CMMC Guide · Level 3

CMMC Level 3: Enhanced Requirements and DIBCAC Assessment

CMMC Level 3 is for companies that handle CUI on the Department of War’s most critical programs. It adds 24 enhanced requirements from NIST SP 800-172 on top of Level 2 and is assessed by the government’s DCMA DIBCAC team every three years. A Final Level 2 (C3PAO) status is required first.

Who needs CMMC Level 3?

Very few companies. The Department of War reserves Level 3 for contracts that support its most critical programs and technologies, where CUI is a likely target for advanced persistent threats. Program managers decide this; a company cannot be placed at Level 3 without a contract that requires it.

What does Level 3 add to Level 2?

The 24 additional requirements shift security from prevention toward detecting and responding to capable attackers:

AreaCountFocus
Risk Assessment7Threat-informed risk assessment, threat hunting, supply chain risk planning and response
Configuration Management3Authoritative component inventory and automated detection of unauthorized components
System and Information Integrity3Integrity checks, threat intelligence in monitoring, protection of specialized assets
Access Control2Company-owned resources only; controlled transfer between security domains
Awareness and Training2Threat-focused awareness training with practical, role-based exercises
Identification and Authentication2Cryptographic device authentication; only known components may connect
Incident Response2A security operations center and a cyber incident response team
Personnel Security, Security Assessment, System Protection1 eachInsider-risk actions, penetration testing, isolation of critical systems

How does a Level 3 assessment work?

  1. Hold Final Level 2 (C3PAO)

    The same systems must first pass a third-party Level 2 certification assessment.

  2. DIBCAC assesses Level 3

    Government assessors check the 24 enhanced requirements. Self-assessment is not an option.

  3. Close any open items

    With at least 80% met, limited items may go on a plan of action for up to 180 days. Core capabilities such as the security operations center and incident response team cannot be deferred.

  4. Maintain both levels

    Repeat the Level 2 (C3PAO) and Level 3 assessments every three years, and affirm both every year.

Questions about CMMC Level 3

Can a company self-assess for Level 3?

No. Only DCMA DIBCAC, a government team, conducts Level 3 certification assessments, and only after the company holds a Final Level 2 (C3PAO) status for the same systems.

Does Level 3 replace Level 2?

No. Level 3 sits on top of Level 2. A company must keep its Level 2 (C3PAO) status current and affirm both levels every year to stay eligible for Level 3 contracts.

Supporting a critical program?

Talk to CMMCMARK about building the Level 2 foundation and the capabilities Level 3 will expect.

Prefer the phone? Call +1 (202) 867-8444.

Sources