The right CMMC level depends on your contract requirements and the information your systems handle—not the size of your company. A small subcontractor can have obligations beyond Level 1. A larger business should still begin by confirming the level and assessment type specified for its work.
For Austin and Houston defense contractors, that review should happen before purchasing a new platform or commissioning a large remediation project. BCS CMMC consulting services help connect your contract needs to a practical readiness scope.
Level 1 versus Level 2: the core difference
| Question | CMMC Level 1 | CMMC Level 2 |
|---|---|---|
| Information focus | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Security baseline | 15 safeguarding requirements in FAR 52.204-21 | 110 requirements in NIST SP 800-171 Revision 2 under the CMMC program |
| Assessment path | Annual contractor self-assessment | Self-assessment or authorized third-party assessment as specified in the solicitation; generally a three-year cycle |
| Affirmation | Annual affirmation | Annual affirmation |
Source: official contractor cybersecurity guidance. Review current program updates and your contract before relying on a rollout date or assessment assumption.
Start with three questions
- What does the solicitation or contract require? Collect the applicable clauses, statements of work, and customer instructions.
- What information will we receive or create? Ask your contracting officer or prime contractor to clarify uncertain handling requirements.
- Where will that information go? Follow the workflow through email, workstations, file shares, cloud services, remote users, and outside providers.
Do not select Level 1 simply because your business has ten employees or because your current software is marketed to small businesses.
For more detail and practical examples, read What Is FCI vs. CUI?.
What is FCI?
FCI is nonpublic information provided by or generated for the government under a contract to deliver a product or service. Publicly released information and simple payment-processing information are excluded from the FAR definition.
Illustrative example: An Austin supplier receives nonpublic delivery instructions for government contract work. The supplier should establish how those instructions are handled and confirm whether its contract requires Level 1. This example does not determine the status of your actual records.
What if our customer says we handle CUI?
That is a reason to review the Level 2 requirements and assessment path carefully. Ask for clear instructions about the information, permitted systems, and applicable contract obligations. An informal description such as “sensitive files” is not enough to define the entire project.
Illustrative example: A Houston subcontractor’s customer identifies a set of technical files as CUI and specifies Level 2 requirements. The next step is to map where those files will be used and agree on a compliant handling approach—not to assume Level 1 covers the work.
Does every Level 2 engagement require a third-party assessment?
The official program describes both Level 2 self-assessment and C3PAO assessment paths. Confirm the assessment type applicable to your solicitation and current implementation guidance. A generic checklist or another contractor’s experience cannot make that decision for your company.
What if different projects involve different information?
Bring the workflows into the scoping discussion. For example, your office may have general administration, contract files, and a separate technical project environment. Ask which systems support each workflow and where people transfer information between them.
BCS can help organize that inventory and identify questions requiring customer clarification. An intended separation should be reviewed and implemented; naming a folder “restricted” does not establish a system boundary.
Common mistakes when choosing a CMMC level
- Using company size as the deciding factor. Start with contractual obligations and information handling.
- Treating a software purchase as the complete solution. People, procedures, configurations, and evidence need to work together.
- Ignoring subcontractor instructions. Review the requirements passed to your business by the prime contractor.
- Preparing documentation before understanding the environment. Inventories and workflows help make the documentation accurate.
- Assuming readiness ends after an assessment. New accounts, devices, and services can change the environment.
How BCS helps Austin and Houston contractors
Business Communication Solutions offers CMMC consulting in Austin and Houston, with an initial focus on Level 1 readiness. We help with scope reviews, gap identification, remediation, documentation, and self-assessment preparation. Where your work involves Level 2, establish the required scope and assessment path before treating a Level 1 engagement as sufficient.
Our consulting can connect to hands-on cybersecurity and IT support. We can also work alongside your existing IT team on agreed tasks.
Need help defining your CMMC readiness scope?
Bring your contract requirements and an overview of your systems. We will discuss the review and implementation work your business needs.
Austin: 512-257-1433
Houston: 281-815-8784
Reference resources
- Official contractor cybersecurity guidance
- CMMC program updates
- FAR 52.204-21: FCI safeguarding and definition
BCS provides consulting and readiness support, not CMMC certification. Confirm contract interpretation and assessment obligations with the appropriate contracting authority.