If your DoD contracts involve Federal Contract Information (FCI) but no Controlled Unclassified Information, CMMC Level 1 is your requirement: 17 basic safeguarding practices, an annual self-assessment, and an annual affirmation by a senior official — no third-party assessor required. It's the most manageable tier of CMMC, and with the right help it's quick to get right. Here's what Level 1 actually asks of you, where contractors trip, and how we make it simple.
Get Level 1 Done RightLevel 1 covers contractors whose systems store, process, or transmit Federal Contract Information — information provided by or generated for the government under contract that isn't intended for public release. Think contract documents, technical correspondence, performance reports. The requirements come from FAR 52.204-21's basic safeguarding rules, expressed in CMMC as 17 practices. There's no C3PAO and no certification audit at Level 1: you assess yourself every year, record the result in the Supplier Performance Risk System (SPRS), and a senior company official affirms it. That affirmation is a certification to the federal government — which is exactly why it's worth getting the details right. Our Level 1 services are built to be quick, contained, and proportionate to the requirement.
Explore Readiness Assessment ServicesA focused review of your environment against all 17 practices. You get a punch list of exactly what passes, what doesn't, and what to fix — not an oversized enterprise assessment for a Level 1 problem.
Hands-on help closing the gaps: multi-factor authentication and access cleanup, patching and malware protection, physical and media controls, and the documentation to show each practice is actually in place.
We prepare you to run the annual self-assessment yourself — templates, evidence checklists, and a review of your results with our team before your SPRS submission and affirmation.
Level 1's practices map to the basic safeguarding requirements of FAR 52.204-21, across six areas. None of them require enterprise tooling — they require discipline.
Limit system access to authorized users, devices, and processes; limit what each user can do to what their job requires; and control connections to external systems and what gets posted publicly.
Know who's on your systems: identify every user uniquely and authenticate them before granting access. Shared logins fail this on the spot.
Sanitize or destroy drives, disks, and other media containing FCI before disposal or reuse — the practice small contractors most often forget to document.
Limit physical access to systems and facilities to authorized people; escort visitors, log physical access, and manage who holds keys and badges.
Monitor and control communications at your network boundary, and keep public-facing systems — like your website — separated from internal networks that hold FCI.
Fix flaws promptly, run malware protection and keep it current, and scan files arriving from email and external sources before they land.
Once a year, you assess your environment against all 17 practices and record the result in SPRS, the DoD's Supplier Performance Risk System. A senior company official then affirms continuing compliance — also annually. With the CMMC acquisition rule now in effect and CMMC requirements appearing in new DoD solicitations, expect that affirmation to be a precondition for new awards.
Treat the affirmation with the seriousness of any certification made to the federal government: it attaches a named executive to a factual claim about your security. The good news is that Level 1 is small enough to verify properly — an afternoon of honest checking beats a year of assumed compliance.
Five patterns account for most of the failed practices we see:
1. Shared and stale accounts — group logins, ex-employees with live credentials, and admin rights handed out for convenience.
2. No boundary between public and internal — the public website, guest Wi-Fi, and FCI file shares all living on one flat network.
3. Undocumented physical controls — visitors wander unescorted, nobody logs access, and server hardware sits in an unlocked closet.
4. Media that never dies properly — old laptops and drives leave the building with FCI still readable on them.
5. "Our IT provider handles it" — assumed compliance with no evidence. If you can't show a practice is in place, you can't affirm it.
Level 1 only holds if FCI is genuinely all you touch — and in practice, CUI creeps. A drawing with a distribution statement lands in email. An export-controlled spec arrives from a prime. A program office shares marked technical data. The moment CUI touches your systems, you're in Level 2 territory: 110 controls and, for most contracts, a triennial C3PAO assessment. If any of that sounds familiar, size the real requirement before you affirm the wrong one.
See CMMC Level 2 Compliance ServicesLevel 1 shouldn't require an open-ended consulting arrangement, so we deliver it as a contained engagement: readiness check, remediation punch list, implementation help where you want it, and self-assessment preparation through your SPRS submission and affirmation. And if you'd rather have ongoing cover, the same team behind our Level 2 clients — former Big Four auditors and top-tier security engineers — is available for the long haul.
Read the CMMC 2.0 OverviewVisit Our CMMC FAQ