As of Today, Init Cyber is now CMMC Level 1 Certified!
If your business works with the Department of Defense (DoD), you’ve probably come across the Cybersecurity Maturity Model Certification (CMMC). For many small contractors and subcontractors, the requirement is CMMC Level 1.
Level 1 is the most basic tier. It’s designed for companies that handle Federal Contract Information (FCI) and focuses on 17 straightforward security practices. While it’s not a heavy lift, there are some steps you need to take to do it correctly.
Step 1: Know the Requirements
CMMC Level 1 is built on FAR 52.204-21, which outlines 17 safeguarding practices. These are fundamental cybersecurity measures such as:
-
Restricting access to systems and data
-
Verifying users before granting access
-
Using and updating antivirus and malware protection
-
Applying security patches
-
Properly sanitizing or destroying media before disposal
-
Removing access when employees leave If you have basic IT hygiene in place, you’re already covering much of this.
Step 2: Register in PIEE
To submit your CMMC Level 1 self-assessment, you need access to the Procurement Integrated Enterprise Environment (PIEE).
-
Go to [https://piee.eb.mil]
-
Click Register
-
Select the role: Supplier – SPRS (Supplier Performance Risk System)
-
Provide your company’s CAGE Code and UEI (formerly DUNS)
-
Complete identity verification and wait for approval
Once approved, you’ll be able to log into PIEE and access SPRS.
Step 3: Perform the Self-Assessment
The self-assessment process is straightforward:
-
Review each of the 17 practices and confirm your company does them
-
Document how you meet each requirement (short notes or policies are enough), could even do an IT Security Plan/IT Security Implementation Plan (an SOP)
-
DO NOT LIE about your self-assessment.* This self-assessment is reflective of how YOU actually conduct business day-to-day, and your cybersecurity posture. If you have doubts about your self-assessment, hire a third-party auditor to review your documentation and cybersecurity practices to ensure they are up to par with the requirements.
-
- Note: If you falsify your self-assessment and cannot back up your claims, you run the risk of being investigated for the False Claims act, which could put your company, your customers and your contracts at risk!!!
Step 4: Submit in SPRS
Log into PIEE, open SPRS, and submit your results. You’ll need to provide:
-
Your number of employees
-
The date of the assessment
-
Your attestation (yes or no) to being compliant with each of the security requirements specified in FAR clause 52.204‐21.
-
Your CAGE Code and company details
-
The name and title of the person who performed the assessment – This person is held responsible for attesting to meeting the controls outlined. This submission is what primes and contracting officers look for to verify compliance.
Step 5: Maintain Compliance
Once you submit, you’re attesting that your company is actually following these practices. That means you need to keep them in place over time and maintain evidence.
Examples of evidence include*:
-
Screenshots of antivirus running
-
Patch/update logs
-
Account removal checklists when employees leave
-
Records of sanitizing equipment before disposal
-
- Note: While SPRS doesn’t require uploading evidence, if you are ever audited or investigated, having these documents will provide evidence that you are compliant.
Closing Thoughts
CMMC Level 1 is not about advanced security controls. It’s about proving you’ve got the basics covered and can responsibly handle Federal Contract Information.
The process is straightforward:
-
Implement the 17 practices
-
Register in PIEE
-
Complete the self-assessment
-
Report your score in SPRS
-
Maintain compliance
If you’ve already been practicing basic cybersecurity hygiene, you’re well on your way. If you have questions about obtaining or maintaining CMMC level 1, reach out to us, we will be happy to help!