CMMC Requirements Header

CMMC Requirements for Subcontractors & Vendors

CAPE helps vendors understand whether they need CMMC Level 1 or Level 2 based on the information they handle.

Review Official Resources      Contact CAPE

Which CMMC level do you need?

Level 1

For FCI only

Level 1 applies when a subcontractor handles Federal Contract Information (FCI) and requires annual self-assessment and affirmation in SPRS.

Start your Level 1 certification here

Level 2

For CUI

Level 2 applies when a subcontractor will receive, store, transmit, or process Controlled Unclassified Information (CUI).

Quick Decision Guide

 

  You may need Level 1 if...
  • You handle Federal Contract Information (FCI) only.
  • You review contracts, POAs, invoices, or other FCI.
  • You do not receive, store, transmit, or process CUI.
  You may need Level 2 if...
  • You receive CUI by email or other means.
  • You store CUI in company systems, cloud storage, or devices.
  • You transmit CUI to others.
  • You process or work with CUI in any way.
  Not allowed with Level 1only...
  • Downloading CUI.
  • Printing CUI.
  • Storing CUI on any device or system.
  • Editing or working with CUI locally.
  • Transmitting CUI to others.

Important: Level 1 does not authorize handling CUI

Level 1 vendors should not receive, store, transmit, print, or locally edit CUI. With Level 1, you may only view CUI in limited CAPE-controlled situations as directed by your contract.

What vendors should be prepared to provide:

 

CMMC status

Confirm your required CMMC level (Level 1 or Level 2).

SPRS confirmation

Provide confirmation of your SPRS registration.

Assessment evidence

Provide self-assessment results (Level 1) or assessment reports (Level 2).

SSP / Policies

Submit your System Security Plan (SSP) or policies as applicable.

No CUI with Level 1

Confirm you will not handle CUI unless Level 2 applies.

 

Official resources

  DLA Cybersecurity Resources→   32 CFR 170.15 Level 1 Requirements→   DoD CMMC Program Resources→   SPRS→   Cyber AB Marketplace→

 

Error Message