Skip to content

Self-assessment

Which CMMC level am I?

A CMMC level is not a property of your company. It is a property of the contract. The requiring activity selects it, and it reaches you through a clause.

These five questions ask what the contract says and what information the work puts on your systems. The result tells you which level that combination points to, and what to do next.

It is guidance, not a determination. The requiring activity selects the level, and the clause carries it.

5 questions

Answer as your situation actually is, not as you would like it to be. Nothing is stored and nothing is sent anywhere.

Step 1 of 5

0% answered

Who is the customer for the work you want to win?

CMMC is a Department of War program. The customer decides whether it applies at all.

This is guidance, not a determination. A result here is a reading of what you told us, against rules that are cited on this page so you can check them. It is written to be generally correct, and it still cannot know your specific use case or every variable that applies to you. Every result is therefore an explanation of how a rule works, offered as a suggestion, and never an official or definitive answer. It is not legal advice, it is not a compliance opinion, and it does not bind a contracting officer. The solicitation in front of you governs. Where the two disagree, the solicitation is right and this page is wrong.

Every question and every result, written out

Nothing on this page is hidden behind the interactive version. Read the whole thing here, link straight to any result, or check the routing for yourself.

The questions

Show
  1. 1. Who is the customer for the work you want to win?

    CMMC is a Department of War program. The customer decides whether it applies at all.

    • The Department of War, as a prime contractor.
    • A prime contractor, on Department of War work.
    • Civilian federal agencies only. No Department of War work.
    • We do not know yet.
  2. 2. What does the clause list of the solicitation you're targeting say?

    Section I of a solicitation in uniform contract format holds the contract clauses.

    • It names DFARS 252.204-7021 and states a level.
    • It includes DFARS 252.204-7012.Safeguarding covered defense information and cyber incident reporting.
    • It includes FAR 52.204-21 and no DFARS cybersecurity clause.
    • We have not read the clause list.
  3. 3. What government information will touch your systems?

    • Controlled Unclassified Information (CUI).Marked as CUI, or specified as CUI by the contract.
    • Federal Contract Information (FCI) only.Not public, but nothing that carries a CUI marking.
    • None. The contract is exclusively for off-the-shelf items.Commercially available off-the-shelf products, sold as they are.
    • We do not know which category applies.
  4. 4. Does the program name requirements above NIST SP 800-171?

    Level 3 adds selected enhanced requirements from NIST SP 800-172.

    • Yes. The program names selected NIST SP 800-172 requirements.
    • No. NIST SP 800-171 is the highest standard named.
    • We do not know.
  5. 5. Where does the government information live in your environment?

    This does not change your level. It changes what the level costs you.

    • In a defined enclave with a documented boundary.
    • Across the whole company network.
    • We have not scoped it.
    • No government information touches our systems today.

The results

Show

Each of these is an explanation of how a rule works, written to be generally correct and offered as a suggestion. None of them is an official or definitive answer, because none of them can know your specific use case or every variable that applies to you. The solicitation in front of you governs.

Your clause list already answered this. Use the level it states.

When a solicitation names DFARS 252.204-7021 and states a level, that level is the requirement for that contract, and no self-assessment quiz overrides it.

The requiring activity selects the level for each procurement. The clause carries that selection to you. A different level on a different contract is normal, and it is not a contradiction.

The program remains in Phase 1 today, so the practical form of the requirement is a self-assessment with an annual affirmation. Read the clause for the level. Read the phase for the verification method.

What to do

  1. Record the stated level against this opportunity.
  2. Compare it to the level you already affirmed in SPRS.
  3. Close the difference before you submit a price.
  4. Flow the clause down to each subcontractor that touches the same information.

The rules behind this result

DFARS 252.204-7021
States the CMMC level the contract requires, and mandates flowdown.

The signals point to Level 3 (Expert).

A program that names selected NIST SP 800-172 enhanced requirements points to CMMC Level 3. Level 3 covers a narrow set of programs that support the most critical technology.

Level 3 sits on top of Level 2. You still owe the 110 requirements of NIST SP 800-171 Revision 2. The enhanced requirements are additional, not a replacement.

Level 3 arrives with Phase 3 of the program. The program remains in Phase 1 today, so no Level 3 assessment applies to a current award. Treat this as a planning answer, not as a due date.

What to do

  1. Confirm the named requirements with the program office in writing.
  2. Complete the Level 2 work first, because Level 3 builds on it.
  3. Ask which government organization performs the assessment for your program.

The rules behind this result

32 CFR part 170
Codifies the CMMC program, its levels and its phased introduction.

The signals point to Level 2 (Advanced).

CUI on your systems, or DFARS 252.204-7012 in the clause list, points to CMMC Level 2. Level 2 is the 110 security requirements of NIST SP 800-171 Revision 2.

DFARS 252.204-7012 is the practical trigger. It requires NIST SP 800-171 implementation, and it requires cyber incident reporting within 72 hours of discovery. That obligation is live today and the suspension of Phase 2 did not change it.

The program remains in Phase 1, so the verification method today is a self-assessment every three years with an annual affirmation. The C3PAO certification assessment arrives with Phase 2, and Phase 2 does not run today. Do not plan a certification against a date that nobody has published.

Read this as the risk it is. The suspension removed an external forcing function and left the contract duty in place. A false affirmation is a False Claims Act exposure whatever phase the program sits in.

What to do

  1. Define the CUI boundary before you buy any control.
  2. Assess honestly against all 110 requirements.
  3. Write the system security plan against your real environment.
  4. Post a score in SPRS that your evidence supports.
  5. Affirm annually, because an assessment lapses without the affirmation.

