CMMC Level 2 vs Level 3: What's the Difference?
First developed as part of our LinkedIn content series, June 2026. Expanded and updated for this site.
CMMC Level 2 vs Level 3: What's the Difference?
A mid-tier defense subcontractor discovered during proposal review that the contract they had been pursuing for eight months required CMMC Level 3. Their entire compliance program had been built toward Level 2. The delta was not "24 more controls"---it was a fundamentally different organizational posture: threat hunting, dual authorization, DIBCAC instead of C3PAO, and 18-36 additional months of implementation. They withdrew from the bid.
That discovery should have happened on day one. Understanding what separates Level 2 from Level 3 is not academic---it determines which contracts you can pursue, how much you invest, and whether you build an entirely different security organization.
Why Now
The CMMC 2.0 final rule at 32 CFR Part 170 became effective December 16, 2024. The phased rollout means contracts are beginning to include CMMC requirements in solicitations now. C3PAO assessments are live. DIBCAC is scheduling Level 3 assessments. The window for "we will figure it out later" has closed. Contractors who have not already begun implementation face a 12-36 month timeline before they can credibly bid on contracts requiring certification---and the competition is not waiting.
CMMC 2.0 Structure
| Level | Information Protected | Practices | Assessment |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 (FAR 52.204-21) | Annual self-assessment |
| Level 2 | Controlled Unclassified Information (CUI) | 110 (NIST SP 800-171 Rev 2) | Self-assessment or C3PAO |
| Level 3 | CUI on critical programs / high-value assets | 110 + 24 (NIST SP 800-172) | DIBCAC assessment |
Each level is cumulative. Level 3 includes all 110 Level 2 practices plus 24 enhanced requirements.
What Triggers Each Level
Level 2 Triggers
Level 2 applies to contractors handling CUI under DFARS 252.204-7012---the majority of DIB contractors who receive, store, process, or transmit CUI. Categories include Controlled Technical Information, export-controlled information, proprietary business information marked CUI, and operations security information.
Level 2 splits into two assessment tracks:
- Self-assessment --- for CUI not associated with a "prioritized acquisition." Contractor conducts assessment, submits to SPRS, attests via senior official affirmation.
- C3PAO certification --- for "prioritized acquisitions." A CMMC Third-Party Assessment Organization accredited by the Cyber AB conducts the assessment.
Level 3 Triggers
Level 3 is reserved for the most sensitive DoD programs: CUI on critical programs, high-value assets, and programs where advanced persistent threats pose strategic risk. Think major weapons systems, satellite programs, nuclear C2, critical intelligence systems. This is not the average subcontractor---it targets primes and key subs where compromise would be catastrophic.
The 110 Practices: NIST SP 800-171 Rev 2
Level 2 maps one-to-one to 800-171 Rev 2 across 14 control families:
| Family | Requirements |
|---|---|
| Access Control (3.1.x) | 22 |
| Awareness and Training (3.2.x) | 3 |
| Audit and Accountability (3.3.x) | 9 |
| Configuration Management (3.4.x) | 9 |
| Identification and Authentication (3.5.x) | 11 |
| Incident Response (3.6.x) | 3 |
| Maintenance (3.7.x) | 6 |
| Media Protection (3.8.x) | 9 |
| Personnel Security (3.9.x) | 2 |
| Physical Protection (3.10.x) | 6 |
| Risk Assessment (3.11.x) | 3 |
| Security Assessment (3.12.x) | 4 |
| System and Communications Protection (3.13.x) | 16 |
| System and Information Integrity (3.14.x) | 7 |
Full implementation typically requires 12-24 months for an organization starting from scratch---infrastructure, policies, procedures, and personnel training.
The 24 Additional Practices: NIST SP 800-172
Level 3 adds 24 enhanced requirements designed specifically to counter advanced persistent threats. These are not harder versions of Level 2 controls---they represent fundamentally different capabilities.
