Do I Need CMMC? (And Which Level?)

The answer comes down to one thing: the kind of government data you touch — FCI or CUI.
Update — July 13, 2026: CMMC Phase 2 was suspended (the third-party certification rollout that had been set for Nov 10, 2026 is paused). This doesn't change whether you need CMMC: if your contract carries the clause, your Phase 1 self-assessment, SPRS score, and annual affirmations still apply. What the suspension actually means →

One fact decides everything downstream: the kind of government data you handle. FCI puts you at Level 1; CUI puts you at Level 2. Get this right before you spend a dollar — contractors routinely under-call CUI as "just FCI" and get caught short.

Before you spend a dime or a weekend on CMMC, answer one question: what kind of government information do you actually handle? That single fact decides whether CMMC applies to you and, if it does, which level you have to meet. Almost everything else is downstream of it.

The 30-second answer

Start here: does a contract put CUI in your hands? — controlled technical data, specs, ITAR/export-controlled, or anything with CUI markings.
Yes → Level 2The 110 NIST SP 800-171 controls, an SSP, and a SPRS score — by self-assessment or C3PAO certification.
No → keep goingNo CUI in play. Check the lower bar next.
Do you handle FCI? — non-public contract information like statements of work, schedules, or internal correspondence.
Yes → Level 1The 15 basic safeguards in FAR 52.204-21, confirmed by an annual self-assessment.
No → likely exemptNo FCI and no CUI means CMMC generally doesn't apply. COTS-only contracts are excluded — but most DoW vendors hold at least FCI.
What you handleCMMC levelHow it's assessed
Neither FCI nor CUINone*CMMC generally doesn't apply
FCI onlyLevel 1Annual self-assessment
CUILevel 2Self-assessment or C3PAO certification
CUI on the most sensitive programsLevel 3Government-led (DIBCAC)

*Contracts solely for commercial off-the-shelf (COTS) items are generally excluded — but most DoW vendors handle at least FCI.

FCI vs CUI — the distinction that sets your level

CMMC has three levels, but for most small contractors the real fork is just two: Level 1 or Level 2. Which one you land on is decided by whether you hold FCI, CUI, or both.

Level 1

FCI

  • Federal Contract Information — non-public contract info not meant for release
  • 15 basic safeguards (FAR 52.204-21)
  • Annual self-assessment
  • No third party, no 110 controls
Level 2

CUI

  • Controlled Unclassified Information — a government-defined protection category
  • 110 controls (NIST SP 800-171)
  • SSP + SPRS score; self-assessment or C3PAO
  • Where most of the work and cost live

FCI — Federal Contract Information

FCI is information provided by or generated for the government under a contract that isn't meant for public release — think a non-public statement of work, delivery schedules, or internal contract correspondence. If FCI is the most sensitive thing you touch, you're at Level 1: the 15 basic safeguarding requirements in FAR 52.204-21, confirmed by an annual self-assessment.

CUI — Controlled Unclassified Information

CUI is information the government specifically requires you to protect under a defined category — technical drawings and specifications, controlled technical information, ITAR/export-controlled data, and similar. The moment a contract puts CUI in your hands, you step up to Level 2: the 110 controls of NIST SP 800-171, documented in an SSP and scored in SPRS. (CMMC currently assesses against Revision 2 of 800-171.)

Rule of thumb: FCI → Level 1, CUI → Level 2. The hard part isn't the rule — it's correctly identifying which kind of data you actually have. Contractors routinely under-call CUI as "just FCI" and get caught short.

Which level applies to you

Level 1 (FCI)

Small footprint, basic cyber hygiene, annual self-assessment, and an affirmation in SPRS. No third party, no 110 controls — but it's still a real requirement, not a checkbox.

Level 2 (CUI)

The 110 NIST 800-171 controls. Some lower-risk CUI contracts permit a self-assessment; many will require a C3PAO certification as the rollout proceeds. This is where most of the work — and cost — lives.

Level 3

Reserved for the most sensitive programs. It builds on Level 2 with a subset of NIST SP 800-172 enhancements and is assessed by the government (DIBCAC). Most small contractors will never touch Level 3.

"I'm just a subcontractor / I don't touch CUI"

CMMC flows down. If a prime sends you CUI to do the work, you generally inherit the same Level 2 obligation they have for that data — your tier in the supply chain doesn't lower the bar. The flip side is just as important: if your prime only ever sends you FCI, you're at Level 1, not Level 2, even on a big program. What you receive sets your level, not how large the contract is.

Think you're Level 2? See where you stand — free

If CUI is in play, the next step is a self-assessment against the 110 controls. Our free calculator gives you a SPRS score and shows exactly which gaps cost you the most — no signup.

Calculate your SPRS score free →

How to confirm what you actually handle

Do I need CMMC — frequently asked

Do I need CMMC if I'm a subcontractor?

Yes, if FCI or CUI flows down to you. If a prime sends you CUI, you generally carry the same Level 2 obligation for that data. If you only receive FCI, Level 1 applies. The data you receive sets your level — not your tier.

What's the difference between FCI and CUI?

FCI is non-public contract information and maps to Level 1 (15 FAR safeguards). CUI is information in a government-defined protection category and maps to Level 2 (110 NIST 800-171 controls).

How do I know if I handle CUI?

Look for DFARS 252.204-7012 in your contract, CUI markings on documents and CDRLs, and controlled technical data from the prime. When unsure, ask your contracting officer in writing.

Does every defense contractor need CMMC?

Effectively any contractor handling FCI or CUI on DoW work falls under Level 1 or Level 2. COTS-only contracts are generally excluded, but most DoW vendors handle at least FCI.

Next step

If you've confirmed you handle CUI, you're a Level 2 shop — start by finding out where you stand. Calculate your SPRS score, then turn the gaps into a documented plan with the free SSP generator. Still not sure on cost? See how much CMMC actually costs, and what's changing at CMMC Phase 2 on November 10, 2026.

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.