two clipboards with Level 1 and Level 2 heading on each one respectively.

For Department of Defense (DoD) contractors, the Cybersecurity Maturity Model Certification (CMMC) 2.0 is no longer a distant requirement. It is a fundamental shift in how the defense industrial base (DIB) secures sensitive information. Understanding which level your organization must achieve is the first step toward maintaining your eligibility for federal contracts.

The distinction between Level 1 and Level 2 hinges entirely on the type of data your company handles. If you miscalculate your requirements, you risk either over-investing in unnecessary security measures or, more dangerously, failing to meet mandatory compliance standards. This guide will help you navigate the nuances between Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

What is Federal Contract Information (FCI)?

To determine your CMMC level, you must first identify if you handle Federal Contract Information (FCI). The government defines FCI as information provided by or generated for the government under a contract to develop or deliver a product or service. This data is not intended for public release but does not reach the level of sensitivity required for higher-tier protections.

FCI typically includes basic contract details, performance reports, and organizational communications that are not publicly available. If your organization only handles this level of data, you fall under CMMC Level 1. This level focuses on “foundational” cybersecurity and is designed to protect the broad ecosystem of small businesses working with the DoD.

Level 1 requirements align with the basic safeguarding requirements specified in FAR Clause 52.204-21. These 15 (often cited as 17) security practices include fundamental tasks like using antivirus software, managing passwords, and limiting physical access to your systems. For most small contractors, these are standard business practices that ensure a baseline of digital hygiene.

a representation of classified information on monitor screen

What is Controlled Unclassified Information (CUI)?

Controlled Unclassified Information (CUI) is significantly more sensitive than FCI and requires more rigorous protection. CUI is defined as information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.

Common examples of CUI include technical drawings, blueprints, proprietary research, and sensitive financial data related to defense programs. If your contract involves the handling, storage, or transmission of CUI, you are legally required to meet CMMC Level 2. This tier is classified as “Advanced” and is intended to protect information that, if compromised, could pose a threat to national security.

Level 2 is far more complex than Level 1 because it requires the implementation of all 110 security controls outlined in NIST SP 800-171. These controls cover 14 distinct domains, ranging from access control and incident response to system and communications protection. Transitioning from Level 1 to Level 2 is a major undertaking that requires significant documentation and technical investment.

How do the security requirements differ between levels?

The jump from Level 1 to Level 2 is not just a slight increase in security; it is a comprehensive overhaul of your cybersecurity posture. While Level 1 focuses on 15 basic practices, Level 2 requires 110 advanced practices. This represents a nearly seven-fold increase in the number of security requirements your organization must satisfy.

  1. Access Control: Level 1 requires basic identification and authentication, while Level 2 demands multi-factor authentication (MFA) and granular permission management.
  2. Incident Response: Level 1 has no specific requirement for incident response, but Level 2 requires a formal plan to detect, analyze, and report breaches.
  3. System Integrity: Level 2 necessitates advanced monitoring to detect malicious code and unauthorized changes, whereas Level 1 covers basic antivirus protection.
  4. Configuration Management: Level 2 requires you to establish and maintain baseline configurations for all IT products, a requirement entirely absent from Level 1.

Furthermore, Level 2 requires the creation of a System Security Plan (SSP) and a Plan of Action and Milestones (POAM). These documents serve as your roadmap for compliance, detailing exactly how each control is met or when it will be addressed. Without an SSP, a Level 2 contractor cannot demonstrate compliance to the DoD or its primary contractors.

Does Level 2 require a third-party assessment?

One of the most critical differences between the two tiers is how compliance is verified. For CMMC Level 1, contractors are generally allowed to perform an annual self-assessment. A high-ranking official within the company must sign off on the assessment, certifying that the organization meets the 15 basic practices.

black and white motorola solutions logoHowever, CMMC Level 2 introduces a split in assessment requirements based on the “criticality” of the information handled. While some Level 2 contractors may still perform self-assessments, the vast majority of companies handling CUI will require a third-party assessment. These assessments must be conducted by a Certified Third-Party Assessment Organization (C3PAO).

Lunarline, a subsidiary of Motorola Solutions, is a leading C3PAO that specializes in these rigorous evaluations. Engaging with a C3PAO like Lunarline ensures that your security controls are verified by experts who understand the complexities of NIST SP 800-171. For many contractors, passing a C3PAO assessment is the final hurdle before they can bid on high-value DoD projects.

Why is identifying your data type the first step?

You cannot build an effective compliance strategy until you know exactly what data flows through your network. Many contractors mistakenly assume they handle CUI when they only handle FCI, leading to thousands of dollars in wasted compliance costs. Conversely, failing to recognize CUI on your systems can lead to immediate contract termination and legal liability.

Start by reviewing your current and prospective contracts for specific clauses. Look for DFARS 252.204-7012, which indicates the presence of CUI and the requirement for NIST SP 800-171 compliance. If you only see FAR 52.204-21, you are likely in the Level 1 category, focusing only on FCI.

It is also vital to communicate with your Prime contractor if you are a subcontractor. Primes are responsible for flowing down the appropriate requirements to their supply chain. They can provide clarity on whether the data they are sharing with you is categorized as CUI or if it has been de-identified to the level of FCI.

What are the costs associated with Level 2?

cable organization outside of server-related hardware/infrastructureAchieving CMMC Level 2 is a significant financial commitment, particularly for small to medium-sized businesses. The costs include not only the technical implementation of hardware and software but also the administrative burden of documentation. You must account for the time spent by staff to create policies, procedures, and evidence artifacts for every one of the 110 controls.

  1. Gap Analysis: Most organizations begin with a gap analysis to identify where their current security falls short of Level 2 standards.
  2. Remediation: This involves purchasing new technology, such as encrypted cloud storage or advanced firewalls, to close identified gaps.
  3. Assessment Fees: If a C3PAO assessment is required, your organization must pay for the time and expertise of the assessment team.
  4. Ongoing Maintenance: Compliance is not a one-time event; Level 2 requires continuous monitoring and triennial assessments to maintain certification.

While these costs are high, they should be viewed as an investment in your company’s future. The DoD is increasingly making CMMC certification a “go/no-go” criterion for contract awards. Being “Level 2 Ready” positions your company as a trusted partner in the defense industrial base, capable of handling the nation’s most sensitive technical data.

How can Lunarline help you achieve compliance?

Navigating the transition from Level 1 to Level 2 is a daunting task, but you don’t have to do it alone. As a part of the Motorola Solutions family, Lunarline provides the technical depth and regulatory expertise needed to streamline the certification process. We work with contractors to demystify the 110 controls of NIST SP 800-171 and prepare them for a successful C3PAO audit.

Our team helps you distinguish between FCI and CUI, ensuring you don’t over-scope your environment. By narrowing the scope of your CUI environment, we can help reduce the overall cost and complexity of your Level 2 implementation. Whether you need a preliminary readiness assessment or a final C3PAO certification, our experts provide a clear path forward.

man and woman in conference room discussing data presented on screen

Is your organization ready for the next level?

The DoD’s timeline for CMMC implementation is moving forward, and the requirements are becoming more stringent. Waiting until a contract requires certification is a recipe for failure, as Level 2 implementation can take 12 to 18 months for the average organization. Now is the time to evaluate your data, identify your tier, and begin the remediation process.

If you handle CUI, the shift to Level 2 is inevitable. By partnering with an experienced C3PAO like Lunarline, you can turn a complex regulatory hurdle into a competitive advantage. Protect your contracts, protect your data, and ensure your organization remains a vital part of the American defense mission.