CMMC Level 1 for Small Businesses: What One Landscaping Company Learned
- Shay

- May 29
- 13 min read
Updated: 7 days ago

When one of my landscaping clients first called me about CMMC, it wasn't because they had started a cybersecurity project or decided they wanted to become a defense contractor. They were bidding on work and encountered a question about their CMMC level.
Like a lot of small businesses that occasionally pursue government or subcontracting opportunities, they weren't sure what the question meant, whether CMMC applied to them or what they were supposed to do next. They certainly didn't have an internal compliance department or cybersecurity team sitting around waiting to figure it out.
That original conversation happened several years ago, and I've continued managing this client's IT environment ever since. A lot has changed—not just with CMMC, but inside the company's technology.
Update: I originally wrote this article after this landscaping client encountered CMMC Level 1 while bidding on government work. Since then, CMMC requirements have evolved, and I've continued managing and strengthening this client's IT environment. I've updated this article to reflect the current CMMC Level 1 requirements and to share what has changed inside the client's Microsoft 365 and endpoint environment since that original conversation.
More recently, I completed a full Microsoft 365 Audit for the company and then implemented the findings from that audit. An email account compromise involving an unauthorized sign-in from another country also reinforced why some of those changes needed to happen.
The result is a much stronger Microsoft 365 and endpoint environment than the company had when CMMC first came up.
Those changes weren't made simply to check CMMC boxes. They were changes the business needed to better protect and manage its environment. But they also put the company on a much stronger technical path if the owners decide to pursue contracts requiring CMMC Level 1 in the future.
What Is CMMC Level 1 for a Small Business?
CMMC Level 1 applies to contractor information systems that process, store or transmit Federal Contract Information, or FCI. FCI is generally non-public information provided by or generated for the federal government under a contract to develop or deliver a product or service.
Under the current CMMC framework, Level 1 is based on the 15 basic safeguarding requirements in FAR 52.204-21.
If you've been researching CMMC and have found older information referring to 17 Level 1 practices, you're not imagining it. The earlier CMMC 1.0 model used 17 Level 1 practices. The current framework aligns Level 1 with the 15 safeguards contained in FAR 52.204-21.
That's an important correction to the original version of this article.
Level 1 is a self-assessment, but self-assessment doesn't mean self-declaration without doing the technical work first. The safeguards still need to be implemented in the systems that process, store or transmit FCI.
That's where a lot of small businesses get stuck. Understanding CMMC Level 1 for a small business is one thing; determining how those requirements apply to the company's actual technology is another.
What Do the 15 CMMC Level 1 Safeguards Actually Cover?
The 15 safeguards cover six basic areas:
Access Control
Identification and Authentication
Media Protection
Physical Protection
System and Communications Protection
System and Information Integrity
For a small business owner, I think it's more useful to translate those requirements into practical questions.
Who can access the company's systems? Are employees using individual accounts? How are their identities verified? Are computers protected from unauthorized access? Are systems and applications being updated? Is malware protection installed, configured and maintained? What happens when an employee leaves? Who has administrative access? How are outside connections controlled? How is the network protected? What happens to company information stored on a computer when that computer is retired?
Those are IT questions, not just compliance questions.
That's why I don't think a small contractor should begin a CMMC project by buying products.
Start by understanding the information, the requirements and the environment you already have.
Does Every Small Government Contractor Need CMMC Level 1?
No. A business doesn't automatically need CMMC simply because it occasionally bids on government work.
The requirements depend on the contract and the information involved. FAR 52.204-21 applies when Federal Contract Information resides in or transits through a covered contractor information system.
That's important for businesses like this landscaping company because their normal commercial operations aren't suddenly transformed into a CMMC environment just because they considered a government opportunity.
When CMMC appears in a solicitation or a prime contractor asks about it, I want the business to first understand what requirement actually applies to the work it wants to perform and what information its systems will handle.
That's very different from telling a small company, “You want government work, so replace everything.”
What Happened With This Landscaping Company?
When CMMC originally came up, my client needed to understand what Level 1 meant and whether it was relevant to the opportunity they were pursuing.
I didn't recommend that they immediately start buying technology simply so they could call themselves “CMMC ready.” The business first needed to understand the contractual requirement.
I continued managing their IT environment as I normally would.
Over time, the environment changed. The business changed. Microsoft's capabilities changed. Threats changed. And eventually we had a real security incident that demonstrated why some additional protections were necessary.
An Email Account Was Compromised
More recently, one of the company's Microsoft 365 email accounts was compromised. The unauthorized access included a sign-in originating from another country.