The rules behind this result

DFARS 252.204-7012
Requires NIST SP 800-171 implementation and 72-hour cyber incident reporting.
32 CFR 170.21(a)(2)
Permits a plan of action at Level 2, and requires closure within 180 days.

The signals point to Level 1 (Foundational).

Federal Contract Information with no CUI, and FAR 52.204-21 with no DFARS cybersecurity clause, points to CMMC Level 1 and its 15 basic safeguarding requirements.

A contractor verifies Level 1 by an annual self-assessment, with an annual affirmation from a senior official. A plan of action is not permitted at Level 1. Each requirement is either met or it is not.

Level 1 is the smallest version of this problem, and it is the one that changes fastest. A single new task order that introduces CUI moves you to Level 2. Check the clause list of every new opportunity rather than the status you hold today.

What to do

  1. Meet all 15 requirements, because a plan of action is not permitted here.
  2. Affirm annually.
  3. Re-read the clause list on each new opportunity.
  4. Escalate to the Level 2 plan the moment a solicitation mentions CUI.

The rules behind this result

FAR 52.204-21
Sets the 15 basic safeguarding requirements for contractor information systems.

A contract exclusively for off-the-shelf items falls outside the program.

CMMC program requirements do not apply to a solicitation exclusively for commercially available off-the-shelf items, under 32 CFR 170.3(c).

The exception is narrow and it is about the contract, not about the company. It covers a procurement that is exclusively for off-the-shelf items. One line of configuration work or one delivery of government data can take the contract outside the exception.

The exception also says nothing about your other contracts. A company can hold one contract outside the program and another inside it.

What to do

  1. Confirm in writing that the requirement is exclusively off-the-shelf.
  2. Re-run this check on each opportunity that adds a service.
  3. Keep government information off your systems while the exception applies.

The rules behind this result

32 CFR 170.3(c)
Applies the program to acquisitions of commercial items except those exclusively for off-the-shelf items.

CMMC does not reach civilian-agency work. Another rule does.

CMMC is a Department of War program. It reaches a contractor through a Department of War contract or a subcontract, so civilian-agency work carries no CMMC level.

This is not the same as no cybersecurity obligation. FAR 52.204-21 applies across the government wherever a contractor holds Federal Contract Information. Many civilian agencies also add their own requirements by clause.

The distinction matters for a second reason. A company that wins its first Department of War subcontract inherits the program on that day, and the work to prepare takes months.

What to do

  1. Read the clause list of your civilian contracts for their own security terms.
  2. Meet FAR 52.204-21 wherever you hold Federal Contract Information.
  3. Start the CMMC work before you chase the first Department of War subcontract, not after.

The rules behind this result

FAR 52.204-21
Sets the 15 basic safeguarding requirements for contractor information systems.

There is not enough on the table yet. The clause list decides this.

No honest answer exists while the information category or the clause list is unknown. The level is a determination the contract carries, not a property of your company.

This is the most common real position, and it is a better place to be than a confident wrong answer. The two facts you need are short. What does Section I list, and what category of information does the work put on your systems.

Both facts are free. One is in the solicitation. The other is a question to the contracting officer, and it is a reasonable question to ask before the question deadline.

What to do

  1. Open Section I and list every cybersecurity clause you find.
  2. Ask the contracting officer which information category applies.
  3. Ask before the question deadline, because the deadline falls early.
  4. Return to this page once you hold both answers.

How the answers route

Show

The rules below run in order. The first one whose conditions hold decides the result. When none of them holds, the weighted answers decide, and the result defaults to There is not enough on the table yet. The clause list decides this..

  1. A solicitation exclusively for commercially available off-the-shelf items sits outside the program under 32 CFR 170.3(c). See that result.
  2. CMMC reaches a contractor through a Department of War contract or subcontract, and you named neither. See that result.
  3. A clause that states a level is the determination itself, and it outranks every other signal on this page. See that result.
  4. Only Level 3 adds selected enhanced requirements from NIST SP 800-172. See that result.
  5. CUI on your systems, or DFARS 252.204-7012 in the clause list, is the Level 2 trigger. See that result.
  6. Federal Contract Information with no CUI and no DFARS cybersecurity clause is the Level 1 case. See that result.
  7. A weighted guess cannot replace a missing fact about the contract. See that result.

Common questions

Show

Does this quiz decide my CMMC level?

No. The requiring activity selects the level for each procurement and the contract carries it to you in a clause. This page reads the same signals a capture team reads, and it points you at the document that holds the answer.

Is CMMC Phase 2 a deadline I need to plan against right now?

No. The Department of War suspended Phase 2 implementation on July 13, 2026 and established a reform task force. The program remains paused in Phase 1, which began on November 10, 2025. Only self-assessments apply today. The suspension changed the verification mechanism and did not remove the obligation in DFARS 252.204-7012.

Can one company have two different CMMC levels?

Yes. The level attaches to a contract, not to a company. A firm can hold one contract at Level 1 and another at Level 2 at the same time. The honest answer to "what level are we" is always "on which contract".

Need an answer that binds?

Everything above explains how the rule reads. It cannot tell you how the rule lands on your contract, and that is the question worth paying someone for. Tell us what you are looking at and we will point you toward counsel who works in this area, rather than guess at it.
Ask about a referral

A quiz compresses. These entries do not.

Silas™ reads the clause set of a solicitation and surfaces the cybersecurity level it implies before the bid decision.

Run this against the solicitation on your desk.

A quiz answers from what you can tell it. The version that decides a bid reads the actual document, against the actual profile of the company bidding it.
Talk to Vortex Computation™