CMMC ComplianceCyber Grants Alliance Blog

CMMC Level 2 vs Level 3: Which Applies to Your Defense Subcontract?

July 31, 2026 Cyber Grants Alliance 5 min read

CMMC Level 2 vs Level 3 is the comparison that matters once a defense subcontractor knows Controlled Unclassified Information is in play. We covered the more common Level 1 versus Level 2 question in an earlier post, but a growing number of suppliers supporting sensitive programs are being asked about Level 3, and the difference between the two levels is substantial in cost, effort, and who conducts your assessment. Here is how to tell which one your subcontract actually requires.

The quick answer

Level 2 is the standard tier for any contractor or subcontractor that handles CUI. It requires implementing all 110 security controls in NIST SP 800-171, and for most contracts, passing an independent assessment by a certified third-party assessor organization. Level 3 applies to a much smaller set of companies supporting the DoD's most critical programs, where the department judges that information faces advanced persistent threats. It adds selected enhanced controls from NIST SP 800-172 on top of a completed Level 2 certification, and the assessment is conducted by the government itself.

The overwhelming majority of subcontractors reading this need Level 2. Level 3 is the exception, and your contract will say so explicitly. Current DoD planning anticipates that only a small fraction of assessed companies will ever require Level 3, while tens of thousands of subcontractors will need Level 2 certification over the next three years. Plan for Level 2 unless told otherwise in writing.

What Level 2 requires

Level 2 is a serious undertaking for a small business. The 110 controls span fourteen families, covering access control, incident response, media protection, system monitoring, and more. Most subcontractors need months of remediation to close gaps, and the official program documentation makes clear that a passing score requires evidence, not intentions: written policies, configured systems, and practices an assessor can verify.

Two assessment paths exist at Level 2. A limited set of contracts allow self-assessment with an executive affirmation. Contracts involving the most common categories of defense CUI require certification by a C3PAO, and that path is becoming the default.

What Level 3 adds and who needs it

Level 3 exists for suppliers whose compromise would matter to national security at a program level: think components of critical weapons platforms or technology the DoD explicitly designates as high priority. Beyond the enhanced 800-172 controls, the defining difference is the assessor. Level 3 assessments are performed by the Defense Industrial Base Cybersecurity Assessment Center, a government body, after the company already holds a Level 2 certification.

If your subcontract requires Level 3, you will not discover it by accident. The requirement appears in the solicitation, and your prime will raise it early because so few suppliers currently qualify.

How to tell which level your subcontract demands

  1. Read the solicitation or subcontract for the CMMC level clause. The required level is stated, not implied.
  2. Check for DFARS 252.204-7021 and related clauses that carry the requirement down from your prime.
  3. Identify the data you will receive. CUI means at least Level 2. Our CUI explainer helps you recognize it.
  4. Ask your prime's contracts office directly if anything is ambiguous. They carry flow-down responsibility and would rather clarify than replace you later.

Cost and effort: what the jump between levels really means

The practical gulf between the levels is wide. Level 2 typically demands months of remediation, documented policies across fourteen control families, and a third-party assessment that DoD estimates place at a six-figure triennial cost for many small entities once preparation is included. It is demanding but achievable for a committed small business, especially with funded help.

Level 3 is another order of magnitude. The enhanced 800-172 controls address advanced persistent threats, meaning nation-state adversaries, and implementing them involves capabilities like advanced threat hunting and penetration-resistant architecture that few small firms can build alone. Companies facing a genuine Level 3 requirement generally work with specialized providers and treat the effort as a strategic investment tied to specific high-value programs.

Timing pressure: the November 2026 milestone

Whichever level applies, the calendar is unforgiving. On November 10, 2026, third-party certification becomes mandatory for new Level 2 awards, ending the self-assessment window for most contracts. Assessor capacity is already tight, and remediation before assessment routinely takes six months or more. Subcontractors who begin now will be certified when 2027 solicitations arrive. Those who wait will be watching those solicitations pass by.

Start with a Funded Gap Assessment

Every path -- Level 2 or Level 3 -- begins with an honest measurement of where you stand against the 110 baseline controls. The CMMC Gap Assessment Grant funds that measurement at no cost to qualifying businesses.

Apply for the Gap Assessment Grant →

Start with a funded gap assessment

Every path, Level 2 or Level 3, begins the same way: an honest measurement of where you stand against the 110 baseline controls. The CMMC Gap Assessment Grant funds that measurement -- a $5,000 professional assessment with a prioritized remediation roadmap -- at no cost to qualifying businesses. Apply for the grant and find out exactly what stands between your firm and certification while there is still time to fix it.

Share this article: LinkedIn X Email