What Level 1 is
- Level 1 is exactly the 15 basic safeguarding requirements of FAR 52.204-21(b)(1)(i) to (xv). (32 CFR 170.14(c)(2))
- Your organization must reach MET on every Level 1 requirement, and no POA&M is permitted at Level 1. (32 CFR 170.15(a)(1))
- Level 1 self-assessments do not permit a POA&M at any time. (32 CFR 170.21(a)(1))
- The self-assessment is annual, and its results are entered in SPRS: the CMMC level, the CMMC status date, the assessment scope, the CAGE codes of the in-scope systems and the compliance result. (32 CFR 170.15(a)(1), (a)(1)(i))
- An affirmation is required: before award of a contract or subcontract that requires Level 1 (Self), your organization must hold Level 1 (Self) with its affirmation in SPRS. (32 CFR 170.15(a)(2), 170.15(b))
- The self-assessment uses the NIST SP 800-171A (June 2018) assessment objectives of each mapped requirement, with Federal Contract Information in place of CUI. (32 CFR 170.15(c)(1))
- Your organization keeps the artifacts used as evidence for six years from the CMMC Status Date; they stay with you. (32 CFR 170.15(c)(2))
- Your Affirming Official, a senior representative with authority to affirm, affirms at completion of the self-assessment and annually thereafter, in SPRS. (32 CFR 170.22)
- Each requirement is found MET, NOT MET or NOT APPLICABLE. An N/A objective counts as MET, one NOT MET objective fails the requirement, and Level 1 has no point score. (32 CFR 170.24(b)(1) to (b)(3), (c)(1))
- Level 1 scope is the systems that process, store or transmit Federal Contract Information. Specialized Assets such as operational technology are not part of it, and your organization considers people, technology, facilities and external service providers when it scopes. (32 CFR 170.19(b))
| CMMC id | Short title | FAR reference |
|---|---|---|
| AC.L1-b.1.i | Authorized Access Control | FAR 52.204-21(b)(1)(i) |
| AC.L1-b.1.ii | Transaction & Function Control | FAR 52.204-21(b)(1)(ii) |
| AC.L1-b.1.iii | External Connections | FAR 52.204-21(b)(1)(iii) |
| AC.L1-b.1.iv | Control Public Information | FAR 52.204-21(b)(1)(iv) |
| IA.L1-b.1.v | Identification | FAR 52.204-21(b)(1)(v) |
| IA.L1-b.1.vi | Authentication | FAR 52.204-21(b)(1)(vi) |
| MP.L1-b.1.vii | Media Disposal | FAR 52.204-21(b)(1)(vii) |
| PE.L1-b.1.viii | Limit Physical Access | FAR 52.204-21(b)(1)(viii) |
| PE.L1-b.1.ix | Manage Visitors & Physical Access | FAR 52.204-21(b)(1)(ix) |
| SC.L1-b.1.x | Boundary Protection | FAR 52.204-21(b)(1)(x) |
| SC.L1-b.1.xi | Public-Access System Separation | FAR 52.204-21(b)(1)(xi) |
| SI.L1-b.1.xii | Flaw Remediation | FAR 52.204-21(b)(1)(xii) |
| SI.L1-b.1.xiii | Malicious Code Protection | FAR 52.204-21(b)(1)(xiii) |
| SI.L1-b.1.xiv | Update Malicious Code Protection | FAR 52.204-21(b)(1)(xiv) |
| SI.L1-b.1.xv | System & File Scanning | FAR 52.204-21(b)(1)(xv) |
What the agents do
The eleven deliverables, each a deterministic record of what was measured and what your team recorded. At Level 1 the agents make no AI model call: every state follows fixed rules from what your connected sources report and what your team records.
- FCI Scope Record: your legal entity, CAGE codes, the kinds of Federal Contract Information you receive (described, never copied), the in-scope people, technology, facilities and service providers, and which connected sources are in your FCI scope, each classified by a named person.
- 15-Requirement Compliance Record: one row per requirement: its state, the basis for each objective (measured, substantiated by your team, or an exception your team recorded) and when it was last observed.
- Evidence Register: measured findings with their check, source and time, and your team’s evidence index records with the SHA-256 hash your browser computed, labelled as submitter-asserted.
- Automated Measurement Record: which requirements and objectives your in-scope connected sources could observe this cycle, from which sources, when the scan started and ended, and every source that failed or was set aside as out of scope.
- Gap and Exception Report: every NOT SATISFIED and UNOBSERVED objective and why, every N/A with its written reason, and every exception your team recorded.
- Remediation Action Report: the action, owner, target date and status your team records for each NOT SATISFIED requirement. It is not a POA&M.
- Annual Self-Assessment Package: MET, NOT MET or N/A per objective, with its basis and evidence references, prepared when you press “Prepare the annual packages” in your Level 1 workspace, or 30 days before your anniversary.
