CMMC Level 1 · GuideSEC / GDE

Guide

Do I need a C3PAO or a third-party assessor for CMMC Level 1?

Short Answer

No. Level 1 is self-assessed. A C3PAO, the accredited third-party assessor, is part of Level 2, not Level 1. You may bring in a consultant or managed IT provider to help, but it remains your self-assessment.

Where a C3PAO fits

A Certified Third-Party Assessment Organization conducts the third-party assessments used at Level 2. At Level 1 there is no third-party assessment and no audit. You evaluate your own systems.

Getting help without a C3PAO

A consultant, an external service provider, or a managed IT provider can assist with the work, and a requirement can be met by what that provider implements. The affirmation, however, must be signed by your own senior Affirming Official. A third party cannot affirm for you.

Primary Sources

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.