Access Control Enhancements. Dual authorization for critical operations (3.1.1e)---two authorized individuals must approve changes to security configurations, access to sensitive data, or audit log modifications. System access restrictions beyond basic RBAC.
Situational Awareness and Threat Hunting. Active threat hunting (3.11.2e)---proactively searching for indicators of compromise, not relying solely on automated detection. SOC capabilities (internal or MSSP). Cyber threat intelligence integration with actionable feeds.
System Hardening. Enhanced network segmentation isolating CUI environments. Diversity and redundancy in security mechanisms---different vendors to avoid single-vulnerability cascading failures. Specialized mechanisms for IoT, OT, and embedded systems.
Incident Response Enhancements. Documented procedures including DoD coordination. Forensic capabilities available within defined timeframes. Supply chain risk incident procedures.
Penetration Testing and Red Teaming. Periodic penetration testing with realistic adversary simulation. Red team exercises against organizational systems.
The Contrarian Take: Level 3 Is a Different Organization
The industry frames this as "Level 2 plus 24 more controls." That framing causes more failed assessments than any single technical gap.
Level 3 is not an extension of Level 2. It is a different operating model. Dual authorization changes how every sensitive operation works---it adds a second person to configuration changes, access grants, and audit log management. Active threat hunting means hiring (or contracting) people whose entire job is finding threats that your automated tools missed. Enhanced network segmentation may require redesigning architectures that took years to build.
Organizations that approach Level 3 as "close 24 more POA&M items" will fail the DIBCAC assessment. The correct mental model: Level 2 is a well-managed IT organization with dedicated cybersecurity staff. Level 3 is a mature security operations center with 24/7 coverage, dedicated intelligence analysts, and adversary simulation capability. If your current org chart does not have those roles, the conversation starts at hiring, not at controls implementation.
Assessment Methodology: C3PAO vs. DIBCAC
Level 2: C3PAO Assessment
- Assessor: CMMC Third-Party Assessment Organization accredited by the Cyber AB
- Duration: 1-2 weeks on-site plus preparation and reporting
- Validity: 3 years with annual affirmation
- Cost: $50,000 - $250,000+ depending on scope
- POA&M: Limited items allowed; must close within 180 days; certain requirements cannot be on POA&M
- Result: Certification reported to eMASS
Level 3: DIBCAC Assessment
- Assessor: Defense Industrial Base Cybersecurity Assessment Center (component of DCMA)
- Prerequisite: Valid Level 2 C3PAO certification (not self-assessment)
- Duration: Several weeks---significantly longer than Level 2
- Validity: 3 years with annual affirmation
- Cost: Government-conducted (no direct charge), but preparation costs $200K-$1M+
- Result: Certification reported to eMASS
The key distinction: Level 3 is government-led. This reflects the sensitivity of the programs and the government's interest in directly verifying security posture of critical suppliers.
Cost and Timeline Comparison
| Factor | Level 2 | Level 3 |
|---|---|---|
| Control implementation | $100K - $1M+ | $500K - $5M+ (incremental above L2) |
| Assessment cost | $50K - $250K (C3PAO) | Government-conducted (prep $200K-$1M+) |
| Annual maintenance | $75K - $300K | $200K - $800K |
| Timeline | 12-24 months | 18-36 months (after L2 in place) |
| Staff | 1-3 dedicated security FTEs | 3-8+ FTEs including SOC/threat hunting |
| Technology | SIEM, endpoint, MFA, encryption, backup | All L2 + threat hunting, advanced segmentation, red team |
The cost differential is not the 24 additional controls. It is the capabilities those controls demand---capabilities requiring different staffing, tooling, and operational maturity.
The Practical Gap
Continuous Monitoring Expectations
- Level 2: Periodic vulnerability scanning, annual penetration testing, log review, patch management.
- Level 3: Continuous or near-continuous monitoring with automated alerting, proactive threat hunting, rapid APT detection and response. This aligns closely with cATO readiness.
Supply Chain
Level 3 contractors must evaluate subcontractor security postures, implement supply chain risk management, and monitor for counterfeit components, compromised software, and insider threats at subcontractors.