I didn't want to treat that as an isolated incident where we simply changed the password and moved on.
A compromised account should raise a bigger question:
What can I change in the environment to make another compromise more difficult and reduce the company's risk going forward?
I had also completed a full Microsoft 365 Audit for the company. That gave me a much better picture of the tenant's existing configuration, licensing, identity controls, security configuration and the areas I believed needed to be strengthened.
The audit wasn't the end of the project.
The next step was implementing what I found.
Why I Upgraded Them to Microsoft 365 Business Premium
The company had been using Microsoft 365 Business Standard. I upgraded them to Microsoft 365 Business Premium because I wanted to take advantage of the additional identity, endpoint-management and security capabilities available with that licensing.
Business Premium gave me access to capabilities including Microsoft Entra ID P1 and Conditional Access, Microsoft Intune, Microsoft Defender for Business and Defender for Office 365 Plan 1. Those were tools I could use to address actual risks I had identified in the client's environment. But buying Business Premium wasn't the security project.
Configuring it was.
That's an important distinction. A company doesn't become secure simply because it owns a Microsoft license containing security features. Those capabilities need to be configured around the business, its users, its devices and its actual risks.
Strengthening Identity and Authentication
Because the compromised account had been accessed from another country, I implemented Conditional Access policies, including location-based sign-in restrictions appropriate for the way this particular company operates.
This business doesn't have employees routinely signing into Microsoft 365 from countries around the world. There was no legitimate operational reason to leave authentication open in the same way to locations where the company doesn't do business.
That doesn't mean I would configure identical restrictions for every client. A company with employees who regularly travel internationally has very different requirements.
Security controls should fit the business.
I also removed older authentication methods the company no longer needed and implemented passkeys to provide users with a stronger, phishing-resistant authentication option.
The goal wasn't to add as many Microsoft security features as possible. It was to reduce unnecessary authentication paths and make it harder for an attacker to successfully gain access to an employee's account.
Strengthening Email Protection
The account compromise also gave me a reason to take a closer look at the protections surrounding email.
As part of the implementation, I strengthened the company's Microsoft Defender email-security configuration, including domain impersonation protection and user impersonation protection.
An attacker doesn't necessarily need to successfully compromise an employee's mailbox to cause damage. Sometimes the objective is to send a message that looks convincing enough that an employee believes it came from the company's domain, an owner, another employee, a vendor or someone else they trust.
Microsoft 365 Business Premium also gave me additional Defender for Office 365 capabilities for strengthening the company's email protections.
For me, the important part wasn't simply that those capabilities existed in the license. It was making sure the appropriate protections were actually configured for the company.
Managing and Protecting the Company's Computers
I also significantly changed how the company's computers are managed.
I brought applicable devices under Microsoft Intune policies so security and configuration settings could be centrally managed rather than relying on every computer to remain correctly configured on its own.
As part of those policies, I enabled BitLocker drive encryption across the company's managed Windows devices and configured device compliance policies in Intune. This gives me a centralized way to require and monitor important device-security settings and identify devices that fall out of compliance rather than simply assuming a computer is still configured the way it was when I originally worked on it.
I also removed the company's previous antivirus solution and configured Microsoft Defender for Business. Bringing endpoint protection into the Microsoft security environment gives me a much more centralized approach to endpoint security and management.
Adding RMM for Ongoing Management
I also deployed an RMM solution across the applicable devices.
The RMM gives me additional visibility into the computers I'm responsible for, makes controlled remote support easier, helps me maintain device and software inventory and provides better capabilities for managing third-party applications and updates.
This is an area where I think small businesses sometimes misunderstand what Managed IT actually means.
It's not just being available when someone's computer breaks.
I need to know what devices exist, what software they're running, whether they're encrypted, whether they're meeting the security policies I've established, whether applications are being updated, what protection is installed and whether the controls I implemented six months ago are still operating correctly today.
Security controls need to be maintained, not just installed.
What Does All of This Have to Do With CMMC Level 1?
This is where the original CMMC story comes back around.
CMMC wasn't the reason I made these changes. Securing and properly managing my client's environment was.
But there is significant overlap between building a well-managed IT environment and creating a stronger technical foundation for future cybersecurity requirements.
