CMMC Level 3 represents the highest level of cybersecurity assurance in the current Cybersecurity Maturity Model Certification framework. It is intended for selected defense programs where Controlled Unclassified Information requires additional protection against sophisticated adversaries. Level 3 does not replace Level 2. An organization must first establish a fully compliant Level 2 environment and then add enhanced cybersecurity capabilities focused on advanced threats, cyber resiliency, threat hunting, supply chain risk, security operations, and incident response. The framework remains defined in federal regulation in 2026, but contractors also need to understand the distinction between those regulatory requirements and the current CMMC implementation suspension.
In This Guide
- 01
What Is CMMC Level 3? - 02
Who Needs CMMC Level 3? - 03
What Is the Current Status of CMMC Level 3 in 2026? - 04
What Are the CMMC Level 3 Requirements? - 05
CMMC Level 2 vs. Level 3: What Is the Difference? - 06
What Is Included in the CMMC Level 3 Assessment Scope? - 07
How Does the CMMC Level 3 Assessment Process Work? - 08
How Is a CMMC Level 3 Assessment Conducted? - 09
How Does CMMC Level 3 Scoring and Conditional Status Work? - 10
How Long Does CMMC Level 3 Certification Last? - 11
What Are the Biggest Challenges With CMMC Level 3? - 12
How Should Contractors Prepare for CMMC Level 3? - 13
How Nexeris Helps Contractors Prepare for CMMC Level 3 - 14
Frequently Asked Questions
What Is CMMC Level 3?
CMMC Level 3 is the highest level in the current CMMC model and is intended for selected defense programs involving CUI that requires enhanced protection against Advanced Persistent Threats. It requires Final Level 2 (C3PAO) status, 24 selected NIST SP 800-172 requirements, and a government-led assessment performed by DCMA DIBCAC. The simplest way to understand the structure is: CMMC Level 3 = Final Level 2 (C3PAO) + 24 selected NIST SP 800-172 requirements + DCMA DIBCAC assessment. The Level 2 foundation consists of all 110 NIST SP 800-171 Revision 2 security requirements. Level 3 then adds 24 enhanced requirements selected from the February 2021 edition of NIST SP 800-172. This produces a combined cybersecurity baseline of 134 security requirements, although the Level 3 certification assessment itself specifically evaluates the 24 additional Level 3 requirements while retaining the fully implemented Level 2 environment as a prerequisite.
CMMC Level 3 at a Glance
| Factor | CMMC Level 3 |
|---|---|
| Purpose | Higher-level protection of CUI against Advanced Persistent Threats |
| Prerequisite | Final Level 2 (C3PAO) |
| Level 2 baseline | 110 NIST SP 800-171 Rev. 2 requirements |
| Additional requirements | 24 selected NIST SP 800-172 requirements |
| Combined security baseline | 134 requirements |
| Level 3 assessor | DCMA DIBCAC |
| Assessment frequency | Every three years |
| Affirmation | Annually |
| POA&M | Limited use permitted |
| Information protected | Selected CUI requiring enhanced protection against sophisticated threats |
Federal regulations require Final Level 2 (C3PAO) before an organization can begin a Level 3 certification assessment. They also specify DCMA DIBCAC as the government assessor and require Level 3 reassessment every three years, along with annual affirmation.
Who Needs CMMC Level 3?
CMMC Level 3 is not the default requirement for every organization that handles Controlled Unclassified Information. Most contractors that need to protect CUI fall under CMMC Level 2. Level 3 is reserved for selected programs where the government determines that the information, mission, or threat environment justifies stronger protection.
Which Defense Contracts Require Level 3?
Whether CMMC Level 3 applies is determined by the cybersecurity requirement associated with a specific solicitation or contract. Company size does not determine the level. A small contractor could potentially support highly sensitive work requiring advanced protection, while a very large organization could work on contracts requiring only Level 1 or Level 2. Contracting officers include the applicable CMMC level specified by the program office or requiring activity in covered solicitations and contracts. Factors that can influence the required level include:
- The sensitivity of the CUI involved
- The defense program being supported
- Threats associated with the program
- Mission criticality
- Acquisition requirements
- Government risk determinations
The organization should therefore start with its actual contract requirements rather than choosing a CMMC level based on assumptions.
