top of page
CMMC 2.0 Compliance Levels
  • Level 1: No third-party audit required; self-assessment for contractors handling Federal Contract Information (FCI).

  • Level 2: Protects sensitive but not top-secret data (Controlled Unclassified Information - CUI); aligns with NIST SP 800-171 and requires third-party assessment.

  • Level 3: Highest defense for critical DoD information; requires compliance with NIST SP 800-171 plus a subset of NIST SP 800-172, assessed by the DCMA Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). 
     

97 Buckingham Ave Suite 3

Milford, CT 06460

Tel: 203-659-7377

© 2025 by STSAV LLC

bottom of page