Skip to main content

🔔 Notifications Hub: See compliance updates in one place

CMMC Level 1 Self-Assessment Guide

CMMC Level 1 applies to any defense contractor that handles only Federal Contract Information (FCI), which might include emails with your contracting officer or prime, invoices, and the contract document itself. This level requires an annual self-assessment and affirmation of compliance with 15 basic safeguarding requirements, but implementing and proving this doesn't seem so basic to most small contractors and component manufacturers. This guide breaks down the what, why, and how for CMMC Level 1 in simple terms, so you actually understand what to do to get a CMMC Level 1 status and stay eligible for defense contracts.

What's in this guide:

  • The purpose of the CMMC program, starting with Level 1 and the lowest tiers of the supply chain
  • What FCI might look like in your environment
  • Examples of CMMC Level 1 contractors and how they handle FCI
  • What types of policies, evidence, and tasks you might need to complete to meet the underlying cybersecurity requirements and objectives
  • What Level 1 does not require (and why SSP, MFA, GCC High, POA&Ms still come up)
  • What CMMC Level 1 realistically costs and how long it takes (plus why the DoD's cost and labor hour estimates are likely too low)
  • How automation can help get your organization secure faster and stay compliant