CMMC Level 1 Self-Assessment Services: What Government Contractors Should Look For

CMMC Level 1 is 15 requirements, an annual self-assessment, and a senior official's affirmation — with no POA&Ms allowed. Here's what a self-assessment service must deliver so that affirmation rests on evidence.

The short answer: a good CMMC Level 1 self-assessment service scopes your Federal Contract Information correctly, tests every one of the 15 requirements against the DoD assessment objectives, backs the technical requirements with real technical evidence, fixes what fails before you affirm, and keeps monitoring after you do. Anything less leaves your senior official signing an affirmation they cannot defend.

Level 1 looks simple on paper — 15 requirements, a self-assessment, no outside assessor. That is exactly why mid-sized government contractors get it wrong. The work is easy to under-scope, the evidence is easy to skip, and the affirmation carries real legal weight. This guide covers what Level 1 actually requires and what to demand from anyone you hire to help.

What CMMC Level 1 actually requires

CMMC Level 1 applies when a DoD contract requires it — typically for contractors that handle Federal Contract Information (FCI) but not Controlled Unclassified Information (CUI). Contracts solely for commercially available off-the-shelf (COTS) items are excluded. It is built on the 15 basic safeguarding requirements in FAR 52.204-21. The mechanics are set by the CMMC program rule (32 CFR Part 170):

  • Annual self-assessment against all 15 requirements.
  • Results entered in SPRS, the Supplier Performance Risk System.
  • Annual affirmation of continued compliance by a senior company official.
  • No POA&Ms. Every requirement must be fully met when you affirm. There is no partial credit and no “we’ll fix it later.”

CMMC requirements are now appearing in DoD solicitations and contracts under the phased rollout, which means Level 1 status is increasingly a condition of award rather than a future concern.

The 15 requirements, in plain terms

The FAR 52.204-21 requirements fall into six areas:

  • Access control: limit system access to authorized users, processes, and devices; limit them to the transactions they are allowed to perform; control connections to external systems; and control information posted on publicly accessible systems.
  • Identification and authentication: identify users, processes, and devices, and authenticate them before granting access.
  • Media protection: sanitize or destroy media containing FCI before disposal or reuse.
  • Physical protection: limit physical access to systems and facilities, escort visitors, and maintain and control physical access logs and devices.
  • System and communications protection: monitor and protect communications at system boundaries, and separate publicly accessible system components from internal networks.
  • System and information integrity: identify, report, and correct system flaws in a timely manner; provide malicious code protection; keep that protection updated; and perform periodic and real-time scans.

Notice how many of these are technical. Flaw remediation, malware protection, protection updates, scanning, and boundary protection cannot be proven with a policy document. They need technical evidence.

What to look for in a CMMC Level 1 self-assessment service

1. Scoping that starts with where FCI actually lives

Every other decision depends on scope. A provider should map where FCI is received, stored, processed, and transmitted — email, file shares, ERP, laptops, cloud tenants — before assessing anything. Over-scoping wastes money. Under-scoping is worse: it means your affirmation covers systems that were never assessed.

2. Assessment against objectives, not a questionnaire

DoD publishes a Level 1 assessment guide that breaks each requirement into specific assessment objectives, tested by examining documentation, interviewing people, and testing systems. A yes/no questionnaire is not an assessment. Ask the provider to show you how they test each objective and what evidence they record for it.

3. Technical evidence for the technical requirements

For flaw remediation and scanning, the evidence is scan results showing what was found and proof it was fixed. For malicious code protection, it is endpoint status showing protection is installed and current on in-scope machines. For boundary protection, it is firewall and network configuration. A provider that only collects screenshots and signed policies leaves the most testable requirements unproven.

4. Remediation, not just a gap report

Because POA&Ms are not allowed at Level 1, a list of gaps does not get you to an affirmation. The service should include driving fixes to completion and re-verifying them, so that every requirement is met before your official signs.

5. Clear separation between preparation and affirmation

The provider prepares; your company affirms. A credible provider will say so plainly. Treat “CMMC Level 1 certified” badges or guaranteed outcomes as a red flag — there is no third-party certification at Level 1.

6. Monitoring between annual affirmations

The annual affirmation attests to continued compliance. If malware protection lapses on a laptop in month four, or a critical flaw goes unpatched for months, your affirmation is no longer true. Look for continuous scanning and alerting, not a once-a-year snapshot.

7. A path to Level 2 if CUI is coming

Many Level 1 contractors will eventually bid on work involving CUI. The Level 1 requirements are a subset of the 110 NIST SP 800-171 requirements behind Level 2, so evidence collected now should carry forward. Ask whether the provider can grow with you, or whether you will start over.

Get CMMC Level 1 Ready With Evidence You Can Defend

Scan Ninja scopes your FCI, tests every Level 1 requirement, backs the technical ones with scan-based evidence from our own AI-native scanner, and drives remediation to verified closure — so your affirmation rests on proof.

Or Request a Consultation

Why the affirmation is the part to take seriously

A Level 1 self-assessment involves no outside assessor, but it is not low-stakes. The affirmation is a representation to the federal government, and the Department of Justice has pursued contractors under the False Claims Act for misrepresenting their cybersecurity compliance. The practical takeaway: the person signing should be able to point to evidence for every requirement, not a vendor’s assurance.

Questions to ask before you sign with a provider

  • How do you determine which systems are in scope for FCI?
  • Show me the evidence you would record for the flaw remediation and malicious code protection requirements.
  • Do you fix what fails, or hand us a gap report?
  • How do we know we are still compliant in month six?
  • If we pursue Level 2 later, what carries over and what starts over?

Frequently asked questions

Who needs CMMC Level 1?

Defense contractors and subcontractors whose DoD contract or solicitation requires CMMC Level 1 — typically because they process, store, or transmit Federal Contract Information (FCI), information provided by or generated for the government under a contract that is not intended for public release, and do not handle Controlled Unclassified Information (CUI). Contracts solely for commercially available off-the-shelf (COTS) items are excluded. Contractors that handle CUI generally need Level 2.

How many requirements are in CMMC Level 1?

Fifteen. They are the basic safeguarding requirements from FAR 52.204-21, covering access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity.

Can a third party certify my company at CMMC Level 1?

No. Level 1 is a self-assessment. Your company assesses itself annually, enters the result in the Supplier Performance Risk System (SPRS), and a senior company official affirms compliance. A service provider can prepare you and gather evidence, but the affirmation is yours. Be wary of anyone selling a Level 1 "certificate."

Can I use a POA&M for CMMC Level 1?

No. Plans of Action and Milestones are not permitted at Level 1. Every one of the 15 requirements must be fully met at the time you self-assess and affirm.

How often do I have to do a CMMC Level 1 self-assessment?

Annually, with an annual affirmation of continued compliance. Because the affirmation covers ongoing compliance, the controls have to keep working between assessments — not just on assessment day.

What should a CMMC Level 1 self-assessment service include?

At minimum: FCI scoping, an objective-by-objective assessment against the DoD Level 1 assessment guide, technical evidence for the technical requirements (vulnerability scans, malware protection status, boundary configuration), remediation of anything not met, an organized evidence package, and continuous monitoring between annual affirmations.

For the full Level 2 picture — SPRS scoring, SSP, PoAM, and C3PAO-ready evidence — see CMMC 2.0 readiness with Scan Ninja.

Related Resources