Fortinetics Book a call →
Menu
DEFENSE · CUI

CMMC Level 2 vs Level 3: who needs which, and what the jump actually costs

CMMC has three levels. Level 1 is basic FCI hygiene. The real distinction for CUI-handling contractors is Level 2 versus Level 3: 110 NIST 800-171 controls assessed by a C3PAO, versus that plus a subset of NIST 800-172 enhanced controls assessed by DIBCAC for the narrow set of programs facing advanced persistent threats. Note that the Phase 2 transition was suspended on July 13, 2026, so neither Level 2 (C3PAO) nor Level 3 (DIBCAC) can currently be designated on new DoD work — the levels below describe the framework as written, which is still what a prime's flowdown and any reformed successor will be built on.

The short answer

Most CUI-handling contractors need Level 2, not Level 3. Level 3 applies to a narrow set of programs where the adversary threat model justifies the enhanced 800-172 control set, and the contract tells you so. Do not pursue Level 3 on speculation; build Level 2 well. That advice is unchanged by the July 13, 2026 suspension — what the suspension changed is who signs off, not what has to be true.

CMMC Level 2

You handle Controlled Unclassified Information on standard DoD contracts. Level 2 — the 110 NIST 800-171 Rev 2 controls — is what the vast majority of the Defense Industrial Base needs. During the suspension it is designated as Level 2 (Self); as written the same requirements are C3PAO-assessed.

CMMC Level 3

Your contract explicitly requires Level 3 because the program faces advanced persistent threats. Level 3 adds selected NIST 800-172 enhancements on top of Level 2 and is assessed by DIBCAC, not a commercial C3PAO. No new Level 3 (DIBCAC) designations are being made during the suspension.

Side by side
CMMC Level 2 compared with CMMC Level 3 across 8 dimensions
Dimension CMMC Level 2 CMMC Level 3
Protects CMMC Level 2 Controlled Unclassified Information (CUI) CMMC Level 3 CUI against advanced persistent threats
Control basis CMMC Level 2 110 controls from NIST SP 800-171 Rev 2 CMMC Level 3 Level 2 + a subset of NIST SP 800-172 enhancements
Assessed by CMMC Level 2 C3PAO (commercial, Cyber AB-accredited) — self-assessment only during the suspension CMMC Level 3 DIBCAC (government — Defense Contract Management Agency) — not designated during the suspension
Who needs it CMMC Level 2 The ~76,600 entities DoD estimates will need a Level 2 certification assessment CMMC Level 3 Narrow set of programs with advanced-threat models
Passing bar CMMC Level 2 Perfect 110/110, narrow POA&M flexibility CMMC Level 3 Level 2 baseline + 800-172 enhancements met
Assessment cadence CMMC Level 2 Every three years, with an annual affirmation in SPRS in between (32 CFR 170.22) CMMC Level 3 Every three years, government-led by DIBCAC, plus the annual affirmation
Typical preparation CMMC Level 2 6-9 months from a sound IT baseline CMMC Level 3 Level 2 first, then the 800-172 enhancement delta
When it applies CMMC Level 2 DFARS 7021 flowdown with CUI CMMC Level 3 Contract explicitly designates Level 3

Scroll sideways for CMMC Level 3 →

Status: Phase 2 is suspended, and it does not change the answer

On July 13, 2026 the Department of War CIO suspended the November 2026 CMMC Phase 2 transition and held all pending CMMC implementation milestones in abeyance pending a 60-day review. During the suspension, program managers may designate only Level 1 (Self) or Level 2 (Self) — not Level 2 (C3PAO) and not Level 3 (DIBCAC) — and solicitations already carrying those requirements are directed to be amended to remove them.

So the practical answer to "Level 2 or Level 3?" on new DoD work today is neither, in the sense that no third-party or government CMMC assessment can be designated at all. What the comparison below is still for: the rule at 32 CFR Part 170 has not been rescinded, DFARS 252.204-7021 has not been removed, primes remain free to require whatever assurance they want in a subcontract, and the review is chartered to recommend a reformed framework rather than nothing. The technical difference between the two levels is what it was.

Full read: [CMMC Phase 2 is suspended](/insights/cmmc-phase-2-suspended/).

The honest answer: you probably need Level 2

The most useful thing we tell contractors asking "Level 2 or Level 3?" is that the question usually answers itself. Level 3 is not a tier you opt into for extra assurance. It applies to a narrow set of programs where the adversary threat model justifies the enhanced control set, and the contract designates it explicitly.

