Skip to content

CMMC levels and their requirements

Level 1 protects FCI with the 15 basic safeguarding requirements of 48 CFR 52.204-21. Level 2 protects CUI and incorporates the 110 security requirements of NIST SP 800-171. The level that applies follows from the information the contract involves, not from the size or preference of the OSC.

Recall

The terms and figures from this lesson, one at a time.

Card 1 of 3Level 2 of 5

Which document states the Level 2 requirements, and which states how to assess them?

This deck does not remember you yet. Spaced repetition arrives with accounts.

Check yourself

1. How many security requirements does CMMC Level 2 incorporate?
2. What determines which CMMC level applies to a given contract?
3. Which source document contains the assessment objectives used to determine whether a Level 2 requirement is met?

By QualExam editorial. Written against the awarding body’s published blueprint and checked against it on every build.

Source: ISACA CCA/CCP Exam Candidate Guide

Last checked against the source: 2026-09-22