Updated on May 6, 2024
CMMC FAQ
Estimated reading: 1 minute 2214 views
- Self-attest L1 starts with a CMMC L1 for the basic set of requirements from CMMC. Level 1 protects Federal Contract Information (FCI).
- Mature with Level 2 if you handle CUI, add policies and procedures and a few controls.
Each CMMC level is built on the one below it, so compliance with the lower-level requirements and the use of additional processes are needed to implement the cyber security-based practices.
- Level 1: This is the most “basic cybersecurity practice,” such as using antivirus software and ensuring employees change their passwords regularly. This should be done to protect Federal Contract Information (FCI).
- Level 2: This is likely to be the level that most contractors fall into. Level 2 is an intermediate level between Level 1 and Level 3 and consists of good cyber hygiene. This level must be completed if the organization holds CUI (Controlled Unclassified Information) on their network.
- Level 3: At the expert level, the organization must demonstrate the effectiveness of the level 1 and level 2 practices.