A customer said, "CMMC." Here's what Level 1 actually asks of a small manufacturer, no scare tactics included.
------------------------------------------------------------------------------------------------------------------
TL;DR: CMMC Level 1 applies to any small shop handling Federal Contract Information, and it comes down to 15 specific safeguarding practices pulled from a federal contracting rule that's been around since 2016. A shop with decent IT hygiene already meets most of them without knowing it. The real work is documenting what you're doing, closing the two or three gaps that show up, and signing an annual affirmation that's accurate rather than hopeful. None of this requires an enterprise security budget or a rebuilt network.
-------------------------------------------------------------------------------------------------------------------
A generator doesn't run your whole shop. It runs the handful of circuits you decided mattered enough to wire to it ahead of time: the walk-in cooler, the server rack, maybe the lights in the main bay. Everything else stays dark until the power's back, and that's fine, because someone already figured out in advance what actually needed to keep going.
CMMC Level 1 works the same way. It's not a mandate to lock down every machine in the building. It's a short list of specific things that need to keep running, tied to the information a shop handles for a government contract, and nothing more.
Here's why this landed on someone's desk this month instead of last year: a customer flowed the requirement down, or it showed up as a clause in a purchase order that almost got skimmed past. For a long time, this whole area ran on the honor system. Companies said they'd read the rules and moved on. That era is over. The Department of Defense is checking now, and the checking reaches smaller and smaller subcontractors every quarter, including shops that never thought of themselves as part of the defense industry.
One thing worth flagging before getting into specifics: CMMC's broader certification rulemaking got paused by the Department of War in July 2026, and it's been under review since. That pause is real, but it doesn't touch the self-assessment and reporting requirements already written into contracts today.
The point of all this: a shop that's already being run well is a lot closer to meeting Level 1 than it looks from the outside, and the gap between "doing the work" and "passing the assessment" is almost always paperwork, not infrastructure.
Table of Contents
- What CMMC Level 1 Actually Protects
- The 15 Practices, Grouped by Type
- What's In Scope and What Isn't
- The Self-Assessment and Affirmation Process
- What This Actually Costs a Small Shop
- Where Shops Get This Wrong
- The Circuits Were Already Wired
- Key Takeaways
- Frequently Asked Questions
What CMMC Level 1 Actually Protects
CMMC stands for Cybersecurity Maturity Model Certification, and it's the Department of Defense's way of checking that companies in its supply chain protect government information at a level that matches what they actually handle. There are three tiers. Level 1 sits at the bottom, and it's built from 15 basic safeguarding practices lifted straight out of Federal Acquisition Regulation (FAR) clause 52.204-21, a rule that's been sitting on the books since 2016. Level 2 stacks on the full 110 controls from NIST SP 800-171 once the information involved gets more sensitive. Level 3 is a small, specialized group working on the most critical programs, and it's not something a shop this size needs to spend energy on.
Level 1 exists for one specific reason: protecting Federal Contract Information, or FCI. That's the information the government hands over, or that gets generated for the government, in order to build or deliver whatever's under contract, as long as it isn't meant for public release. Most shops that qualify for Level 1 have never used the term FCI in their life. It doesn't usually feel like "sensitive government data." It looks like a purchase order with specs that weren't meant for a public bid board, or delivery schedules tied to a program nobody outside the building needed to know about.
One thing worth knowing before getting into specifics: Level 1 is self-assessed. Nobody's showing up with a clipboard. The company evaluates its own systems against the 15 practices, submits the result, and affirms once a year that things are still holding. Level 2 usually brings in outside eyes once real sensitive data enters the picture, and that's a different conversation for a different post in this series.
The 15 Practices, Grouped by Type
Reading FAR 52.204-21 straight through feels exactly like reading a government document, because that's what it is. Grouped by what they're actually asking a shop to do, though, the 15 practices settle into four natural clusters, and none of them should feel like a stretch for a business that's already being run with any discipline.
The first cluster is about who gets access. Systems should only be reachable by people who are supposed to be on them, and those people need to be verified before they log in, not just trusted because they showed up. If a former employee still has an active account somewhere, or three people share one login because setting up individual ones felt like a hassle, this is the cluster that catches it.
The second is about what crosses the boundary. Connections to outside networks need some kind of control, public-facing systems need to be kept separate from internal ones, and anything posted somewhere public needs a second look before it goes out. A shop running its website and its accounting server on the exact same unsegmented network is the textbook example this cluster exists to fix, and it's a more common setup than most owners would guess.