Why Only a Small Portion of the Defense Industrial Base Needs Level 3
Level 3 is designed around a different threat problem than the one addressed by ordinary CUI protection. NIST SP 800-172 was created to supplement the baseline requirements used for protecting CUI when that information is connected with critical programs or high-value assets and requires protection from Advanced Persistent Threats. NIST describes APTs as sophisticated adversaries with significant expertise and resources that may use multiple attack vectors, maintain persistent access, adapt to defensive measures, and pursue objectives over extended periods. That level of threat does not apply equally to every DoD procurement. Level 3 therefore focuses on selected higher-risk programs rather than becoming the expected certification target for the entire Defense Industrial Base.
How Do Contractors Know Whether Level 3 Applies?
Contractors should review the CMMC requirement stated in the applicable:
- Solicitation
- Contract
- Task or delivery order
- Prime contractor flow-down
- Cybersecurity requirement documentation
If the requirement is unclear, the organization should confirm it with the contracting or requiring activity, or with the prime contractor where applicable. Handling CUI by itself should not be interpreted as an automatic CMMC Level 3 trigger. In fact, the regulation contains important distinctions for subcontractors. Even where a prime contract requires Level 3, the regulatory minimum for a subcontractor processing CUI may be Level 2 (C3PAO), unless the government provides other specific guidance.
What Is the Current Status of CMMC Level 3 in 2026?
Understanding CMMC Level 3 in 2026 requires separating two issues:
- What the CMMC regulation defines.
- What assessment requirements may currently be introduced through procurements during the implementation suspension.
The Level 3 framework has not simply disappeared. Its regulatory requirements remain defined in 32 CFR Part 170. However, the planned procurement rollout has changed.
How the July 2026 CMMC Suspension Affects Level 3
On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to begin on November 10, 2026. Phase I self-assessment requirements remain in effect while the CMMC program undergoes review. The accompanying implementation direction also held pending and future CMMC implementation milestones in abeyance during the review. This means previously published future Phase II, Phase III, and Level 3 rollout dates should not be treated as active contractor deadlines. This creates an important distinction: The Level 3 framework still exists in regulation. Its broader procurement implementation is currently paused. Contractors should therefore avoid relying on older CMMC articles that describe previously scheduled Level 3 rollout dates as though those dates were still active.
What Requirements Still Apply During the Suspension?
The July suspension did not erase the cybersecurity obligations that already apply through contracts and Phase I. Phase I self-assessment requirements remain active, and applicable contractors may still have obligations involving:
- NIST SP 800-171 Revision 2
- DFARS 252.204-7012
- CUI safeguarding
- Applicable self-assessments
- SPRS information
- Cyber incident reporting
- Flow-down requirements
Organizations can review the current CMMC Phase 2 suspension for a more detailed explanation of what remains in force and what has been paused. The practical lesson for organizations that may eventually pursue Level 3 is not to stop building cybersecurity maturity. The timetable changed, but developing a fully mature Level 2 environment and advanced threat capabilities remains a significant undertaking.
What Are the CMMC Level 3 Requirements?
CMMC Level 3 combines a fully implemented Level 2 foundation with 24 selected enhanced requirements. It is not an independent security framework that allows an organization to skip Level 2.
Final CMMC Level 2 Is a Prerequisite
One of the most important CMMC Level 3 certification requirements is achieving Final Level 2 (C3PAO) status first. A Level 2 self-assessment does not satisfy this prerequisite. Conditional Level 2 status is also insufficient when unresolved POA&M items remain. The organization must close applicable Level 2 deficiencies and achieve Final Level 2 (C3PAO) status for the information systems that will fall within the Level 3 assessment scope before DCMA DIBCAC can begin the Level 3 certification assessment. The Level 3 scope must also be equal to or a subset of the Level 2 certification scope. Organizations that need a deeper understanding of the underlying baseline should first review the CMMC Level 2 requirements before planning their Level 3 program.
110 Requirements From NIST SP 800-171 Rev. 2
The Level 2 foundation includes all 110 NIST SP 800-171 Revision 2 security requirements. These address areas such as:
- Access control
- Authentication
- Configuration management
- Logging
- Incident response
- Risk assessment
- Security assessment
- Media protection
- Physical security
- System integrity
- Communications protection
By the time an organization reaches Level 3 assessment readiness, these controls should already be fully implemented and supported by assessment evidence. Level 3 is therefore built on top of an operational Level 2 environment, not a partially completed Level 2 project.
24 Additional Requirements From NIST SP 800-172
CMMC Level 3 adds 24 selected requirements from NIST SP 800-172. The math is straightforward:
110 Level 2 requirements + 24 Level 3 requirements = 134 requirements supporting the complete Level 3 cybersecurity environment.
