5.3 Level 2 & Level 3: CUI Protection and Assessment Authority

Key Takeaways

  • Level 2 uses all 110 NIST SP 800-171 Revision 2 requirements across 14 families.
  • A solicitation may require Level 2 Self or Level 2 C3PAO; both underlying assessments are triennial, followed by annual affirmation.
  • Level 2 certification teams use at least a Lead CCA and one additional CCA; eligible CCPs are additional limited participants.
  • Level 3 adds 24 selected NIST SP 800-172 requirements and requires Final Level 2 (C3PAO) status covering the proposed Level 3 scope, which must be equal to or a subset of that Level 2 scope.
  • DCMA DIBCAC, not a commercial C3PAO, conducts Level 3 assessment.
Last updated: August 2026

5.3 Level 2 & Level 3: CUI Protection and Assessment Authority

Levels 2 and 3 protect Controlled Unclassified Information (CUI) against increasingly capable threats. The levels share a Level 2 foundation, but differ in added requirements, assessment authority, and contract use.

Level 2 baseline

Level 2 adopts the 110 security requirements in NIST SP 800-171 Revision 2 across 14 families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

The CMMC Level 2 Assessment Guide expresses assessment objectives and procedures aligned to NIST SP 800-171A. A requirement is MET only when all applicable objectives are satisfied. Examine, Interview, and Test are assessment methods, selected according to the objective and needed evidence. They are not a mandatory two-method checklist for every determination.

Level 2 assessment paths

A solicitation or contract specifies one of two types:

  • Level 2 Self: the organization performs the assessment every three years and records it in SPRS. This path applies only where the acquisition permits it.
  • Level 2 C3PAO: an authorized or accredited C3PAO conducts a certification assessment every three years under CAP and reports through CMMC eMASS.

Both paths require the organization's Affirming Official to affirm after the assessment, after a POA&M closeout when applicable, and annually thereafter. Do not confuse the annual affirmation with the assessment cadence.

For a C3PAO assessment, the minimum team is a Lead CCA and at least one additional CCA. More CCAs and eligible CCPs may join. Current ISACA guidance limits CCP verification during Level 2 work to Level 1 practices, without final determination authority.

Level 2 scope and status

The Level 2 scope includes CUI Assets and Security Protection Assets and addresses Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets under the scoping guide. External providers, cloud services, people, and facilities are included according to functions and access. The same 110 requirements can therefore produce very different evidence plans across organizations.

A perfect result yields Final status. Conditional status is possible only under 32 CFR §170.21. The score divided by 110 must be at least 0.8, and each unmet requirement must be eligible. Requirements worth more than one point are generally barred, with the narrow SC.L2-3.13.11 nonvalidated-encryption exception, and six named requirements are always barred. Successful closeout must occur within 180 days.

Level 3

Level 3 adds 24 selected NIST SP 800-172 enhanced security requirements to the Level 2 baseline for programs facing advanced persistent threats. It is not a commercial C3PAO assessment. DCMA DIBCAC performs the Level 3 assessment.

Before Level 3, the organization needs a current Final Level 2 (C3PAO) status covering the information systems in the proposed Level 3 scope; the Level 3 scope must be equal to or a subset of the Level 2 scope. A Level 2 Self status is not the prerequisite. DIBCAC may verify underlying Level 2 requirements and can pause, hold, or terminate the Level 3 process when foundational implementation is deficient under the rule.

Level 3 has its own conditional-status limitations. The organization must meet the applicable ratio, and specified enhanced requirements cannot remain on a POA&M. DIBCAC performs the closeout assessment for Level 3 POA&M items.

Data and contract analysis

CUI is not any information a contractor considers sensitive. The government-authorized category and marking, contract, CUI Registry authority, and information flow determine the safeguarding obligation. An organization may operate multiple enclaves or contracts requiring different statuses. A CMMC status applies to the defined assessment scope, not automatically to every corporate system.

For a subcontract, the required status follows the data and the clauses applicable to that subcontracted performance. A prime cannot replace the contracting officer's stated requirement, but it must protect and flow down information correctly.

Worked comparison

Organization A receives FCI only and needs Level 1. Organization B receives CUI under a solicitation that permits Level 2 Self; it assesses all 110 requirements every three years and affirms annually. Organization C supports a prioritized CUI acquisition requiring Level 2 C3PAO; its C3PAO team assesses the same 110 requirements and reports through eMASS. Organization D supports a designated highest-priority program; after Final Level 2 C3PAO status covering the proposed Level 3 scope, DIBCAC assesses the 24 Level 3 enhancements.

The technical baseline alone does not identify the assessor. Always read the required assessment type.

Common traps

Do not say every CUI contractor always needs a C3PAO assessment; the solicitation distinguishes Level 2 Self from Level 2 C3PAO. Do not call a Level 2 self-assessment annual. Do not let a CCP make final Level 2 findings. Do not assign Level 3 to a C3PAO. Do not treat an annual affirmation as proof that an unassessed new scope has inherited status.

Test Your Knowledge

A solicitation permits Level 2 Self. What is the assessment cadence?

A
B
C
D
Test Your Knowledge

What prerequisite and scope relationship apply before Level 3?

A
B
C
D
Test Your Knowledge

Who conducts Level 3?

A
B
C
D