Almost every confusing thing about CMMC gets simpler once you answer one question: what kind of government information do you actually hold? That single answer sets your level, and your level sets everything downstream — how many controls you owe, whether you write a System Security Plan, and what you post to SPRS. Here is the whole picture in plain English.

The Two Kinds of Information

FCI — Federal Contract Information

Information provided by, or generated for, the government under a contract to develop or deliver a product or service, and not intended for public release. Delivery schedules. Non-public statements of work. Contract correspondence. Process documents you produced for the customer. It is ordinary contract paperwork that simply is not public.

What it isn't: anything the government publishes openly, and simple transactional information like an invoice being processed for payment. If you hold a DoD contract of any size, assume you hold FCI.

CUI — Controlled Unclassified Information

A narrower and more sensitive category the government specifically defines and usually marks for protection. In the defense world this is most often controlled technical data — engineering drawings, specifications, test results, source code for a delivered system — plus export-controlled material under ITAR/EAR, and certain contract detail like non-public pricing and proposal data.

CUI is a subset of the sensitive world, not a synonym for it. Most small contractors hold FCI. Fewer hold CUI. The ones who hold CUI carry a substantially larger obligation.

The practical tell: look for DFARS 252.204-7012 in your contracts. When that clause is present, the government is telling you to plan for CUI — and that puts you on the Level 2 path. If you're still unsure, our guide to whether you actually handle CUI walks the decision in detail.

Level 1 — The FCI Tier

Level 1 exists because basic hygiene should not require an audit industry. It rests on FAR 52.204-21, which lists 15 basic safeguarding requirements — the security equivalent of locking the front door:

What Level 1 does not require: the 110 NIST SP 800-171 controls, a formal System Security Plan, or a scored SPRS submission. Under the CMMC program rule, Level 1 is a self-assessment with an annual affirmation — no third-party assessor, at any point.

Level 2 — The CUI Tier

Handle CUI and the bar rises sharply. Level 2 means all 110 controls of NIST SP 800-171 Revision 2, across 14 families — access control, audit and accountability, configuration management, identification and authentication, incident response, media protection, and the rest.

It also means the paperwork that proves it:

The scoring runs from 110 (everything implemented) down to a floor of −203 (nothing implemented), because unmet controls subtract 1, 3, or 5 points according to their security impact. Our step-by-step scoring guide covers the arithmetic and which controls hurt most.

Side by Side

Level 1Level 2
Information typeFCICUI
Governing clauseFAR 52.204-21DFARS 252.204-7012 / -7019 / -7020
Security standard15 basic safeguardsNIST SP 800-171 Rev 2 — 110 controls
System Security PlanNot requiredRequired
POA&MNot requiredRequired for unmet controls
Scored SPRS submissionNo numeric scoreYes — the −203 to 110 score
Annual affirmationYesYes
Third-party assessmentNeverWas phasing in — suspended July 13, 2026
Typical effortDays to weeksMonths, plus ongoing operation

Where SPRS Fits — and Where It Doesn't

This is the single most common mix-up we see, so it's worth stating carefully. SPRS — the Supplier Performance Risk System — is the DoD database where your assessment results live. Both levels touch it, but not in the same way:

So when a prime emails asking for "your SPRS score," they are almost always asking a Level 2 question. If you are FCI-only, the correct answer isn't a number — it's an explanation that your contracts don't carry the CUI clause, which is a much better response than inventing a score.

Don't post a number you can't defend. Whatever your level, an inflated or invented SPRS entry is a representation to the government attached to your invoices. With third-party certification paused, self-assessment accuracy is the enforcement mechanism — a defensible low score beats an indefensible high one every time someone checks.

What the CMMC Pause Changed for Each Level

On July 13, 2026 the Department of War suspended CMMC Phase 2, including the November 10 milestone that would have started putting C3PAO certification into new solicitations. What that did and didn't touch:

The reform task force is expected to report around mid-September. Since any future version of CMMC will still be built on NIST SP 800-171, work done now carries forward intact.

Not sure which level you're on? Find out for free.

CMMC Map's scoping wizard asks about your contracts and the data you handle, then tells you which controls actually apply. From there, walk all 110 in plain English and watch your SPRS score build — free, no credit card. Documents come later, only if you want them.

Start free →
Free to assess · No credit card · Documents $149/mo

Four Mistakes That Cost Small Contractors Real Money