However, saying that Level 3 contains “134 controls” can sometimes create confusion. The Level 3 certification assessment specifically scores the 24 additional selected requirements. Full Level 2 implementation has already been demonstrated through the prerequisite Level 2 C3PAO certification and remains subject to government verification during the Level 3 process.
What Are the 24 CMMC Level 3 Requirements Designed to Do?
The 24 requirements are better understood by their security objectives than as an unexplained checklist. They address advanced capabilities across several areas.
Organizationally controlled assets and secure information movement
AC.L3-3.1.2e restricts access to organizational systems to resources owned, provisioned, or issued by the organization. AC.L3-3.1.3e addresses secure information transfer between security domains. These requirements reduce exposure created by unmanaged technologies and uncontrolled information paths.
Advanced security awareness
Level 3 training goes beyond general annual awareness. It includes training based on current social engineering, advanced threat, breach, and suspicious-behavior scenarios, along with role-specific practical exercises.
Authoritative configuration and asset management
Requirements CM.L3-3.4.1e through CM.L3-3.4.3e focus on maintaining authoritative information about approved system components, automatically identifying misconfigured or unauthorized devices, and using automated discovery to maintain an accurate inventory. The objective is to make it harder for unmanaged, unauthorized, or incorrectly configured technology to remain unnoticed.
System and component authentication
Enhanced identification requirements address authentication between systems and the prevention of unauthorized or untrusted components from connecting to organizational environments.
Security Operations Center capability
IR.L3-3.6.1e requires a Security Operations Center capability operating 24/7, with allowance for remote or on-call personnel. That moves Level 3 toward continuous operational security rather than periodic compliance activity.
Cyber Incident Response Team capability
IR.L3-3.6.2e requires an incident response team that the organization can deploy within 24 hours. The organization must be capable of responding rapidly when sophisticated incidents occur.
Threat-informed risk assessment
RA.L3-3.11.1e requires threat intelligence to inform risk assessments and decisions involving architecture, security solutions, monitoring, threat hunting, response, and recovery.
Threat hunting
RA.L3-3.11.2e introduces proactive hunting for indicators of compromise and threats that may have avoided existing defensive controls.
Advanced analytics
Level 3 includes the use of advanced automation and analytics to help analysts identify and predict security risks.
Security solution rationale
The organization must document why security solutions were selected and how risk considerations informed those decisions.
Supply chain risk management
Level 3 requires organizations to assess, respond to, monitor, and formally plan for risks arising through their technology and system-component supply chains.
Penetration testing
Annual penetration testing, as well as testing after significant security changes, becomes part of the enhanced protection strategy.
Isolation and resiliency
Level 3 includes stronger physical or logical isolation approaches intended to limit adversary movement and damage.
Software integrity
Security-critical and essential software must have integrity verified through mechanisms such as cryptographic signatures or roots of trust.
Specialized asset protection
IoT, IIoT, OT, Government Furnished Equipment, Restricted Information Systems, and test equipment receive specific enhanced treatment.
Threat-informed intrusion detection
Threat indicators and mitigation information from commercial, open, and DoD-provided sources must inform intrusion detection and threat-hunting activities. These selected requirements are defined directly in the CMMC regulation.
How NIST SP 800-172 Supports Protection Against Advanced Persistent Threats
NIST SP 800-171 provides a strong baseline for protecting CUI, but it was not designed by itself to address every challenge created by highly sophisticated adversaries. NIST SP 800-172 supplements that baseline with enhanced requirements intended to strengthen:
- Resistance to attack
- Detection of hidden adversaries
- Cyber resiliency
- Damage limitation
- Threat-informed security decisions
- Recovery
- Survivability
- Defensive adaptation
NIST describes the original SP 800-172 strategy as combining penetration-resistant architecture, damage-limiting operations, and cyber resiliency and survivability. One 2026 point deserves clarification. NIST released SP 800-172 Revision 3 and SP 800-172A Revision 3 in May 2026. However, the current CMMC regulation still specifically incorporates the February 2021 SP 800-172 and March 2022 SP 800-172A editions for CMMC Level 3. Contractors should not independently substitute the new NIST revisions for the versions incorporated into CMMC unless the applicable regulations or contractual requirements are updated.