Cultural Impact
Dual authorization slows certain operations deliberately. Enhanced segmentation may require network redesign. Threat hunting requires specialized personnel who do not merely respond to alerts but actively seek threats. These are organizational changes, not checkbox items.
Planning Your Path
If You Need Level 2
- Gap assessment against NIST 800-171 Rev 2 (110 requirements)
- Develop your SSP documenting implementation
- Remediate gaps; document remaining items in POA&M
- Calculate SPRS score
- Engage C3PAO for certification (prioritized acquisitions) or self-assess
- Submit to SPRS; maintain annual affirmation
If You Need Level 3
- Achieve Level 2 C3PAO certification first (self-assessment insufficient)
- Gap assessment against 24 NIST SP 800-172 enhanced requirements
- Build or contract SOC, threat hunting, red team, and forensics capabilities
- Implement enhanced network segmentation and dual authorization
- Request DIBCAC assessment through DoD channels
- Maintain both levels through continuous monitoring and annual affirmation
Key Takeaways
- Level 2 (110 practices from NIST 800-171) covers most DIB contractors handling CUI; Level 3 (110 + 24 from NIST 800-172) targets critical programs
- Level 2 uses C3PAO assessment ($50K-$250K); Level 3 uses government-led DIBCAC
- Level 3 is not "harder Level 2"---it requires different organizational capabilities (SOC, threat hunting, dual authorization, red team)
- Level 3 requires valid Level 2 C3PAO certification as a prerequisite
- Plan 12-24 months for Level 2; 18-36 additional months for Level 3 after Level 2 is in place
- Start with which contracts you need to pursue---that determines which level you build toward
Frequently Asked Questions
Can a contractor hold Level 2 self-assessment and pursue Level 3?
No. Level 3 requires a valid Level 2 C3PAO certification as a prerequisite---self-assessment does not qualify. The government wants third-party verification of the baseline before conducting its own enhanced assessment.
What percentage of DIB contractors need Level 3?
A small fraction. Level 3 targets prime contractors and key subcontractors on the most sensitive programs. Most DIB companies---including most subcontractors handling CUI---require Level 2. If you are unsure, look at the specific contracts you pursue: if they involve weapons systems, satellite programs, nuclear C2, or critical intelligence, expect Level 3. Otherwise, Level 2 is likely sufficient.
Can POA&M items exist at Level 3?
The final rule permits limited POA&M items at both levels, with closure required within 180 days. However, certain requirements at both Level 2 and Level 3 cannot be placed on a POA&M---the system must fully implement them before assessment. The DIBCAC assessors have historically been less tolerant of open POA&M items than C3PAOs.
How does NIST 800-171 Rev 3 affect CMMC?
CMMC 2.0 as codified in the final rule references NIST SP 800-171 Revision 2 specifically. A future rulemaking would be required to update the reference to Rev 3. Until that happens, contractors should implement against Rev 2 for CMMC certification while tracking Rev 3 changes for future readiness.
What is the SPRS score threshold for Level 2?
A perfect SPRS score is 110 (all practices implemented). Under the final rule, a conditional certification with a POA&M requires a minimum assessment score of 88 (80% of 110), POA&M items must close within 180 days, and certain requirements can never be placed on a POA&M. A score below 88 at the time of assessment means the gaps cannot fit within the POA&M constraints at all.
How Advisedly Helps
Advisedly maps every CMMC Level 2 and Level 3 practice to your implemented controls, calculates your SPRS score in real time, and generates the SSP, POA&M, and continuous monitoring evidence that C3PAO and DIBCAC assessors require. With 500+ frameworks cross-mapped through a single platform, organizations preparing for Level 3 can track enhanced 800-172 requirements alongside baseline 800-171 controls without maintaining separate spreadsheets or GRC tools. Contact us at begin@advisedly.ai.
<!-- LI hook: Level 3 is not harder Level 2. It is a different organization. -->