Today, this company has a stronger environment around:
User authentication and phishing-resistant authentication
Identity and access controls
Conditional Access and location-based sign-in restrictions
Managed endpoints
Device compliance policies
BitLocker drive encryption
Endpoint protection through Microsoft Defender
Email and impersonation protection
Remote monitoring and management
Device and software inventory
Third-party application management
Patch and update management
Centralized visibility into the systems I support
Does that automatically make the company CMMC Level 1 compliant?
No.
And I think that's an important distinction for small businesses to understand.
Microsoft 365 Business Premium isn't a CMMC certification. Intune isn't a CMMC certification. Defender isn't a CMMC certification. BitLocker isn't a CMMC certification. An RMM platform isn't a CMMC certification.
They're technologies and controls that can help me build and manage a stronger environment.
If this company decides to pursue a contract requiring CMMC Level 1, we would still need to identify the applicable FCI and systems, determine the proper scope, evaluate the environment against all 15 safeguards and address anything that remains.
But we wouldn't be starting from zero.
You Don't Have to Wait for CMMC to Build Better IT
I think this is one of the most important lessons from this particular client.
Small businesses sometimes approach cybersecurity as something they'll deal with when a government contract, insurance company, customer questionnaire or compliance requirement forces them to.
I don't think that's the best way to build an IT environment.
You don't need CMMC to justify protecting employee accounts from compromise. You don't need a government contract to justify encrypting laptops. You don't need an auditor to tell you that old authentication methods you no longer use should be removed. You don't need a compliance framework to justify patching third-party applications or knowing which computers belong to the business.
Those are things I want to address because they're part of running a better-managed and more secure business.
Then, when CMMC, cyber insurance, a customer security questionnaire or another requirement comes along, we're building on top of an environment we already understand instead of discovering years of unmanaged technology at the same time the business is trying to meet a deadline.
A Microsoft 365 Audit Can Be a Good Place to Start
One of the reasons SNL-Tech Services offers a Microsoft 365 Audit as a standalone service is because many small businesses don't actually know how their Microsoft environment is configured.
Microsoft 365 may have been set up years ago. Employees have come and gone. Licenses have changed. Applications have been connected. Administrators may have changed. MFA may have been enabled at some point. Security capabilities may be included in the company's licensing but never properly configured.
An audit gives me a chance to understand the environment before I start recommending changes.
Depending on the tenant, I can review areas such as:
Users and licensing
Administrative access
Authentication methods
MFA and identity security
Conditional Access
Email security
Microsoft Defender configuration
Device management
Existing security policies
Sharing and permissions
Other Microsoft 365 settings that affect the security and management of the business
Then I can explain to the owner:
Here's what you have. Here's what concerns me. Here's what I recommend changing.
That's what happened with this client.
The Microsoft 365 Audit wasn't a report I handed to the owner and walked away from. It
gave me the information I needed to implement the changes correctly.
What If the Rest of My IT Environment Needs to Be Reviewed Too?
Microsoft 365 is only one part of a company's technology.
If a business is considering CMMC and doesn't have a clear understanding of its overall IT environment, an SNL-Tech Services Baseline IT Assessment may make more sense as the starting point.
That's where I can look more broadly at the company's computers, servers, network, firewall, wireless infrastructure, backups, remote access, security tools, Microsoft 365 and other technology the business depends on.
That distinction is important.
If the concern is primarily “How secure and properly configured is our Microsoft 365 environment?”, a Microsoft 365 Audit may be appropriate.
If the question is “What technology do we actually have, how is everything connected and what needs attention?”, the Baseline IT Assessment gives me a broader starting point.
What If My Business Doesn't Know Whether It Needs CMMC?
Don't start with a shopping cart.
Start with the opportunity or contract that caused the question.
What information will your company receive? Will Federal Contract Information be processed, stored or transmitted through your systems? What CMMC level does the solicitation or contract require? Which computers, accounts, applications and other systems will actually be involved?
If the business needs CMMC Level 1 and doesn't have internal IT capable of evaluating and implementing the technical safeguards, that's where SNL-Tech Services can help.
My focus is on the technical environment: Microsoft 365, identity, authentication, computers, networks, endpoint management, security tools, access controls, patching and the other technology underneath the requirements.
When a business also needs specialized CMMC compliance assistance outside my technical role, I believe in working with professionals who specialize in that side of CMMC and providing them with accurate technical information about the environment I've implemented.
Frequently Asked Questions
How many requirements are in CMMC Level 1?
CMMC Level 1 currently uses the 15 basic safeguarding requirements in FAR 52.204-21. Older CMMC materials may refer to 17 Level 1 practices because the earlier CMMC 1.0 model used 17 practices.
What is FCI?
