CMMC Guide · Level 3
CMMC Level 3: Enhanced Requirements and DIBCAC Assessment
CMMC Level 3 is for companies that handle CUI on the Department of War’s most critical programs. It adds 24 enhanced requirements from NIST SP 800-172 on top of Level 2 and is assessed by the government’s DCMA DIBCAC team every three years. A Final Level 2 (C3PAO) status is required first.
Who needs CMMC Level 3?
Very few companies. The Department of War reserves Level 3 for contracts that support its most critical programs and technologies, where CUI is a likely target for advanced persistent threats. Program managers decide this; a company cannot be placed at Level 3 without a contract that requires it.
What does Level 3 add to Level 2?
The 24 additional requirements shift security from prevention toward detecting and responding to capable attackers:
| Area | Count | Focus |
|---|---|---|
| Risk Assessment | 7 | Threat-informed risk assessment, threat hunting, supply chain risk planning and response |
| Configuration Management | 3 | Authoritative component inventory and automated detection of unauthorized components |
| System and Information Integrity | 3 | Integrity checks, threat intelligence in monitoring, protection of specialized assets |
| Access Control | 2 | Company-owned resources only; controlled transfer between security domains |
| Awareness and Training | 2 | Threat-focused awareness training with practical, role-based exercises |
| Identification and Authentication | 2 | Cryptographic device authentication; only known components may connect |
| Incident Response | 2 | A security operations center and a cyber incident response team |
| Personnel Security, Security Assessment, System Protection | 1 each | Insider-risk actions, penetration testing, isolation of critical systems |
How does a Level 3 assessment work?
Hold Final Level 2 (C3PAO)
The same systems must first pass a third-party Level 2 certification assessment.
DIBCAC assesses Level 3
Government assessors check the 24 enhanced requirements. Self-assessment is not an option.
Close any open items
With at least 80% met, limited items may go on a plan of action for up to 180 days. Core capabilities such as the security operations center and incident response team cannot be deferred.
Maintain both levels
Repeat the Level 2 (C3PAO) and Level 3 assessments every three years, and affirm both every year.
Questions about CMMC Level 3
Can a company self-assess for Level 3?
No. Only DCMA DIBCAC, a government team, conducts Level 3 certification assessments, and only after the company holds a Final Level 2 (C3PAO) status for the same systems.
Does Level 3 replace Level 2?
No. Level 3 sits on top of Level 2. A company must keep its Level 2 (C3PAO) status current and affirm both levels every year to stay eligible for Level 3 contracts.
Supporting a critical program?
Talk to CMMCMARK about building the Level 2 foundation and the capabilities Level 3 will expect.
Prefer the phone? Call +1 (202) 867-8444.
Sources
- 32 CFR Part 170 (§ 170.5, § 170.14 table 1, § 170.18, § 170.21)
- NIST SP 800-172, Enhanced Security Requirements for Protecting CUI
- DoW CIO, Implementing Suspension of CMMC Phase II (July 13, 2026)
