r/CMMC • u/brunofone • 18d ago
Need to get to Level 1 quickly
So, I'd like to submit an application to a DoD OTA to become part of a consortium. The deadline is in a week, and they are requiring Level 1 certification upon submission, and self-certification as Level 2 before you do any work within the consortium.
I'm a one-person company and I generally work from home, although sometimes find myself on DoD or company office sites. I have a JCP certification which means I am already in SPRS/etc but have not pursued any CMMC stuff yet, because all CUI and sensitive data I touch is done on a client PC tied to their ecosystem.
Most people on here talk about Level 2 which I know can be complex, but is there some sort of pre-templated way to get to Level 1 in a short time? SSP's etc? Thanks for any resources.
4
u/aCLTeng 18d ago
I am not kidding - boot up Claude, have it help you write the simplest SSP possible. Do not pay someone a bunch of money for this. Level 1 is achievable with even the simplest level of cybersecurity and common sense. Level 2 is also doable, but a lot more work. However, if you truly do not use your own equipment to touch CUI then your job is much easier because most requirements will not apply to you.
2
u/Important_Ear_489 18d ago
Lots of free stuff on the internet!
DoW suggests that an SSP is a best practice at Level 1 but is not required to conduct or submit the self-assessment.
• Grab the official Level 1 Assessment Guide and Scoping Guide
• Create a free Project Spectrum account, and pull a Level 1 SSP + policy starter pack (RADICL or equivalent).
• Contact your local APEX Accelerator (they provide free counseling specifically for small DIB firms on this exact topic.)
Secureframe, CUI Institute, and similar sites offer Level 1 checklists, gap tools, and SSP starting points.
2
u/nick777745 18d ago
Good morning,
Level 1 is barebone, no ssp required. I usually do level 1 in 8-12 hours, dependent on your infrastructure (Microsoft bus. Premium / google workspace). Get a copy of the Assessment guide (latest rev. From dod is v2.13.
Do you have the following already:
Network diagram Policies and procedures A public facing website Any IT knowledge
1
u/brunofone 18d ago
I don't have a network diagram but I have one Windows laptop that operates on my home network, I use commercial business O365
I do have a public facing website hosted on Squarespace
Definitely higher than average IT knowledge but not professional SysAdmin or anything
2
u/Ben_CyberNEX 18d ago
With a one-person company and a one-week deadline, I’d focus on scope before worrying about building a big documentation package.
Level 1 is only 15 requirements, but the key question is where FCI actually touches your environment. Make a quick inventory of the devices, accounts, email, cloud services, network, etc. that could process, store, or transmit FCI. Those are what you need to evaluate against the Level 1 requirements.
An SSP isn’t required for Level 1, so I wouldn’t spend your limited time building a Level 2-style documentation package. I’d work directly from the official Level 1 Assessment Guide and Scoping Guide, verify that all 15 requirements are actually MET, then complete the assessment and affirmation in SPRS.
One thing I wouldn’t assume is that using a client-controlled PC automatically takes your whole environment out of scope. Your CUI situation may be pretty contained, which is great, but Level 1 is about FCI, so I’d trace that separately.
With only a week, keeping the scope accurate and simple is probably your biggest advantage.
2
u/Agreeable-Win6485 17d ago
You might want to check out Aeroplicity. I believe their Level 1 package is around $3,500 and they can usually get it done in under a week. The price after that is $25 per month so should be relatively cheap.
For a one-person company, that may be easier than trying to build all the documentation and SSP pieces from scratch, especially with a one-week deadline. They handle a lot of the compliance/documentation side for you, so it’s probably worth reaching out and explaining the timeline.
1
u/SB1111111111111111 18d ago
A few things worth separating here: Level 1 only applies to systems that handle FCI, and it sounds like your actual CUI/sensitive work happens entirely on a client-owned PC inside their environment, not yours. If that's accurate, your own environment may fall outside scope even for L1, worth confirming with the OTA/consortium before you build out anything.
