MalakarConsulting

HomeGuides › CMMC Level 1 self-assessment checklist for small defense contractors

CMMC Level 1 self-assessment checklist for small defense contractors

Updated September 19, 2026

What CMMC Level 1 actually requires

CMMC (Cybersecurity Maturity Model Certification) Level 1 applies to contractors who handle Federal Contract Information (FCI) but not Controlled Unclassified Information (CUI). It maps to a set of basic safeguarding requirements, and at Level 1 it is a self-assessment, meaning you evaluate your own environment against the requirements and submit the result, rather than going through a third-party assessor.

If your contract or a prime's flow-down clause instead points you to Level 2, that generally means CUI is involved, and Level 2 draws on the fuller NIST SP 800-171 control set (110 controls) rather than the smaller Level 1 set. This guide focuses on the Level 1 self-assessment checklist; if you are not sure which level applies, check the DFARS or CMMC clause cited in your contract, or ask your prime contractor directly.

This is general information, not legal or compliance advice, and it does not replace reading the current requirements published by the Department of Defense and the CMMC program. Confirm your applicable level and current requirement language before you submit anything.

Self-assessment checklist, by category

Work through your environment against each of these areas. For each one, note whether it is in place, partially in place, or not yet addressed.

  • Access control: Are user accounts limited to authorized people, and are inactive or terminated accounts removed promptly?
  • Identification and authentication: Does every user and device have to authenticate before accessing systems that process FCI?
  • Media protection: Is FCI on removable media (USB drives, backup disks) sanitized or destroyed before disposal or reuse?
  • Physical protection: Are physical access points to facilities and equipment that process FCI limited and monitored?
  • System and communications protection: Are public-facing systems separated from internal systems that handle FCI, with boundary protections like a firewall in place?
  • System and information integrity: Is there a process for identifying and correcting system flaws (patching) and for protecting against malicious code?

These categories are a working checklist, not the full text of the requirement. Before you submit a self-assessment, compare your notes against the current requirement language published for your applicable level.

What to document for each item

A self-assessment is stronger, and easier to defend if a prime or an auditor ever asks about it, when each item has something behind it. For each control area, keep:

  • A short written statement of how you meet it (for example, which tool enforces multifactor authentication, or which policy governs media disposal)
  • The name of who owns that control internally
  • Any configuration screenshot, policy document or vendor confirmation that backs up the statement

You do not need a formal System Security Plan to complete a Level 1 self-assessment, but building one anyway gives you a single place to keep this evidence, and it becomes the starting document if a future contract pushes you toward Level 2.

Where small contractors usually have gaps

AreaTypical gapUsually the fastest fix
Access controlFormer employees or contractors still have active accountsA quarterly account review tied to HR offboarding
Media protectionNo documented process for wiping USB drives or old laptopsA short written media-sanitization policy, even a one-page one
System and communications protectionNo clear boundary between the office network and systems handling FCINetwork segmentation, even a basic VLAN split, with a firewall rule set reviewed at least yearly
System and information integrityPatching happens ad hoc with no record of whenA monthly patch cadence with a simple log of what was applied and when

Submitting your self-assessment

Level 1 self-assessments are affirmed by a senior company official and, depending on the current program requirements, may need to be entered into the Department of Defense's Supplier Performance Risk System (SPRS) or a successor system named in your contract. The exact submission mechanism and required frequency have been updated as the CMMC program has rolled out, so check the current process on the official CMMC program page or your contracting officer's guidance rather than relying on an older version of the requirement.

If your prime contractor requires proof of your assessment before subcontract award, they will usually tell you exactly what format they want (a signed summary, an SPRS score, or both). Ask before you build the packet so you are not reformatting it twice.

If a future contract pushes you to Level 2

Level 2 draws on the full NIST SP 800-171 control set, 110 controls across 14 families, rather than the smaller Level 1 set. The jump is bigger than it looks from the outside: you need a documented System Security Plan (SSP) that states, control by control, whether each one is implemented, planned or not applicable to your environment, plus a Plan of Action and Milestones (POA&M) for anything not yet in place.

Contractors moving from Level 1 to Level 2 usually find that the access control, media protection and system-and-communications-protection work they already did for Level 1 carries over directly into several of the 110 controls, but the remaining controls (incident response, security assessment, configuration management, and others) need to be built from scratch if you have never documented them before. Starting that inventory early, even informally, saves time when a contract deadline forces the issue.

A realistic timeline for getting this done

For a small shop with no dedicated security staff, working through the Level 1 checklist honestly, gathering evidence, and fixing the two or three most obvious gaps typically takes a few weeks of part-time attention, not a single afternoon. Budget time for:

  • An honest first pass through each control area (a few hours)
  • Closing the access-control and media-protection gaps, which are usually the fastest to fix
  • Getting a written statement or screenshot for each control before you affirm the assessment
  • A final read-through against the current published requirement language before submission

Waiting until a contract deadline is a week away turns a manageable checklist into a scramble, and it is exactly when gaps get skipped rather than fixed.

Want this done for you? The CMMC / NIST 800-171 SSP + Policy Pack builds a full SSP draft, 14 policy documents and a POA&M mapped to all 110 controls if your contract points to Level 2. — see what's included and order →