CMMC 2.0 Level 1 Compliance Services

CMMC Level 1 Compliance: The 17 Practices and How to Self-Assess

If your DoD contracts involve Federal Contract Information (FCI) but no Controlled Unclassified Information, CMMC Level 1 is your requirement: 17 basic safeguarding practices, an annual self-assessment, and an annual affirmation by a senior official — no third-party assessor required. It's the most manageable tier of CMMC, and with the right help it's quick to get right. Here's what Level 1 actually asks of you, where contractors trip, and how we make it simple.

Get Level 1 Done Right

Make CMMC Level 1 Compliance Your Company’s Competitive Advantage

Learn How

Who Level 1 Applies To — and How We Help

Level 1 covers contractors whose systems store, process, or transmit Federal Contract Information — information provided by or generated for the government under contract that isn't intended for public release. Think contract documents, technical correspondence, performance reports. The requirements come from FAR 52.204-21's basic safeguarding rules, expressed in CMMC as 17 practices. There's no C3PAO and no certification audit at Level 1: you assess yourself every year, record the result in the Supplier Performance Risk System (SPRS), and a senior company official affirms it. That affirmation is a certification to the federal government — which is exactly why it's worth getting the details right. Our Level 1 services are built to be quick, contained, and proportionate to the requirement.

Explore Readiness Assessment Services
CMMC 2.0 Level 1 Readiness Assessment

A focused review of your environment against all 17 practices. You get a punch list of exactly what passes, what doesn't, and what to fix — not an oversized enterprise assessment for a Level 1 problem.

CMMC 2.0 Level 1 Implementation Support

Hands-on help closing the gaps: multi-factor authentication and access cleanup, patching and malware protection, physical and media controls, and the documentation to show each practice is actually in place.

CMMC 2.0 Level 1 Self-Assessment Preparation

We prepare you to run the annual self-assessment yourself — templates, evidence checklists, and a review of your results with our team before your SPRS submission and affirmation.

Level 1's practices map to the basic safeguarding requirements of FAR 52.204-21, across six areas. None of them require enterprise tooling — they require discipline.

Access Control
Identification & Authentication
Media Disposal
Physical Protection
System & Communications Protection
System & Information Integrity

Once a year, you assess your environment against all 17 practices and record the result in SPRS, the DoD's Supplier Performance Risk System. A senior company official then affirms continuing compliance — also annually. With the CMMC acquisition rule now in effect and CMMC requirements appearing in new DoD solicitations, expect that affirmation to be a precondition for new awards.

Treat the affirmation with the seriousness of any certification made to the federal government: it attaches a named executive to a factual claim about your security. The good news is that Level 1 is small enough to verify properly — an afternoon of honest checking beats a year of assumed compliance.

Not Sure Whether You're Level 1 or Level 2?

Talk to an Expert

Five patterns account for most of the failed practices we see:

1. Shared and stale accounts — group logins, ex-employees with live credentials, and admin rights handed out for convenience.

2. No boundary between public and internal — the public website, guest Wi-Fi, and FCI file shares all living on one flat network.

3. Undocumented physical controls — visitors wander unescorted, nobody logs access, and server hardware sits in an unlocked closet.

4. Media that never dies properly — old laptops and drives leave the building with FCI still readable on them.

5. "Our IT provider handles it" — assumed compliance with no evidence. If you can't show a practice is in place, you can't affirm it.

Level 1 only holds if FCI is genuinely all you touch — and in practice, CUI creeps. A drawing with a distribution statement lands in email. An export-controlled spec arrives from a prime. A program office shares marked technical data. The moment CUI touches your systems, you're in Level 2 territory: 110 controls and, for most contracts, a triennial C3PAO assessment. If any of that sounds familiar, size the real requirement before you affirm the wrong one.

See CMMC Level 2 Compliance Services

Level 1 shouldn't require an open-ended consulting arrangement, so we deliver it as a contained engagement: readiness check, remediation punch list, implementation help where you want it, and self-assessment preparation through your SPRS submission and affirmation. And if you'd rather have ongoing cover, the same team behind our Level 2 clients — former Big Four auditors and top-tier security engineers — is available for the long haul.

Read the CMMC 2.0 OverviewVisit Our CMMC FAQ

CMMC 2.0 Readiness assessment

Comply with security requirements & manage network vulnerability.

Explore CMMC Readiness Assessments

cui secure enclave

An ongoing, systematic approach to security.

View Secure Enclave Services

CMMC 2.0 l2 compliance services

How We Can Help