top of page

CMMC Level 1 for Small Businesses: What Do I Actually Need to Do?

  • Writer: Shay
    Shay
  • Aug 12
  • 15 min read
CMMC Level 1 for small businesses showing the steps to understand requirements, evaluate the IT environment and implement security changes.

If you own a small business that currently performs work for the Department of War (DoW), or you are considering bidding on DoW contracts for the first time, CMMC Level 1 is something worth understanding before an opportunity lands in front of you.

I have seen how quickly this can come up.


A client of mine was working on a bid when they came across a question asking for their CMMC level. They own a landscaping company and had never had a reason to think about CMMC before. Now they were being asked whether they were Level 1, Level 2 or Level 3, and they had no idea how to answer the question.

They contacted me to find out what it meant and what they needed to do.


I think their situation is a good example of why CMMC is not limited to companies that most of us would picture when we hear the term "defense contractor." A construction company, landscaper, electrical contractor, manufacturer, engineering firm or another small service business may find an opportunity to perform government work and encounter CMMC as part of the bidding process.


If your company is interested in this type of work, I would rather have you understand the basics before you are sitting in front of a bid with a deadline approaching.

This article explains what CMMC Level 1 means, how Federal Contract Information fits into it, what some of the requirements look like inside an ordinary small business, and what you should consider if government contracting is part of your company's plans.


What is CMMC Level 1?

CMMC stands for the Cybersecurity Maturity Model Certification program.

Level 1 focuses on protecting Federal Contract Information, commonly called FCI.

FCI is non-public information that your company receives or creates while performing certain federal contract work. If you are not sure what qualifies as FCI, I recommend reading my article about FCI vs. CUI first. Understanding what information your company will handle makes the rest of the CMMC conversation much easier.

CMMC Level 1 is based on 15 security requirements from FAR 52.204-21. They address fundamental cybersecurity protections that businesses handling FCI are expected to have in place.


You will sometimes see these described as "basic" cybersecurity requirements. That description can give a small business owner the impression that Level 1 is simply a checklist of things they probably already have.


You may already have many of the protections, especially if your IT environment is being properly managed. The assessment still requires you to look at how those protections are configured and whether your company is actually following the requirements.


How do I know if I need CMMC Level 1?

Start with the contract or solicitation.

Your industry does not determine your CMMC level. Being a construction company, landscaping business or manufacturer does not automatically make you Level 1, and being interested in government contracting does not automatically mean you need to complete a Level 1 assessment.

The solicitation identifies the CMMC requirement for the work.


This is why I would never recommend guessing when a bid asks about your CMMC level.

If you are filling out a bid and suddenly encounter a question asking whether your company is CMMC Level 1, Level 2 or Level 3, don't select Level 1 simply because it is the lowest option. Find out what the solicitation requires and what type of information your company will be expected to handle.


That answer determines what needs to happen next.


Should I think about CMMC before I start bidding on DoW contracts?

If DoW contracting is something your company seriously wants to pursue, I think it makes sense to understand your cybersecurity environment ahead of time.

Consider what happens if you spend months looking for opportunities and finally find a contract that is a great fit for your company. You have the people and equipment to perform the work, your company has the right experience, and you are comfortable with the numbers.


Then you discover that the solicitation requires CMMC Level 1.

When Level 1 is required for an award, the contractor needs the applicable Final Level 1 (Self) status. Level 1 does not have the conditional status available in certain situations at Levels 2 and 3.

Discovering that requirement a few days before a bid is due puts you in a very different position than knowing about it ahead of time.


I am not suggesting that every company interested in government work should immediately spend money building a CMMC environment. I would first want to understand the type of work you intend to pursue and what requirements are likely to come with it.


For a company that is serious about pursuing DoW contracts, though, an early look at the IT environment can uncover issues while there is still time to deal with them properly.


Is CMMC Level 1 a certification?

This is a common source of confusion because CMMC has the word "Certification" in its name. Level 1 uses an annual self-assessment. You do not hire a C3PAO to perform a Level 1 certification assessment. A self-assessment does not mean that you look around the office, decide your cybersecurity seems pretty good and check a box saying that you are Level 1. Your company has to evaluate its environment against the Level 1 security requirements. Every requirement must receive a MET result for the company to achieve Final Level 1 (Self) status.

The results are submitted to the Supplier Performance Risk System, commonly called SPRS, and an affirmation is required. The Level 1 assessment is performed annually.


What do the 15 CMMC Level 1 requirements actually mean?

