Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CMMC Level 3 explained

CMMC Level 3: A Clear Guide to the 24 NIST 800-172 Requirements

CMMC Level 3 is the tier of the Cybersecurity Maturity Model Certification reserved for CUI in the programs the Department of Defense considers highest risk. It adds 24 enhanced security requirements selected from NIST SP 800-172 on top of the 110 requirements of Level 2, it can only be attempted by an organization that already holds a Final Level 2 (C3PAO) certification on the same scope, and it is assessed not by a C3PAO but by the government’s own Defense Industrial Base Cybersecurity Assessment Center. The July 2026 suspension of Phase 2 paused Level 3 requirements in contracts along with third-party Level 2 certification, but the rule that defines it is unchanged. This guide lists the 24 requirements as 32 CFR Part 170 sets them out, explains the prerequisite chain, the DIBCAC assessment, the POA&M limits and the scoping differences, and says who should be preparing for it despite the pause.

CMMC Level 3: 24 requirements from NIST SP 800-172, assessed by DIBCAC
Level 3 sits on a Final Level 2 (C3PAO) certification and adds 24 enhanced requirements across 10 families, with DoD-set parameters.

What CMMC Level 3 is for

The CMMC model at 32 CFR 170.14 draws on three sources: the fifteen FAR 52.204-21 requirements for Level 1, the 110 requirements of NIST SP 800-171 Revision 2 for Level 2, and “selected security requirements from NIST SP 800-172” for Level 3. SP 800-172 was written for CUI associated with critical programs and high value assets, where the adversary is assumed to be an advanced persistent threat that will get in, and the enhanced requirements are about penetration-resistant architecture, damage-limiting operations and cyber resiliency rather than baseline hygiene. DoD decides which contracts carry a Level 3 requirement; the rule expects them to be a small fraction of the industrial base.

The prerequisite: Final Level 2 (C3PAO) on the same scope

Section 170.18(a) is unambiguous: “A CMMC Status of Final Level 2 (C3PAO) for information systems within the Level 3 CMMC Assessment Scope is a prerequisite to undergo a Level 3 certification assessment.” Not Conditional Level 2, not Level 2 (Self) — Final Level 2 from a C3PAO, with any POA&M closed. Recertification carries the same chain: a new Level 2 certification assessment is required every three years to maintain Level 3, alongside the Level 3 assessment itself. Achieving Level 3 satisfies Level 1, Level 2 (Self) and Level 2 (C3PAO) for the same scope. Our guide to choosing a C3PAO covers the first link in that chain.

The 24 CMMC Level 3 requirements

Table 1 to 32 CFR 170.14(c)(4) lists the selected SP 800-172 requirements with DoD’s organization-defined parameters filled in. The families and requirements are:

ID Requirement (condensed, with DoD-set parameters)
AC.L3-3.1.2e Restrict access to systems and components to information resources owned, provisioned or issued by the organization
AC.L3-3.1.3e Employ secure information transfer solutions to control flows between security domains on connected systems
AT.L3-3.2.1e Awareness training on initial hire, after a significant cyber event and at least annually, focused on recognizing and responding to threats from social engineering, APT actors, breaches and suspicious behaviour
AT.L3-3.2.2e Practical exercises in awareness training for all users, tailored by role
CM.L3-3.4.1e An authoritative source and repository for approved and implemented system components
CM.L3-3.4.2e Automated mechanisms to detect misconfigured or unauthorized components; remove or quarantine on detection
CM.L3-3.4.3e Automated discovery and management tools for an up-to-date, complete, accurate component inventory
IA.L3-3.5.1e Identify and authenticate systems and components before network connection using cryptographically based bidirectional authentication, where possible
IA.L3-3.5.3e Mechanisms to prohibit components connecting unless known, authenticated, in a properly configured state or in a trust profile
IR.L3-3.6.1e A security operations center capability operating 24/7, with allowance for remote or on-call staff
IR.L3-3.6.2e A cyber incident response team deployable within 24 hours
PS.L3-3.9.2e Protect systems if adverse information develops about individuals with access to CUI
RA.L3-3.11.1e Threat intelligence from open or commercial sources and any DoD-provided sources, informing risk assessment and the development of systems and security architectures
RA.L3-3.11.2e Cyber threat hunting on an ongoing aperiodic basis or when indications warrant
RA.L3-3.11.3e Advanced automation and analytics supporting analysts to predict and identify risks
RA.L3-3.11.4e Document in the SSP the security solution selected, the rationale and the risk determination
RA.L3-3.11.5e Assess effectiveness of security solutions at least annually, on relevant threat information or after a relevant incident
RA.L3-3.11.6e Assess, respond to and monitor supply chain risks
RA.L3-3.11.7e A supply chain risk management plan, updated at least annually and on relevant threat information
CA.L3-3.12.1e Penetration testing at least annually or on significant security change, using automated tools and ad hoc tests by subject matter experts
SC.L3-3.13.4e Physical or logical isolation techniques, or both, in systems and components
SI.L3-3.14.1e Verify integrity of security-critical and essential software using root-of-trust mechanisms or cryptographic signatures
SI.L3-3.14.3e Specialized assets — IoT, IIoT, OT, GFE, restricted systems, test equipment — included in the scope of the enhanced requirements or segregated in purpose-specific networks
SI.L3-3.14.6e Use threat indicator information and mitigations from open, commercial and DoD sources to guide intrusion detection and threat hunting

Two things stand out from the list. Seven of the 24 are in the risk assessment family, and four of those are about supply chain and threat-informed decision-making — Level 3 is as much a governance tier as a technical one. And three requirements are standing capabilities rather than controls: a 24/7 SOC, a 24-hour-deployable incident response team, and continuous threat hunting. Those are what separate the cost of Level 3 from Level 2.

