Who actually needs CMMC Level 1
Level 1 applies if your contracts give you access to Federal Contract Information — information provided by or generated for the government under a contract that is not intended for public release. That is a much wider net than most subcontractors expect. If you receive purchase orders, statements of work, delivery schedules, or drawings from a prime under a federal contract, you are almost certainly in scope.
The distinction that determines your level is simple: FCI only means Level 1. Any Controlled Unclassified Information means Level 2. Contractors routinely misclassify here, and the cost of guessing wrong in either direction is high — under-scoping means a failed affirmation, over-scoping means paying for a Level 2 program you did not need.
- Machine shops and fabricators receiving prime-supplied drawings
- Logistics, staffing, and professional services vendors on federal contracts
- Software and IT vendors delivering to DoD primes
- Distributors and suppliers holding non-public delivery schedules
The 15 Level 1 requirements
Level 1 maps to the 15 basic safeguarding requirements in FAR clause 52.204-21. They cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.
None of them are exotic. Most are things a competently run business already does in part — the work is proving you do them consistently and documenting the evidence.
- Limit system access to authorized users and devices
- Limit what authorized users can execute and transact
- Verify and control connections to external systems
- Control information posted on publicly accessible systems
- Identify users and devices before granting access
- Authenticate identities before allowing access
- Sanitize or destroy media containing FCI before disposal or reuse
- Limit physical access to systems, equipment, and operating environments
- Escort visitors and monitor visitor activity
- Maintain physical access audit logs
- Manage physical access devices
- Monitor and control communications at system boundaries
- Implement subnetworks for publicly accessible components
- Identify, report, and correct system flaws in a timely manner
- Provide protection from malicious code and update it as new releases become available
The self-assessment and affirmation trap
Level 1 has no C3PAO involved, which contractors read as low-stakes. It is not. A senior company official has to affirm in SPRS that all 15 requirements are met — a representation to the federal government. Unlike Level 2, Level 1 allows no POA&Ms: you either meet all 15 at the time of affirmation or you do not affirm.
This is the single most common place we see contractors expose themselves. The fix is not complicated, but it does require someone to actually verify each requirement against the environment rather than reading the list and nodding.
What a Level 1 engagement looks like with us
We scope your FCI boundary, assess all 15 requirements against your live environment, remediate what fails, produce the evidence package, and set up the annual reassessment cadence so next year is a review rather than a rediscovery. For most small contractors this is measured in weeks, not quarters.
We have delivered exactly this — including for a Georgia-based industrial robotics manufacturer that needed Level 1 to stay eligible on its supply agreements.

