Skip to content

CMMC Level 1 Assessment Services

CMMC Level 1 Self-Assessment Support

CMMC Level 1 Self-Assessment Support

Do you have a Department of Defense contract that requires CMMC Level 1?

CMMC Level 1 helps protect Federal Contract Information (FCI) by meeting 15 basic safeguarding requirements from FAR 52.204-21. Unlike CMMC Level 2, Level 1 does not require a third-party C3PAO certification. Contractors complete a yearly self-assessment, submit results through the Supplier Performance Risk System (SPRS), and confirm compliance each year.

Tanner Security helps defense contractors prepare for their CMMC Level 1 assessment. We review your systems that handle FCI, check the required safeguards, find any gaps, review your documentation, and help your team collect the evidence and processes needed for the self-assessment.

We go beyond checking boxes. We help you understand what each requirement means for your business and whether your current technology, policies, and processes meet those needs.

Schedule a CMMC Level 1 Assessment

Talk with an expert about your contract requirements, assessment scope, and controls.

CMMC Level 1 Audit

CMMC Level 1, CMMC Level 2, CMMC Level 3

What Is CMMC Level 1?

CMMC Level 1 is the basic safeguarding level within the Cybersecurity Maturity Model Certification program.

It applies to contractors and subcontractors that need to protect Federal Contract Information (FCI) under applicable DoD contracting requirements.

The 15 Level 1 requirements come from FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Those requirements address areas such as limiting system access, controlling external connections, identifying and authenticating users and devices, protecting communications, controlling physical access, correcting system flaws, protecting against malicious code, and performing security scans.

CMMC Level 1 does not require the same depth of controls as Level 2. Level 2 protects Controlled Unclassified Information (CUI) and incorporates the security requirements of NIST SP 800-171 Rev. 2. Current DoD guidance distinguishes Level 1 from Level 2 in both the required controls and the assessment process.

This difference is important when deciding what your company needs to put in place.

Find Your CMMC Level 1 Gaps

Get an independent review before you complete your annual self-assessment.

Does CMMC Level 1 Require an Audit?

Many people look up “CMMC Level 1 audit,” but it’s important to know the official process.

For Level 1, the DoD currently identifies the required assessment as an annual self-assessment rather than a third-party C3PAO assessment that has recently changed. The contractor conducts the self-assessment against the 15 applicable requirements and maintains the required annual affirmation.

Tanner Security can help your company prepare for that self-assessment through an independent readiness review.

In practice, this means Tanner reviews your environment before you submit your own assessment. We do not represent the government or provide a Level 1 third-party certification.

This approach also gives your leadership team a more objective view before you submit your affirmation.

Who Needs CMMC Level 1?

CMMC Level 1 generally applies to contractors and subcontractors that handle Federal Contract Information but do not need the CMMC Level 2 audit protection requirements for CUI under the applicable contract.

FAR 52.204-21 defines FCI as information provided by or generated for the government under a contract that is not intended for public release, while excluding information the government makes publicly available and simple transactional information needed to process payments.

Your contract language ultimately determines which CMMC level applies.

A company should not assume that handling FCI automatically means Level 1 and stop there. If your systems handle CUI or your contract specifies a higher CMMC level, you may need Level 2 or CMMC Level 3 requirements instead.

Tanner Security can help you determine which requirements you need to evaluate based on your contract and information environment.

The 15 CMMC Level 1 Requirements

CMMC Level 1 incorporates 15 basic safeguarding requirements from FAR 52.204-21. The requirements cover access control, user and device identification, authentication, external-system connections, public information, media disposal, physical access, communications protection, network separation, flaw remediation, malicious-code protection, updates, and security scanning.

Instead of listing a long compliance checklist here, Tanner Security can guide your team through how these requirements apply to your systems.

The key question is not just whether a requirement is written in a policy.

What matters is whether your company has put the safeguard in place and can show how it works.

It is my pleasure to highly recommend Tanner Security Consultants.  As a company dealing with large-scale construction projects, the safety and integrity of our digital infrastructure is crucial. Tanner Security not only met but exceeded all of our expectations.

Jeff M. – Chief Information Officer

What Does a CMMC Level 1 Assessment Evaluate?

A Level 1 self-assessment evaluates whether your company has implemented the 15 required basic safeguards in the systems that handle FCI.

Tanner Security can review areas such as account and access management, authentication, external system connections, public-facing information, media sanitization, physical access, network boundaries, vulnerability and flaw remediation, malware protection, security software updates, and security scanning.

We also review the evidence that supports your assessment.

For example, simply having antivirus software does not prove your company meets the safeguarding requirement. Your team needs to know where the control applies, how it is managed, and how to show that it works as needed.

