CMMC Level 3 is the tier of the Cybersecurity Maturity Model Certification reserved for CUI in the programs the Department of Defense considers highest risk. It adds 24 enhanced security requirements selected from NIST SP 800-172 on top of the 110 requirements of Level 2, it can only be attempted by an organization that already holds a Final Level 2 (C3PAO) certification on the same scope, and it is assessed not by a C3PAO but by the government’s own Defense Industrial Base Cybersecurity Assessment Center. The July 2026 suspension of Phase 2 paused Level 3 requirements in contracts along with third-party Level 2 certification, but the rule that defines it is unchanged. This guide lists the 24 requirements as 32 CFR Part 170 sets them out, explains the prerequisite chain, the DIBCAC assessment, the POA&M limits and the scoping differences, and says who should be preparing for it despite the pause.

What CMMC Level 3 is for
The CMMC model at 32 CFR 170.14 draws on three sources: the fifteen FAR 52.204-21 requirements for Level 1, the 110 requirements of NIST SP 800-171 Revision 2 for Level 2, and “selected security requirements from NIST SP 800-172” for Level 3. SP 800-172 was written for CUI associated with critical programs and high value assets, where the adversary is assumed to be an advanced persistent threat that will get in, and the enhanced requirements are about penetration-resistant architecture, damage-limiting operations and cyber resiliency rather than baseline hygiene. DoD decides which contracts carry a Level 3 requirement; the rule expects them to be a small fraction of the industrial base.
The prerequisite: Final Level 2 (C3PAO) on the same scope
Section 170.18(a) is unambiguous: “A CMMC Status of Final Level 2 (C3PAO) for information systems within the Level 3 CMMC Assessment Scope is a prerequisite to undergo a Level 3 certification assessment.” Not Conditional Level 2, not Level 2 (Self) — Final Level 2 from a C3PAO, with any POA&M closed. Recertification carries the same chain: a new Level 2 certification assessment is required every three years to maintain Level 3, alongside the Level 3 assessment itself. Achieving Level 3 satisfies Level 1, Level 2 (Self) and Level 2 (C3PAO) for the same scope. Our guide to choosing a C3PAO covers the first link in that chain.
The 24 CMMC Level 3 requirements
Table 1 to 32 CFR 170.14(c)(4) lists the selected SP 800-172 requirements with DoD’s organization-defined parameters filled in. The families and requirements are:
| ID | Requirement (condensed, with DoD-set parameters) |
|---|---|
| AC.L3-3.1.2e | Restrict access to systems and components to information resources owned, provisioned or issued by the organization |
| AC.L3-3.1.3e | Employ secure information transfer solutions to control flows between security domains on connected systems |
| AT.L3-3.2.1e | Awareness training on initial hire, after a significant cyber event and at least annually, focused on recognizing and responding to threats from social engineering, APT actors, breaches and suspicious behaviour |
| AT.L3-3.2.2e | Practical exercises in awareness training for all users, tailored by role |
| CM.L3-3.4.1e | An authoritative source and repository for approved and implemented system components |
| CM.L3-3.4.2e | Automated mechanisms to detect misconfigured or unauthorized components; remove or quarantine on detection |
| CM.L3-3.4.3e | Automated discovery and management tools for an up-to-date, complete, accurate component inventory |
| IA.L3-3.5.1e | Identify and authenticate systems and components before network connection using cryptographically based bidirectional authentication, where possible |
| IA.L3-3.5.3e | Mechanisms to prohibit components connecting unless known, authenticated, in a properly configured state or in a trust profile |
| IR.L3-3.6.1e | A security operations center capability operating 24/7, with allowance for remote or on-call staff |
| IR.L3-3.6.2e | A cyber incident response team deployable within 24 hours |
| PS.L3-3.9.2e | Protect systems if adverse information develops about individuals with access to CUI |
| RA.L3-3.11.1e | Threat intelligence from open or commercial sources and any DoD-provided sources, informing risk assessment and the development of systems and security architectures |
| RA.L3-3.11.2e | Cyber threat hunting on an ongoing aperiodic basis or when indications warrant |
| RA.L3-3.11.3e | Advanced automation and analytics supporting analysts to predict and identify risks |
| RA.L3-3.11.4e | Document in the SSP the security solution selected, the rationale and the risk determination |
| RA.L3-3.11.5e | Assess effectiveness of security solutions at least annually, on relevant threat information or after a relevant incident |
| RA.L3-3.11.6e | Assess, respond to and monitor supply chain risks |
| RA.L3-3.11.7e | A supply chain risk management plan, updated at least annually and on relevant threat information |
| CA.L3-3.12.1e | Penetration testing at least annually or on significant security change, using automated tools and ad hoc tests by subject matter experts |
| SC.L3-3.13.4e | Physical or logical isolation techniques, or both, in systems and components |
| SI.L3-3.14.1e | Verify integrity of security-critical and essential software using root-of-trust mechanisms or cryptographic signatures |
| SI.L3-3.14.3e | Specialized assets — IoT, IIoT, OT, GFE, restricted systems, test equipment — included in the scope of the enhanced requirements or segregated in purpose-specific networks |
| SI.L3-3.14.6e | Use threat indicator information and mitigations from open, commercial and DoD sources to guide intrusion detection and threat hunting |
Two things stand out from the list. Seven of the 24 are in the risk assessment family, and four of those are about supply chain and threat-informed decision-making — Level 3 is as much a governance tier as a technical one. And three requirements are standing capabilities rather than controls: a 24/7 SOC, a 24-hour-deployable incident response team, and continuous threat hunting. Those are what separate the cost of Level 3 from Level 2.
