If your company touches Federal Contract Information on a Department of Defense contract, CMMC Level 1 applies to you. The requirement has been in place since 2016 under FAR clause 52.204-21. What changed is verification. Every DIB subcontractor now self-assesses against 15 basic safeguarding requirements, submits the results to the Supplier Performance Risk System, and affirms compliance every year.
This white paper walks through what Level 1 actually requires, what it does not require, and how to reach Final Level 1 (Self) status without overbuilding your security program. It is written for subcontractors who need a clear, fast path, not a consulting pitch.
13 pages. PDF format. No form, no email required.
What the White Paper Covers
The paper is built around one idea: Level 1 is the floor, not the ceiling. Contractors who treat it as a ceiling spend money on controls the rule does not ask for. Contractors who treat it as a floor position themselves for Level 2 work later, at a lower incremental cost.
Table of Contents
- What CMMC Level 1 Really Requires
- Keep Your Scope Small on Purpose
- Low-Cost, High-Leverage Paths to Each Control Family
- The Part Companies Underestimate: Annual Affirmation
- Build Internally or Maintain Through an MSSP
- A Practical 30-Day Path to Level 1
- Staying Certified Is the Mandate
The guide maps all 15 requirements to their six control families and shows low-cost, high-leverage ways to satisfy each one using tools most small businesses already own. Named user accounts, MFA on email and cloud apps, a locked door and a visitor log, a consumer-grade firewall, and automatic patching cover the large majority of the checklist without new capital spend.
Every requirement must be MET at Level 1. There is no partial credit and no Plan of Action and Milestones, unlike Level 2.
Scope, Cost, and the Annual Affirmation
The paper spends real time on scope, because scope is the single biggest cost lever. Under 32 CFR ยง 170.19(b), only assets that process, store, or transmit FCI are in the assessment boundary. A tight, well-defined enclave shrinks both the initial assessment and the ongoing burden of the annual affirmation.
It also covers the part most subcontractors underestimate: staying certified. An Affirming Official must submit a new SPRS affirmation every year attesting that all 15 requirements remain MET. Assessment artifacts must be retained for six years. A material change in scope, a network expansion, a merger, a new location handling FCI, triggers a new assessment, not just a new affirmation.
The paper includes the Department of Defense's own cost estimates for building Level 1 internally: roughly $5,977 for a small entity's first-year self-assessment and initial affirmation, plus an estimated $560 for each annual reaffirmation after that, assuming no drift or gaps. It also breaks down where that estimate falls short for most subcontractors, and why configuration drift, not the initial assessment, is where the real recurring cost lives.
Who Should Read It
This paper is written for DIB subcontractors who handle FCI but not CUI, typically companies under roughly 50 employees without a dedicated security function. If your contracts involve Controlled Unclassified Information, you need Level 2, which is a separate and larger undertaking covered elsewhere in our resource library.
How Aetos One Supports the Path to Level 1
Getting to Final Level 1 (Self) status is the milestone. Staying certified is the mandate. Aetos One's Citadel module keeps your affirmation current, your evidence audit-ready, and your scope clean for the annual cycle, so the next assessment is a formality, not a fire drill.
Named fractional CISO leadership for your DIB program.
AI-driven security operations that keep controls live between assessments.
Continuous GRC and compliance automation, built for the annual affirmation cycle.
Prefer to score your own environment first? Run our CMMC Level 1 Self-Assessment tool. It walks all 15 requirements through Examine, Interview, and Test objectives from NIST SP 800-171A, so you see exactly what an assessor would look for before you submit to SPRS. Nothing is saved or transmitted.
Questions about your specific scope or timeline? Schedule a 30-minute conversation.