Our CMMC Level 1 Assessment Process

  1. Understand Your Contract Requirements: We start by understanding your DoD contract requirements, the type of information you handle, and the systems you use to perform contract work.
  2. Define the Assessment Scope: We identify the systems that process, store, or transmit FCI and determine the perimeter of the environment you need to evaluate. Defining the right scope is important because the wrong scope can lead to an incomplete assessment.
  3. Review the 15 Requirements: We evaluate your environment against the applicable Level 1 safeguards and determine how your existing controls address each requirement.
  4. Review Documentation and Evidence: We review relevant policies, procedures, system configurations, inventories, training records, security settings, logs, and other evidence supporting your self-assessment.
  5. Identify Gaps: We document areas where controls do not meet the applicable requirements or where your company cannot adequately demonstrate implementation.
  6. Prioritize Remediation: We help your team decide which issues need to be fixed right away and which improvements can be part of a longer-term security plan.
  7. Prepare for the Self-Assessment: We help your team organize the documentation and evidence it needs to complete the self-assessment and maintain supporting records.
  8. Support Continuous Compliance: CMMC Level 1 requires a yearly assessment and affirmation. Tanner Security can help your company maintain the controls and documentation needed for future assessments.

Prepare for Your CMMC Self-Assessment

Tanner Security can help you identify and address any gaps in your evidence or requirements.

Common CMMC Level 1 Gaps

Many contractors think they already meet Level 1 because they use modern cybersecurity technology.

Technology is helpful, but it does not automatically meet every safeguarding requirement.

Tanner Security often finds issues with incomplete asset identification, inconsistent account management, inadequate authentication practices, weak network boundaries, missing procedures, outdated malware protection, insufficient scanning processes, and incomplete documentation.

Another common problem is when the technology works, but the company cannot clearly show how it meets the requirement.

This difference is important because a self-assessment means your company must check that safeguards are in place and keep the information needed to support the assessment.

CMMC Level 1 and Federal Contract Information

Understanding FCI is a key first step.

FCI differs from CUI. FAR 52.204-21 establishes the basic safeguarding requirements that protect FCI, while CMMC Level 2 uses the security requirements associated with NIST SP 800-171 Rev. 2 to protect CUI.

A company that handles only FCI may fall under Level 1 when the applicable contract requires it.

A company that handles CUI may need Level 2 instead.

This difference can affect your assessment scope, the controls you need, your documentation, costs, and how much time you need to prepare.

CMMC Level 1 vs. Level 2

The difference between Level 1 and Level 2 is important.

Level 1 focuses on basic safeguarding of FCI and uses 15 requirements from FAR 52.204-21. DoD guidance identifies an annual self-assessment and annual affirmation.

Level 2 focuses on wider CUI protection and incorporates 110 security requirements from NIST SP 800-171 Rev. 2. Depending on contract and program requirements, Level 2 may require a self-assessment or a C3PAO assessment.

If you are not sure which level applies, Tanner Security can review your contract requirements and information environment with you.

What Documentation Does CMMC Level 1 Require?

CMMC Level 1 does not require the same extensive documentation program that companies often associate with Level 2.

However, your company has to maintain enough documentation and evidence to support its self-assessment and demonstrate that the required safeguards exist.

Depending on the environment, that evidence may include security policies, procedures, system inventories, account records, configuration information, training records, security settings, scanning records, and other evidence relevant to the 15 requirements.

Tanner Security helps your team find evidence that fits your environment, rather than creating paperwork that does not add value.

CMMC Level 1 and POA&Ms

This is an important distinction between CMMC levels.

Current DoD guidance states that Plans of Action and Milestones (POA&Ms) are not permitted for CMMC Level 1. Level 1 requires the 15 applicable safeguards rather than allowing a company to defer deficiencies through a Level 1 POA&M.

This makes it especially important to prepare ahead of time.

Finding gaps before your self-assessment gives your company a chance to fix them before submitting the assessment and affirmation.

Why Choose Tanner Security for CMMC Level 1?

Tanner Security brings more than two decades of cybersecurity consulting experience to CMMC preparation, risk assessments, penetration testing, vulnerability assessments, IT audits, and compliance projects.

Our experience goes beyond CMMC.

We also work with NIST, PCI DSS, ISO 27001, CIS Controls, HIPAA, cybersecurity risk assessments, and technical security testing.

This broader experience allows us to look at the security issues behind each requirement.

For example, an access-control deficiency may affect CMMC while also creating a wider cybersecurity risk. An inadequate network boundary may affect FCI protection while also giving an attacker an opportunity to reach other systems.

We help your team see these connections and give your IT staff practical recommendations.

