Handle FCI? Get to Level 1 without the guesswork.
If your contracts involve Federal Contract Information — but not CUI — CMMC Level 1 is your requirement. Fifteen basic safeguards, met through an annual self-assessment. We make sure it’s done right, documented, and defensible.
What CMMC Level 1 actually is.
Level 1 is the entry tier of the Cybersecurity Maturity Model Certification. It applies to contractors who handle Federal Contract Information (FCI) — information provided by or generated for the government under a contract that isn’t intended for public release. It maps to 15 basic safeguarding requirements from FAR 52.204-21.
15 requirements
Fundamental cyber hygiene — access control, authentication, media handling, physical and boundary protection.
Annual self-assessment
You assess your own compliance once a year and submit an affirmation — no third-party (C3PAO) assessment is required at Level 1.
FCI, not CUI
If you handle Controlled Unclassified Information, you’re Level 2 — a different, heavier requirement. Getting this line right matters.
You know you need it. The hard part is doing it right.
Level 1 looks simple on paper. In practice, most small contractors hit the same walls — and a self-assessment you can’t actually back up is worse than no assessment at all.
What gets in the way
- Not sure whether you’re actually Level 1 — or handling CUI and quietly on the hook for Level 2.
- No security team, no documentation, and 15 requirements written in language built for auditors.
- A self-assessment and affirmation you’re signing — without the evidence to defend it if challenged.
How Greypike addresses it
- We confirm your true scope first — FCI vs. CUI, which systems are in play — so you’re solving the right problem.
- We implement the 15 safeguards and build the documentation behind them — in plain terms, sized to your team.
- You walk away with a defensible self-assessment and the evidence to stand behind your affirmation.
CMMC Level 1 Service
A done-with-you package that takes you from “where do we start” to a defensible self-assessment — in fixed-fee tiers sized to your team.
Our Level 1 service is built for contractors who need to meet the requirement cleanly and affordably — without standing up an enterprise security program for a small operation. We handle the scoping, the safeguards, and the documentation; you get a self-assessment you can actually stand behind.
- Scope confirmation — we verify you’re truly Level 1 and identify every system that touches FCI.
- Implementation of all 15 safeguarding requirements, mapped to FAR 52.204-21.
- Self-assessment documentation & evidence to back your annual affirmation.
- Tiered, fixed-fee pricing by headcount — no surprise hourly bills.
- RPA-led throughout, with a clear path to grow into Level 2 if your work changes.
Not every contractor is a textbook case. Maybe you have an unusual system setup, a mix of FCI and a little CUI, an existing MSP to work around, or you simply want an expert in the room rather than a fixed package. Consulting blocks give you expert, RPA-led time for situations the standard tier doesn’t neatly cover.
- Scoping & gap analysis for non-standard or mixed environments.
- Guidance when you’re straddling Level 1 and Level 2 and need to plan the right path.
- Advisory support that works alongside your existing IT or MSP, not around them.
- Help preparing for prime or customer security questionnaires tied to your contracts.
Consulting Blocks
Expert, RPA-led advisory for the cases that don’t fit a fixed package — scoped to exactly what you need.
Let’s get your Level 1 done right.
See transparent, fixed-fee pricing for your team size — or talk it through with us first.