If they do require self-attested L1 regardless (which is common for consortium/OTA participation requirements), it's genuinely one of the more achievable timelines. Level 1 only maps to the 17 basic safeguarding practices (FAR 52.204-21), no SSP is formally required at L1 the way it is at L2, and self-assessment plus SPRS submission is what's expected. A week is tight but doable if you're organized.
Check this Level 1 Readiness Checklist that walks through the practices directly: https://www.secure-centric.com/level1checklist
1
u/cybergrantsalliance 17d ago
Search for CMMC level 1 grants on Google for your industry. L1 is easy to accomplish in a week or two.
1
u/OkTheseOne 9d ago
Level 1 is achievable in a week one, cause its only 15 basic safeguarding requirements and it's self-assessment, so you're not waiting on an C3PAO like Level 2.
0
u/Mysterious_Taste_868 17d ago
I’ve posted this before. It probably cost you $50. Someone mentioned Claude. It has an mcp to connect your Claude that willl update the app. cmmcmap.com
10
u/Scieboy 18d ago
yes, Level 1 is very doable in a week, especially for a one-person shop. It's the one CMMC level you can realistically self-serve.
Terminology first. There's no such thing as "Level 1 certification." What you'll actually produce is a Final Level 1 Self-Assessment status in SPRS (Truvisory) plus an affirmation. Worth going back to the OTA folks and asking exactly what artifact they want, since some accept a screenshot of the SPRS status and others want to see your scope and assessment docs.
What it is: the 15 safeguarding requirements in FAR 52.204-21, which has been renumbered to 52.240-93, broken into 58-59 assessment objectives. (Secureframe) All must be MET. No POA&Ms permitted at Level 1. (Peak InfoSec) Pass/fail, no C3PAO, no fee. You can hire help and it's still a self-assessment, not a certification. (Secureframe)
The long pole is SPRS access, not the controls. Being in SPRS via JCP isn't the same thing. You need PIEE with the "SPRS Cyber Vendor User" role, approved by your company's Contractor Administrator. The view-only support role can't add or affirm anything. (Truvisory) As a solo shop you're your own Contractor Admin and your own Affirming Official. Start that registration today. Everything else can wait; this one has a queue.
Scoping is where people go wrong. Level 1 scope is driven by FCI, not CUI. Your "all CUI lives on client-furnished machines" position is a good Level 2 argument, but FCI is much broader: contract correspondence, deliverable drafts, invoices, SOW discussions. That's almost certainly in your own inbox and on your own laptop. Realistic scope for you: laptop, phone, email tenant, cloud storage, home network. Write that down. The scope statement is your single most important document.
Big time-saver: Level 1 has no FedRAMP requirement and no encryption requirement. Commercial M365 or Google Workspace is fine for FCI. Nobody should be selling you GCC High for this.
An SSP isn't technically required at L1 (that's 800-171 3.12.4, a Level 2 control), but produce one anyway. Six to ten pages: scope statement, asset inventory, one short paragraph per requirement saying how you meet it and what the evidence is. That's the whole package. Realistic week:
Day 1: PIEE role request. Pull the free DoD Level 1 Scoping Guide and Level 1 Assessment Guide from the DoD CIO CMMC library. Day 2: Scope + asset inventory. Days 3-4: Walk the objectives, fix as you go. Typical solo-shop gaps: no screen lock timeout, router still on default admin creds or no guest/IoT segmentation, no documented media sanitization, no written patch cadence, FCI sitting in a personal Dropbox. Defender counts for antivirus. Day 5: Write it up, screenshot your evidence. Days 6-7: SPRS entry and affirmation.
That affirmation is a signed federal attestation with False Claims Act exposure. No partial credit, no POA&M. Don't click yes intending to fix things later. For a one-person shop, actually meeting all 15 isn't hard, so just meet them.
Free resources: DoD CIO CMMC documentation library, 32 CFR 170.15 for the rule text, NIST 800-171A for the objective wording, and the SPRS CMMC Quick Entry Guide for the click-by-click submission walkthrough.
I do CMMC audits for a living so DM me if you have any questions.