CMMC Level 3 Explained: Who Needs It and What It Takes
Most CMMC coverage stops at Level 2, and for good reason: that is where the vast majority of defense contractors land. But the question keeps coming up in readiness conversations: "What about Level 3? Do we need it? Should we plan for it?" The short answer for most companies is no, and knowing why is worth ten minutes. Because if a program you support ever does require Level 3, the path runs directly through the work you are doing right now: a clean, final Level 2.
| Factor | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Information handled | FCI | CUI | CUI on the most sensitive programs |
| Requirements | 17 practices (FAR 52.204-21) | 110 (NIST SP 800-171 Rev 2) | 110 + 24 (NIST SP 800-172 subset) |
| Assessed by | Annual self-attestation | Self-assessment or C3PAO | Government (DCMA DIBCAC) |
| Prerequisite | None | None | Final Level 2 certification, same scope |
| Validity | Annual | 3 years + annual affirmation | 3 years + annual affirmation |
| Who needs it | Nearly every DoW contractor | Most CUI handlers | A small set of designated programs |
What CMMC Level 3 Actually Is
Level 3, the Expert tier of CMMC 2.0, exists for one reason: some defense programs handle information so sensitive that the baseline protections of NIST SP 800-171 are not considered enough against a well-resourced, persistent adversary. For those programs, the Department of War layers on a selected set of 24 enhanced security requirements from NIST SP 800-172, the companion publication written specifically to counter Advanced Persistent Threats (APTs).
Where 800-171 asks "are the doors locked and monitored," 800-172 asks harder questions: can you keep operating while a capable adversary is actively working against you? The enhanced requirements push into areas like threat hunting, penetration-resistant architecture, and cyber resiliency, disciplines that assume compromise will be attempted and build for it.
The Prerequisite: A Final Level 2 Certification
Before a Level 3 assessment can even be scheduled, you must hold a final CMMC Level 2 certification(from a C3PAO assessment) covering the same scope. Final means final: a conditional Level 2 certification with an open POA&M does not qualify. Every one of the 110 requirements has to be closed out for the environment in question.
This is why "should we plan for Level 3?" almost always resolves to the same answer: get Level 2 fully done first. Whatever your eventual ceiling, the floor is identical, and the contractors who will be ready for Level 3 when a program requires it are the ones whose Level 2 house is already in order.
The 24 Enhanced Requirements: What They Cover
The Level 3 requirement set is a DoW-selected subset of NIST SP 800-172, 24 requirements in all. Without walking every control, the themes are consistent:
- Penetration-resistant architecture: network and system design that limits how far an intruder can move even after an initial foothold
- Threat awareness and hunting: actively looking for adversaries in your environment rather than waiting for alerts, and feeding current threat intelligence into defenses
- Advanced access and supply chain controls: stronger identity proofing, and scrutiny of the components and services your systems depend on
- Cyber resiliency: the ability to fight through an attack, preserving essential functions while a compromise is contained and eradicated
Each requirement is scored at one point, for a maximum of 24. Conditional Level 3 status requires meeting at least 80 percent of the requirements, with anything remaining limited to POA&M-eligible items closed within 180 days, the same closeout discipline Level 2 uses.
The Assessment: Government-Led, Not C3PAO
The single biggest procedural difference at Level 3: you do not hire the assessor. Level 3 assessments are conducted by the government itself, specifically the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC), the same organization that has run the DoD's highest-rigor NIST SP 800-171 assessments for years.
A Level 3 certification is valid for three years and, like Level 2, requires an annual affirmation of continuing compliance by a senior company official. The affirmation carries the same False Claims Act weight it does at every other level: it is a representation to the government, not a formality.
Who Actually Needs Level 3 (and Who Does Not)
The honest answer: very few companies. Level 3 applies only where the DoW designates a program as requiring it, typically programs whose CUI is of the highest sensitivity and where APT targeting is a named concern. You do not decide you need Level 3, and you cannot be surprised by it: if a contract requires Level 3, the solicitation will say so explicitly.
Signals that Level 3 could eventually be in your future:
- You support programs your customers describe as high-priority or APT-targeted
- Your prime has raised 800-172 or "enhanced requirements" in flow-down conversations
- You handle CUI tied to critical defense technologies or platforms
Signals that Level 2 is your ceiling (true for most CUI handlers): none of your contracts or primes have ever mentioned Level 3, your work touches standard categories of CUI, and your contracting officers point you at DFARS 252.204-7012 and the 110 requirements. In that case, plan and budget for Level 2, and treat Level 3 as a fact worth understanding rather than a requirement worth chasing.
Know Where You Stand at Every Level
The practical takeaway is a sequence, not a choice. Level 1 is the floor: 17 basic safeguarding practices that every DoW contractor must meet and self-attest annually, with no POA&M allowance. Level 2 is the main event for anyone handling CUI: 110 requirements, an SPRS score, and an 88-point conditional line. Level 3 is a designated-program layer on top, government-assessed, and unreachable until Level 2 is final.
That is exactly how our assessment reports your results: because the Level 1 practices are a strict subset of the 110, a completed Level 2 assessment tells you your Level 1 standing exactly, your Level 2 SPRS estimate and certification outlook, and whether the Level 3 prerequisite is met. One assessment, three answers, no guessing about which conversation to have with your contracting officer.
WHERE DO YOU STAND?
See Your Level 1, 2, and 3 Standing — Free
The free Dragonfli Pulse Check takes ten minutes and shows your directional standing at every CMMC level. The full assessment computes it exactly, across all 110 requirements. No credit card required.
Start Free Pulse Check →