Skip to content

Services / CMMC Level 1

Level 1 is a self-assessment. Your signature is still on it.

If your contracts put Federal Contract Information in your hands, someone at your company has to affirm to the Government that all 15 requirements are met. We do the work that makes that affirmation defensible.

Security requirements
15Security requirements
Assessment objectives
59Assessment objectives
POA&Ms permitted
0POA&Ms permitted
Affirmation renewal cycle
1 yrAffirmation renewal cycle

What Level 1 actually is

Level 1 covers Federal Contract Information — information the Government provides or that is generated for the Government under a contract, and that isn't intended for public release. A delivery schedule, a statement of work, an email carrying a requirement. Nearly every DoD contract at any tier produces it.

There is no Level 1 certificate

No third-party assessor, no certification body, and no such thing as a "Level 1 certified" company. It is a self-assessment your senior official affirms in SPRS. Anyone selling you a Level 1 certificate is selling you something that does not exist.

Every applicable objective must be met on day one

Each of the 59 objectives is scored MET, NOT MET, or NOT APPLICABLE. One NOT MET fails the entire requirement, and there is no POA&M pathway at Level 1. Nothing gets fixed later.

Level 1 and Level 2 are not a ladder

You don't do Level 1 on the way to Level 2. Which one applies is decided by the data your contract puts in your hands — FCI or CUI. Getting that determination wrong is the single most expensive mistake in this process.

You do not need GCC High for FCI

Level 1 imposes no FedRAMP requirement. Microsoft 365 Commercial and Google Workspace are both appropriate for FCI-only environments. If someone has told you otherwise, get a second opinion before you sign the invoice.

The determination that comes first

Before we assess anything, we establish in writing whether your contracts involve FCI or CUI. We review your clause list, ask what your prime has actually sent you — drawings, specifications, technical data, anything marked or carrying a distribution statement — and have you confirm the required level with your contracting officer.

If the answer is CUI, this is a different engagement: 110 requirements under NIST SP 800-171, a third-party assessment, and DFARS 252.204-7012 obligations. We will tell you that plainly rather than sell you the smaller project.

We see companies who are clearly Level 2 buy Level 1 anyway because a contract is dangling in front of them. That is not a shortcut. It is an affirmation to the federal government that does not match reality.

How a Level 1 engagement runs

Roughly six weeks, structured so you finish with artifacts you can maintain without us.

  1. 01

    Intake and level determination

    We confirm scope, contacts, and contract posture — then run the FCI/CUI determination and document the answer in writing before any assessment work begins.

  2. 02

    Scope the environment

    Where FCI actually lives: email, shared drives, a quoting system, a folder on somebody's desktop. Who touches it, how many locations, whether there's an on-prem server or specialized equipment. We define the system boundary and write it down.

  3. 03

    People, policies, and training

    Users organized by function, policies assigned by group rather than by individual, and awareness training assigned with a per-person completion record — because that record is your evidence.

  4. 04

    Work the framework

    The bulk of the engagement. Every one of the 59 objectives gets a status and attached evidence, worked against the DoD Level 1 Assessment Guide as the authority. We keep a task log showing how each conclusion was reached.

  5. 05

    Remediate to zero NOT MET

    Configuration work in your Microsoft 365 or Google Workspace tenant, plus the short written artifacts most small companies are missing: an external systems position, a defined patch cadence, a media disposal procedure, and a visitor log you will actually keep.

  6. 06

    SPRS handoff and closeout

    Your Affirming Official submits the status and signs the affirmation. We walk them through it live, confirm they have access, and make sure they understand exactly what they are signing — a representation to the Government, renewed annually, with records retained six years.

The math of zero POA&Ms

Every square is one of the 59 assessment objectives. Each has to be MET on the day your official affirms — a single NOT MET fails its entire requirement, and Level 1 has no POA&M pathway to fix it later.

That is why remediation sits inside the engagement, not in a report we leave behind.

58 objectives MET
58 objectives MET
1 NOT MET — the requirement fails
1 NOT MET — the requirement fails

What we own — and what stays with you

We own

  • The FCI/CUI determination, documented in writing
  • The gap assessment across all 15 requirements and 59 objectives
  • Remediation recommendations and the hands-on configuration work
  • Policies, evidence, and training assignments loaded into your compliance platform
  • Getting you to the point where your Affirming Official can submit

You own

  • The affirmation itself — your senior official signs it, always
  • Telling us when scope changes: a second site, an on-prem server, new headcount
  • Maintaining the artifacts between annual cycles

L2CS is never the Affirming Official and never a signatory to your representation to the Government. That line does not move.

