Back to Blog
A hand ticking off a handwritten checklist, in a navy duotone.

CMMC Level 1

How to Complete Your CMMC Level 1 Self-Assessment

A plain-English walkthrough of the CMMC Level 1 self-assessment. The 15 requirements, the 59 objectives, evidence, and the annual SPRS affirmation.


If a Department of Defense contract or a prime just asked you to meet CMMC Level 1, you do not need a consultant on retainer and you do not need to become a security expert. Level 1 is a self-assessment you run yourself. This guide walks through exactly what that means, what you have to prove, and how to keep the whole thing organized so you can finish it and defend it later.

The short version. CMMC Level 1 asks you to meet 15 requirements, broken into 59 assessment objectives across 6 domains, to protect Federal Contract Information. You check each objective as MET, NOT MET, or N/A, keep the evidence behind each call, and then a senior official at your company affirms the result annually in SPRS. There is no third-party assessor and no numeric score.

What CMMC Level 1 Actually Is

CMMC stands for Cybersecurity Maturity Model Certification. Level 1 is the foundational tier, and it exists to protect Federal Contract Information, or FCI. FCI is any non-public information the government gives you, or that you generate for the government, under a contract to deliver a product or service. It is not the more sensitive Controlled Unclassified Information (CUI). CUI and the larger Level 2 world are a different, heavier standard. If you only handle FCI, Level 1 is your finish line.

The 15 requirements come from a federal rule called FAR 52.204-21. They are basic cyber hygiene. Use strong passwords, control who can log in, keep antivirus current, limit physical access to your systems. You are very likely doing several of them already.

The AssessrLog Command Center, tracking the 15 requirements and 59 objectives across the six domains with the Ready gauge.
AssessrLog Command Center

Do You Actually Need It?

If your company handles FCI under a Department of Defense contract or subcontract, Level 1 applies to you. The DoD estimates that most of the defense supply base falls into exactly this category. The trigger is usually the contract language itself. Once the clause requiring CMMC shows up in a solicitation, you need your self-assessment done and affirmed before award. Waiting until a bid is on the table is how good suppliers lose work they were qualified for.

Step 1: Scope Your FCI First

Before you touch a single requirement, figure out where FCI actually lives. Which laptops, email accounts, servers, and cloud tools store it, move it, or touch it? Everything inside that boundary is in scope. Everything cleanly outside it is not.

This is the step suppliers most often skip, and skipping it is what causes gaps later. Scoping is a boundary decision you make about your own environment. No tool and no AI should make that call for you. A good system can help you think it through by naming the facts that matter, but the decision stays yours. You can see how we approach that on the product overview.

Step 2: Work the 59 Objectives

Each of the 15 requirements breaks down into smaller assessment objectives, 59 in total, spread across six domains:

  • Access Control: 19 objectives
  • Identification and Authentication: 6 objectives
  • Media Protection: 2 objectives
  • Physical Protection: 10 objectives
  • System and Communications Protection: 10 objectives
  • System and Information Integrity: 12 objectives

For each objective you make one of three determinations. MET means you satisfy it. NOT MET means you do not, yet. N/A means it genuinely does not apply to your environment. Those are the only three answers. There is no partial credit, no percentage, and no compliance score at Level 1.

Step 3: Keep the Evidence Behind Every Call

A determination is only as good as the proof behind it. For each objective, hold the artifact that backs your answer. A screenshot of your password policy, a configuration export, a written procedure, a photo of a locked server closet. Most small suppliers have the safeguards in place. What they lack is the organized proof, which is exactly what turns a shaky self-assessment into a defensible one.

The Evidence tab in the AssessrLog assessment workbench, listing the artifacts uploaded to back an objective.
AssessrLog Evidence Tab

This matters more than it sounds. A self-assessment is a formal attestation, so an inaccurate one is a claim you cannot defend. Keeping evidence in one place, tied to each objective, is how you stay honest and how you defend the result if anyone ever asks.

Step 4: Affirm in SPRS

When every applicable objective is MET or N/A, you are ready to affirm. A senior official at your company records the result in the Supplier Performance Risk System, or SPRS. That affirmation is an annual commitment, and one important detail trips people up. You cannot use a Plan of Action and Milestones at Level 1. There is no "we will fix it later." Every objective has to be resolved before you affirm.

You keep the records for six years. Then you do it again next year.

How Much It Costs and How Long It Takes

There is no assessor fee at Level 1 because there is no assessor. The cost is your time and whatever tooling you use to stay organized. The DoD's own estimate for the manual self-assessment effort is $5,977 per year, most of it labor. Timelines vary. A supplier with basic IT already in place can often work through all 59 objectives at a steady pace, a little at a time. When you are ready to plan the spend, our pricing is straightforward and public.

Run the Whole Assessment in One Place

This is the exact work AssessrLog was built for. It is the system of record where your Level 1 self-assessment lives. Scope your FCI, work all 59 objectives at your own pace, and log each determination with its evidence uploaded and held in one protected place. Come back anytime and see exactly what is done, what is not, and what needs attention. When you are ready, hand your affirming official a clean, defensible package.

One boundary we hold firmly. AssessrLog assembles the package, but it never makes a determination for you, and it never submits or affirms in SPRS. Those steps stay with you and your official, by design.

Frequently Asked Questions

Do I need a third-party assessor for CMMC Level 1? No. Level 1 is a self-assessment. You complete it yourself and a senior official affirms it. Third-party assessors are for Level 2 and CUI, not Level 1.

Is CMMC Level 1 a certification? It is a self-assessment, not a certification. No outside body certifies you at Level 1. You attest to the result and affirm it in SPRS.

How often do I have to do it? Annually. You reassess and re-affirm each year, and you keep the records for six years.

Can I submit with a few objectives still open? No. Plans of Action and Milestones are not allowed at Level 1. Every applicable objective must be MET or N/A before you affirm.

What is the difference between FCI and CUI? FCI is non-public information tied to a government contract. CUI is more sensitive and carries heavier requirements under Level 2. Level 1 is about FCI only.

Filed Under
  • CMMC Level 1
  • Self-Assessment
  • FCI
Start Today

Know Exactly Where Your Assessment Stands.

Work your CMMC Level 1 self-assessment a little at a time, with every determination and its evidence in one place.