CMMC Level 1

Handle FCI? Get to Level 1 without the guesswork.

If your contracts involve Federal Contract Information — but not CUI — CMMC Level 1 is your requirement. Fifteen basic safeguards, met through an annual self-assessment. We make sure it’s done right, documented, and defensible.

15 safeguarding requirements Annual self-assessment RPA-led
The basics

What CMMC Level 1 actually is.

Level 1 is the entry tier of the Cybersecurity Maturity Model Certification. It applies to contractors who handle Federal Contract Information (FCI) — information provided by or generated for the government under a contract that isn’t intended for public release. It maps to 15 basic safeguarding requirements from FAR 52.204-21.

15 requirements

Fundamental cyber hygiene — access control, authentication, media handling, physical and boundary protection.

Annual self-assessment

You assess your own compliance once a year and submit an affirmation — no third-party (C3PAO) assessment is required at Level 1.

FCI, not CUI

If you handle Controlled Unclassified Information, you’re Level 2 — a different, heavier requirement. Getting this line right matters.

Self-assessed isn’t self-explanatory. “No assessor required” doesn’t mean “no work required.” The controls still have to be genuinely in place, the evidence has to exist, and a senior official has to affirm it — with real consequences for getting it wrong.
The problem — and the fix

You know you need it. The hard part is doing it right.

Level 1 looks simple on paper. In practice, most small contractors hit the same walls — and a self-assessment you can’t actually back up is worse than no assessment at all.

What gets in the way

  • Not sure whether you’re actually Level 1 — or handling CUI and quietly on the hook for Level 2.
  • No security team, no documentation, and 15 requirements written in language built for auditors.
  • A self-assessment and affirmation you’re signing — without the evidence to defend it if challenged.

How Greypike addresses it

  • We confirm your true scope first — FCI vs. CUI, which systems are in play — so you’re solving the right problem.
  • We implement the 15 safeguards and build the documentation behind them — in plain terms, sized to your team.
  • You walk away with a defensible self-assessment and the evidence to stand behind your affirmation.
Solution 1

CMMC Level 1 Service

A done-with-you package that takes you from “where do we start” to a defensible self-assessment — in fixed-fee tiers sized to your team.

Our Level 1 service is built for contractors who need to meet the requirement cleanly and affordably — without standing up an enterprise security program for a small operation. We handle the scoping, the safeguards, and the documentation; you get a self-assessment you can actually stand behind.

  • Scope confirmation — we verify you’re truly Level 1 and identify every system that touches FCI.
  • Implementation of all 15 safeguarding requirements, mapped to FAR 52.204-21.
  • Self-assessment documentation & evidence to back your annual affirmation.
  • Tiered, fixed-fee pricing by headcount — no surprise hourly bills.
  • RPA-led throughout, with a clear path to grow into Level 2 if your work changes.

Not every contractor is a textbook case. Maybe you have an unusual system setup, a mix of FCI and a little CUI, an existing MSP to work around, or you simply want an expert in the room rather than a fixed package. Consulting blocks give you expert, RPA-led time for situations the standard tier doesn’t neatly cover.

  • Scoping & gap analysis for non-standard or mixed environments.
  • Guidance when you’re straddling Level 1 and Level 2 and need to plan the right path.
  • Advisory support that works alongside your existing IT or MSP, not around them.
  • Help preparing for prime or customer security questionnaires tied to your contracts.
Solution 2

Consulting Blocks

Expert, RPA-led advisory for the cases that don’t fit a fixed package — scoped to exactly what you need.

Let’s get your Level 1 done right.

See transparent, fixed-fee pricing for your team size — or talk it through with us first.