CMMC Level 1, finished end to end.
$3,950 fixed fee · 15 practices · FCI only · 2–3 weeks
If you handle Federal Contract Information but not CUI, Level 1 is your obligation: 15 practices, assessed by you, affirmed in SPRS, every year. It is a bounded requirement and it can be finished.
Fifteen practices, FCI only, self-assessed.
CMMC Level 1 applies to contractors who handle Federal Contract Information — information provided by or generated for the Government under contract that is not intended for public release. It covers the 15 basic safeguarding requirements from FAR 52.204-21. You assess yourself, you enter the result in SPRS, and a senior official affirms it. There is no C3PAO assessment at Level 1.
The Phase 2 suspension did not pause this.
The suspension announced on 13 July 2026 paused the third-party certification mandate. It did not pause Phase 1 self-assessment requirements, DFARS 252.204-7012, or NIST SP 800-171 as the standard — and a self-attested score you cannot substantiate carries False Claims Act exposure either way. Level 1 is a self-assessment, so it sits entirely on the side of the program that is still running.
The whole requirement, not a piece of it.
- FCI scoping — which systems handle Federal Contract Information, and which do not
- All 15 practices assessed against how your environment actually runs
- Remediation guidance for anything not yet met, sequenced by effort
- The documentation the requirement expects, written to survive being read by someone else
- Support entering your result in SPRS and preparing the annual affirmation
- A clear statement of anything that would push you toward Level 2
It recurs, so the support does too
The Level 1 self-assessment and affirmation are annual. An annual refresh re-runs the assessment against whatever changed in your environment and prepares the next affirmation, so the obligation does not quietly lapse between contracts.
If you handle CUI, this is not your level
Level 1 covers FCI only. If Controlled Unclassified Information is in play, the obligation is the 110 NIST SP 800-171 requirements, and the first question is where that CUI actually lives.
Common questions.
How is Level 1 different from Level 2?
Level 1 covers Federal Contract Information and 15 basic safeguarding requirements, assessed by you and affirmed in SPRS. Level 2 covers Controlled Unclassified Information and the 110 NIST SP 800-171 requirements. The trigger is the kind of information in your contract, not the size of your company.
Do we need a C3PAO for Level 1?
No. Level 1 is a self-assessment. You assess your own environment, enter the result in SPRS, and a senior official affirms it. No third-party assessor is involved, which is also why the CMMC Phase 2 suspension did not pause Level 1.
How often do we have to redo it?
Annually. The Level 1 self-assessment and the affirmation both recur every year, so this is an ongoing obligation rather than a one-time project. An annual refresh re-runs the assessment against whatever changed and prepares the next affirmation.
What happens if we affirm something we cannot support?
An affirmation is a statement to the Government. A self-attested result you cannot substantiate carries False Claims Act exposure, which is why the assessment behind it needs to be honest and the evidence needs to exist. That risk does not depend on whether anyone comes to audit you.
What if we turn out to handle CUI?
Then Level 1 is not your obligation and the 110 requirements are. If that looks likely, the first question is where the CUI actually lives, which is a scoping engagement rather than a readiness one.
