CMMC Model β€” Official DoD FAQ

How Will My Organization Know What CMMC Level Is Required for a Contract?

πŸ’Ό
Unsure which CMMC level applies to your contracts? Jun Cyber can help you determine your requirements.
Schedule Free Consultation
Source Source: DoD CIO CMMC FAQs v5 (B-Q1)

Once CMMC is implemented contractually, the Department will specify the required CMMC level in the solicitation and the resulting contract.

Understanding CMMC Level Requirements

The CMMC level required for your organization is determined by the type of information you handle under the contract, not by your organization's size or preference.

How Levels Are Determined

  • Level 1: Includes 15 security requirements from FAR 52.204-21 and requires an annual self-assessment and annual affirmation. It applies to the protection of FCI.
  • Level 2: Includes 110 security requirements from NIST SP 800-171 Revision 2. Depending on the solicitation or contract, it requires either a Level 2 self-assessment or a certification assessment by an authorized or accredited C3PAO. Assessments are generally valid for three years, with an annual affirmation of continuous compliance.
  • Level 3: Builds upon the 110 Level 2 requirements and adds 24 selected enhanced security requirements from NIST SP 800-172. It requires a government assessment performed by DCMA DIBCAC and an annual affirmation.

Where to Find This Information

The required CMMC level will be explicitly stated in:

  • The solicitation (RFP/RFI)
  • The resulting contract (Section H or similar)
  • DFARS clause 252.204-7021

If you're unsure what level your current contracts require, review the DFARS clauses in your existing contracts. If they include 252.204-7012 and you handle CUI, you'll likely need CMMC Level 2. If you only handle FCI under FAR 52.204-21, Level 1 applies.

Pro tip: Don't guess β€” ask your Contracting Officer for clarification on the specific CMMC requirements for your contract.

Have More Questions?

ChatCMMC can answer detailed questions about CMMC compliance, NIST 800-171, assessment preparation, and more β€” with source citations when available from selected official DoD and NIST sources.

Ask ChatCMMC β†’

CMMC Readiness Assessment

Find out where your organization stands and what steps you need to take. Jun Cyber's CMMC experts can help you interpret the requirements.

By submitting, you agree to be contacted by Jun Cyber. No spam, ever.

You Might Also Want to Know

Ready to Start Your CMMC Journey?

Jun Cyber helps defense contractors prepare for applicable CMMC requirements. From scoping and gap assessments to documentation, remediation, and C3PAO assessment readiness β€” Jun Cyber provides hands-on compliance support.

πŸ“… Schedule a Consultation Learn About CMMC Select β†’