Schedule a call

Compliance

CMMC Level 1 and FAR 52.204-21

The lighter obligation, for contractors handling Federal Contract Information rather than CUI. A lot of businesses are quoted Level 2 work when this is all their contracts actually require.

FCI or CUI — the question that decides everything

Almost every other question about your compliance obligations follows from this one, and it is worth settling before you spend anything.

Federal Contract Information is information provided by or generated for the government under a contract, not intended for public release. If that is all you hold, your obligation is the basic safeguarding requirements of FAR 52.204-21 — and CMMC Level 1, which is a self-assessment against that same baseline.

Controlled Unclassified Information is a different matter. CUI brings DFARS 252.204-7012, all 110 controls of NIST SP 800-171, incident reporting, and CMMC Level 2. It is a substantially larger undertaking and a substantially larger bill.

If nobody has told you plainly which of those you hold, that is the first thing to fix. It is also a fair question to put to any provider quoting you compliance work.

What Level 1 asks for

Basic safeguarding: limiting access to authorised users, controlling what goes on public systems, authenticating users, sanitising media before disposal, keeping systems patched, screening for malicious code, and controlling physical access. Fifteen basic requirements under FAR 52.204-21, expressed as seventeen practices at CMMC Level 1.

It is self-assessed annually, with results and an affirmation entered by a named senior official. No third-party assessor is involved at this level, and none was planned before the Phase II suspension either.

Level 1 was not affected by the Phase II suspension. Phase I has been in effect since November 2025 and contracting officers may still require Level 1 (Self) today.

What the engagement involves

  • Establishing whether you hold FCI, CUI, or both — before anything else is decided.
  • Assessing your environment against the basic safeguarding requirements.
  • Closing whatever gaps that finds, most of which are configuration rather than purchase.
  • Getting your self-assessment and affirmation properly recorded in SPRS.
  • Making sure it stays true, since the affirmation is annual and continuous.

It is a smaller piece of work than Level 2, and it should cost accordingly. If a provider quotes you the same for both, ask them to explain the difference.

When you do need Level 2 instead

If CUI is genuinely in scope, Level 1 will not cover you, and discovering that late is expensive. The signals worth checking: DFARS 252.204-7012 in your contracts, a flowdown from a prime referencing CUI, technical data with export-control markings, or anything your customer treats as controlled.

Where that is the case, the work is CMMC Level 2 readiness, usually alongside a move to GCC High.

Not sure which applies to you?

That is the conversation to have first, and it is a short one. We offer a free CMMC gap assessment for qualifying contractors.

Schedule a call