CMMC Level 1 vs Level 2
The level depends on the information you handle under the contract: Federal Contract Information (FCI) means Level 1, Controlled Unclassified Information (CUI) means Level 2.
| Aspect | Level 1 | Level 2 |
|---|---|---|
| Information | FCI | CUI |
| Requirements | 15, from FAR 52.204-21(b)(1) | 110, from NIST SP 800-171 Rev 2 |
| Scoring | Met or not met, all 15 required | 110 minus 5, 3 or 1 point per requirement not met (minimum -203) |
| POA&M | Not allowed | Allowed for a Conditional status: score of at least 88, limited requirements, 180 days to close |
| Assessment | Self-assessment every year | Self-assessment or C3PAO certification every three years, as the contract says |
| Affirmation | Every year | At each assessment and every year |
Why "15" and "17"
The FAR clause lists 15 requirements. They map to 17 NIST SP 800-171 requirements because FAR (b)(1)(ix) covers three: escorting visitors (3.10.3), physical access logs (3.10.4) and physical access devices (3.10.5). That is why some guides speak of 17 Level 1 practices (32 CFR 170.15, Level 1 self-assessment).
Level 2 includes Level 1
Every Level 1 requirement maps to a Level 2 requirement, and a Level 2 (Self) status also satisfies Level 1 for the same scope (32 CFR 170.16, Level 2 self-assessment).
The Level 1 requirements
- AC.L1-b.1.i (NIST 3.1.1): Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
- AC.L1-b.1.ii (NIST 3.1.2): Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
- AC.L1-b.1.iii (NIST 3.1.20): Verify and control/limit connections to and use of external information systems.
- AC.L1-b.1.iv (NIST 3.1.22): Control information posted or processed on publicly accessible information systems.
- IA.L1-b.1.v (NIST 3.5.1): Identify information system users, processes acting on behalf of users, or devices.
- IA.L1-b.1.vi (NIST 3.5.2): Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
- MP.L1-b.1.vii (NIST 3.8.3): Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
- PE.L1-b.1.viii (NIST 3.10.1): Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
- PE.L1-b.1.ix (NIST 3.10.3, 3.10.4, 3.10.5): Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
- SC.L1-b.1.x (NIST 3.13.1): Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
- SC.L1-b.1.xi (NIST 3.13.5): Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
- SI.L1-b.1.xii (NIST 3.14.1): Identify, report, and correct information and information system flaws in a timely manner.
- SI.L1-b.1.xiii (NIST 3.14.2): Provide protection from malicious code at appropriate locations within organizational information systems.
- SI.L1-b.1.xiv (NIST 3.14.4): Update malicious code protection mechanisms when new releases are available.
- SI.L1-b.1.xv (NIST 3.14.5): Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.