How the CMMC Level 3 assessment works

Assessed by DIBCAC

The Level 3 certification assessment “will be performed by DCMA DIBCAC on behalf of the DoD” — the same government assessment centre that assesses C3PAOs themselves. Results go into the CMMC instantiation of eMASS and from there automatically to SPRS. The record includes the result for each security requirement objective, the SSP name and version, and a hash of every artifact relied on.

All 24 must be MET, with a narrow POA&M

The OSC “must complete and achieve a MET result for all security requirements” in the table. A Conditional Level 3 with a POA&M is permitted only if the assessment score is at least 80% of the requirements and none of seven named requirements are on the POA&M: the SOC (3.6.1e), the incident response team (3.6.2e), threat-informed risk assessment (3.11.1e), supply chain risk response and plan (3.11.6e, 3.11.7e), security solution rationale (3.11.4e) and specialized asset security (3.14.3e). The POA&M must be closed by a DIBCAC closeout assessment within 180 days or the conditional status expires.

Every three years, on both levels

Level 3 must be re-assessed within three years of the status date, and because Final Level 2 (C3PAO) is the prerequisite, the Level 2 certification assessment must also be repeated every three years. Two assessments, two assessor types, one cycle. Affirmation by the Affirming Official is required after every assessment and annually thereafter under 170.22.

Level 3 scoping is stricter

The Level 2 scoping tables let Contractor Risk Managed Assets — systems that can but are not intended to handle CUI — sit in scope without being assessed if the SSP documents them adequately. Table 5 to 170.19(d)(1) removes that relief: at Level 3, assets that can but are not intended to handle CUI are treated as CUI Assets, receive a limited check against Level 2 and are assessed against all Level 3 requirements. Security Protection Assets are in scope “irrespective of whether or not these assets process, store, or transmit CUI”. And Specialized Assets, which Level 2 exempts from assessment, are the subject of their own Level 3 requirement (3.14.3e): include them or segregate them. Organizations that scoped Level 2 generously by relying on the CRMA category should expect the Level 3 scope to be larger. Our guide to CMMC scoping sets out the Level 2 categories the Level 3 table modifies.

What the 2026 suspension means for CMMC Level 3

On 13 July 2026 the Department of War suspended the transition to Phase 2 and “pending and future CMMC implementation milestones across the Department of War solicitations and contracts”, with a memo directing that active solicitations and contracts already carrying Level 2 (C3PAO) or Level 3 requirements be amended to remove them. Level 3 was scheduled to enter contracts in Phase 3 of the rollout; that milestone is now suspended along with Phase 2. The rule at 32 CFR Part 170 is untouched, DIBCAC still exists, and Level 1 and Level 2 self-assessment obligations continue. Our guide to the CMMC Phase 2 suspension tracks the review.

Who should still prepare: contractors on programs DoD has told them will carry Level 3, contractors whose primes are flowing Level 3 down contractually regardless of the pause, and anyone whose Level 2 environment already runs a SOC and threat hunting — because for them the gap is documentation and the DIBCAC schedule, not capability. Everyone else should hold Level 2 and wait for the review outcome before buying a 24/7 SOC.

Frequently asked questions

How many requirements does CMMC Level 3 add?
Twenty-four, selected from NIST SP 800-172 with DoD-set parameters, on top of the 110 Level 2 requirements. They span ten families, with seven in risk assessment.

Who assesses CMMC Level 3?
DCMA DIBCAC, the government’s Defense Industrial Base Cybersecurity Assessment Center — not a C3PAO. Results go to eMASS and SPRS.

Can we go straight to Level 3?
No. A Final Level 2 (C3PAO) certification on the same scope is a prerequisite, and it must be renewed every three years alongside the Level 3 assessment.

Is a POA&M allowed at Level 3?
Only if the score is at least 80% and none of seven named requirements — including the SOC, the incident response team and the supply chain plan — are on it, and only for 180 days.

Is Level 3 currently required in contracts?
No. The July 2026 suspension paused the Phase 2 transition and future milestones, including Level 3 requirements, and directed existing solicitations and contracts to remove them while DoD reviews the program.

Where this leaves you

CMMC Level 3 is a Final Level 2 (C3PAO) certification plus 24 enhanced requirements, three of which are standing operational capabilities, assessed by DIBCAC on a scope that no longer offers the risk-managed-asset relief. It is paused in contracts but intact in the rule. If your program is one DoD has named, keep the Level 2 certification current and build the SOC, threat hunting and supply chain plan now; if not, hold Level 2 and read the review when it lands.

References

More on CMMC

The policies and procedures behind all 110 Level 2 requirements, the SSP template and CUI scoping guide the Level 3 assessment builds on, and the incident response plan and POA&M procedure are in the CMMC Documentation Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.