The third cluster covers the physical side of the building. Media gets wiped or destroyed before it's tossed out, physical access to equipment and facilities is limited to people who belong there, and visitors get logged instead of wandering the floor on their own. Manufacturers tend to have a head start here, since safety requirements already mean somebody's watching who's near the machines.
The fourth is about keeping the systems themselves clean. Known flaws get patched within a reasonable window, malware protection runs and stays current, and the network gets scanned on a regular basis rather than left alone until something breaks. This is the cluster that overlaps almost entirely with what a competent IT provider should already be doing without anyone calling it a compliance framework.
Look at those four clusters again. A shop with solid IT practices is likely already covering ten or eleven of these fifteen without ever having framed it that way. Where the gap tends to show up isn't the doing, it's the proving: nobody wrote down that the patching happens on schedule, or documented why that one system sits outside the network segmentation. Self-assessment asks for the paper trail, not just the practice.
What's In Scope and What Isn't
The boundary for a Level 1 assessment is drawn around anything that processes, stores, or transmits FCI, and nothing beyond that. Processing means the information is actively in use: getting typed in, reviewed, edited, printed. Storing means it's sitting somewhere, even when nobody's touching it, whether that's a server, a laptop, or a drawer full of printouts nobody's gotten around to shredding. Transmitting means it's moving from one place to another, whether that's over the network or on a flash drive that somebody walked across the building.
Anything that never touches FCI in one of those three ways falls outside the assessment entirely, and that matters more than it sounds like it should. The instinct when a shop first hears "federal compliance" is to assume every machine in the building needs to meet the same standard, and that instinct turns a manageable project into an unnecessary one. The break room WiFi, the marketing laptop that's never been near a government PO, half the shop floor equipment: none of it needs to meet these 15 practices unless it's genuinely handling the information in question.
There's also a short list of equipment the Department of Defense excludes from Level 1 scoping outright, because it can't realistically be secured the same way office systems can. Government Furnished Equipment, Internet of Things devices, operational technology like SCADA systems running older shop floor controls, and dedicated test equipment all fall into that carved-out category.
Level 1 doesn't require a formal written record of how the scoping decision got made, unlike some of what comes with Level 2. Building one anyway is still worth doing, because "we assumed that system didn't count" is a rough thing to be explaining out loud during an assessment.
The Self-Assessment and Affirmation Process
Here's how this actually plays out once a shop decides to get serious about it. Someone, either in-house or with outside help, sits down and checks the environment against all 15 practices using three methods the Department of Defense calls examine, interview, and test. Examine means looking at whatever documentation exists. Interview means actually talking to the people doing the work instead of trusting a policy binder nobody's opened since it was printed. Test means confirming the controls do what they claim to do, not just that someone wrote a nice sentence about them once.
None of that requires bringing in an outsider. A shop can run this whole process internally, or lean on a compliance partner if the internal bandwidth isn't there. Either way, the result gets submitted into the Supplier Performance Risk System, known as SPRS, which is the Department of Defense's system for tracking how reliable its suppliers actually are, cybersecurity included. For Level 1, the goal is to land on a status of Final Level 1 (Self) once everything checks out.
The part that deserves more attention than it usually gets is the annual affirmation. A senior person at the company, an Affirming Official, has to sign off every year that the shop still meets these requirements. That's not a rubber stamp buried in a folder somewhere. It's a specific person putting their name behind a specific claim, and if that claim doesn't hold up, the exposure is real rather than theoretical. There's a companion post later in this series that gets into exactly what's at stake when an affirmation doesn't match reality, and it's worth reading before anyone signs one on autopilot.
So don't hand this off to whoever's free that afternoon and hope for the best. Someone who's actually looked at all 15 practices and can stand behind what they found needs to be the one putting their name on it.
What This Actually Costs a Small Shop
Nobody wants a vague answer here, so let's get specific, while being honest that it depends a lot on where a shop is starting from.
For a business that's been running its IT with any real discipline, patches happening on a schedule, actual access controls in place, someone paying attention to the network boundary, Level 1 tends to be mostly a documentation and gap-closing project. Shops in that position often get through it in a matter of weeks of focused work. None of the 15 practices are technically difficult on their own. The effort goes into writing down what's already happening, fixing the handful of things that aren't quite there yet, and organizing the proof so an affirmation is a statement of fact instead of a hopeful guess.
A shop coming from a break-fix relationship, where nobody's been thinking about security as its own job, is looking at a longer runway, because now it's not just documentation, it's actually building the practices from the ground up. That's a bigger project, and it's the kind of thing worth getting a real assessment for rather than guessing at what's missing and hoping for the best.
