Step-by-Step for Small Contractors

For small defense contractors and subcontractors, CMMC Level 1 self-assessment is often the first step toward compliance with the Department of Defense’s cybersecurity requirements. Under CMMC 2.0, Level 1 is designed to be attainable for organizations that handle Federal Contract Information (FCI) and want to continue bidding on DoD contracts.

This guide breaks down the CMMC Level 1 requirements, the self-assessment process, and common pitfalls—so you can prepare confidently and avoid delays.

What Is CMMC Level 1?

CMMC Level 1 focuses on basic cyber hygiene and consists of 17 security controls derived from FAR 52.204-21. Unlike CMMC Level 2, which aligns with NIST 800-171, Level 1 does not require a third-party assessment. Instead, organizations complete an annual CMMC self-assessment and attest to compliance.

If your organization does not handle CUI (Controlled Unclassified Information), Level 1 is likely the correct starting point in the CMMC program.

CMMC Level 1 Requirements Overview

CMMC Level 1 CMMC Level 2

The CMMC Level 1 requirements are organized to ensure foundational CMMC security practices are in place. These include:

While Level 1 controls are simpler than higher levels, documentation and evidence are still critical during a CMMC audit review or spot check.

Step-by-Step CMMC Level 1 Self-Assessment Process

Step 1: Identify Your Scope

Determine which systems, users, and data are involved in handling FCI. Many small contractors limit scope by using a secure environment or CMMC enclave.

Step 2: Review the 17 Controls

Map each CMMC control to your existing policies and technical safeguards. This forms the basis of your CMMC documentation.

Step 3: Gather Evidence

Evidence can include screenshots, access lists, policies, and training records. This step is often overlooked but essential for proving compliance.

Step 4: Complete the Self-Assessment

Upload your results to the Supplier Performance Risk System (SPRS) as required by the CMMC guidelines.

Step 5: Address Gaps

If controls are not fully met, conduct a CMMC gap assessment or gap analysis to remediate weaknesses before attestation.

Common Mistakes Small Contractors Make

  • Assuming Level 1 means “no documentation”

  • Confusing CMMC Level 1 self-assessment with Level 2 requirements

  • Ignoring future CMMC certification requirements

Even though Level 1 is simpler, many organizations still benefit from guidance from a CMMC MSP or cybersecurity advisor.

Completing a CMMC Level 1 self-assessment is more than a checkbox—it’s your entry point into the DoD supply chain. By understanding the assessment process, documenting controls, and addressing gaps early, small contractors can meet CMMC compliance requirements and prepare for future certification levels.

If you need help identifying what level CMMC you may need, click the link below and schedule a call for a free, 15 no obligation CMMC Checkup to see what your current Cybersecurity posture is and identify what level of CMMC you need to keep bidding on federal contracts.

FREE 15-Min Discovery

15 Minutes Can Save You 58% on CMMC. No Commitment. No Obligations. Learn How You Can Get To CMMC Without Overspending or Overcomplicating.

CMMC Done On Budget, On Time & On Your Terms

CMMC doesn’t have to be expensive or painful. We help DoD contractors reach compliance efficiently, affordably, and correctly.

For More Content

What Security Tools Will Be Required for FedRAMP 20x

Learn what security tools support FedRAMP 20x, including automation, evidence, monitoring, IAM, vulnerability, and readiness needs.

FedRAMP 20x Evidence Requirements Explained

Learn FedRAMP 20x evidence requirements, including machine-readable evidence, KSI validation, automation, and readiness steps for SaaS.

How to Prepare for FedRAMP 20x Certification

Learn how to prepare for FedRAMP 20x certification, build reusable evidence, address KSIs, and connect FedRAMP Moderate readiness to Class C.

Can Azure Help With FedRAMP and CMMC Compliance?

Learn how Azure and Azure Government can support FedRAMP and CMMC compliance, what they help with, and what your team still owns

Can FedRAMP 20x Help You Achieve CMMC Level 2?

Learn how FedRAMP 20x can support CMMC Level 2 readiness, where the frameworks overlap, and what gaps contractors still need to close.