The vast majority need Level 2: the 110 NIST SP 800-171 Rev 2 controls across 14 families. DoD's own estimate in the CMMC final rule is that roughly 76,600 entities would require a Level 2 certification assessment, against 1,487 at Level 3. If your DFARS 252.204-7021 flowdown involves CUI and the contract does not specifically call for Level 3, Level 2 is your target.

Pursuing Level 3 on speculation is expensive and usually unnecessary. The right move is to build Level 2 to a genuine 110/110, which also positions you cleanly if a future contract does require Level 3.

What Level 3 actually adds

Level 3 is Level 2 plus a selected subset of NIST SP 800-172 controls. NIST 800-172 is the enhanced security requirements publication aimed at protecting CUI against advanced persistent threats. Its controls assume a sophisticated, well-resourced adversary rather than opportunistic compromise.

The 800-172 enhancements push into areas like enhanced monitoring and threat hunting, more rigorous access control and isolation, supply-chain protections against sophisticated tampering, and dual-authorization controls for high-impact actions. They are operationally heavier than the 800-171 baseline: more continuous, more analyst-driven, more architecturally demanding.

Level 3 is assessed by DIBCAC, the Defense Contract Management Agency's assessment center, not by a commercial C3PAO. This is a government-led assessment reserved for the programs that warrant it.

The path: Level 2 first, always

Even contractors who know they need Level 3 build Level 2 first. The 110 NIST 800-171 controls are the foundation; the 800-172 enhancements layer on top. There is no shortcut that skips the Level 2 baseline.

So the practical sequence for a Level 3-bound contractor is: design and implement the Level 2 program to a genuine 110/110, then scope the 800-172 enhancement delta as a second phase. For everyone else, which is the majority, Level 2 is the destination.

Our [realistic CMMC Level 2 timeline](/insights/cmmc-level-2-timeline-realistic/) covers what the Level 2 engagement looks like month by month, and the [CMMC self-assessment vs C3PAO](/insights/cmmc-self-assessment-vs-c3pao/) piece covers when third-party assessment is required.

Frequently asked

CMMC Level 2 vs Level 3 — common questions.

Do I need CMMC Level 2 or Level 3?
Almost certainly Level 2. Level 2 protects Controlled Unclassified Information with the 110 NIST 800-171 Rev 2 controls and is what the vast majority of CUI-handling defense contractors need. Level 3 adds NIST 800-172 enhancements for programs facing advanced persistent threats and is assessed by DIBCAC rather than a C3PAO. It applies only to a narrow set of programs, and the contract designates it explicitly. If your contract doesn't specifically require Level 3, you need Level 2. Note that CMMC Phase 2 was suspended on July 13, 2026: during the suspension program managers may designate only Level 1 (Self) or Level 2 (Self), so neither level is currently being required on new DoD work, though primes may still impose their own flowdown.
What is the difference between CMMC Level 2 and Level 3?
Level 2 is the 110 NIST SP 800-171 Rev 2 controls, assessed every three years with an annual affirmation in SPRS in between. As written, that assessment is performed by a commercial C3PAO; while the Phase 2 transition is suspended (since July 13, 2026) only self-assessment can be designated. Level 3 is Level 2 plus a selected subset of NIST SP 800-172 enhanced controls aimed at advanced persistent threats, assessed by DIBCAC (the government's Defense Contract Management Agency assessment center) and likewise not being designated during the suspension. Level 3 is operationally heavier and reserved for programs whose threat model justifies it.
Who assesses CMMC Level 3?
DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center, part of the Defense Contract Management Agency. This is a government-led assessment, unlike Level 2 which is assessed by commercial C3PAOs accredited by the Cyber AB. The DIBCAC assessment is reserved for the narrow set of CMMC Level 3 contracts and other DoD-designated programs.
Can I skip Level 2 and go straight to Level 3?
No. Level 3 is built on the Level 2 baseline: the 110 NIST 800-171 controls are the foundation, and the NIST 800-172 enhancements layer on top. Even contractors who know they need Level 3 implement Level 2 first to a genuine 110/110, then scope the 800-172 enhancement delta as a second phase. There is no path that skips the Level 2 foundation.
Is CMMC Level 3 worth pursuing for competitive advantage?
Generally no. Level 3 applies to specific programs whose contracts designate it, and the 800-172 enhancements carry real ongoing operational cost. It is not a marketing differentiator. Pursuing it speculatively means absorbing that cost without a contract requiring it. The better investment is building Level 2 to a genuine 110/110, which positions you cleanly if a Level 3 requirement ever arrives.
If this is a live decision
Not sure which fits your situation?

Book a scoping call.

Thirty minutes. We'll walk through your target, your current posture, and which path (or which combination) actually fits. If the answer is "neither yet," we'll say so.

Book a scoping call →