Federal Contract Information, or FCI, is information not intended for public release that is provided by or generated for the federal government under a contract to develop or deliver a product or service. FAR 52.204-21 establishes the basic safeguards for covered contractor information systems handling FCI.
Is CMMC Level 1 a self-assessment?
Yes. CMMC Level 1 uses an annual self-assessment rather than a third-party assessment. The Level 1 requirements still need to be implemented and assessed; Level 1 does not allow a business to simply declare itself compliant without evaluating the environment.
Does Microsoft 365 Business Premium make my company CMMC Level 1 compliant?
No. Business Premium provides security and management capabilities that can be useful when implementing technical safeguards, but purchasing a Microsoft license doesn't make a company CMMC compliant.
The applicable environment still needs to be properly scoped, configured, managed and assessed against the requirements.
Do I need Microsoft 365 Business Premium for CMMC Level 1?
Not simply because you need CMMC Level 1. Technology and licensing should be selected based on the company's environment, the information being protected and the controls that need to be implemented.
For this client, I chose Business Premium because I wanted its additional identity, endpoint-management and security capabilities to address risks in the company's actual environment.
Do I need Conditional Access for CMMC Level 1?
I wouldn't treat an individual Microsoft feature as a universal CMMC requirement. The business needs to satisfy the applicable safeguards across its environment.
I implemented Conditional Access for this client because it made sense for their security risk and business operations, particularly after the foreign sign-in associated with the compromised account.
Does BitLocker make a computer CMMC compliant?
No. BitLocker provides drive encryption, but no single product or setting makes a computer or company CMMC compliant. It is one security control within a larger technical environment that needs to be evaluated against the applicable requirements.
Does every small business bidding on government work need CMMC?
No. The business needs to review the specific solicitation or contract and understand what information its systems will process, store or transmit. Don't assume every government opportunity automatically requires the same CMMC level.
Can SNL-Tech Services help with CMMC Level 1?
Yes. I focus on the technical implementation and management of the IT environment. That can include reviewing Microsoft 365, identity and authentication, endpoints, networks, security tools, access controls, patching and the other technical safeguards involved in the environment.
A Microsoft 365 Audit or Baseline IT Assessment can also provide a practical starting point when a business doesn't know what it currently has or where its technical weaknesses are.
The Lesson From This Client
When CMMC first appeared on a bid, this landscaping company needed an answer to a question it hadn't encountered before.
Since that original conversation, the company's IT environment has continued to evolve. And I think that's an important part of this story.
We didn't rush out and build a “CMMC network.”
I continued doing what I believe good IT management should do: understanding the business, managing the environment, responding when risks changed and improving the technology where it made sense.
When an email account was compromised, I didn't stop at resetting the password.
I looked deeper.
I audited the Microsoft 365 environment. I upgraded the licensing when the additional capabilities made sense. I strengthened identity and authentication. I restricted unnecessary sign-in locations. I implemented passkeys. I removed older authentication methods. I strengthened email and impersonation protections. I brought devices under Intune management. I implemented compliance policies and BitLocker encryption. I moved endpoint protection to Microsoft Defender for Business. I added RMM capabilities so I could better monitor, support and maintain the devices going forward.
None of that gives the company a CMMC Level 1 badge.
What it gives them today is something much more useful: a stronger, better-managed IT environment.
And if the right government opportunity comes along tomorrow and CMMC Level 1 becomes a business requirement, we've already done a significant amount of foundational technical work.
That's how I think small businesses should approach security: build the environment correctly because the business needs it, understand the requirements that actually apply to you and be ready to build on that foundation when new opportunities come along.
Additional Information & Resources
FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information SystemsOfficial FAR clause covering the 15 basic safeguarding requirements for covered contractor information systems handling FCI.FAR 52.204-21 on Acquisition.gov
FAR Subpart 4.19 — Basic Safeguarding of Covered Contractor Information SystemsOfficial FAR guidance covering the application of FAR 52.204-21.FAR Subpart 4.19 on Acquisition.gov
CMMC Program — 32 CFR Part 170Current federal regulations governing the CMMC Program, including Level 1 assessment and affirmation requirements.CMMC Program regulations on eCFR
Microsoft 365 Business Premium SecurityMicrosoft documentation covering security capabilities available with Microsoft 365 Business Premium.Microsoft 365 Business Premium security overview
Microsoft Intune Compliance PoliciesMicrosoft documentation explaining device compliance policies and how compliance can be used with Conditional Access.Microsoft Intune compliance documentation


Comments