If your systems process, store, or transmit Federal Contract Information, you must complete an annual CMMC Level 1 self-assessment, score MET or N/A on all 15 applicable requirements, and submit the results plus a senior-official affirmation into the Supplier Performance Risk System. There's no partial credit at Level 1. You either meet a requirement or you don't, and gaps have to be closed before you affirm, not documented in a future plan.
Three things need your attention this week:
- Scope it correctly. Identify every system, application, and facility that touches FCI, and just as important, identify what doesn't.
- Run a gap check now. Compare your current environment against the 15 safeguarding requirements before you assume you're ready.
- Start building your affirmation packet. You'll need final-form evidence, not drafts, and a senior official ready to sign off.
Under 32 CFR § 170.15, Level 1 permits no Plans of Action and Milestones. Every requirement gets fixed or excluded with documented justification, and you keep the supporting evidence for six years from your CMMC status date.
TL;DR:
- Scope only assets that process, store, or transmit federal contract information to avoid inflating assessment effort.
- Complete final-form evidence such as approved policies and system logs, not drafts or hand-typed spreadsheets.
- Remediate all unmet requirements before affirmation, as no Plans of Action or Milestones are allowed at Level 1.
- Keep all supporting evidence secured and organized for at least six years from the assessment date to satisfy record retention rules.
- Consider outside help if your scope is unclear, evidence is lacking, or your contract involves controlled unclassified information requiring Level 2.
Table of Contents
- What Is a CMMC Self-Assessment, and Who Needs Level 1?
- The CMMC Self-Assessment Checklist: Six Steps From Scope to Submission
- How to Keep Your Assessment Scope Tight
- Common Mistakes That Sink a Self-Assessment
- When It Makes Sense to Bring in Outside Help
- Why Most Small Businesses Overcomplicate This
- Get a Free Security Gap Assessment From Symmnet
- Key Takeaways
- Official Rules and Reference Guides
- Sources
What Is a CMMC Self-Assessment, and Who Needs Level 1?
CMMC Level 1 exists because of two overlapping rules. 32 CFR § 170.15 establishes the annual self-assessment and affirmation requirement, while FAR 52.204-21 lays out the 15 basic safeguarding requirements that Level 1 actually tests. If your contract requires Level 1, these two documents are your entire rulebook.
The dividing line between Level 1 and Level 2 comes down to data type. Federal Contract Information is information the government provides or generates under a contract that isn't intended for public release, think purchase orders, delivery schedules, and basic technical specs. Controlled Unclassified Information is more sensitive, and handling it almost always pushes you into Level 2, with its 110 requirements and, in many cases, third-party assessment.
The 15 Level 1 practices cover the basics: access control, media handling, physical protection, system monitoring, and identification and authentication. Each one gets scored as MET, NOT MET, or N/A, with no room for a fourth category.

The CMMC Self-Assessment Checklist: Six Steps From Scope to Submission
A Level 1 self-assessment breaks into six manageable phases. Skip the order and you'll end up redoing work.
-
Define your assessment scope. List every asset, laptops, servers, cloud applications, printers, that processes, stores, or transmits FCI. The CMMC Scoping Guide for Level 1 is the definitive reference here, and getting this step wrong inflates every step after it.
-
Run the gap analysis. Use the assessment objectives in NIST SP 800-171A alongside the interview, examine, and test methods described in the CMMC Assessment Guide for Level 1. You don't have to use every method for every requirement. DoD guidance gives you flexibility to choose whichever combination provides adequate assurance at the lowest cost for your size of operation.
-
Collect final-form evidence. Approved policies (not drafts), system logs, configuration exports, screenshots of active settings, and training completion records. Map each artifact directly to the requirement it supports.
-
Remediate every NOT MET finding. This is the step small businesses underestimate. Level 1 doesn't accept a remediation timeline as a substitute for remediation itself.
-
Affirm and submit to SPRS. A senior company official reviews the results and submits your CMMC level, assessment date, scope description, CAGE code, and compliance status directly into the Supplier Performance Risk System.
-
Retain everything for six years. The clock starts on your CMMC status date, and reviewers can request that evidence well after the fact.
Pro Tip: Build your evidence folder as you go, organized by requirement number, rather than scrambling to assemble it the week before affirmation. A gap analysis done in March is worthless in December if you can't find the log file that proved it.
How to Keep Your Assessment Scope Tight
Scope discipline is the single biggest lever you have for controlling cost and effort. The operational rule is simple: only assets that process, store, or transmit FCI belong in scope. Everything else, including your marketing laptop or the office guest Wi-Fi, stays out.
The DoD's Level 1 scoping guidance also carves out specialized assets that can sit outside your assessed environment when properly documented:
- IoT devices (smart thermostats, badge readers) that can't run standard security agents
- Operational technology on the shop floor
- Government furnished equipment issued for a specific contract
- Test equipment that doesn't connect to your FCI-handling network
Segmenting your network into an enclave that isolates FCI-handling systems from the rest of your business is often the fastest way to shrink your assessed footprint. If your accounting system touches FCI but your design software doesn't, a firewall rule and a VLAN separating the two can keep the design environment entirely out of scope. Manufacturers weighing where to draw that line should look at network segmentation approaches built specifically for shop-floor environments.
Pro Tip: Every N/A determination needs a written reason tied to your actual scope, plus a name attached to who approved it. "Not applicable" without justification is one of the fastest ways to draw follow-up questions during a review.
Common Mistakes That Sink a Self-Assessment
Reviewers see the same failure patterns repeatedly. Draft policies and working papers don't count as evidence. Only approved, final-form documents or system-generated logs hold up.
Weak N/A justifications get flagged fast, especially when scope descriptions shift between the SPRS entry and the supporting documentation. Common SPRS submission errors include:
- Entering the wrong CAGE code or omitting one for a multi-site company
- Scope wording in SPRS that doesn't match the scope described in your assessment records
- Missing or incorrect status dates that throw off your six-year retention clock
- Submitting before the senior official has actually reviewed the findings
A strong evidence example for access control might be a screenshot of your active user permissions list, timestamped and pulled directly from your system. A weak one is a spreadsheet someone typed up from memory.
When It Makes Sense to Bring in Outside Help
Some businesses can run this process entirely in-house. Others shouldn't try. Consider outside help if any of these apply:
- You can't clearly define what's in scope after reading the DoD scoping guide
- Your internal IT function is one person wearing five hats
- You're missing evidence for more than a couple of requirements
- Your contract actually involves CUI, pushing you toward Level 2
A competent managed IT provider or consultant should deliver a written scope memo, an evidence map tied to each requirement, a remediation plan with realistic timelines, and a checklist for the SPRS submission itself, not just a verbal "you're good to go."
On cost, industry estimates place a Level 1 assessment-only engagement in the low thousands of dollars, with full implementation running higher depending on how many gaps need closing. Budget conservatively, and ask any vendor for a fixed-scope quote before you sign anything. For broader context on how Level 1 fits into the larger CMMC framework, this CMMC 2.0 requirements guide breaks down the differences across all three levels.
Why Most Small Businesses Overcomplicate This
Most of the friction in a Level 1 self-assessment isn't technical. It's scope creep. Business owners assume every laptop in the building needs to be assessed, when in reality a well-drawn enclave around the two or three systems that actually touch FCI cuts the workload by more than half.
The conventional advice, "just work through all 15 requirements company-wide," is backwards for a ten-person shop. Scope first, then assess. Doing it in the reverse order means re-scoping halfway through, which is exactly when businesses start missing their own deadlines.

