CMMC Level 1 · Federal Contract Information

Your CMMC Level 1 compliance state, established, maintained and evidenced: all 15 requirements recorded, a complete cycle every 30 days, and the self-assessment and affirmation decision kept with your team.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC readiness and compliance operations. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Not SaaS. Not consulting. Not a C3PAO.

What Level 1 is

CMMC idShort titleFAR reference
AC.L1-b.1.iAuthorized Access ControlFAR 52.204-21(b)(1)(i)
AC.L1-b.1.iiTransaction & Function ControlFAR 52.204-21(b)(1)(ii)
AC.L1-b.1.iiiExternal ConnectionsFAR 52.204-21(b)(1)(iii)
AC.L1-b.1.ivControl Public InformationFAR 52.204-21(b)(1)(iv)
IA.L1-b.1.vIdentificationFAR 52.204-21(b)(1)(v)
IA.L1-b.1.viAuthenticationFAR 52.204-21(b)(1)(vi)
MP.L1-b.1.viiMedia DisposalFAR 52.204-21(b)(1)(vii)
PE.L1-b.1.viiiLimit Physical AccessFAR 52.204-21(b)(1)(viii)
PE.L1-b.1.ixManage Visitors & Physical AccessFAR 52.204-21(b)(1)(ix)
SC.L1-b.1.xBoundary ProtectionFAR 52.204-21(b)(1)(x)
SC.L1-b.1.xiPublic-Access System SeparationFAR 52.204-21(b)(1)(xi)
SI.L1-b.1.xiiFlaw RemediationFAR 52.204-21(b)(1)(xii)
SI.L1-b.1.xiiiMalicious Code ProtectionFAR 52.204-21(b)(1)(xiii)
SI.L1-b.1.xivUpdate Malicious Code ProtectionFAR 52.204-21(b)(1)(xiv)
SI.L1-b.1.xvSystem & File ScanningFAR 52.204-21(b)(1)(xv)

What the agents do

The eleven deliverables, each a deterministic record of what was measured and what your team recorded. At Level 1 the agents make no AI model call: every state follows fixed rules from what your connected sources report and what your team records.

  1. FCI Scope Record: your legal entity, CAGE codes, the kinds of Federal Contract Information you receive (described, never copied), the in-scope people, technology, facilities and service providers, and which connected sources are in your FCI scope, each classified by a named person.
  2. 15-Requirement Compliance Record: one row per requirement: its state, the basis for each objective (measured, substantiated by your team, or an exception your team recorded) and when it was last observed.
  3. Evidence Register: measured findings with their check, source and time, and your team’s evidence index records with the SHA-256 hash your browser computed, labelled as submitter-asserted.
  4. Automated Measurement Record: which requirements and objectives your in-scope connected sources could observe this cycle, from which sources, when the scan started and ended, and every source that failed or was set aside as out of scope.
  5. Gap and Exception Report: every NOT SATISFIED and UNOBSERVED objective and why, every N/A with its written reason, and every exception your team recorded.
  6. Remediation Action Report: the action, owner, target date and status your team records for each NOT SATISFIED requirement. It is not a POA&M.
  7. Annual Self-Assessment Package: MET, NOT MET or N/A per objective, with its basis and evidence references, prepared when you press “Prepare the annual packages” in your Level 1 workspace, or 30 days before your anniversary.
  8. SPRS Submission Worksheet: the fields 32 CFR 170.15(a)(1)(i) lists, prepared for your team to enter in SPRS.
  9. Annual Affirmation Package: prepared for your named Affirming Official’s decision; your official affirms in SPRS, using SPRS’s own affirmation wording.
  10. Drift Monitoring: every 30 days, connected sources about every seven days: between annual assessments, every objective whose state changed since the previous cycle or re-scan, with both observation times.
  11. Historical Assurance Record: every cycle’s documents by name and SHA-256, every affirmation decision, every scope version and every exception, oldest first.

