Here’s the thing nobody tells you when a prime asks about your “CMMC Level 1 certification”: there is no certificate. Nobody issues one. No assessor visits. No invoice for an audit arrives. Level 1 is something you do, not something you buy — a self-assessment against 15 basic safeguards, recorded in SPRS, and affirmed once a year on an executive’s signature.
That’s genuinely good news, because it means the whole thing is within reach of a small shop in days, not months. It also means the companies quoting you five figures to “get you Level 1 certified” are selling you something that does not exist. Here is the actual path.
Step 0: Confirm Level 1 Is Actually Your Level
Level 1 applies when you handle FCI only — Federal Contract Information: delivery schedules, non-public statements of work, contract correspondence, ordinary contract paperwork that isn’t public. The moment CUI enters the picture — controlled technical data, drawings, specs, export-controlled material — you’re in Level 2 territory, which is a different and much larger obligation.
The practical tell: check your contracts for DFARS 252.204-7012. Present? Plan for Level 2. Absent, and no CUI in your work? Level 1 is your lane. Not sure? Walk the decision here — most contractors guess wrong in one direction or the other, and both wrong guesses are expensive.
What “Getting Level 1” Actually Consists Of
- A self-assessment of your environment against the 15 basic safeguarding requirements of FAR 52.204-21;
- A record of that self-assessment result in SPRS, the DoD’s Supplier Performance Risk System; and
- An annual affirmation of continued compliance by your Affirming Official — a senior person in your company who puts their name on it.
Note what’s absent: no C3PAO, no scored −203-to-110 submission, no formal System Security Plan requirement. Those belong to Level 2. If someone asks for your “Level 1 SPRS score,” there isn’t one — Level 1 records a status, not a number.
The 15 Safeguards, in Plain English
FAR 52.204-21 reads like contract law, but the 15 requirements group into six pieces of ordinary security hygiene:
- Who gets in (4 controls): limit systems to authorized users and to the transactions those users are allowed to perform; identify users and devices; authenticate them before granting access.
- What leaves (2): control information posted on public-facing systems; verify and control connections to external systems.
- Physical space (2): limit physical access to systems; escort visitors and keep logs of physical access.
- Old media (1): sanitize or destroy drives and media containing FCI before disposal or reuse.
- Network boundary (2): monitor and protect communications at your boundary; keep publicly accessible components (like a web server) on their own subnetwork.
- Malware and patching (4): run malicious-code protection, keep it updated, scan files as they arrive, and fix flagged system flaws promptly.
Read that list against a typical small business running Microsoft 365 or Google Workspace with a business-grade firewall: you likely already meet most of it. The gaps we see most are the unglamorous ones — no visitor log, no documented media-disposal habit, nobody able to say where the network boundary actually is.
The Walkthrough
1. Scope where FCI actually lives
Which machines, accounts, and services touch contract information? In most small shops the honest answer is “the whole office network” — which is fine and keeps the assessment simple. If FCI is confined to a few machines, say so and assess those. Scoping, in detail.
2. Walk the 15, honestly
For each safeguard, answer: do we do this, everywhere in scope? “Mostly” is a no with a to-do attached. The assessment is only useful — and only defensible — if a stranger reading your answers would reach the same conclusions looking at your systems.
3. Fix what you found
Typical Level 1 gap-closing is measured in hours and hundreds of dollars, not consultant engagements: start a visitor log, write down the disposal rule (and wipe the drawer of old laptops), confirm the firewall actually separates your public-facing anything from everything else, check that antivirus is on and updating on every machine, turn on automatic updates.
4. Write down what you did
No formal SSP is required at Level 1 — but a dated record of your self-assessment, who performed it, what you checked, and what you fixed is what makes next year’s affirmation an easy signature instead of an act of faith. A few pages is plenty.
5. Record it in SPRS and affirm
Access runs through the same PIEE/SPRS path as everything else DoD: an active SAM registration, a PIEE account tied to your CAGE code, and the SPRS role for entering assessment results — the same portal plumbing our submission guide walks through. Your Affirming Official — typically the owner in a small shop — then affirms continuing compliance, and re-affirms annually. How affirmations work.
6. Put next year on the calendar
The affirmation is annual, and a lapsed affirmation undoes the status. Diarize it eleven months out, alongside a quick re-run of the 15 questions — your environment will have changed more than you think.
Start with the free readiness check
CMMC Map’s scoping wizard asks about your contracts and the data you handle, tells you whether Level 1 or Level 2 actually applies, and walks the requirements in plain English — so you fix the right gaps instead of buying the wrong tier of help. Free, no credit card.
Find your level →What It Costs, and How Long It Takes
For a typical FCI-only shop: days to a few weeks of part-time attention, mostly spent confirming and documenting rather than buying. The direct spend is usually small — maybe a firewall setting change, a shredding vendor, a password-manager or MFA rollout you wanted anyway. Compare that honestly against any quote you’ve received that treats Level 1 as an engagement.
The Four Mistakes We See
- Buying Level 2 when you’re FCI-only. The 110-control stack, SSP packages, and enclave products are real obligations — for CUI handlers. If no contract puts CUI in your environment, that spend is solving a problem you don’t have.
- Inventing a number. A prime asks for “your SPRS score,” and someone posts one to be helpful. If you’re FCI-only the correct response is an explanation, not a number — your contracts don’t carry the CUI clause, and a made-up score is a representation you’ll regret.
- Assuming the CMMC pause paused this. The July 13 suspension touched the third-party certification rollout — which never applied to Level 1 anyway. The 15 safeguards are a standing contract requirement, and primes are still checking.
- Doing it once. The affirmation is annual. A Level 1 status from last year with no re-affirmation behind it is a lapsed status, and it’s the first thing a prime’s supplier-risk review notices.
That’s the whole path. No certificate, no assessor, no mystery — fifteen questions answered honestly, a record in SPRS, and a signature you renew every year.