate consistently rather than only during a short preparation period.

Maintain records such as security policies, training logs, system configurations, vulnerability scans, patch reports, access reviews, and audit logs in a centralized repository. Regularly review this evidence for completeness and accuracy so that documentation remains aligned with the current environment. Continuous evidence collection helps organizations identify compliance gaps early and address them before formal assessments.

Key actions:

  • Store compliance evidence in a centralized repository.
  • Collect audit logs, scan results, and configuration records regularly.
  • Review evidence periodically for completeness and accuracy.
  • Address documentation and control gaps before assessments.

Meeting CMMC Requirements with Airlock Digital

The Cybersecurity Maturity Model Certification (CMMC) is a critical framework for organizations working with the U.S. Department of Defense (DoD), requiring stringent cybersecurity controls to protect controlled unclassified information (CUI) and Federal Contract Information (FCI). Airlock Digital provides precision application control that addresses key requirements across CMMC's practices and capabilities, supporting compliance while reducing risk to sensitive systems.

Key capabilities of Airlock Digital:

  • Deny by Default application control: Airlock Digital implements a Deny by Default, allow-by-exception model in which only trusted applications and files are permitted to run, ensuring systems maintain their baseline configuration and operate with only essential software.
  • Configuration Management support: Enforcement of application allowlists prevents the execution of unapproved or unnecessary programs and maintains a consistent application baseline, supporting CM.L2-3.4.1 (establish and maintain baseline configurations), CM.L2-3.4.6 (least functionality), and CM.L2-3.4.7 (restrict or prevent the use of nonessential programs).
  • Malicious code protection: By allowing only trusted and approved files to execute, Airlock Digital blocks malicious code including ransomware, zero-day malware, and fileless attacks, supporting System and Information Integrity requirements such as SI.L2-3.14.1, SI.L2-3.14.2, SI.L2-3.14.4, and SI.L2-3.14.5.
  • Audit and accountability logging: Centralized logging of all file executions and execution attempts on endpoints supports AU.L2-3.3.1, which requires creating and retaining audit records to enable monitoring, analysis, investigation, and reporting of unauthorized system activity.
  • Endpoint integrity: Endpoints are kept in a known good state by preventing all untrusted applications, scripts, and processes from running.
  • File execution visibility: Visibility into endpoint execution and execution attempts helps teams address issues and support investigations.
  • Operational resilience: Protection extends to critical IT and OT systems, helping ensure uninterrupted service delivery.

Learn more about how Airlock Digital supports CMMC compliance