Government security requirements make more sense when you put them into the context of an ordinary business.


Suppose you own a company with five employees. Each employee has a laptop and a Microsoft 365 account. The office has a firewall and a printer, your computers have endpoint security, and your business uses a cloud backup service.

That is a fairly normal small-business IT environment, and some of what you already have may help satisfy Level 1 requirements.

What matters is how everything is being used and managed.


For example, I would look at how employees sign into their computers and company systems. If several employees are sharing an account, that is very different from having individual accounts with access assigned according to each person's job.

I would also want to know what happens when somebody leaves the company. Disabling a former employee's Microsoft 365 account is one part of that process, but I would also look at remote access, shared accounts and any other systems the person could still reach.


The computers themselves matter too. They need to be maintained, security updates need to be addressed, and malware protection needs to be installed and kept current where required.


Some of the requirements have very practical physical implications. If a computer containing FCI is sitting in an accessible area of the office, who can use it? When an old computer or hard drive is retired, what happens to the information stored on it before that equipment leaves the business?


These are the kinds of situations hiding behind some of the formal compliance language.

I am going to cover the 15 Level 1 requirements individually in another article because I think each one is easier to understand when it is explained using examples that make sense to an ordinary business owner.


Having antivirus does not make you CMMC Level 1

One mistake I see with cybersecurity compliance is focusing too heavily on which products a company owns.

A business might have a very good firewall that has never been configured properly. Endpoint protection may be installed on most computers but missing from one that is still being used. Microsoft 365 may be in place while old user accounts, excessive permissions or weak administrative practices remain.

The products are only part of the environment.

This matters for small businesses because cybersecurity projects can get expensive very quickly when the conversation starts with a shopping list.


Before recommending that a company replace its firewall, change Microsoft environments or purchase another security product, I want to know what is already there and whether it can meet the requirement when it is configured and managed correctly.

Sometimes new technology will be necessary. Sometimes the company already owns much of what it needs. The assessment should help us determine the difference.


Do I need GCC or GCC High for CMMC Level 1?

I would not assume that your company needs to move to Microsoft GCC or GCC High simply because CMMC Level 1 appears in a solicitation.

Level 1 focuses on safeguarding FCI. The Microsoft environment that makes sense for your company depends on the information you handle along with any other contractual, regulatory or data-handling requirements associated with the work.


If your company already uses Microsoft 365, I would want to understand the existing tenant before recommending a migration. That includes the licensing, security configuration, user access and how FCI would move through the environment.

I would approach a company using Google Workspace the same way.

Moving a small company into a more expensive cloud environment without first establishing that it is necessary can add considerable cost and complexity. I want the requirements to drive that decision.


Does my entire company have to be included in CMMC Level 1?

Not necessarily, and this is where CMMC scope becomes very important.

Level 1 can apply across an entire business environment, but it can also apply to a particular enclave depending on where FCI is processed, stored or transmitted.

Suppose your company has twenty employees but only three of them need to handle FCI for a particular contract. Instead of allowing that information to move throughout the company's normal technology environment, it may be possible to create a smaller environment for the people and systems that need it.


For some businesses, that can make much more sense than bringing the entire company into scope. An enclave is not as simple as putting three computers on a different Wi-Fi network, though.

Before I could determine whether an enclave makes sense, I would want to map how the FCI actually moves through the business. I need to know how the company receives it, where employees save it, whether it travels through email, what happens to it during backups, which computers can access it and whether anyone needs remote access.

Printers can matter. Cloud services can matter. External service providers can matter.

If FCI is supposed to remain inside an enclave but employees routinely email copies to people outside it or save files somewhere else, the boundary you thought you created may not be the boundary you actually have.


For a small company preparing to pursue DoW contracts, this is worth discussing before spending money on a company-wide CMMC project. If only a few people need to handle FCI, I would want to know whether limiting the scope is practical.


Can a five-person company realistically meet CMMC Level 1?

Yes.

The size of the company does not change the requirements, but a smaller IT environment can sometimes make them easier to manage.

Think about two companies that each have five employees.


The first has managed laptops, individual user accounts, properly configured Microsoft 365 security, endpoint protection and a business-grade firewall. There is also an established process for removing access when an employee leaves.


The second company also has five computers and Microsoft 365, but everyone is a local administrator, passwords are shared, an account belonging to an employee who left six months ago is still active, and nobody is quite sure when the computers were last updated.


Those businesses may look similar on paper. From a cybersecurity standpoint, they are starting in very different places. This is why I would not look at a five-person company and automatically assume that becoming ready for Level 1 will either be easy or expensive. I need to see the environment first.