CMMC Level 2 vs. Level 3: What Is the Difference?
| Area | CMMC Level 2 | CMMC Level 3 |
|---|---|---|
| Primary purpose | Broad protection of CUI | Enhanced protection of selected CUI against APTs |
| Security baseline | NIST SP 800-171 Rev. 2 | Level 2 plus selected NIST SP 800-172 requirements |
| Requirements | 110 | 110 + 24 |
| Assessment | Self or C3PAO depending on applicable requirement | DCMA DIBCAC |
| Level 2 prerequisite | N/A | Final Level 2 (C3PAO) |
| Assessment cycle | Three years for applicable Level 2 assessments | Three years |
| Annual affirmation | Yes | Yes |
| POA&M | Limited | Limited with additional Level 3 restrictions |
| Typical applicability | Organizations handling applicable CUI | Selected higher-risk CUI and defense programs |
Why Level 3 Is More Than a More Difficult Level 2
It is tempting to think of CMMC Level 3 as simply Level 2 with 24 extra controls. That misses the bigger difference. Level 2 primarily establishes a strong cybersecurity baseline for protecting CUI. Level 3 assumes that baseline already works and then introduces capabilities intended to address adversaries capable of bypassing conventional defenses. That is why Level 3 emphasizes areas such as:
- Threat hunting
- Threat intelligence
- 24/7 security operations
- Rapid incident response
- Penetration testing
- Automated asset discovery
- Supply chain risk
- Stronger isolation
- Specialized asset protections
- Advanced analytics
The security program becomes more proactive and adversary-focused.
Why a C3PAO Cannot Issue Your Level 3 Status
C3PAOs have an important role in CMMC, but that role does not extend to performing Level 3 certification assessments. A C3PAO conducts applicable Level 2 certification assessments. A Level 3 assessment is conducted by DCMA DIBCAC on behalf of the government. Federal regulations explicitly assign Level 3 certification assessments to DCMA DIBCAC. The C3PAO’s role is still essential because Final Level 2 (C3PAO) status must be achieved first.
What Is Included in the CMMC Level 3 Assessment Scope?
CMMC Level 3 scoping determines which assets, services, systems, networks, and technologies must be considered during assessment. An organization should define this boundary before it begins formal assessment preparation. The regulation divides Level 3 assets into several categories.
CUI Assets
CUI Assets include systems and other assets that process, store, or transmit Controlled Unclassified Information. For Level 3, assets that can process, store, or transmit CUI but are intended not to do so because of risk-management practices are also treated within the CUI Asset category. Organizations must document applicable assets in:
- Asset inventories
- The System Security Plan
- Network diagrams
CUI Assets should be prepared for Level 3 assessment and may also receive limited verification of underlying Level 2 requirements.
Security Protection Assets
Security Protection Assets provide security capabilities to the CMMC environment. Examples may include:
- Firewalls
- SIEM platforms
- Endpoint security tools
- Identity systems
- Vulnerability-management platforms
- Security monitoring systems
- Authentication infrastructure
A Security Protection Asset can fall inside the CMMC assessment scope even if it does not itself process or store CUI. Its role in protecting the environment makes it relevant. At Level 3, these assets can be evaluated against Level 3 requirements relevant to the capabilities they provide, along with limited Level 2 verification.
Specialized Assets
Specialized Assets can include:
- Operational Technology
- Internet of Things devices
- Industrial Internet of Things
- Government Furnished Equipment
- Restricted Information Systems
- Test equipment
These technologies often cannot be secured in exactly the same way as conventional IT assets. That does not automatically put them outside the assessment. At Level 3, they must be identified, documented, reflected in network diagrams, and addressed in accordance with applicable security requirements and specialized-asset treatment.
Out-of-Scope Assets
An asset may remain outside the Level 3 assessment scope when it:
- Cannot process, store, or transmit CUI
- Does not provide security protection for CUI Assets
- Is appropriately separated from CUI systems
The organization should still be capable of explaining and supporting why the asset cannot interact with CUI. Simply labeling a device “out of scope” is not sufficient if the architecture allows it to access CUI or protect systems that do. A fuller explanation of how to document a defensible CMMC assessment scope can help organizations define their boundary before beginning assessment preparation.
External Service Providers and Cloud Service Providers
Using an external provider does not automatically transfer CMMC responsibility outside the contractor. An organization needs to understand:
- What the provider does
- Whether it processes CUI
- Whether it processes Security Protection Data
- Which security capabilities are inherited
- Which responsibilities remain with the contractor
- Whether the provider is a CSP
- What cloud security requirements apply
For Level 3, ESP services used to meet security requirements can become part of the assessment scope. Where an ESP processes CUI and is not a CSP, the service is included in the organization’s assessment scope. Where a CSP processes CUI, applicable FedRAMP requirements under DFARS must be addressed. Security responsibilities should also be documented in the SSP and associated customer responsibility information.