Either way, don't let anyone talk this into being smaller or bigger than it actually is. Nobody needs to hear that Level 1 is "just paperwork," because paperwork that doesn't match reality is exactly what gets a shop in trouble later. And nobody needs an enterprise security budget to get here either. Fifteen specific things, done and written down, is genuinely the whole assignment at this tier.
Where Shops Get This Wrong
The most common mistake comes from the short list itself. Fifteen items sounds manageable, and it is, but there's a real gap between "we generally do most of this" and fully implementing all 15 practices with documented policies, accurate configurations, and an honest self-assessment behind them. That gap is exactly where shops get caught flat-footed, usually right when it matters most.
Scoping trips people up almost as often. Some shops swing too wide, treating the entire network like it's all part of the assessment, which turns a manageable job into a much bigger one than it needed to be. Others swing too narrow, assuming a system doesn't count without actually checking whether it processes, stores, or transmits FCI. Both mistakes come from skipping the same step: nobody sat down and mapped out where the information actually lives.
There's a third mistake that's a little subtler, and it shows up in shops that are otherwise doing fine. It's treating Level 1 as a placeholder, something to get serious about later once Level 2 becomes relevant, as if the smaller tier can wait. It can't. Level 1 compliance is required today, independent of whether Level 2 ever enters the picture. For a shop whose contracts only ever involve FCI, Level 1 isn't a warm-up act. It's the entire show.
And then there's the affirmation itself, which gets treated with less weight than it deserves more often than it should. Signing off on compliance that hasn't actually been verified isn't a shortcut; it's a liability waiting for someone to ask the wrong question at the wrong time.
The Circuits Were Already Wired
Level 1 comes down to 15 specific practices, grouped into who gets access, what crosses the network boundary, how the physical building is handled, and keeping the systems themselves clean, all tied to a narrow, well-defined slice of information rather than a mandate to lock down everything in the building. Scoped correctly, most shops find the assessment covers a fraction of what they first assumed. Assessed honestly, a shop with any real discipline in how it runs IT usually turns out to be much closer to done than that first phone call made it feel.
The gap that's left almost never lives in the technology. It lives in the paperwork, catching up to what's already true, and in making sure the person signing the annual affirmation actually knows it holds up rather than hoping it does. That distinction matters more than it sounds like it should, because an inaccurate affirmation isn't a filing error sitting harmlessly in a folder. It's a claim with a signature on it, and the practices in this post are exactly what that signature is supposed to be backed by.
CNWR has spent three decades building this kind of environment for manufacturers, veterinary practices, and small businesses across Northwest Ohio and Southeast Michigan, the kind where patching happens on schedule and access controls exist because someone decided they should, not because a federal contract demanded it. That track record comes with real cybersecurity recognition behind it, not just a claim on a website, and it's the reason CNWR can walk a shop through exactly which of these 15 practices are already covered and which genuinely need work, instead of guessing or padding the list.
If a customer just said the word CMMC and there's no clear answer for where things actually stand, that's worth sorting out before an affirmation gets signed on a hunch. Reach out to CNWR for a free assessment, and get a straight answer instead of one built on assumptions.
Key Takeaways
- CMMC Level 1 covers 15 specific practices tied to Federal Contract Information, not a full network lockdown
- The practices group into four areas: access control, network boundaries, physical security, and system hygiene
- Assessment scope only includes systems that process, store, or transmit FCI, with a short list of equipment carved out entirely
- Level 1 is self-assessed, with results submitted to SPRS and backed by an annual affirmation from a senior official
- A well-run shop often meets most of the 15 practices already; the real work is usually documentation, not new infrastructure
- CMMC's broader certification rulemaking being paused doesn't pause the underlying self-assessment and SPRS requirements already in contracts
- An inaccurate affirmation carries real weight, since it's a signed claim, not just paperwork sitting in a folder
Frequently Asked Questions
1. Do I need a third-party auditor for CMMC Level 1?
No. Level 1 is entirely self-assessed. A shop can handle it internally or bring in outside help, but no accredited third-party assessor is required at this tier. That requirement shows up at Level 2.
2. What happens if CMMC certification requirements are still paused?
The broader CMMC certification rulemaking has been under review since the Department of War's suspension in July 2026, but the DFARS clauses requiring NIST SP 800-171 self-assessment and SPRS submission are separate, existing contract requirements that remain in force.
3. How do I know if my shop even handles FCI?
If work is being done under a government contract and information tied to that contract isn't meant for public release, that's likely FCI. A more detailed self-audit for this exact question is coming in the next post in this series.
