What the requirement actually says · 1.1
What the three levels are, and which applies
The level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.
For broader operational context, more information describes a related workforce-management workflow that remains separate from formal compliance evidence.
For an independent reference point, see CMMC resources and documentation.
The levels
Three levels, and most suppliers are at the second
The certification programme defines levels by the sensitivity of the information a contract involves and by how the supplier's compliance is verified.
Level 1 covers federal contract information and rests on a small set of basic safeguarding requirements, verified by annual self-assessment.
Level 2 covers controlled unclassified information and rests on the security requirements in the relevant NIST publication. Verification is by third-party assessment for most contracts and by self-assessment for a subset.
Level 3 covers the highest-priority programmes, adds requirements from a further NIST publication, and is assessed by the government rather than by a commercial body.
The level that applies to you is determined by the contract, not by your size or your preference.
Where it comes from
The requirement is not new; the verification is
The obligation to protect controlled unclassified information was already carried by a defence acquisition clause requiring compliance with the NIST requirements and self-attestation of that compliance.
What certification changed is the verification: from an assertion to an assessment, with eligibility for award attached.
This matters when somebody tells you the requirement arrived recently. In substance it did not. What arrived was somebody checking.
The defence acquisition regulation clause on safeguarding covered defense information, and the NIST publication on protecting controlled unclassified information in nonfederal systems. Both are published in full.
The distinction between the underlying obligation and its verification is visible in the dates of those two documents.
The controls
What the standard actually contains
Requirements grouped into families covering access control, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
They are written for an information system. Applying them to a machine tool is the work, and the entry on legacy equipment in the next part is about what that involves.
The gap
Self-assessment and reality
Suppliers have been self-attesting for years, and the scores submitted have on average been considerably more optimistic than what assessments subsequently found. That gap is the reason the programme exists.
It is not usually dishonesty. It is that a requirement reads as met when nobody has tried to produce the evidence for it, and producing evidence is where most of the effort turns out to be.
What to do first
Three things, in order
Read your contract. The clause names what applies. Suppliers frequently plan against a level their contracts do not require, in both directions.
Define the boundary. Which systems handle covered information. A narrower boundary is cheaper to assess and harder to defend; a wider one is the reverse. The entry on scoping treats this properly.
Find out what you can evidence. Not what you do: what you can show an assessor twelve months from now. The two are different and the difference is the project.
Not advice
What this page is not
It is a description of a published programme. Which level applies to your contracts, what your boundary should be, and whether any particular control is satisfied are questions for a qualified assessor with sight of your environment.
Where this site describes a requirement it names the document the requirement comes from, so that you can read the source rather than trusting a vendor's summary of it. That includes ours.
The subset
When the second level is self-assessed
Not every contract at the second level requires a third-party assessment. A subset is permitted to self-assess, and which contracts fall into it is determined by the acquiring agency rather than by the supplier.
The practical consequence is that a supplier can be at the second level and never see an assessor, and can also be at the second level and be assessed within the year. Planning on the first and receiving the second is the expensive version of this mistake.
Flow-down
The requirement travels down the chain
A prime contractor with an obligation passes it to subcontractors who handle the same information. A supplier three tiers down can therefore acquire a requirement from a contract it never read, communicated in a purchase order clause.
If you supply into defence at any depth, the question is not whether this applies to you but which of your customers will ask first, and asking them is better than waiting.
Common misreadings
Four things suppliers get wrong about the levels
That size determines the level. It does not. A twelve-person shop handling covered information is at the same level as a large prime handling the same information.
That a certificate covers the company. It covers a defined boundary. Work performed outside that boundary is not covered by it, which is why the scoping decision matters more than the technology decision.
That certification is permanent. It has a validity period and requires annual affirmation in between.
That preparing is mostly buying. The documentation, the boundary definition and the evidence collection are the bulk of the work, and no purchase removes them.
What good preparation looks like
Twelve months, roughly
A quarter establishing the boundary and the gap. A quarter implementing what is missing. A quarter producing evidence and running an internal check against the requirements. A quarter waiting for and undergoing an assessment, because assessor availability is a real constraint rather than a scheduling detail.
That shape is common and it is not a promise. Yours will differ with the state of your documentation and the size of your boundary, which is why this site declines to quote a duration before seeing an environment.
Where to read the source
Both documents are public
The programme documentation and the NIST publication behind it are published in full by the issuing bodies and are free. Anybody selling you a summary, including this page, is standing between you and a document you can read yourself.
Read the control families relevant to your environment before the first vendor conversation. It takes an afternoon and it changes what you are able to ask.
Also
Elsewhere in what the requirement actually says
- Reading the clause that binds youReading the clause that binds you. What the requirement says, what it means in practice, and what an assessor will ask.
- Which systems are in scopeWhich systems are in scope. What the requirement says, what it means in practice, and what an assessor will ask.
- Self-assessment, and why the scores driftedSelf-assessment, and why the scores drifted. What the requirement says, what it means in practice, and what an assessor will ask.
- Who assesses you, and how each kind worksWho assesses you, and how each kind works. What the requirement says, what it means in practice, and what an assessor will ask.
- What the standard does not requireWhat the standard does not require. What the requirement says, what it means in practice, and what an assessor will ask.
- Machines older than the requirementsA control written for a server, applied to a lathe with a shared login, a decade-old operating system and a USB port.
- Drawings, job packets and paperDrawings, job packets and paper. What the requirement says, what it means in practice, and what an assessor will ask.
- Removable media, and why bans failRemovable media, and why bans fail. What the requirement says, what it means in practice, and what an assessor will ask.
- Vendor remote accessVendor remote access. What the requirement says, what it means in practice, and what an assessor will ask.
- Technical data packages and what they containTechnical data packages and what they contain. What the requirement says, what it means in practice, and what an assessor will ask.
- Segmentation, and what it does not solveSegmentation, and what it does not solve. What the requirement says, what it means in practice, and what an assessor will ask.
- What insider risk actually coversWhat insider risk actually covers. What the requirement says, what it means in practice, and what an assessor will ask.
- What detection can and cannot establishWhat detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.
- Monitoring, and where the law constrains itMonitoring, and where the law constrains it. What the requirement says, what it means in practice, and what an assessor will ask.
- The fortnight around a departureThe fortnight around a departure. What the requirement says, what it means in practice, and what an assessor will ask.
- Privileged access, and who reviews itPrivileged access, and who reviews it. What the requirement says, what it means in practice, and what an assessor will ask.
- False positives, and what they costFalse positives, and what they cost. What the requirement says, what it means in practice, and what an assessor will ask.
- The documents an assessor reads firstThe documents an assessor reads first. What the requirement says, what it means in practice, and what an assessor will ask.
- What counts as evidenceWhat counts as evidence. What the requirement says, what it means in practice, and what an assessor will ask.
- The findings that recurThe findings that recur. What the requirement says, what it means in practice, and what an assessor will ask.
- Plans of action, and their limitsPlans of action, and their limits. What the requirement says, what it means in practice, and what an assessor will ask.
- What the assessment week is likeWhat the assessment week is like. What the requirement says, what it means in practice, and what an assessor will ask.
- The certificate, and what it coversThe certificate, and what it covers. What the requirement says, what it means in practice, and what an assessor will ask.