How Does the CMMC Level 3 Assessment Process Work?
The CMMC Level 3 assessment process is a government-led evaluation rather than a traditional commercial certification audit. A practical path looks like this.
Step 1: Confirm That the Contract Requires Level 3
Do not begin by assuming Level 3 is necessary because your organization handles CUI. First identify the requirement in the solicitation, contract, or direction from the requiring activity. During the current 2026 suspension, contractors should also verify the latest procurement status rather than relying on historical rollout dates.
Step 2: Achieve Final Level 2 (C3PAO) Status
Before beginning the Level 3 assessment, the organization must achieve Final Level 2 (C3PAO) for the applicable systems. This means the Level 2 C3PAO assessment must be complete and any eligible Level 2 POA&M deficiencies must already be closed. Conditional Level 2 does not satisfy the prerequisite. The Level 3 scope must then be equal to or narrower than the scope covered by the Final Level 2 certification.
Step 3: Validate the Level 3 Assessment Scope
Reconfirm the assessment boundary before implementing Level 3 controls. Document:
- CUI flows
- Networks
- Systems
- Endpoints
- Users
- Applications
- Security Protection Assets
- Specialized Assets
- External providers
- Cloud services
- Remote access paths
- Security boundaries
Level 3 scoping may change how some assets were treated during Level 2, so organizations should not assume the previous asset classification remains unchanged.
Step 4: Perform a Level 3 Gap Assessment
Next, compare the current environment against all 24 selected CMMC Level 3 requirements. The review should go beyond asking whether the organization has a relevant policy. Evaluate:
- Technical implementation
- Operational maturity
- Assessment objectives
- Evidence
- Documentation
- Personnel responsibilities
- Security processes
- Monitoring capabilities
- Response capabilities
The goal is to identify what DCMA DIBCAC would be able to verify today.
Step 5: Implement the 24 Enhanced Security Requirements
Close the identified gaps. Implementation may require substantial operational changes, particularly around:
- Security operations
- Threat hunting
- Incident response
- Threat intelligence
- Asset discovery
- Penetration testing
- Supply chain risk management
- Specialized assets
- Automated security capabilities
- Configuration enforcement
For many organizations, this is significantly more complex than simply buying another security product. People, processes, technology, governance, and documentation must operate together.
Step 6: Prepare Documentation and Objective Evidence
Level 3 assessment readiness requires evidence that demonstrates implementation. Relevant artifacts can include:
- System Security Plan
- Network diagrams
- Asset inventories
- Security policies
- Procedures
- System configurations
- Logging records
- SIEM evidence
- Threat intelligence records
- Threat-hunting documentation
- Incident response records
- Penetration-testing results
- Training records
- Security assessments
- Supply chain risk documentation
- Configuration baselines
- Component inventories
Evidence should be final, current, and consistent with actual operations. Federal scoring rules specifically state that MET findings must be supported by final-form evidence rather than drafts or unofficial policies.
Step 7: Undergo the DCMA DIBCAC Assessment
The organization initiates the formal Level 3 process with DCMA DIBCAC after meeting the Level 2 prerequisite. Under the regulatory process, DCMA DIBCAC validates the Level 2 certification information and schedules the Level 3 assessment. The assessment evaluates the selected Level 3 requirements using the applicable CMMC assessment procedures and assessment scope. DCMA DIBCAC records results through the government’s CMMC systems, with information ultimately transmitted to SPRS. A C3PAO does not conduct this stage.
Step 8: Resolve Any Eligible POA&M Items
If the organization does not meet every Level 3 requirement but meets the regulatory conditions for conditional status, limited deficiencies may be placed on a Plan of Action and Milestones. Not every requirement qualifies. The organization must close eligible open requirements and complete a DIBCAC POA&M closeout assessment within 180 days of the Conditional Level 3 status date.
Step 9: Achieve Final Level 3 Status and Maintain Compliance
Final Level 3 status is achieved when all required Level 3 security requirements are MET. The organization must then maintain:
- The Level 3 requirements
- The underlying Level 2 environment
- Required documentation
- Applicable assessment status
- Annual affirmations
- Updated scope information
- Current evidence
CMMC compliance continues after assessment day.
How Is a CMMC Level 3 Assessment Conducted?
