Common Cyber
Which CMMC Level Applies to You?
Your CMMC level is set by your contract and the information you handle, not by preference. An organization may choose to meet a higher requirement than its contract sets. It cannot choose a lower one.
What decides your CMMC level?
Three things: the clauses in your contract, whether you receive Federal Contract Information or Controlled Unclassified Information, and the rules in force at the time of award.
The FAA certificate you hold, the size of your company, and the number of defense contracts you have do not decide it. Neither does what your prime tells you informally. Determining which level applies is the first thing an assessment establishes, and it is subject to discovery and validation.
What is CMMC Level 1?
Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21. It applies to organizations that handle Federal Contract Information but not Controlled Unclassified Information.
Level 1 is a self-assessment, performed annually and affirmed in SPRS. All 15 requirements must be assessed as met or not applicable. There is no POA&M at Level 1, so a requirement that is not met cannot be carried forward. No third-party assessor is involved.
For a small supplier or repair station this is a smaller scope than Level 2 and a shorter path. The affirmation still carries accountability for its accuracy.
What is CMMC Level 2?
Level 2 covers all 110 requirements in NIST SP 800-171 Revision 2. There are two ways to meet it, and your contract decides which one applies.
Self-assessment. Your organization performs the assessment, and your Affirming Official submits the affirmation in SPRS. No third-party assessor is involved.
Certification. An authorized C3PAO performs the assessment. Common Cyber is not a C3PAO and does not perform certification assessments.
Both paths cover the same 110 requirements, and each one has to be supported by evidence. The CMMC Assessment Guide for Level 2 states that organizations conducting a self-assessment are expected to evaluate compliance using the same criteria used for third-party assessments. What changes is who performs the assessment.
A final status requires every applicable requirement to be met. Where some are still open, the rule allows a conditional status within defined limits. Certain requirements cannot be deferred at all, and the plan of action must be closed out within 180 days or the conditional status expires.
What is CMMC Level 3?
Level 3 applies to a limited set of programs handling the most sensitive information. It requires a Level 2 certification first, adds further requirements, and is assessed by the Government rather than by a C3PAO.
Common Cyber does not perform Level 3 assessments.
Where does Common Cyber fit?
On the Level 1 and Level 2 self-assessment paths, Common Cyber provides experienced execution capacity across the full path: establishing the boundary, closing gaps, building evidence, and preparing the self-assessment record. Your organization performs the self-assessment and your Affirming Official submits the affirmation.
Engaging outside help does not change what the assessment is. The CMMC Assessment Guide for Level 1 states that an organization may perform the annual self-assessment internally or engage a third party to assist, and that using a third party is still considered a self-assessment.
On the certification path, we prepare you for the C3PAO and the assessment decision remains theirs.
Common Cyber is not a C3PAO and does not perform certification assessments.
Frequently asked questions
Do I need a C3PAO, or can we self-assess?
That is set by your contract and the information you handle, not by preference. Level 1 and the Level 2 self-assessment path involve no third-party assessor. Level 2 certification requires an authorized C3PAO. You may meet more than your contract requires; you cannot meet less.
How many controls are in CMMC Level 1?
Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21. All 15 must be assessed as met or not applicable, and there is no POA&M at Level 1. The assessment is self-performed annually and affirmed in SPRS.
How many controls are in CMMC Level 2?
Level 2 covers all 110 requirements in NIST SP 800-171 Revision 2. The count is the same whether the level is met by self-assessment or by a C3PAO assessment.
Does a self-assessment mean less work?
No. The assessor changes. The requirements do not. Every requirement still has to be implemented, every implementation still has to be evidenced, and the affirmation is a statement your senior official is accountable for. An assessment that cannot survive a question is worse than no assessment, because it is on the record.
What if our requirement changes to certification later?
Level 2 rests on the same 110 requirements whether it is self-assessed or assessed by a C3PAO. Requirements you have met and evidence you have built carry forward. A C3PAO applies its own independent judgment to scope and to the sufficiency of evidence, so some rework should be assumed. Building the evidence properly now is designed to shorten a later certification assessment and reduce its uncertainty.
Can Common Cyber take us through a self-assessment?
On the Level 1 and Level 2 self-assessment paths, yes. The CMMC Assessment Guide for Level 1 states that an organization may perform the annual self-assessment internally or engage a third party to assist, and that using a third party is still considered a self-assessment. We support the work up to the point of self-assessment and affirmation, which your organization performs and your Affirming Official submits in SPRS. Common Cyber is not a C3PAO and does not perform certification assessments.
Who signs the affirmation?
Your organization's Affirming Official submits it in SPRS and is accountable for its accuracy. That responsibility cannot be transferred to a services provider, and no provider should offer to take it.
How do we find out which level applies to us?
The CMMC Readiness and Scope Assessment establishes applicability, scope, and where you stand against the requirements, and produces a prioritized statement of work. It has a fixed fee of $30,000. Applicability findings are subject to discovery, validation, and the specifics of your contracts, systems, and information environment.
Is it still a self-assessment if we bring in outside help?
Yes. The CMMC Assessment Guide for Level 1 states that an organization may perform the annual self-assessment internally or engage a third party to assist, and that using a third party is still considered a self-assessment. It does not produce a certification. At Level 2, the Assessment Guide states that a self-assessment is evaluated using the same criteria used for third-party assessments. Your organization remains responsible for the assessment, and your Affirming Official submits the affirmation.
A clear next step
Define the boundary before you build.
The fixed-fee assessment clarifies what is in scope and turns the findings into a practical statement of work.
Start an Assessment