Almost every confusing thing about CMMC gets simpler once you answer one question: what kind of government information do you actually hold? That single answer sets your level, and your level sets everything downstream — how many controls you owe, whether you write a System Security Plan, and what you post to SPRS. Here is the whole picture in plain English.
The Two Kinds of Information
FCI — Federal Contract Information
Information provided by, or generated for, the government under a contract to develop or deliver a product or service, and not intended for public release. Delivery schedules. Non-public statements of work. Contract correspondence. Process documents you produced for the customer. It is ordinary contract paperwork that simply is not public.
What it isn't: anything the government publishes openly, and simple transactional information like an invoice being processed for payment. If you hold a DoD contract of any size, assume you hold FCI.
CUI — Controlled Unclassified Information
A narrower and more sensitive category the government specifically defines and usually marks for protection. In the defense world this is most often controlled technical data — engineering drawings, specifications, test results, source code for a delivered system — plus export-controlled material under ITAR/EAR, and certain contract detail like non-public pricing and proposal data.
CUI is a subset of the sensitive world, not a synonym for it. Most small contractors hold FCI. Fewer hold CUI. The ones who hold CUI carry a substantially larger obligation.
Level 1 — The FCI Tier
Level 1 exists because basic hygiene should not require an audit industry. It rests on FAR 52.204-21, which lists 15 basic safeguarding requirements — the security equivalent of locking the front door:
- Limit system access to authorized users, and to the transactions those users are allowed to perform
- Control what gets posted to public-facing systems
- Verify and control connections to external systems
- Identify users and authenticate them before granting access
- Sanitize or destroy media before disposal or reuse
- Limit physical access, escort visitors, and keep audit logs of physical access
- Monitor and protect your network boundaries, with subnetworks for publicly accessible components
- Run antivirus, keep it updated, and scan files as they arrive
- Install security patches promptly
What Level 1 does not require: the 110 NIST SP 800-171 controls, a formal System Security Plan, or a scored SPRS submission. Under the CMMC program rule, Level 1 is a self-assessment with an annual affirmation — no third-party assessor, at any point.
Level 2 — The CUI Tier
Handle CUI and the bar rises sharply. Level 2 means all 110 controls of NIST SP 800-171 Revision 2, across 14 families — access control, audit and accountability, configuration management, identification and authentication, incident response, media protection, and the rest.
It also means the paperwork that proves it:
- A System Security Plan describing how each of the 110 controls is implemented in your environment (and NIST requires the SSP outright, as control 3.12.4)
- A POA&M for every control not yet met, with owners and dates
- A scored self-assessment posted in SPRS under DFARS 252.204-7019
- Evidence retained for every control you claim is met
The scoring runs from 110 (everything implemented) down to a floor of −203 (nothing implemented), because unmet controls subtract 1, 3, or 5 points according to their security impact. Our step-by-step scoring guide covers the arithmetic and which controls hurt most.
Side by Side
| Level 1 | Level 2 | |
|---|---|---|
| Information type | FCI | CUI |
| Governing clause | FAR 52.204-21 | DFARS 252.204-7012 / -7019 / -7020 |
| Security standard | 15 basic safeguards | NIST SP 800-171 Rev 2 — 110 controls |
| System Security Plan | Not required | Required |
| POA&M | Not required | Required for unmet controls |
| Scored SPRS submission | No numeric score | Yes — the −203 to 110 score |
| Annual affirmation | Yes | Yes |
| Third-party assessment | Never | Was phasing in — suspended July 13, 2026 |
| Typical effort | Days to weeks | Months, plus ongoing operation |
Where SPRS Fits — and Where It Doesn't
This is the single most common mix-up we see, so it's worth stating carefully. SPRS — the Supplier Performance Risk System — is the DoD database where your assessment results live. Both levels touch it, but not in the same way:
- Level 2 / CUI: you post an actual numeric score from a real assessment of all 110 controls, along with the assessment date, scope, your SSP name and version, and a POA&M completion date. That score has a three-year shelf life and a contracting officer checks it before award. The full submission walkthrough is here.
- Level 1 / FCI: you record a self-assessment status and an annual affirmation — there is no 110-point number, because the 110 controls aren't your standard in the first place.
So when a prime emails asking for "your SPRS score," they are almost always asking a Level 2 question. If you are FCI-only, the correct answer isn't a number — it's an explanation that your contracts don't carry the CUI clause, which is a much better response than inventing a score.
What the CMMC Pause Changed for Each Level
On July 13, 2026 the Department of War suspended CMMC Phase 2, including the November 10 milestone that would have started putting C3PAO certification into new solicitations. What that did and didn't touch:
- Level 1 contractors: essentially nothing changed. FAR 52.204-21's 15 safeguards are a contract requirement in their own right, independent of the CMMC program. You still owe them.
- Level 2 contractors: the third-party verification is paused. The obligations — implement NIST SP 800-171, keep an SSP, post and maintain a current SPRS score — are untouched, because they flow from DFARS clauses the suspension never addressed. More on what's still due.
The reform task force is expected to report around mid-September. Since any future version of CMMC will still be built on NIST SP 800-171, work done now carries forward intact.
Not sure which level you're on? Find out for free.
CMMC Map's scoping wizard asks about your contracts and the data you handle, then tells you which controls actually apply. From there, walk all 110 in plain English and watch your SPRS score build — free, no credit card. Documents come later, only if you want them.
Start free →Four Mistakes That Cost Small Contractors Real Money
- Assuming Level 2 because CMMC sounds serious. Plenty of FCI-only shops start building toward 110 controls they don't owe. Check your clauses before you spend — the difference is weeks versus months.
- Assuming Level 1 because nobody has complained. The more expensive error. If DFARS 7012 is in your contract and you're treating it as FCI work, you have an unposted obligation accruing quietly.
- Letting CUI sprawl across the whole company. Level 2 applies to the environment where CUI lives. Contain it in an enclave and you shrink the assessment boundary dramatically. Our scoping guide covers how.
- Treating "not sure" as an answer. It isn't, and it won't be when a prime asks. Ask your contracting officer in writing and keep the reply — a documented determination is itself a piece of evidence.