A Level 3 assessment evaluates whether the organization’s safeguards are actually implemented. Assessment activity generally uses three core methods: examination, interviews, and testing. The CMMC regulation currently incorporates NIST SP 800-172A March 2022 for Level 3 assessment procedures. NIST’s assessment methodology is designed to evaluate evidence and determine whether enhanced security requirements have been satisfied.
Examination
During examination, assessors review objective evidence. That may include:
- Policies
- Procedures
- Configurations
- Records
- Architecture documents
- Security plans
- Logs
- Diagrams
- Inventories
- Reports
- Security-tool outputs
The question is whether the evidence supports the claimed implementation. A polished policy cannot compensate for a safeguard that does not operate as described.
Interviews
Assessors may interview people responsible for implementing or operating the cybersecurity program. That can include:
- Security leadership
- System administrators
- Incident responders
- SOC personnel
- IT administrators
- Risk professionals
- System owners
- Other relevant users
Interviews help determine whether processes described in documentation are understood and consistently followed in practice.
Testing
Testing requires the organization to demonstrate that relevant technical and procedural safeguards work. For example, an assessor may need to verify how:
- Unauthorized systems are detected
- Security events are escalated
- Threat hunting is conducted
- Components are authenticated
- Security monitoring operates
- Incident-response processes are triggered
NIST assessment procedures are designed to support evidence-based evaluation rather than simple policy review.
How Does CMMC Level 3 Scoring and Conditional Status Work?
Level 3 has its own scoring method. Unlike Level 2, where different security requirements can carry different point values, every Level 3 requirement is worth one point. The maximum Level 3 score is therefore 24.
MET, NOT MET and N/A Findings
Assessment findings can be:
MET: All applicable assessment objectives have been satisfied with acceptable evidence.
NOT MET: One or more applicable objectives have not been satisfied.
N/A: The requirement or objective does not apply to the assessment environment. Under the scoring methodology, N/A is treated equivalently to MET for assessment purposes.
A partially implemented security requirement does not automatically receive partial credit. The Level 3 assessment is designed to determine whether each requirement has been satisfactorily implemented.
What Score Is Required for Conditional Level 3 Status?
The regulatory threshold for Conditional Level 3 (DIBCAC) is: Assessment score ÷ total Level 3 security requirements ≥ 0.80 With 24 Level 3 requirements, this distinction matters. 19 out of 24 equals approximately 79.17%, not 80%. Therefore, 19 MET-equivalent points do not reach the regulatory threshold. At least 20 of 24 points, or approximately 83.33%, are required mathematically to meet or exceed 80%. Even reaching the score threshold does not automatically permit conditional status. The POA&M must also exclude several specifically prohibited requirements.
Which Level 3 Requirements Cannot Go on a POA&M?
Seven Level 3 requirements cannot remain open when pursuing Conditional Level 3 status:
- IR.L3-3.6.1e: Security Operations Center
- IR.L3-3.6.2e: Cyber Incident Response Team
- RA.L3-3.11.1e: Threat-Informed Risk Assessment
- RA.L3-3.11.4e: Security Solution Rationale
- RA.L3-3.11.6e: Supply Chain Risk Response
- RA.L3-3.11.7e: Supply Chain Risk Plan
- SI.L3-3.14.3e: Specialized Asset Security
If one of these requirements is NOT MET, the organization cannot simply place it on a POA&M and use that item to qualify for conditional Level 3 status.
How Long Do You Have to Close a Level 3 POA&M?
Eligible POA&M deficiencies must be successfully closed within 180 days of the Conditional Level 3 status date. DCMA DIBCAC performs the Level 3 POA&M closeout assessment. If the organization does not successfully close the POA&M within the required timeframe, the Conditional Level 3 status expires.
How Long Does CMMC Level 3 Certification Last?
CMMC Level 3 is not permanent. Organizations need to maintain both their assessment status and continuous security implementation.
Level 3 Assessment Every Three Years
The Level 3 certification assessment must be performed every three years for the systems within the applicable assessment scope. The regulatory three-year period is measured from the applicable CMMC status date.
Level 2 Must Also Remain Current
Level 3 does not replace the Level 2 certification underneath it. Because Final Level 2 (C3PAO) is a prerequisite, the organization must also maintain a current Level 2 certification. Federal regulations explicitly require a new Level 2 C3PAO certification assessment every three years to maintain Level 3 status. This means an organization pursuing Level 3 effectively maintains two connected layers:
Level 2: The complete NIST SP 800-171 Rev. 2 baseline.
Level 3: The additional 24 enhanced NIST SP 800-172 requirements.