- SPRS Submission Worksheet: the fields 32 CFR 170.15(a)(1)(i) lists, prepared for your team to enter in SPRS.
- Annual Affirmation Package: prepared for your named Affirming Official’s decision; your official affirms in SPRS, using SPRS’s own affirmation wording.
- Drift Monitoring: every 30 days, connected sources about every seven days: between annual assessments, every objective whose state changed since the previous cycle or re-scan, with both observation times.
- Historical Assurance Record: every cycle’s documents by name and SHA-256, every affirmation decision, every scope version and every exception, oldest first.
Three states, and the evidence request
Every requirement shows one of three states: SATISFIED, NOT SATISFIED or UNOBSERVED. UNOBSERVED means not yet shown by a connected source that covers your in-scope systems, or by evidence your team recorded. The agent asks for exactly the evidence it needs, checks that the record is complete (every objective answered, an accepted evidence type, dated within the year, a named submitter), records the SHA-256 hash your browser computed, and closes the request. Your files stay with you; what they show is your team’s statement.
- N/A is recorded with a written reason, as the CMMC Level 1 Assessment Guide recommends.
- An enduring exception described in the system security plan your organization keeps, if any (Enclave AI does not prepare one at Level 1), or a temporary deficiency that arose after the requirement was implemented and is addressed in your operational plan of action (which is not a POA&M), is recorded by your team and reported as MET with that basis (32 CFR 170.24(b)(1)). Every Level 1 requirement must still be fully implemented to be MET: “All CMMC Level 1 security requirements must be fully implemented to be considered MET. No POA&M is permitted for CMMC Level 1” (32 CFR 170.24(c)(1)).
- The self-assessment package reports MET, NOT MET or N/A per objective.
Measured where an in-scope connected source can observe; substantiated by your team where not. Systems outside your FCI scope are not assessed (32 CFR 170.19(b)).
What is measured
Requirements are measured where a connected source can observe them; the rest stay UNOBSERVED until your team substantiates them. Connected sources are the identity, cloud and endpoint connectors you connect and classify as in your FCI scope; they read configuration metadata only.
Cadence
A complete Level 1 cycle every 30 days on Starter; connected sources re-scanned about every seven days.
What Level 1 does not include
No system security plan, no CUI scoping, no Level 2 control analysis, no assessment-objective responsibility matrix, no SPRS score work, no C3PAO preparation and no POA&M.
The annual decision
Your Affirming Official makes the annual affirmation decision and enters it in SPRS (32 CFR 170.22). The agents prepare the self-assessment package, the SPRS worksheet with the fields 32 CFR 170.15(a)(1)(i) lists, and the affirmation package. ElasticD3M submits nothing to the government.
If an accountable official must affirm compliance, Enclave AI™ gives that official technical evidence, refreshed on a recurring schedule, supporting the state being affirmed.
Price
- Fifteen questions, one per FAR 52.204-21 requirement. Each answer is recorded as you gave it: in place, not in place, does not apply, or needs evidence. Level 1 has no point score, so none is shown.
- Your FCI Scope Record, from a short intake
- One complete Level 1 measurement cycle: what your in-scope connected sources can observe is measured; everything else gets a short evidence request
- Your 15-Requirement Compliance Record, Gap and Exception Report and Remediation Action Report (not a POA&M)
- Credited in full if you start Level 1 Starter with the same billing email within 30 days of receiving the Snapshot PDF: against your first invoice, with any amount above that invoice applied to the invoices after it
- FCI Scope Record
- 15-Requirement Compliance Record
- Evidence Register
- Automated Measurement Record
- Gap and Exception Report
- Remediation Action Report
- Annual Self-Assessment Package
- SPRS Submission Worksheet
- Annual Affirmation Package
- Drift Monitoring, every 30 days, connected sources about every seven days
- Historical Assurance Record
- Every requirement shows one of three states: SATISFIED, NOT SATISFIED or UNOBSERVED. UNOBSERVED means not yet shown by a connected source that covers your in-scope systems, or by evidence your team recorded. The agent asks for exactly the evidence it needs, checks that the record is complete (every objective answered, an accepted evidence type, dated within the year, a named submitter), records the SHA-256 hash your browser computed, and closes the request. Your files stay with you; what they show is your team’s statement.
- A complete Level 1 cycle every 30 days on Starter, with connected sources re-scanned about every seven days
- No POA&M: Level 1 does not permit one (32 CFR 170.21(a)(1)). The Remediation Action Report is not a POA&M.
- Your Affirming Official makes the annual affirmation decision and enters it in SPRS; the agents prepare the package.
Level 1 checkout is not open yet. The free Level 1 Gap Check is available now.