Step-by-Step for Small Contractors
For small defense contractors and subcontractors, CMMC Level 1 self-assessment is often the first step toward compliance with the Department of Defense’s cybersecurity requirements. Under CMMC 2.0, Level 1 is designed to be attainable for organizations that handle Federal Contract Information (FCI) and want to continue bidding on DoD contracts.
This guide breaks down the CMMC Level 1 requirements, the self-assessment process, and common pitfalls—so you can prepare confidently and avoid delays.
What Is CMMC Level 1?
CMMC Level 1 focuses on basic cyber hygiene and consists of 17 security controls derived from FAR 52.204-21. Unlike CMMC Level 2, which aligns with NIST 800-171, Level 1 does not require a third-party assessment. Instead, organizations complete an annual CMMC self-assessment and attest to compliance.
If your organization does not handle CUI (Controlled Unclassified Information), Level 1 is likely the correct starting point in the CMMC program.
CMMC Level 1 Requirements Overview
The CMMC Level 1 requirements are organized to ensure foundational CMMC security practices are in place. These include:
Access control for systems and users
Identifying and authenticating authorized users
Protecting systems from malicious code
Limiting physical access to systems and devices
While Level 1 controls are simpler than higher levels, documentation and evidence are still critical during a CMMC audit review or spot check.
Step-by-Step CMMC Level 1 Self-Assessment Process
Step 1: Identify Your Scope
Determine which systems, users, and data are involved in handling FCI. Many small contractors limit scope by using a secure environment or CMMC enclave.
Step 2: Review the 17 Controls
Map each CMMC control to your existing policies and technical safeguards. This forms the basis of your CMMC documentation.
Step 3: Gather Evidence
Evidence can include screenshots, access lists, policies, and training records. This step is often overlooked but essential for proving compliance.
Step 4: Complete the Self-Assessment
Upload your results to the Supplier Performance Risk System (SPRS) as required by the CMMC guidelines.
Step 5: Address Gaps
If controls are not fully met, conduct a CMMC gap assessment or gap analysis to remediate weaknesses before attestation.
Common Mistakes Small Contractors Make
Assuming Level 1 means “no documentation”
Confusing CMMC Level 1 self-assessment with Level 2 requirements
Ignoring future CMMC certification requirements
Not aligning cybersecurity practices with long-term growth plans
Even though Level 1 is simpler, many organizations still benefit from guidance from a CMMC MSP or cybersecurity advisor.
Completing a CMMC Level 1 self-assessment is more than a checkbox—it’s your entry point into the DoD supply chain. By understanding the assessment process, documenting controls, and addressing gaps early, small contractors can meet CMMC compliance requirements and prepare for future certification levels.
If you need help identifying what level CMMC you may need, click the link below and schedule a call for a free, 15 no obligation CMMC Checkup to see what your current Cybersecurity posture is and identify what level of CMMC you need to keep bidding on federal contracts.