We also understand the difference between CMMC readiness support and formal CMMC assessment roles. For Level 1, we focus on helping your company prepare and complete its self-assessment rather than claiming to issue a third-party Level 1 certification.

Talk With a CMMC Level 1 Expert

Know the requirements that apply and what needs to be fixed before your self-assessment.

CMMC Level 1 Frequently Asked Questions

CMMC Level 1 is not going away and it is the basic safeguarding level of the Cybersecurity Maturity Model Certification program. It focuses on protecting Federal Contract Information and contains 15 requirements derived from FAR 52.204-21.

CMMC Level 1 applies to organizations that handle Federal Contract Information and focuses on foundational cybersecurity safeguards. CMMC Level 2 applies to organizations that handle Controlled Unclassified Information and aligns with the requirements of NIST SP 800-171. The following blog post outlines the main differences between NIST 800-171 and CMMC.

No. Current DoD guidance identifies Level 1 as an annual self-assessment, not a third-party C3PAO assessment. The company also needs to complete an annual affirmation of continuous compliance. Read more about some of the changes to the CMMC framework.

“CMMC Level 1 audit” represents a common search term and informal description, but the formal CMMC process for Level 1 uses an annual self-assessment. Tanner Security can perform an independent readiness review to help your company prepare for that self-assessment. Read more about some of the common CMMC challenges and some practical solutions for defense contractors.

CMMC Level 1 contains 15 requirements based on the basic safeguarding requirements in FAR 52.204-21.

It can. The applicable contract requirements can flow CMMC requirements to subcontractors and suppliers when their systems handle the information covered by the contract. Current DFARS language addresses CMMC requirements and flow-down to applicable subcontractors.

Yes. Microsoft 365, Azure, AWS, Google Workspace, and other cloud services may be included in scope if they process, store, or transmit Federal Contract Information.

Level 1 focuses on FCI. CMMC Level 2 protects CUI through the applicable NIST SP 800-171 Rev. 2 security requirements.

Many businesses struggle with documentation, evidence collection, scoping, policy development, and demonstrating that controls are consistently maintained over time. Community discussions frequently note that documentation is often more difficult than the technical controls themselves.

No. Level 1 uses the 15 basic safeguarding requirements in FAR 52.204-21. NIST SP 800-171 forms the basis for the 110 security requirements associated with CMMC Level 2, that has recently been changed.

Costs vary based on environment size, number of users, systems in scope, existing documentation, and overall cybersecurity maturity. Companies with mature security programs generally require less remediation and preparation effort. The typical range for a CMMC Level 1 assessment is $25,000-$35,000.

No. Current DoD guidance states that Level 1 does not permit a POA&M. The CMMC Level 2 framework outlines POA&M’s are allowed.

The CMMC scope depends on the systems your company uses to process, store, or transmit FCI and the applicable contract requirements. Tanner Security spends a lot of time to define that proper CMMC scope and planning before evaluating the controls.

Absolutely. Readiness assessments help identify gaps before formal submission, reducing risk and helping businesses establish stronger compliance documentation and evidence management processes.

Level 1 uses a self-assessment process. Tanner Security can provide independent readiness and consulting support, but your company is still responsible for completing and certifying its Level 1 self-assessment through the applicable CMMC process. It is important to understand the Cybersecurity Maturity Model certification process before starting.

Related CMMC and Cybersecurity Services

CMMC Level 1 often represents one part of a contractor’s broader cybersecurity program.

CMMC Level 2 Assessment: Companies handling CUI may need broader Level 2 requirements based on NIST SP 800-171 Rev. 2.

NIST SP 800-171 Assessment: Evaluate your security controls against NIST SP 800-171 when your contract or cybersecurity requirements call for protection of CUI.

CMMC Consulting: Get broader guidance on CMMC scope, requirements, documentation, remediation, and assessment preparation.

NIST IT Assessment: Evaluate your cybersecurity program against applicable NIST guidance and identify broader security gaps.

IT Risk Assessment: Identify cybersecurity and technology risks based on likelihood, business impact, and operational priorities.

Network Vulnerability Assessment: Identify known vulnerabilities across systems and infrastructure that support your business and government-contract work.

Network Penetration Testing: Determine whether attackers can exploit weaknesses in your internal or external network environment.

IT Policy Development: Develop IT policies that meet CMMC requirements and your company’s broader cybersecurity program.

Prepare for CMMC Level 1 With Confidence

CMMC Level 1 is often the first step in the CMMC program, but contractors should not take the assessment lightly.

Your company needs to know its FCI environment, implement the right controls, keep supporting evidence, complete the annual self-assessment, and maintain the required affirmation.

Tanner Security can help you find gaps before they become problems and give your team practical steps to reach compliance.