Step 1 · Define the assessment scope
Organization and CMMC Assessment Scope
Per 32 CFR § 170.19(a), specify the assets that process, store, or transmit FCI before assessing. Everything in scope is assessed against the 15 Level 1 requirements. This information populates the report header.
Step 2 · Assess each requirement
Need to close the gaps?
The remediation notes above show the lowest-cost path for each requirement. If several items scored Not Met, or you handle CUI and face Level 2, Aetos One runs a fixed-fee CMMC gap assessment that maps every requirement to a concrete fix and delivers a System Security Plan ready for attestation.
Request a gap assessmentHow findings work. Each requirement is scored at the objective level. One unsatisfied objective makes the entire requirement NOT MET. A requirement is MET only when every applicable objective is satisfied with evidence in final form (drafts and working papers are not acceptable). An objective scored N/A counts the same as MET. To demonstrate Level 1 compliance, every requirement must be MET or N/A.
Remediation guidance is a starting point, not a guarantee. The fixes shown here describe the most common low-cost path to satisfying each requirement for a small business. Your environment, contract flow-downs, and External Service Providers may require more. Validate every fix against your own systems and the official guidance before attesting.
This is a preparation aid, not an official submission. Level 1 results are self-attested and submitted to SPRS by the OSA. This tool does not save or transmit anything. Every entry stays in memory for this browser session only and is cleared when you refresh or close the page. Export or print your report before you leave. Verify findings against the official CMMC Level 1 Self-Assessment Guide, FAR 52.204-21, and 32 CFR § 170 before attesting. Enduring exceptions and temporary deficiencies must be documented in your SSP or operational plan of action to be scored MET.