
Key takeaways
- The July 2026 pause did not touch Level 1. The DoD suspended Phase 2 third-party certification, but Phase 1 self-assessments stay in force, and the 15 requirements come from FAR 52.204-21, so they hold even if CMMC changes.
- Level 1 is 15 requirements you self-assess against your own systems, not a third-party audit. No C3PAO to hire, and you can run it in-house with what you already have.
- Most of Level 1 is proof. Nearly every requirement comes down to a short written policy plus a record showing you followed it, in final form.
- There is no partial credit and no POA&M at Level 1. All 15 must be MET or a genuine N/A, and one unproven MET is the kind of false claim the government has pursued under the False Claims Act.
- You affirm in SPRS through a senior official, keep evidence for six years, and re-assess and re-affirm every year, or your status lapses.
A CMMC Level 1 self-assessment is something you can run yourself this quarter, with the manpower and tools you already have. Under the federal rule, you evaluate your own information system, and if you have opened NIST 800-171 and started on the 110 controls, stop, that is Level 2. This guide covers everything from scoping to a submitted, affirmed result in SPRS, and you will know exactly what proves each one of the 15 requirements.
Does the July 2026 pause change what you owe?
On July 13, 2026, the DoD suspended CMMC Phase 2, which is the stage that would have forced third-party certification. Phase 2 was the mandatory Level 2 certification set for November 10, 2026. It is paused, the program is under a 60-day review, and officials would not rule out scrapping it.
But Level 1 lives in Phase 1, and Phase 1 self-assessments stay in place, so your duty to self-assess and affirm is unchanged. Even if the review guts CMMC, the work holds, because Level 1's 15 requirements come straight from FAR 52.204-21, the clause binding any system that handles Federal Contract Information.
How to complete your CMMC Level 1 self-assessment
The CMMC Level 1 self-assessment has six steps, from scoping your environment to submitting and affirming the result in SPRS. Each step tells you what to do and what you need to accomplish, so you always know whether you can move on to the next step:

Step 1: Scope your environment
Before anything else, you draw a boundary that will decide the size of the whole job. You are finished scoping when you can name every place your FCI lives in. Too wide a search and you assess the whole company for nothing, while a narrow search might cause you to miss the one laptop holding contract files.
Start with the information: FCI is contract information not meant for public release that is provided by or generated for the Government under a contract. These include delivery schedules, statements of work, pricing, and the everyday files of doing the job.
To scope, weigh the people, technology, facilities, and outside providers that process, store, or transmit it. Most contractors think that anything that does not touch FCI is out of scope. Corral FCI into one segmented enclave, and the rest of your company falls outside the assessment. Specialized assets that handle FCI but cannot be locked down, like IoT and operational technology, are also excluded. If someone tells you to fortify every sensor for Level 1, they are selling you Level 2 work you do not owe.
Step 2: Assess each requirement
Each of the 15 requirements now needs a finding you could defend: MET, NOT MET, or N/A.
The three methods in NIST SP 800-171A check a requirement from different angles. Examine the policies and records, interview the people who do the work, and test the control by watching it run. Where what you are told and what the system shows disagree, trust the system. Each requirement breaks into objectives, and every one must come back as MET or N/A for the requirement to score MET. One objective NOT MET fails the whole requirement.
Remember: the affirmation is a legal representation. In June 2026, an Alabama contractor paid $507,144 under the False Claims Act after an audit found its security far below what it had claimed. That case ran on Level 2, but the principle reached Level 1. A MET you cannot prove is what turns an invoice into a false claim.
Step 3: Document the evidence
A finding means little without something to support it. This step gives every MET a dated artifact you could hand over. For all 15 requirements, the Level 1 Assessment Guide lists the exact artifacts an assessor may examine.
Two things decide whether your evidence counts: It must be final and not require a full System Security Plan, which is a Level 2 requirement. If a cloud or IT provider runs part of this, their evidence counts as long as you can produce it.
The pattern is the same down every row: a short written policy and a record that shows you adhered to it.

Collecting and dating every one of those artifacts by hand is the tedious part, and it is the kind of work Koop's Housekeeper AI Agent is built to automate, keeping evidence current as your systems change.