How the CMMC Level 3 assessment works
Assessed by DIBCAC
The Level 3 certification assessment “will be performed by DCMA DIBCAC on behalf of the DoD” — the same government assessment centre that assesses C3PAOs themselves. Results go into the CMMC instantiation of eMASS and from there automatically to SPRS. The record includes the result for each security requirement objective, the SSP name and version, and a hash of every artifact relied on.
All 24 must be MET, with a narrow POA&M
The OSC “must complete and achieve a MET result for all security requirements” in the table. A Conditional Level 3 with a POA&M is permitted only if the assessment score is at least 80% of the requirements and none of seven named requirements are on the POA&M: the SOC (3.6.1e), the incident response team (3.6.2e), threat-informed risk assessment (3.11.1e), supply chain risk response and plan (3.11.6e, 3.11.7e), security solution rationale (3.11.4e) and specialized asset security (3.14.3e). The POA&M must be closed by a DIBCAC closeout assessment within 180 days or the conditional status expires.
Every three years, on both levels
Level 3 must be re-assessed within three years of the status date, and because Final Level 2 (C3PAO) is the prerequisite, the Level 2 certification assessment must also be repeated every three years. Two assessments, two assessor types, one cycle. Affirmation by the Affirming Official is required after every assessment and annually thereafter under 170.22.
Level 3 scoping is stricter
The Level 2 scoping tables let Contractor Risk Managed Assets — systems that can but are not intended to handle CUI — sit in scope without being assessed if the SSP documents them adequately. Table 5 to 170.19(d)(1) removes that relief: at Level 3, assets that can but are not intended to handle CUI are treated as CUI Assets, receive a limited check against Level 2 and are assessed against all Level 3 requirements. Security Protection Assets are in scope “irrespective of whether or not these assets process, store, or transmit CUI”. And Specialized Assets, which Level 2 exempts from assessment, are the subject of their own Level 3 requirement (3.14.3e): include them or segregate them. Organizations that scoped Level 2 generously by relying on the CRMA category should expect the Level 3 scope to be larger. Our guide to CMMC scoping sets out the Level 2 categories the Level 3 table modifies.
What the 2026 suspension means for CMMC Level 3
On 13 July 2026 the Department of War suspended the transition to Phase 2 and “pending and future CMMC implementation milestones across the Department of War solicitations and contracts”, with a memo directing that active solicitations and contracts already carrying Level 2 (C3PAO) or Level 3 requirements be amended to remove them. Level 3 was scheduled to enter contracts in Phase 3 of the rollout; that milestone is now suspended along with Phase 2. The rule at 32 CFR Part 170 is untouched, DIBCAC still exists, and Level 1 and Level 2 self-assessment obligations continue. Our guide to the CMMC Phase 2 suspension tracks the review.
Who should still prepare: contractors on programs DoD has told them will carry Level 3, contractors whose primes are flowing Level 3 down contractually regardless of the pause, and anyone whose Level 2 environment already runs a SOC and threat hunting — because for them the gap is documentation and the DIBCAC schedule, not capability. Everyone else should hold Level 2 and wait for the review outcome before buying a 24/7 SOC.
Frequently asked questions
How many requirements does CMMC Level 3 add?
Twenty-four, selected from NIST SP 800-172 with DoD-set parameters, on top of the 110 Level 2 requirements. They span ten families, with seven in risk assessment.
Who assesses CMMC Level 3?
DCMA DIBCAC, the government’s Defense Industrial Base Cybersecurity Assessment Center — not a C3PAO. Results go to eMASS and SPRS.
Can we go straight to Level 3?
No. A Final Level 2 (C3PAO) certification on the same scope is a prerequisite, and it must be renewed every three years alongside the Level 3 assessment.
Is a POA&M allowed at Level 3?
Only if the score is at least 80% and none of seven named requirements — including the SOC, the incident response team and the supply chain plan — are on it, and only for 180 days.
Is Level 3 currently required in contracts?
No. The July 2026 suspension paused the Phase 2 transition and future milestones, including Level 3 requirements, and directed existing solicitations and contracts to remove them while DoD reviews the program.
Where this leaves you
CMMC Level 3 is a Final Level 2 (C3PAO) certification plus 24 enhanced requirements, three of which are standing operational capabilities, assessed by DIBCAC on a scope that no longer offers the risk-managed-asset relief. It is paused in contracts but intact in the rule. If your program is one DoD has named, keep the Level 2 certification current and build the SOC, threat hunting and supply chain plan now; if not, hold Level 2 and read the review when it lands.
References
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification Program — §170.14(c)(4) Table 1 (the 24 requirements), §170.18 Level 3 assessment, §170.19(d) Level 3 scoping, §170.21 POA&Ms.
- NIST SP 800-172 — Enhanced Security Requirements for Protecting CUI — The source of the Level 3 requirements.
More on CMMC
- CMMC Level 3 — you are here
- CMMC compliance: the phased rollout
- CMMC Level 1: the 15 requirements
- C3PAO: choosing a CMMC assessor
- CMMC scoping: the five asset categories
- CMMC vs NIST 800-171
The policies and procedures behind all 110 Level 2 requirements, the SSP template and CUI scoping guide the Level 3 assessment builds on, and the incident response plan and POA&M procedure are in the CMMC Documentation Toolkit, or start with the free templates.