The difference comes down to one question: does your contract involve Controlled Unclassified Information (CUI)? If no, and you only handle Federal Contract Information (FCI), Level 1 applies, covering 15 basic safeguarding practices from FAR 52.204-21. If yes, Level 2 applies, covering all 110 security requirements in NIST SP 800-171. Most manufacturers in the DoD supply chain end up at Level 2, since technical data, drawings, and part specifications tied to a defense program typically qualify as CUI.

Side-by-Side: Level 1 vs. Level 2

Level 1 (Foundational) Level 2 (Advanced)
Protects Federal Contract Information (FCI) Controlled Unclassified Information (CUI)
Number of controls 15 (FAR 52.204-21) 110 (NIST SP 800-171)
Assessment method Annual self-assessment Self-assessment now; third-party (C3PAO) assessment when Phase 2 resumes
Typical timeline 2-4 months 6-12 months, up to 18
Do you need help? Often achievable without a consultant Most organizations benefit from RPO support

FCI vs. CUI: The Distinction That Decides Everything

Federal Contract Information (FCI): information provided by or generated for the government under a contract, not intended for public release, but without the specific sensitivity markers of CUI. Basic order details and routine deliverables usually fall here.

Controlled Unclassified Information (CUI): a more specific designation governed by 32 CFR Part 2002, covering technical data, export-controlled information, and details tied to defense programs and acquisition. If your contract involves engineering drawings, specifications, or technical data for a DoD program, you're almost certainly handling CUI.

Watch for "CUI creep": plenty of manufacturers believe they're FCI-only until one errant email attachment or shared drawing changes the picture. Scoping your environment accurately before you assume your level is one of the most consequential steps in this whole process.

Getting Certified for Level 2 Doesn't Skip Level 1

A CMMC Level 2 assessment covers every practice from Level 1 through Level 2 in the same review. If you achieve Level 2 certification, you've automatically met Level 1 requirements within that same assessment scope, you don't certify separately for each.

A Cost-Saving Strategy Worth Knowing: Splitting FCI and CUI Environments

If your CUI-handling work is a small slice of your overall operation, you can architect your network so FCI and CUI live in separate environments. Only the CUI environment then needs to meet the full 110-control Level 2 standard; the FCI-only environment can stay at a simpler Level 1 self-assessment. This split can meaningfully lower both your cost and your ongoing compliance burden, but it requires careful, accurate scoping to hold up under review. A shared environment means everything defaults to Level 2 requirements.

How to Know Which Level Applies to You

  • Check your contract or RFI: contracting officers typically specify the required level directly
  • Ask whether your prime flows down CUI to you, or only FCI, if you're a subcontractor
  • Review whether you handle drawings, specs, or technical data tied to a specific defense program

When in doubt, get a professional scoping review before assuming Level 1 is enough

Why Manufacturers Work With Justice IT Consulting

  • Registered Practitioner Organization (RPO) with Certified CMMC Professionals (CCPs) and Registered Practitioners (RPs) on staff
  • We hold our own CMMC Level 2 certification
  • 4-time Top 250 MSSP in the world, 3-time Top 500 MSP in the world
  • Our team includes an Amazon Best-Selling Author on CMMC compliance and hosts The CMMC Compliance Guide Podcast
  • Family-owned, DFW-based, 60+ five-star Google reviews

Not sure if you're Level 1 or Level 2? Contact Justice IT Consulting for a scoping review. We'll tell you plainly, and show you whether splitting your environment could save you money.