CMMC Level 2 (Advanced)
The mid-tier CMMC level requiring all 110 NIST SP 800-171 controls. Third-party (C3PAO) assessment at this level was suspended as an award condition in July 2026 pending review; Level 2 self-assessment remains in force.
Related Terms
CMMC
A DoD framework requiring defense contractors to meet specific cybersecurity standards before handling federal contract information.
CUI
Government-created or -owned information that requires safeguarding controls per law, regulation, or government-wide policy, but is not classified.
NIST SP 800-171
The NIST standard for protecting CUI in non-federal systems. Revision 2 — the revision DoD assesses — specifies 110 security requirements and forms the basis of CMMC Level 2 and DFARS 252.204-7012 compliance.
C3PAO
An organization authorized by the CMMC Accreditation Body (the Cyber AB) to conduct CMMC Level 2 assessments of defense contractors. Third-party assessment as a condition of award was suspended on July 13, 2026 pending review, so a C3PAO assessment is not currently required to be eligible for a contract.
CMMC Level 1 (Foundational)
The basic CMMC tier requiring the 15 safeguarding requirements at FAR 52.204-21(b)(1)(i)-(xv) for protecting Federal Contract Information (32 CFR 170.14(c)(2)). Allows annual self-assessment.
Related Guides
Check Your CMMC Readiness
Run our free compliance tools to see where your organization stands.
Audit Your Tech Stack FreeTurn this gap analysis into a remediation plan
This CMMC Level 2 (Advanced) explainer is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.
Book a 25-min assessmentRelated: how much CMMC certification costs — DoD’s own priced figures