Nationwide CMMC & NIST 800-171 implementation for the Defense Industrial Base

CMMC Level 1 Compliance

If you handle Federal Contract Information but never touch CUI, Level 1 is your bar. It is the most achievable tier in CMMC — and the one contractors most often get wrong by assuming it is optional.

Not sure whether you are Level 1 or Level 2?

That single question changes your budget by an order of magnitude. We will scope it with you at no cost and tell you plainly which tier you are in.

Not sure? That's the most common answer — and it's the first thing we work out with you.

No cost. No obligation. NDA available on request.

We respond within 1 business hour · We are not a C3PAO and do not perform certification assessments

Level 1
achieved for an industrial robotics manufacturer
Defense
software built for defense contractors
Federal
law-enforcement task force under active support
Regulated
HIPAA, IRS WISP & FTC Safeguards work

The short answer

CMMC Level 1 applies to contractors who handle Federal Contract Information (FCI) but not Controlled Unclassified Information. It requires implementing 15 basic safeguarding requirements drawn from FAR 52.204-21, completing a self-assessment annually, and having a senior company official affirm the results in the Supplier Performance Risk System (SPRS). There is no third-party assessment at Level 1 — but the affirmation is a signed statement to the federal government, which carries False Claims Act exposure if it is not accurate.

Who actually needs CMMC Level 1

Level 1 applies if your contracts give you access to Federal Contract Information — information provided by or generated for the government under a contract that is not intended for public release. That is a much wider net than most subcontractors expect. If you receive purchase orders, statements of work, delivery schedules, or drawings from a prime under a federal contract, you are almost certainly in scope.

The distinction that determines your level is simple: FCI only means Level 1. Any Controlled Unclassified Information means Level 2. Contractors routinely misclassify here, and the cost of guessing wrong in either direction is high — under-scoping means a failed affirmation, over-scoping means paying for a Level 2 program you did not need.

  • Machine shops and fabricators receiving prime-supplied drawings
  • Logistics, staffing, and professional services vendors on federal contracts
  • Software and IT vendors delivering to DoD primes
  • Distributors and suppliers holding non-public delivery schedules

The 15 Level 1 requirements

Level 1 maps to the 15 basic safeguarding requirements in FAR clause 52.204-21. They cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.

None of them are exotic. Most are things a competently run business already does in part — the work is proving you do them consistently and documenting the evidence.

  • Limit system access to authorized users and devices
  • Limit what authorized users can execute and transact
  • Verify and control connections to external systems
  • Control information posted on publicly accessible systems
  • Identify users and devices before granting access
  • Authenticate identities before allowing access
  • Sanitize or destroy media containing FCI before disposal or reuse
  • Limit physical access to systems, equipment, and operating environments
  • Escort visitors and monitor visitor activity
  • Maintain physical access audit logs
  • Manage physical access devices
  • Monitor and control communications at system boundaries
  • Implement subnetworks for publicly accessible components
  • Identify, report, and correct system flaws in a timely manner
  • Provide protection from malicious code and update it as new releases become available

The self-assessment and affirmation trap

Level 1 has no C3PAO involved, which contractors read as low-stakes. It is not. A senior company official has to affirm in SPRS that all 15 requirements are met — a representation to the federal government. Unlike Level 2, Level 1 allows no POA&Ms: you either meet all 15 at the time of affirmation or you do not affirm.

This is the single most common place we see contractors expose themselves. The fix is not complicated, but it does require someone to actually verify each requirement against the environment rather than reading the list and nodding.

What a Level 1 engagement looks like with us

We scope your FCI boundary, assess all 15 requirements against your live environment, remediate what fails, produce the evidence package, and set up the annual reassessment cadence so next year is a review rather than a rediscovery. For most small contractors this is measured in weeks, not quarters.

We have delivered exactly this — including for a Georgia-based industrial robotics manufacturer that needed Level 1 to stay eligible on its supply agreements.

We do the work. We don't grade it.

Smith Network Solutions is not a C3PAO and not a registered RPO. We are the engineering and managed-services partner that closes your gaps, writes your System Security Plan, and gets your SPRS score where it needs to be. Your assessment is performed by an independent, authorized C3PAO — and that separation is deliberate. Under CMMC independence rules your assessor cannot remediate what they assess, so you need an implementation partner either way. We are that partner, and we will introduce you to C3PAOs when you are ready.

Not sure whether you are Level 1 or Level 2?

That single question changes your budget by an order of magnitude. We will scope it with you at no cost and tell you plainly which tier you are in.

Nationwide remote delivery · Response within 1 business hour

CMMC Level 1 FAQs

Is CMMC Level 1 a self-assessment or does someone audit us?

Level 1 is a self-assessment. You perform it annually and a senior company official affirms the result in SPRS. No C3PAO assessment is required at Level 1. That said, the affirmation is an official representation to the government, so it should be backed by real evidence rather than a good-faith guess.

Can we use a POA&M for Level 1?

No. Plans of Action and Milestones are not permitted at Level 1. All 15 requirements must be fully implemented before you affirm. This differs from Level 2, where limited POA&Ms are allowed for certain controls and must be closed within 180 days.

How long does Level 1 take?

For a small contractor with a reasonably modern IT environment, typically four to eight weeks from kickoff to affirmation-ready. The variable is almost always documentation and evidence collection, not technical remediation.

What if we discover we actually handle CUI?

Then you are a Level 2 organization and Level 1 will not satisfy your contract. This comes up often, and it is better to find out during scoping than after an affirmation. We check for it explicitly at the start of every engagement.