Can I perform the Level 1 assessment myself?

Yes. Level 1 is specifically a self-assessment.

Your company is responsible for the assessment results and the required affirmation, although you can get outside help with the assessment and preparation.

For many small-business owners, the difficulty is not reading the requirement. It is knowing how to determine whether the technology actually satisfies it.


You may know that your office has a firewall without knowing whether the settings relevant to a particular requirement are configured correctly. The same thing can happen with Microsoft 365. An owner knows that everyone has an account and MFA may be enabled, but that does not necessarily tell them how administrative access, permissions and other security settings are configured.

That is where I can help.


I can evaluate the technical environment, identify gaps and show what is actually configured. Your company still owns the assessment and its answers, but those answers should be based on evidence rather than assumptions.


What evidence should I have?

If your company says that a requirement is MET, you should be able to support that conclusion.


The evidence will not necessarily look the same for every requirement.

A Microsoft 365 configuration may help demonstrate one requirement while another may involve the firewall, endpoint security platform or configuration of the computers themselves. User account records, update information and other technical records may also be relevant.


Some requirements may involve company procedures in addition to technical configurations.


Level 1 assessment artifacts used as evidence must be retained for six years from the CMMC Status Date.


For that reason, I would not treat the assessment as something you complete once, submit and then forget about. You should know what supported your answers and be able to produce that information later.


Can I use a POA&M if I have something left to fix?

No.

CMMC Level 1 does not allow a Plan of Action and Milestones, commonly called a POA&M. All of the Level 1 security requirements have to receive a MET result.

For a small business, I think the practical way to handle this is to find the gaps before completing the final self-assessment.

If I find a computer that is not being properly protected or an access-control issue that prevents a requirement from being MET, I would want to fix the problem and verify the change before the company submits its Level 1 assessment.

This becomes particularly important when you are preparing for a contract award because Level 1 requires final status. You cannot use a conditional Level 1 status while you finish outstanding work.


What is SPRS?

SPRS stands for the Supplier Performance Risk System.

This is where the Level 1 self-assessment results are submitted. The submission includes information about the CMMC level, assessment scope, applicable CAGE codes and the compliance result.

If you are new to government contracting, SPRS is probably one more unfamiliar acronym in a process already full of them.

I would not start there.

First, find out what the contract requires and whether your company will handle FCI. Then make sure the technology environment actually meets the Level 1 requirements. Once you understand those pieces, dealing with the submission itself is much easier.


How much does CMMC Level 1 cost a small business?

There is no single answer because two businesses of the same size can have completely different technology environments.

A five-person company that already has managed computers, appropriate Microsoft 365 licensing and configuration, endpoint protection, a properly configured firewall and good account-management practices may have a relatively short list of things that need attention.

Another five-person business may be using computers purchased at different times, consumer email accounts, shared passwords and an old router, with no centralized management of the devices.

The amount of work required for those companies will not be the same.

That is why I would be cautious about anyone quoting a complete CMMC Level 1 project without first learning what is already in place.

An assessment of the existing environment gives us a much better idea of what actually needs to be changed and what can stay.


What should I do if CMMC Level 1 appears on a bid?

Don't guess.

Read the CMMC language in the solicitation and find out exactly what is being required.

If the company will handle FCI, I would then trace that information through the business. I want to understand how it arrives, which employees and computers have access to it, where it is stored, whether copies end up in email or backups, and how remote access is handled.

Once that picture is clear, the environment can be evaluated against the Level 1 requirements.

That approach gives you a much better starting point than buying cybersecurity products because a bid mentioned CMMC and hoping you bought the right things.


How SNL-Tech Services can help with CMMC Level 1

SNL-Tech Services can help a small business evaluate and prepare the technical side of its CMMC Level 1 environment.


I start by looking at the technology you already have and comparing the applicable technical requirements against what is actually configured. When I find gaps, I can identify what needs to change and implement the technical work needed to correct them.


Depending on the company, that might involve Microsoft 365 or Google Workspace, employee computers, user accounts, endpoint security, firewalls, network security, remote access, system updates or other technology that processes, stores or transmits FCI.


I can also help gather and organize the technical evidence that supports what is in place.

For a company where only a small number of people will handle FCI, I can evaluate whether an enclave may make sense from the technical side and what would be involved in separating that environment. The scope still has to reflect everywhere the FCI actually goes, which is why I want to understand the information flow before designing the solution.


