The Department of Defense (DoD) announced CMMC 2.0 in November 2021, introducing a significant change: Level 1 now requires annual self-assessments instead of third-party audits. If you're a Defense Industrial Base (DIB) contractor handling Federal Contract Information (FCI), executing your first self-assessment correctly is crucial. Failing to do so could jeopardize your response to future Requests for Proposal (RFP).
Self-assessment might seem simpler than hiring a Certified Third-Party Assessment Organization (C3PAO), but it's not. You're certifying to the government that your controls are effective, and inaccuracies can lead to false claims under the False Claims Act. This guide will walk you through conducting a defensible CMMC Level 1 self-assessment.
What You Need Before Starting
Before beginning the assessment, ensure you have the following:
System boundary documentation. Define what's in scope. For Level 1, this includes any system processing, storing, or transmitting FCI. Document every endpoint, server, network segment, and cloud service that interacts with FCI. If you can't create a network diagram showing FCI flow, pause here.
Control responsibility matrix. CMMC Level 1 maps to the 17 controls in NIST SP 800-171 Rev 2's basic safeguarding requirements (a subset from FAR 52.204-21). For each control, determine if you're implementing it directly, inheriting it from a service provider, or using a hybrid approach. For example, using Microsoft 365 GCC means inheriting physical security controls but managing access control configurations.
Evidence collection process. Self-assessment requires proof, not just assertions. Prepare folders for screenshots, configuration exports, policy documents, and logs. The DoD may request supporting evidence, even for Level 1, and you'll need it for your annual review.
Assessment lead assignment. Assign someone familiar with both your IT environment and NIST 800-171 language. This person should not be the one who implemented the controls; an independent review is necessary even for self-assessment.
Step-by-Step Implementation
Week 1-2: Scope Validation and Data Flow Mapping
Start by confirming your FCI inventory. FCI includes any information provided by or generated for the government under a contract, excluding publicly available data. Examples include contract terms, technical drawings marked "Distribution C," pricing data, and delivery schedules.
Review your contract files and identify every location where FCI resides. Check:
- Shared drives and file servers
- Email systems (look for .mil domains and contract numbers)
- Project management tools
- Collaboration platforms
- Backup systems
- Employee laptops with VPN access to FCI repositories
Document the data flow. If engineers download technical specs to their laptops, those laptops are in scope. If your finance team emails invoices to contracting officers, that email system is in scope.
Create a simple asset inventory spreadsheet: Asset Name | Asset Type | FCI Present (Y/N) | Justification | Owner.
Week 3-4: Control Implementation Review
Systematically review the 17 basic safeguarding requirements. For each control, document:
- How you implement it (technical mechanism)
- Where you implement it (systems involved)
- Who's responsible for maintaining it
- What evidence proves it works
Example for Access Control (3.1.1 - Limit system access to authorized users):
Implementation: Active Directory group policies enforce authentication; VPN requires MFA via Duo; Azure AD Conditional Access blocks unmanaged devices.
Location: All FCI systems authenticate against corp.example.com domain.
Responsible party: IT Director.
Evidence: AD security group membership exports, Duo authentication logs, Azure AD sign-in logs, quarterly access reviews.
Don't overlook controls you think are obvious. "We have antivirus" isn't enough for Malicious Code Protection (3.14.1). Document the product name, update frequency, scan schedules, and provide a recent scan report.
Week 5-6: Evidence Collection and Gap Remediation
Gather evidence for every control. Use configuration screenshots with timestamps, not descriptions of future plans. Export actual logs, not summaries.
When you find gaps, document them immediately. CMMC 2.0 allows Plans of Action and Milestones for Level 2 and above, but Level 1 self-assessments require full compliance. If you're missing a control, you have two choices: implement it before assessment or remove FCI from that system.
Common gaps in first-time assessments:
- Incident response plans that don't cover FCI-specific reporting (3.6.1, 3.6.2)
- Media sanitization procedures that don't address SSDs or cloud storage (3.8.3)
- Configuration management without baseline documentation (3.4.1)
- Security awareness training with no attendance records (3.2.1)
Fix the gaps before you certify. You're attesting under penalty that controls are in place and effective.
Week 7-8: Assessment Documentation and Certification
Compile your assessment report. At minimum, include:
- Executive summary of scope and findings
- Asset inventory with FCI justification
- Control-by-control assessment results
- Evidence index
- Signatures from assessment lead and authorizing official
Review the assessment with your legal and contracts teams before submitting anything to the DoD. Once you certify compliance in a proposal or upload an assessment to the Supplier Performance Risk System, you've made a representation to the government.
Validation: How to Verify It Works
Your self-assessment isn't complete until you can answer these questions with documented evidence:
Can you produce your FCI inventory in under 10 minutes? If a contracting officer asks what FCI you have and where it is, you should have a current list.
Can you demonstrate each control with a live walkthrough? Pick three controls randomly and show them working right now, not from a screenshot taken last month.
Do your evidence timestamps align? If your assessment is dated March 2024 but your last Vulnerability Assessment was June 2023, you have a credibility problem.
Does your assessment match your System Security Plan? If you're also pursuing NIST 800-171 compliance for DFARS 252.204-7012, your self-assessment and SSP should tell the same story about your control implementation.
Test your assessment by having someone outside the assessment team review it. Can they understand your scope? Can they follow your evidence trail? If not, strengthen your documentation.
Maintenance and Ongoing Tasks
Self-assessment is annual, but your compliance work isn't. Schedule these recurring tasks:
Quarterly evidence refresh. Update your evidence folders every 90 days. When assessment time comes, you're compiling recent artifacts, not scrambling to recreate history.
Monthly FCI inventory review. New contracts bring new FCI. Review your contract awards monthly and update your scope documentation.
Continuous monitoring of inherited controls. If you're relying on a cloud provider's controls, track their compliance status. GCC High providers publish FedRAMP authorization status, check it quarterly.
Annual training and assessment preparation. Security awareness training is required annually (3.2.1). Schedule it in Q1 so you have current completion records before your assessment window.
Change management integration. When you deploy new systems or modify network architecture, check whether FCI scope changes. Build a trigger into your change management process: "Does this change affect FCI systems? If yes, update boundary documentation."
The biggest ongoing challenge remains CUI identification. Many DIB contractors still aren't confident about what Controlled Unclassified Information (CUI) they have in their environments. For Level 1, you're dealing with FCI, not CUI, but the principle holds: if you can't identify the data, you can't scope the assessment properly. Work with your contracting officers to get clear marking guidance, and push back when contracts arrive with ambiguous data handling requirements.
Your first self-assessment establishes your compliance baseline. Do it right, document thoroughly, and you'll have a repeatable process that scales as CMMC requirements hit your contracts.