Annual Affirmation Requirements
Level 3 also requires annual affirmation. An authorized senior representative must affirm that the organization continues to implement and maintain applicable CMMC security requirements. Because Level 2 and Level 3 assess different requirements, Level 3 organizations must maintain the applicable Level 2 affirmation and Level 3 affirmation. Affirmations are submitted through SPRS.
What Are the Biggest Challenges With CMMC Level 3?
Achieving Level 3 requires more than extending an existing compliance checklist. The biggest challenges usually involve operating advanced security capabilities consistently enough that they can withstand government assessment.
Building Advanced Threat Detection and Response Capabilities
Many Level 2 organizations already log events, deploy endpoint protection, and maintain incident response plans. Level 3 raises expectations. Organizations may need operational capabilities involving:
- 24/7 security operations
- Threat intelligence
- Active threat hunting
- Advanced analytics
- Intrusion detection
- Rapid incident-response deployment
- Continuous monitoring
These capabilities require trained people and mature processes, not only software licenses.
Meeting Advanced Configuration and Asset Management Requirements
Level 3 places stronger emphasis on knowing exactly which components are authorized and connected to organizational systems. This includes:
- Authoritative component repositories
- Automated asset discovery
- Configuration-state monitoring
- Detection of unauthorized components
- Quarantine or remediation processes
- Component authentication
Incomplete inventories and unmanaged assets create serious problems in this type of environment.
Supply Chain Risk Management
Cybersecurity risk does not stop at the company’s network boundary. Level 3 includes explicit requirements to assess, monitor, respond to, and plan for supply chain risk. Organizations may need better visibility into:
- Technology suppliers
- Hardware sources
- Software dependencies
- Third-party components
- External service providers
- Changes in supplier risk
This often requires coordination between cybersecurity, procurement, contracts, engineering, and executive leadership.
Evidence and Documentation at Government Assessment Depth
A government-led assessment places significant pressure on evidence quality. Organizations need documentation that agrees with what assessors observe in systems and hear during interviews. That means the SSP, network diagrams, policies, inventories, risk documentation, response processes, configurations, and evidence should all describe the same environment. Last-minute document creation is unlikely to produce that level of consistency.
Maintaining Level 2 and Level 3 at the Same Time
Another challenge is treating Level 3 as an ongoing augmentation of Level 2. The organization cannot abandon its Level 2 evidence and controls once it passes the C3PAO assessment. If DCMA DIBCAC discovers a Level 2 requirement is no longer MET during Level 3 assessment, the government can pause, hold, or terminate the Level 3 assessment process. Maintaining Level 3 therefore requires continuous discipline across the complete cybersecurity environment.
How Should Contractors Prepare for CMMC Level 3?
Organizations that expect Level 3 requirements should prepare systematically rather than treating the 24 requirements as an isolated checklist.
Do Not Start Level 3 Before Building a Strong Level 2 Foundation
A weak Level 2 environment creates an unstable foundation for Level 3. Before investing heavily in enhanced controls, verify that:
- All 110 Level 2 requirements are operational
- The SSP is accurate
- CUI is properly scoped
- Evidence is current
- Security processes are repeatable
- Level 2 POA&M items are being closed
Level 2 should be treated as an operational cybersecurity program rather than a certification hurdle.
Map CUI and Confirm the Assessment Boundary
Document exactly how CUI moves through the organization. Identify:
- Entry points
- Users
- Endpoints
- Applications
- Servers
- Networks
- Cloud services
- External providers
- Security tools
- Specialized assets
- Storage locations
- Transmission paths
A clear boundary reduces ambiguity and helps teams understand where Level 3 capabilities actually need to operate.
Perform an Assessment Against NIST SP 800-172A Objectives
Do not assess readiness using only the short wording of the 24 requirements. Evaluate how those requirements will be assessed. The CMMC regulation currently relies on NIST SP 800-172A March 2022 for assessment procedures, even though NIST released a newer Rev. 3 version in May 2026. Reviewing applicable assessment objectives helps identify whether sufficient evidence exists to support each claimed implementation.
Prioritize High-Complexity Level 3 Capabilities Early
Some Level 3 requirements are much harder to establish quickly than others. Start early on capabilities such as:
- Threat hunting
- Security Operations Center operations
- Cyber incident response
- Supply chain risk
- Automated component discovery
- Advanced configuration monitoring
- Component authentication
- Penetration testing
- Threat intelligence integration
- Continuous security monitoring
These capabilities may require new staff, service providers, architecture, technology, workflows, and documentation.
