Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
CMMC Level 1 Self-Assessment Guide
Updated July 2026: The July 13 CMMC suspension paused Level 2 third-party audits — it did not touch Level 1. Level 1 was always a self-assessment; it remains fully in force in contracts, and it’s arguably the one CMMC requirement nobody should be waiting on. This guide reflects the current rules.
If your company handles Federal Contract Information but not CUI, you can complete CMMC Level 1 yourself — no auditor, no six-figure project, no consultants required (though we’ll tell you honestly where help pays for itself). Most small contractors finish in 2–4 weeks of part-time effort.
Here’s the whole thing in one sentence: you check that 15 basic security practices are actually in place, keep proof, have a senior official sign a statement to the government that it’s true, and repeat the signature every year.
That last part — the signature — is why this guide exists. The assessment is easy. Signing a federal attestation carelessly is not. Let’s do it right.
FCI stands for Federal Contract Information — information provided by or generated for the government under contract that isn’t meant for public release. Think contract terms, delivery schedules, performance details.
CUI stands for Controlled Unclassified Information — more sensitive material like technical drawings and specifications. If you handle CUI, you’re a Level 2 shop and this guide isn’t enough — start with our Level 2 guide instead.
First: Is Level 1 Actually Your Level?
Thirty seconds of honesty before you invest three weeks. You’re a Level 1 shop if all three are true:
- You have (or want) DoD contracts or subcontracts
- Those contracts involve FCI — which nearly all of them do
- Nothing you receive or create is CUI — no technical data, drawings, specs, or export-controlled material
The classic mistake: a machine shop or services firm assumes “we’re small, we’re Level 1” while a customer drawing marked CUI sits in someone’s inbox. If you’re not sure whether you touch CUI, resolve that question first — it changes everything downstream. Check your contracts for DFARS 252.204-7012 (a CUI signal) versus FAR 52.204-21 alone (the Level 1 clause), or ask your prime.
What You’re Actually Signing Up For
Before the checklist, understand the shape of the obligation — because as the owner or executive, the last step has your name on it:
- The work: verify 15 security basics are implemented on every system that touches FCI
- The proof: keep evidence for each one — screenshots, settings, a photo of the locked door
- The signature: a senior official (probably you) affirms to the federal government, in an official system, that all 15 are met
- The renewal: that affirmation repeats every 12 months, and lapsing invalidates your status
- The stakes: a knowingly false affirmation is False Claims Act territory — the law with treble damages that the DOJ actively uses against contractors who misrepresent cybersecurity
One rule that surprises people: Level 1 is all-or-nothing. Unlike Level 2, there’s no conditional status and no submitting with a POA&M of open items. All 15 met, or you’re not done. The good news: these are the basics — most shops with even modest IT hygiene are closer than they think.
A POA&M is a Plan of Action and Milestones — a tracked list of security gaps and the plan to fix them. At Level 1 it’s a private working document, not something you can submit around.
The 15 Requirements, in Plain English
These come from FAR clause 52.204-21. For each one, we’ve translated the requirement into the question to ask — yourself, your IT person, or your MSP. If every answer is a confident yes with proof behind it, your assessment is nearly done.
Who can get in (Access Control — 4 requirements)
- Limit access to authorized users. — Does every account belong to a current, approved person? No shared logins, no accounts for people who left?
- Limit users to what their job requires. — Can your bookkeeper get into the engineering folder? Should they?
- Control connections to external systems. — Do you know and control what outside systems and services connect to yours?
- Keep FCI off public systems. — Could contract information end up on your public website or a public file link? Who checks?
Proving who’s who (Identification & Authentication — 2 requirements)
- Identify users and devices. — Does every person have their own named account, so activity traces to a human?
- Authenticate before granting access. — Does everything require a real login? Any device or app that just opens?
Old data (Media Protection — 1 requirement)
- Sanitize or destroy media before disposal or reuse. — When a laptop or drive leaves service, does the data get properly wiped or the drive destroyed — and is there a record?
The physical world (Physical Protection — 4 requirements)
- Limit physical access. — Can a stranger walk up to a workstation or into the server closet?
- Escort and monitor visitors. — Are visitors accompanied in work areas, or do they wander?
- Keep physical access logs. — Is there a visitor log or badge record showing who entered?
- Manage keys, badges, and fobs. — Do you know who holds every key and badge, and do you recover them when people leave?
The network edge (System & Communications Protection — 2 requirements)
- Monitor and control communications at the boundary. — Is there a real firewall between you and the internet, configured on purpose?
- Separate public-facing systems from internal ones. — Is your website (or anything public) walled off from the network where FCI lives?
Staying healthy (System & Information Integrity — 2 requirements)
- Identify, report, and correct flaws. — Do updates and patches actually get applied on a schedule, or “when we get to it”?
- Protect against malicious code. — Is real antivirus/anti-malware running on every machine, current, and actually scanning?
Notice what’s not on this list: no encryption mandates, no MFA requirement, no security operations center. Level 1 is genuinely the basics — which is exactly why “we’re probably fine” isn’t an assessment. Probably-fine becomes a federal attestation in step 6.
The Process: Seven Steps, Two to Four Weeks
Here’s the realistic playbook, with who does what. “You” is the owner/executive; “IT” is whoever runs your systems — an employee, an MSP, or you wearing a second hat.
Step 1 — Draw the boundary. (You + IT, ~half a day)
List every system that stores, processes, or transmits FCI: workstations and laptops, email, file storage and shared drives, servers, phones that get work email, network gear. Write down what’s in and — just as important — what’s out and why. This document is your scope, and every later step applies only to what’s inside it. The most common assessment failure isn’t a weak control; it’s a forgotten system.
