CMMC Level 1 Self-Assessment: A Step-by-Step Guide for Small DoD Suppliers

When the Department of War suspended CMMC Phase II on July 13, 2026, a lot of small suppliers heard “CMMC is on hold.” That isn’t what happened. The suspension covers the Phase II milestones that were scheduled for November 10, 2026. Phase I self-assessment requirements remain in place, and so do your existing DFARS 252.204-7012 obligations. (We covered the suspension itself in DoD Just Suspended CMMC Phase II.)

If your company handles Federal Contract Information (FCI), which is most DoD suppliers, the requirement you’re most likely to face today is the CMMC Level 1 self-assessment. It’s also the one that’s easiest to get wrong because nobody from the government checks it before you sign.

This guide walks through the process step by step.

First: do you actually need Level 1?

Level 1 applies to contractors that handle FCI but not Controlled Unclassified Information (CUI). Under FAR 52.204-21, FCI is information “not intended for public release” that is provided by or generated for the Government under a contract to develop or deliver a product or service.

In practice, that includes things like contract-specific drawings, delivery schedules, and correspondence with your contracting officer. It does not include information the government has already released publicly or simple transactional information such as what’s needed to process payments.

If you also handle CUI, such as drawings marked with a CUI banner or export-controlled technical data, you’re in Level 2 territory, and Level 1 alone won’t be enough.

What Level 1 requires

Level 1 is built on the 15 basic safeguarding requirements in FAR 52.204-21. In plain English, they cover:

  • Access control: only authorized people, processes, and devices get into your systems, and only for the work they’re allowed to do
  • External connections: you control and limit connections to outside systems
  • Public information: you control what gets posted on public websites and social media
  • Identity and authentication: you identify users and devices and verify them (for example, with passwords) before granting access
  • Media sanitization: you wipe or destroy drives and media holding FCI before disposal or reuse
  • Physical security: you limit physical access to systems and equipment, escort and log visitors, and manage keys, badges, and codes
  • Boundary protection: you monitor and control communications at the edges of your network, and separate public-facing systems from internal networks
  • Patching: you find and fix system flaws in a timely manner
  • Malware protection: you run anti-malware protection, keep it updated, and scan regularly, including real-time scans of downloaded and opened files

None of this is exotic. Most well-run small businesses already do much of it. The challenge is proving it, consistently, across every system that touches FCI.

Step 1: Define your assessment scope

Before you evaluate a single control, decide which people, devices, systems, and facilities process, store, or transmit FCI. That’s your assessment scope, and you’ll report it in SPRS.

A tight, well-documented scope is the single biggest cost saver in CMMC. If FCI lives in one Microsoft 365 tenant, a file share, and six laptops, your assessment is about those assets, not every device in the building.

Step 2: Assess each requirement against NIST SP 800-171A

32 CFR 170.15 requires you to assess using the objectives in NIST SP 800-171A, substituting FCI wherever that document says CUI. Each requirement is scored MET or NOT MET.

For each one, gather simple evidence:

  1. A written description of how you meet it (one or two paragraphs is fine)
  2. Proof it’s working, such as screenshots, configuration exports, logs, visitor sign-in sheets, or disposal certificates
  3. The person responsible for keeping it that way

Level 1 has no partial credit. You must achieve MET on all 15 requirements.

Step 3: Fix gaps before you affirm, not after

This is where Level 1 differs from Level 2. The regulation is explicit: no POA&Ms (plans of action and milestones) are permitted for CMMC Level 1. You can’t submit a plan to fix things later. Every requirement must be met on the day you affirm.

Common last-minute gaps we see:

  • Shared or generic logins on shop-floor PCs
  • Old laptops and drives that were never securely wiped
  • No visitor log at the front desk
  • Patching that happens “when someone remembers”
  • A firewall nobody has reviewed since it was installed

Step 4: Enter your results in SPRS

Record your results in the Supplier Performance Risk System (SPRS). Per 32 CFR 170.15, the submission includes your CMMC level, status date, assessment scope, all CAGE codes covered, and the compliance result.

Step 5: Affirm, and repeat every year

A senior official at your company, the Affirming Official, must affirm in SPRS that the organization has implemented and will maintain all applicable requirements. Under 32 CFR 170.22, this person must have the authority to make that commitment for the company.

Level 1 is annual. Put the next self-assessment on the calendar the day you submit this one.

Why accuracy matters more than speed

An affirmation is a representation to the federal government. Legal analysts note that the Department of Justice remains focused on cybersecurity noncompliance and may look closely at inaccurate Phase I self-assessments. An honest NOT MET that you fix before affirming is far better than a MET you can’t support with evidence.

A quick Level 1 readiness checklist

  • ☐ We’ve confirmed we handle FCI, and whether we also handle CUI
  • ☐ Our FCI assessment scope is written down
  • ☐ All 15 requirements are MET, with evidence on file
  • ☐ Results and scope are entered in SPRS
  • ☐ Our Affirming Official understands what they’re signing
  • ☐ Next year’s assessment date is on the calendar

Need a second set of eyes?

Quad-B CMMC Readiness helps small and mid-size defense suppliers scope their environment, close gaps, and assemble evidence that holds up. See our services, read about CMMC gap analysis, or request a free CMMC consultation. You can also reach us at info@quadbsystems.com or 949.693.0664.

This article is for general information and isn’t legal advice. Review your specific contract clauses with qualified counsel.

Sources