Step 4: Close every gap
You are done when no gaps remain. Most gaps are missing documents. The recurring ones are a control you perform but never write down (write the one-page policy and get it approved), access left live after someone leaves (an offboarding checklist that pulls accounts and keys the same day), factory passwords never changed, no defined timeframe for fixing flaws, and no visitor or key log.
You cannot defer any gaps because a POA&M is not permitted at Level 1. Level 2 can sometimes list unmet items and fix them later, as long as its overall score is at least 0.8. Level 1 cannot. All 15 land as MET or a genuine N/A, or you cannot truthfully affirm compliance.
Step 5: Submit and affirm in SPRS
Make sure your result and affirmation are both in SPRS. You do not submit your evidence. What goes into SPRS is a short set of facts: your CMMC level, the status date, your assessment scope, your CAGE codes, and the compliance result. The policies and records from Step 3 stay with you. Level 1 carries no numeric score either. Where Level 2 uses the scale that scored the contractor in Step 2 deep in the negatives, your result is just MET or NOT MET across all 15, which you settled in Step 4.
The affirmation is the one part that is not routine. A senior Affirming Official with authority to speak for the company enters it in SPRS, attesting that you have implemented and will maintain every applicable requirement. That word "maintain" is why the False Claims Act exposure from Step 2 is attached here. It is a continuing statement to the government, so whoever signs should be sure it is true and stays true, because it must be renewed.
Step 6: Keep it valid annually
Level 1 is not one and done. Your status lasts twelve months, then you repeat the self-assessment and the affirmation, turning Steps 1 through 5 into a recurring routine rather than a single push.
Two things persist between assessments: the evidence from Step 3 must stay on file because the rule requires you to retain those artifacts for six years from your status date, and the affirmation stays live the whole time, since it attests that you will maintain compliance. Let a control lapse, and that signed affirmation quietly turns false, which is the Step 2 exposure again.
The recurring cycle is exactly what a platform like Koop is for, holding the evidence trail and the re-assessment schedule in one place so nothing lapses between years.
Re-assess, re-affirm, and keep the records, and your status holds as long as the contract does.
Put Level 1 on autopilot with Koop
You can pass Level 1 on your own. Staying past it is the harder promise because the evidence, the annual re-assessment, and a live affirmation all have to hold up long after the first submission. That upkeep is what Koop is built for.
- Housekeeper AI Agent automates the routine work of collecting and refreshing evidence, keeping your artifacts up-to-date.
- Requirements Management tracks the FCI and cybersecurity obligations from your enterprise and government contracts in one place, so nothing slips between assessment years.
The result is that a passing Level 1 today is still a passing Level 1 at renewal. Koop reports that Housekeeper automates up to 95% of that workload, which is the difference between rebuilding your evidence every year and walking into a working cycle each time.
Frequently asked questions
- Does CMMC Level 1 have 15 or 17 requirements?
It is 15. The requirements are taken directly from FAR 52.204-21(b)(1), which lists items (i) through (xv), and the federal rule defines the Level 1 set as exactly those 15. The 17 you may have seen counts the NIST SP 800-171 controls that the 15 map to, because one physical-protection requirement splits into three when mapped. A guide still telling you to document 17 practices is using the mapping count, not the requirement count.
- What is the difference between FCI and CUI?
This distinction decides your level, so it is worth getting right. Federal Contract Information is the ordinary, unclassified information you handle just by doing government contract work: quotes, delivery schedules, task orders, and routine emails. It is not sensitive, it is simply not for public release. Controlled Unclassified Information is more sensitive information that a law, regulation, or government-wide policy requires to be safeguarded, and it is typically marked as CUI.
If your systems hold only FCI, Level 1 is your bar. The moment CUI enters the picture, you are into Level 2 and its 110 requirements. Confirm which one you actually handle, because plenty of contractors prepare for Level 2 when everything they hold is really just FCI.
- Is CMMC Level 1 still required after the July 2026 pause?
Yes. On July 13, 2026, the DoD suspended CMMC Phase 2, the mandatory third-party Level 2 certification. That pause did not reach Level 1, which sits in Phase 1, so if your contract requires it, you still assess and affirm as before. The program is under a 60-day review that could reshape later phases, but your Level 1 obligation today is unchanged.