Build Evidence Before the Formal Assessment
Evidence collection should begin while controls are being implemented. For every requirement, ask:
- What proves this is implemented?
- Where is that evidence generated?
- Who owns it?
- How often is it updated?
- Can it be retrieved quickly?
- Does it agree with the SSP and policies?
- Can personnel demonstrate the process?
This approach is much more reliable than trying to reconstruct months of compliance evidence immediately before assessment. Organizations that need outside support with scoping, gap analysis, documentation, remediation, and evidence preparation can use CMMC compliance consulting to build assessment readiness around the actual environment.
How Nexeris Helps Contractors Prepare for CMMC Level 3
Level 3 preparation requires coordination across cybersecurity, IT, GRC, contracts, leadership, engineering, service providers, and the existing Level 2 compliance program. Nexeris helps defense contractors prepare by connecting those areas into a defensible assessment-readiness program. Support can include:
- Determining applicable CMMC requirements
- Level 2 readiness and remediation
- CUI scoping
- Level 3 gap assessments
- NIST SP 800-172 readiness
- SSP development and updates
- Policy and procedure alignment
- Evidence preparation
- POA&M remediation planning
- Assessment preparation
The goal is not simply to create additional compliance documentation. It is to help the organization build security capabilities that operate consistently, protect sensitive defense information, and can be demonstrated when government assessment requirements apply.
Frequently Asked Questions
1. What is CMMC Level 3?
CMMC Level 3 is the highest level in the current CMMC model. It is intended for selected defense programs involving CUI that requires enhanced protection against Advanced Persistent Threats. Level 3 requires Final Level 2 (C3PAO) status first, followed by implementation of 24 selected NIST SP 800-172 requirements and a government-led DCMA DIBCAC assessment.
2. How many requirements are in CMMC Level 3?
CMMC Level 3 builds on the 110 NIST SP 800-171 Revision 2 requirements required for Level 2 and adds 24 selected NIST SP 800-172 requirements. The combined Level 3 security environment therefore consists of 134 requirements. The formal Level 3 certification assessment specifically scores the 24 additional Level 3 requirements because Final Level 2 is already a prerequisite.
3. Does CMMC Level 3 require Level 2 certification first?
Yes.
An organization must achieve Final Level 2 (C3PAO) status for the applicable information systems before beginning the Level 3 certification assessment. A Level 2 self-assessment is not sufficient. Conditional Level 2 status with unresolved POA&M items is also insufficient. Those items must be closed before Level 3 assessment begins.
4. What is the difference between CMMC Level 2 and Level 3?
CMMC Level 2 protects CUI using the 110 security requirements in NIST SP 800-171 Revision 2. Level 3 builds on that baseline by adding 24 enhanced requirements focused on protecting selected CUI and higher-risk programs against sophisticated adversaries and Advanced Persistent Threats. Level 2 may use self-assessment or a C3PAO assessment depending on the applicable requirement. Level 3 certification assessments are performed by DCMA DIBCAC.
5. Who performs a CMMC Level 3 assessment?
DCMA DIBCAC performs CMMC Level 3 certification assessments. C3PAOs conduct applicable Level 2 certification assessments but cannot issue Level 3 status. An organization must first obtain Final Level 2 (C3PAO) status and then undergo the Level 3 government assessment.
6. Does CMMC Level 3 use NIST SP 800-172?
Yes.
CMMC Level 3 adds 24 selected enhanced security requirements derived from NIST SP 800-172. Under the current CMMC regulation, the incorporated baseline is specifically the February 2021 edition of NIST SP 800-172, even though NIST released Revision 3 in May 2026. Organizations should follow the version incorporated into current CMMC requirements unless the applicable regulation or contract is formally updated.
7. Can CMMC Level 3 requirements be placed on a POA&M?
Some can, but POA&M use is limited. Conditional Level 3 status requires a score of at least 80%, and seven specifically identified Level 3 requirements cannot remain open on the POA&M. Eligible deficiencies must be remediated and successfully validated by DCMA DIBCAC within 180 days of the Conditional Level 3 status date.
8. How does the 2026 CMMC suspension affect Level 3 requirements?
The July 13, 2026 suspension paused the planned transition to CMMC Phase II and held future implementation milestones while the program undergoes review. As a result, contractors should not treat previously scheduled Phase III or Level 3 rollout dates as active deadlines. However, the Level 3 framework remains defined in 32 CFR Part 170, and applicable underlying cybersecurity obligations such as NIST SP 800-171 and DFARS requirements remain important. Phase I self-assessment requirements also remain in effect.