Your company remains responsible for its Level 1 self-assessment and affirmation. My role is to help you understand the technical environment, correct the problems that need to be corrected and make sure the technical answers are supported by what is actually in place.


I can also work with a small business that has not bid on a DoW contract yet but wants to understand whether its current IT environment is headed in the right direction before it begins pursuing opportunities. I do not start that conversation with a list of products to buy. I start by finding out what kind of work you are pursuing, what information you may need to protect and what technology you already have. From there, we can determine what actually needs to change.


CMMC Level 1 Frequently Asked Questions

Do I need a C3PAO for CMMC Level 1?

No. CMMC Level 1 uses an annual self-assessment rather than a certification assessment performed by a C3PAO. You can have a third party assist with the assessment and preparation, but your company remains responsible for the self-assessment and affirmation.


How many security requirements are in CMMC Level 1?

CMMC Level 1 has 15 security requirements based on FAR 52.204-21. Every Level 1 requirement must receive a MET result to achieve Final Level 1 (Self) status.


How often do I have to complete the Level 1 assessment?

The Level 1 self-assessment is completed annually. An affirmation is also required.


Can I use a POA&M for something I still need to fix?

No. Level 1 does not permit POA&Ms. If you find something that prevents one of the requirements from being MET, it needs to be corrected before achieving Final Level 1 (Self) status.


Do I need GCC High for CMMC Level 1?

I would not assume that you need GCC High just because CMMC Level 1 appears in a solicitation.

The right Microsoft environment depends on the information your company will handle and any other contractual or regulatory requirements that come with the work. I would review those requirements and the Microsoft environment you already have before recommending a migration.


Can I use Microsoft 365 for CMMC Level 1?

Potentially. Simply having Microsoft 365 does not answer the compliance question. I would look at how the tenant is configured, how users and administrators are managed, what security controls are in place and how FCI will be processed, stored or transmitted.


Can I use Google Workspace for CMMC Level 1?

Potentially. I would evaluate Google Workspace the same way I would evaluate Microsoft 365. The platform name by itself does not determine whether your environment meets the applicable requirements.


Can employees work from home?

Remote work does not automatically prevent a company from meeting Level 1 requirements, but it does affect the environment that needs to be considered.

For example, an employee working from a properly managed company laptop is very different from an employee downloading FCI onto a shared family computer. The device, connection, storage location and access to the information all need to be considered.


Can I use an enclave for CMMC Level 1?

Potentially.

An enclave can make sense when only part of the company needs to process, store or transmit FCI. A twenty-person company with three employees working on applicable contracts may not necessarily need FCI moving throughout the technology used by the other seventeen employees.

The boundary has to work in practice, though. If information from the enclave ends up in the company's normal email, file storage, backup systems, printers or other computers, those systems may affect the assessment scope.

Before designing an enclave, I would map how the FCI will actually move through the business and who needs access to it.


We only have two employees. Do we still need to meet all of the Level 1 requirements?

Yes, if CMMC Level 1 applies to your company.

Having only two employees can make the technology environment smaller and potentially easier to manage, but it does not reduce the Level 1 requirements that must receive a MET result.


Does having a managed IT provider make me CMMC Level 1?

No.

A well-managed IT environment may mean that many of the necessary technical protections are already in place. The environment still has to be evaluated against the actual Level 1 requirements.


Should I get CMMC Level 1 before I start bidding on DoW contracts?

I would not spend money pursuing a CMMC status simply because your company might bid on government work someday. Different opportunities can have different requirements.

If DoW contracting is something you seriously plan to pursue, however, I think it is worth understanding your current cybersecurity environment ahead of time.

When a solicitation requires CMMC Level 1, the applicable Final Level 1 status needs to be in place before award. Looking at the environment early gives you time to find and correct problems instead of trying to make rushed IT decisions while an opportunity is already in front of you.


Where should I start?

Start with the work.

If you already have a solicitation, determine what CMMC requirement it contains and what information your company will handle. If you are still planning to pursue DoW work, learn what is likely to be required for the types of contracts you are interested in.

Once you know that, look at where FCI would enter your company and how it would move through your technology environment.

That tells us what needs to be evaluated.


You may discover that much of what you need is already in place. You may find gaps that should be corrected before you bid. You may even determine that limiting the environment through an enclave makes sense.

The important part is understanding what you actually need before you start spending money trying to become "CMMC compliant."



This article provides general educational information and is not legal advice, a CMMC certification, or a determination of the requirements that apply to a particular contract.

Comments


bottom of page