Where small companies actually fail

Level 1 looks trivial on paper. In practice the same six gaps turn up on nearly every engagement.

External systems

Personal phones on company email, home networks, a bookkeeper's laptop, unmanaged file-sharing accounts. Six objectives ride on this, and almost nobody has thought about it.

Boundary protection

A consumer ISP router, no documented ruleset, no review cadence. Eight objectives — the largest single count on the list.

Physical access records

No visitor log, no key register. The cheapest fix on the list and almost always open.

Media sanitization

Old laptops in a closet or handed off to employees, with no wipe record and no disposal procedure.

Incomplete malware coverage

The Windows fleet is covered. The Macs, and the one odd machine in the corner, are not.

"Timely" left undefined

You patch — but nothing states the cadence as a number of days, so the objective cannot be evidenced.

What it costs

Fixed-scope pricing, quoted after discovery. No hourly meters, no surprise change orders — if scope shifts materially, we tell you before we do the work, not after.

Level 1 Implementation

From $7,000one-time, per engagement

A complete Level 1 self-assessment engagement: determination, scoping, gap assessment against all 59 objectives, remediation to zero NOT MET, evidence package, and SPRS handoff to your Affirming Official.

  • Written FCI/CUI determination
  • Full 15-requirement, 59-objective assessment
  • Hands-on remediation and configuration
  • Policy set and awareness training rollout
  • Evidence package and assessment task log
  • Live SPRS submission walkthrough

Final price scales with headcount, number of locations, and whether the environment is cloud-only. Larger or multi-site engagements are quoted accordingly.

Book a Discovery Call

Annual Support & Pre-Attestation Guidance

From $2,400per year

The affirmation renews every year, and the evidence has to hold up across all twelve months in between. This keeps your posture current and gets you to each annual re-affirmation without a scramble.

  • Ongoing evidence and policy upkeep
  • Quarterly control reviews against your documented boundary
  • Change review when your environment or contracts shift
  • Pre-attestation readiness pass before each annual affirmation
  • Awareness training cycle management
  • A named advisor who already knows your environment

Priced by environment size and support cadence. Available alongside an implementation or for organizations already affirmed.

Talk about ongoing support

Frequently asked

How do I know whether I'm Level 1 or Level 2?
It depends entirely on the data your contracts put in your hands. If you only handle Federal Contract Information, you're Level 1. If Controlled Unclassified Information is involved — marked documents, technical data from a prime, a DFARS 252.204-7012 flowdown — you're Level 2. We run that determination in writing at the start of every engagement and confirm it against your contracting officer's answer, because it is the one thing nobody can afford to guess at.
Can you sign our affirmation for us?
No, and no one else can either. The affirmation is a representation to the federal government signed by a senior official at your company. We build the assessment and the evidence behind it, and we make sure your Affirming Official understands exactly what they're signing before they do.
Do we need Microsoft GCC High?
Not for FCI. Level 1 imposes no FedRAMP requirement, and Microsoft 365 Commercial or Google Workspace are both appropriate for an FCI-only environment. GCC High is a Level 2 and CUI conversation, and recommending it for Level 1 is an expensive wrong answer.
What if we can't close a gap before the deadline?
Level 1 has no POA&M pathway. Every applicable objective has to be MET on the day your official affirms. That's why remediation is part of the engagement rather than a list we hand you on the way out.
How long does an engagement take?
About six weeks for a clean, cloud-only environment. Multi-site organizations, on-premise servers, or shop-floor operational technology extend that — and often signal a different tier entirely, which we'd raise during discovery rather than midway through delivery.
Is compliance software included in the price?
No. We recommend and configure a GRC platform as part of delivery, but you license it directly and we don't bill it. That keeps our advice about what you need rather than what we resell.
We already affirmed. Can you just handle the annual cycle?
Yes. Annual support and pre-attestation guidance is available on its own. We start with a readiness pass against your existing evidence so we both know what we're maintaining before we take it on.

Find out which level you're actually on.

A short discovery call establishes whether you're looking at Level 1, Level 2, or something in between — before anyone quotes you a number.

Book a Discovery Call