Step 2 — Walk the 15. (IT leads, you spot-check, ~2–4 days)
Go requirement by requirement using the questions above. Each one gets exactly one of two answers: MET (fully implemented and actually operating) or NOT MET. There is no “mostly,” no partial credit, and a written policy nobody follows is a NOT MET. The standard isn’t “we have a firewall” — it’s “the firewall is configured, on, and doing its job today.”
Step 3 — Capture the proof as you go. (IT, concurrent with Step 2)
For every MET, save the evidence in a folder organized by requirement number: a screenshot of the user list, the firewall config, the antivirus dashboard, a photo of the locked server closet, a page of the visitor log. Ten minutes per requirement now saves you a scramble later — this folder is what makes your affirmation defensible if a prime, a contracting officer, or anyone else ever asks you to back it up.
Step 4 — Fix what’s broken. (IT executes, you fund and prioritize, days to weeks)
Every NOT MET goes on your internal POA&M and gets remediated. Most Level 1 gaps are cheap and fast: deleting stale accounts, tightening folder permissions, turning on automatic updates, buying a visitor logbook, putting a lock on a door. Remember the all-or-nothing rule — you can’t submit until this list is empty.
Step 5 — Write the one-page assessment report. (You + IT, ~1 hour)
Nothing fancy: assessment date, your scope statement, the MET status of all 15 requirements, where the evidence lives, who conducted the assessment, and who will affirm it. This is your internal record — you don’t submit the document itself, but you keep it.
Step 6 — The affirmation. (You. Specifically, actually you.)
A senior official — owner, president, executive with authority to bind the company — affirms the results. This is the step to slow down on:
- The affirming official cannot be “the IT guy” or a junior employee; it must be someone who can speak for the company
- Before signing, actually look at the evidence folder. Ask IT to walk you through anything you didn’t personally verify. Your signature says you stand behind all 15 — “my MSP said we’re good” is not a defense you want to test
- The affirmation is a statement to the federal government connected to contract awards. Knowingly false ones live under the False Claims Act: treble damages, and cases frequently started by whistleblowers who know exactly which box was checked on hope
An honest afternoon reviewing evidence is the cheapest legal protection you will ever buy.
Step 7 — Submit in SPRS. (You or IT, ~1 hour once accounts exist)
Results go into SPRS via the PIEE portal (https://piee.eb.mil). You’ll need a PIEE account with the SPRS Cyber Vendor role — and here’s the one logistical trap: account setup and role approval take days, sometimes longer. Start the PIEE registration in week one, in parallel with everything else, so it’s ready when you are. You’ll enter the assessment date, the result (all 15 met), your CAGE code, and the affirming official’s information. Save the confirmation.
SPRS is the Supplier Performance Risk System — the government database contracting officers check before award. PIEE is the portal you reach it through. Full submission walkthrough: How to Submit Your SPRS Score.
Keeping It Alive: The Annual Cycle
Your Level 1 status isn’t a certificate on the wall — it’s a living attestation:
- Every 12 months, the senior official re-affirms that all 15 requirements are still met and nothing has degraded. Calendar this the day you submit. A lapsed affirmation invalidates your status, and contracting officers can see it.
- Re-assess (not just re-affirm) when things change: new systems handling FCI, an office move, a security incident, an acquisition, a new MSP. The honest question each year isn’t “did we sign last year?” — it’s “is last year’s answer still true?”
- A 30-minute annual walkthrough of the evidence folder before signing keeps the affirmation honest and takes less time than one status meeting.
The Five Ways Small Contractors Get This Wrong
- Signing on vibes. The affirmation gets treated as paperwork instead of a legal statement. Review the evidence before you sign — every year, not just the first.
- No evidence trail. “We did the assessment” with nothing to show for it. Self-assessed doesn’t mean undocumented — primes increasingly ask subs to prove Level 1 claims, and the folder is your answer.
- The forgotten system. The shipping PC, the owner’s home laptop, the tablet in the shop — if it touches FCI and wasn’t assessed, the assessment is incomplete and the affirmation is inaccurate.
- The wrong signer. An IT admin’s affirmation doesn’t count. Senior official means senior official.
- The missed anniversary. Nothing about your security changed; your status still lapsed because nobody owned the calendar reminder.
Key Takeaways
CMMC Level 1 is a self-assessment of 15 basic security practices from FAR 52.204-21, covering every system that touches FCI. All 15 must be fully met — no partial credit, no POA&M submission — then a senior official affirms the results in SPRS and re-affirms annually.
The assessment work is genuinely doable in 2–4 weeks for most small shops. The part that deserves executive attention is the signature: it’s a federal attestation with False Claims Act weight, and it’s only as good as the evidence behind it. Draw the scope honestly, keep the proof, review before you sign, and calendar the anniversary.
Start your PIEE account registration on day one — it’s the only step with a waiting line.
Related Articles:
- What is CMMC Level 1?
- How to Submit Your SPRS Score
- CUI vs FCI: Which of Your Systems Actually Need Protection?
- What is SPRS?
- CMMC Phase 2 Is Suspended. Your Compliance Obligations Are Not.
Official Sources: 32 CFR § 170.15 (CMMC Level 1 self-assessment requirements), FAR clause 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems), and the DoD CMMC Level 1 Self-Assessment Guide.
Want it done with you instead of by you? Greypike’s fixed-fee Level 1 packages run $3,500 to $9,500 — from a guided self-assessment for shops of ten or fewer to full implementation with an evidence file per practice — and every tier ends with your senior official’s affirmation done right. Or take this guide and run; that’s what it’s for.