Here’s the thing nobody tells you when a prime asks about your “CMMC Level 1 certification”: there is no certificate. Nobody issues one. No assessor visits. No invoice for an audit arrives. Level 1 is something you do, not something you buy — a self-assessment against 15 basic safeguards, recorded in SPRS, and affirmed once a year on an executive’s signature.

That’s genuinely good news, because it means the whole thing is within reach of a small shop in days, not months. It also means the companies quoting you five figures to “get you Level 1 certified” are selling you something that does not exist. Here is the actual path.

Step 0: Confirm Level 1 Is Actually Your Level

Level 1 applies when you handle FCI only — Federal Contract Information: delivery schedules, non-public statements of work, contract correspondence, ordinary contract paperwork that isn’t public. The moment CUI enters the picture — controlled technical data, drawings, specs, export-controlled material — you’re in Level 2 territory, which is a different and much larger obligation.

The practical tell: check your contracts for DFARS 252.204-7012. Present? Plan for Level 2. Absent, and no CUI in your work? Level 1 is your lane. Not sure? Walk the decision here — most contractors guess wrong in one direction or the other, and both wrong guesses are expensive.

What “Getting Level 1” Actually Consists Of

  1. A self-assessment of your environment against the 15 basic safeguarding requirements of FAR 52.204-21;
  2. A record of that self-assessment result in SPRS, the DoD’s Supplier Performance Risk System; and
  3. An annual affirmation of continued compliance by your Affirming Official — a senior person in your company who puts their name on it.

Note what’s absent: no C3PAO, no scored −203-to-110 submission, no formal System Security Plan requirement. Those belong to Level 2. If someone asks for your “Level 1 SPRS score,” there isn’t one — Level 1 records a status, not a number.

The 15 Safeguards, in Plain English

FAR 52.204-21 reads like contract law, but the 15 requirements group into six pieces of ordinary security hygiene:

Read that list against a typical small business running Microsoft 365 or Google Workspace with a business-grade firewall: you likely already meet most of it. The gaps we see most are the unglamorous ones — no visitor log, no documented media-disposal habit, nobody able to say where the network boundary actually is.

The Walkthrough

1. Scope where FCI actually lives

Which machines, accounts, and services touch contract information? In most small shops the honest answer is “the whole office network” — which is fine and keeps the assessment simple. If FCI is confined to a few machines, say so and assess those. Scoping, in detail.

2. Walk the 15, honestly

For each safeguard, answer: do we do this, everywhere in scope? “Mostly” is a no with a to-do attached. The assessment is only useful — and only defensible — if a stranger reading your answers would reach the same conclusions looking at your systems.

3. Fix what you found

Typical Level 1 gap-closing is measured in hours and hundreds of dollars, not consultant engagements: start a visitor log, write down the disposal rule (and wipe the drawer of old laptops), confirm the firewall actually separates your public-facing anything from everything else, check that antivirus is on and updating on every machine, turn on automatic updates.

4. Write down what you did

No formal SSP is required at Level 1 — but a dated record of your self-assessment, who performed it, what you checked, and what you fixed is what makes next year’s affirmation an easy signature instead of an act of faith. A few pages is plenty.

5. Record it in SPRS and affirm

Access runs through the same PIEE/SPRS path as everything else DoD: an active SAM registration, a PIEE account tied to your CAGE code, and the SPRS role for entering assessment results — the same portal plumbing our submission guide walks through. Your Affirming Official — typically the owner in a small shop — then affirms continuing compliance, and re-affirms annually. How affirmations work.

6. Put next year on the calendar

The affirmation is annual, and a lapsed affirmation undoes the status. Diarize it eleven months out, alongside a quick re-run of the 15 questions — your environment will have changed more than you think.

Sign it like it matters, because it does: the affirmation is a representation to the federal government, on a named executive’s signature, relied on for contract award. Affirming safeguards you don’t actually have isn’t paperwork optimism — it’s False Claims Act exposure. At Level 1 the honest path is also the cheap one, so just do the work first.

Start with the free readiness check

CMMC Map’s scoping wizard asks about your contracts and the data you handle, tells you whether Level 1 or Level 2 actually applies, and walks the requirements in plain English — so you fix the right gaps instead of buying the wrong tier of help. Free, no credit card.

Find your level →
Free to assess · No credit card · Documents $149/mo

What It Costs, and How Long It Takes

For a typical FCI-only shop: days to a few weeks of part-time attention, mostly spent confirming and documenting rather than buying. The direct spend is usually small — maybe a firewall setting change, a shredding vendor, a password-manager or MFA rollout you wanted anyway. Compare that honestly against any quote you’ve received that treats Level 1 as an engagement.

The Four Mistakes We See

That’s the whole path. No certificate, no assessor, no mystery — fifteen questions answered honestly, a record in SPRS, and a signature you renew every year.