Three states, and the evidence request

Every requirement shows one of three states: SATISFIED, NOT SATISFIED or UNOBSERVED. UNOBSERVED means not yet shown by a connected source that covers your in-scope systems, or by evidence your team recorded. The agent asks for exactly the evidence it needs, checks that the record is complete (every objective answered, an accepted evidence type, dated within the year, a named submitter), records the SHA-256 hash your browser computed, and closes the request. Your files stay with you; what they show is your team’s statement.

Measured where an in-scope connected source can observe; substantiated by your team where not. Systems outside your FCI scope are not assessed (32 CFR 170.19(b)).

What is measured

Requirements are measured where a connected source can observe them; the rest stay UNOBSERVED until your team substantiates them. Connected sources are the identity, cloud and endpoint connectors you connect and classify as in your FCI scope; they read configuration metadata only.

Cadence

A complete Level 1 cycle every 30 days on Starter; connected sources re-scanned about every seven days.

What Level 1 does not include

No system security plan, no CUI scoping, no Level 2 control analysis, no assessment-objective responsibility matrix, no SPRS score work, no C3PAO preparation and no POA&M.

The annual decision

Your Affirming Official makes the annual affirmation decision and enters it in SPRS (32 CFR 170.22). The agents prepare the self-assessment package, the SPRS worksheet with the fields 32 CFR 170.15(a)(1)(i) lists, and the affirmation package. ElasticD3M submits nothing to the government.

If an accountable official must affirm compliance, Enclave AI™ gives that official technical evidence, refreshed on a recurring schedule, supporting the state being affirmed.

Price

Free Level 1 Gap Check
$0
free
  • Fifteen questions, one per FAR 52.204-21 requirement. Each answer is recorded as you gave it: in place, not in place, does not apply, or needs evidence. Level 1 has no point score, so none is shown.
Take the free Level 1 Gap Check →
CMMC Level 1 Readiness Snapshot
$299
one-time
  • Your FCI Scope Record, from a short intake
  • One complete Level 1 measurement cycle: what your in-scope connected sources can observe is measured; everything else gets a short evidence request
  • Your 15-Requirement Compliance Record, Gap and Exception Report and Remediation Action Report (not a POA&M)
  • Credited in full if you start Level 1 Starter with the same billing email within 30 days of receiving the Snapshot PDF: against your first invoice, with any amount above that invoice applied to the invoices after it
Level 1 checkout not open yet
Enclave AI Level 1 Starter AaaS
$199
per month or $2,388 per year, per OSA entity
Eleven deliverables
  • FCI Scope Record
  • 15-Requirement Compliance Record
  • Evidence Register
  • Automated Measurement Record
  • Gap and Exception Report
  • Remediation Action Report
  • Annual Self-Assessment Package
  • SPRS Submission Worksheet
  • Annual Affirmation Package
  • Drift Monitoring, every 30 days, connected sources about every seven days
  • Historical Assurance Record
  • Every requirement shows one of three states: SATISFIED, NOT SATISFIED or UNOBSERVED. UNOBSERVED means not yet shown by a connected source that covers your in-scope systems, or by evidence your team recorded. The agent asks for exactly the evidence it needs, checks that the record is complete (every objective answered, an accepted evidence type, dated within the year, a named submitter), records the SHA-256 hash your browser computed, and closes the request. Your files stay with you; what they show is your team’s statement.
  • A complete Level 1 cycle every 30 days on Starter, with connected sources re-scanned about every seven days
  • No POA&M: Level 1 does not permit one (32 CFR 170.21(a)(1)). The Remediation Action Report is not a POA&M.
  • Your Affirming Official makes the annual affirmation decision and enters it in SPRS; the agents prepare the package.
Monthly, $199
Level 1 checkout not open yet
Annual, $2,388
Level 1 checkout not open yet

Level 1 checkout is not open yet. The free Level 1 Gap Check is available now.

Next