The other place small businesses stumble is evidence quality. A screenshot pulled straight from an endpoint management console beats a hand-typed spreadsheet every time, because it can't be second-guessed the way a manually assembled document can. If your internal team doesn't have the bandwidth to build that kind of evidence trail while also running the business, that's a legitimate reason to bring in help, not a sign you've failed at compliance.
Owners who treat this as a one-time fire drill instead of an annual discipline tend to redo more work than necessary. Build the habit once and next year's affirmation is a fraction of the effort.
— Michael
Get a Free Security Gap Assessment From Symmnet
Symmnet gives small manufacturers, aerospace suppliers, and professional services firms a faster path to an accurate Level 1 self-assessment than muddling through the DoD guides alone on a Friday afternoon. Symmnet's free security gap assessment identifies exactly which systems touch FCI, maps your current controls against all 15 requirements, and flags what needs fixing before you ever affirm anything in SPRS.

A typical engagement includes a written scope memo, an evidence map tied to each requirement, a prioritized remediation plan, and a walkthrough of the SPRS submission itself so your senior official signs off with confidence. Symmnet also handles the ongoing pieces, 24/7 monitoring, endpoint security, and firewall management, that keep you compliant year after year, not just at affirmation time.
Before requesting your free assessment, have a rough list of your systems and applications ready, along with a sense of which ones handle government contract information. That alone will speed up the first conversation considerably.
Key Takeaways
A CMMC Level 1 self-assessment demands annual completion, MET or N/A on all 15 requirements, six-year evidence retention, and a senior-official affirmation submitted directly to SPRS.
| Point | Details |
|---|---|
| No partial credit at Level 1 | Every applicable requirement must be MET or N/A before you affirm; POA&Ms are not accepted. |
| Scope drives cost | Limiting assessed assets to FCI-handling systems only is the fastest way to cut assessment time and expense. |
| Evidence must be final-form | Approved policies, logs, and system-generated reports hold up; drafts and hand-built spreadsheets don't. |
| Retention lasts six years | Keep every artifact tied to your assessment from the CMMC status date forward. |
| Symmnet offers a free gap assessment | Symmnet maps scope, evidence, and remediation needs for small businesses preparing to affirm in SPRS. |
Official Rules and Reference Guides
Verify every requirement directly against the source documents before you affirm:
- 32 CFR § 170.15 for annual self-assessment and affirmation rules
- CMMC Scoping Guide – Level 1 for defining in-scope assets
- CMMC Assessment Guide – Level 1 for methodology and evidence standards
- DLA Cybersecurity Resources for small business tools and SPRS guidance
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- 32 CFR § 170.15 - CMMC Level 1 self-assessment and affirmation requirements.
- CMMC Scoping Guide – Level 1 (DoD CIO)
- CMMC Assessment Guide – Level 1 (DoD)
- DLA Cybersecurity Resources for Small Business
