Level 1
Level 1- Scope
- You handle Federal Contract Information (FCI) but not CUI.
- Assessment
- Annual self-assessment attestation.
- Typical audience
- Start with foundational practices and self-assessment guidance.
FOR ORGANIZATIONS
Organizations in the Defense Industrial Base may need CMMC certification to bid on or perform work under applicable Department of Defense contracts. This page outlines the general path — your specific requirements depend on the information you handle and your contract terms.

When a DoD contract requires CMMC, your organization must demonstrate conformance at the applicable level before award or during performance, depending on contract requirements. Certification provides verifiable assurance that your cybersecurity practices meet program standards.
Prime contractors and subcontractors throughout the supply chain are affected. Understanding your role and the information you handle is the first step toward readiness.
Most organizations follow a similar sequence: understand what level applies, close gaps through readiness work, undergo the required assessment, and maintain conformance over time. The Cyber AB ecosystem connects you to accredited assessors and verified providers at each stage.
Review your contracts and the information you handle to determine which CMMC level applies. Use the level comparison below as decision support — not a legal determination.
Close gaps before assessment. The Cyber Engagement Forum supports pre-assessment consulting, gap analysis, and readiness preparation.
Engage an accredited C3PAO for the required third-party assessment, or complete a self-assessment where applicable at Level 1.
Certification is not one-and-done. Plan for ongoing monitoring, reassessment cycles, and contract-driven updates to your security program.
Use this comparison to orient your planning. Your contracting officer and the information you handle determine the authoritative level requirement.