CMMC Level 1 Compliance: Should You DIY or Hire Help? How to Evaluate Your MSP

Contributors

Shantanoo Govilkar
Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions

You may already have an MSP, but that does not automatically mean you are CMMC Level 1 ready. With Level 1 requiring an annual self-assessment and affirmation against 15 FAR 52.204-21 requirements, now cited as FAR 52.240-93 for new solicitations, the bigger question for many contractors is who can actually manage the work accurately: your internal team, your MSP, or a CMMC specialist.

For small and midsize defense contractors, choosing between DIY CMMC Level 1 compliance and outside help comes down to more than technical capability. You need to consider your FCI scope, documentation, existing security controls, internal expertise, and what your MSP actually manages. This guide explains when a DIY approach can make sense, when professional support becomes valuable, and how to determine whether your MSP is equipped to support your CMMC Level 1 requirements.

Also Read: CMMC Level 1 Compliance for DoD Contractors

Can You Handle a CMMC Level 1 Self-Assessment Yourself?

For many smaller contractors, yes, a CMMC Level 1 self-assessment can be managed internally if the organization has clear visibility into its FCI environment, understands the 15 applicable requirements, and can demonstrate how those requirements are implemented. Level 1 is specifically structured as an annual organizational self-assessment, rather than a third-party certification assessment.

If you need outside help, understand the difference between the two provider categories. A Registered Provider Organization (RPO) provides CMMC preparation and implementation support. A Certified Third-Party Assessment Organization (C3PAO) performs an independent assessment. These roles are not interchangeable.

Before choosing the DIY route, check whether your team can confidently handle these areas:

  • Scope your environment: Identify the systems that process, store, or transmit FCI and determine the applicable CMMC assessment boundary.
  • Assess all 15 requirements: Evaluate each requirement rather than relying on a general “security is in place” judgment.
  • Maintain supporting evidence: Keep documentation and technical evidence that supports your assessment conclusions.
  • Manage the SPRS process: Enter the assessment results for the applicable CMMC UID and maintain the required record.
  • Maintain compliance annually: Level 1 status must remain current, with an annual affirmation of continuous compliance.

The deciding factor is not company size; it is internal capability. If your team can accurately define scope, evaluate the controls, document the results, and maintain the assessment over time, a DIY approach may be practical.

What Makes CMMC Level 1 Different from Level 2?

The biggest difference is not simply the number of requirements. Level 1 is designed around basic safeguarding of Federal Contract Information (FCI), while Level 2 provides broader protection for Controlled Unclassified Information (CUI). As of 2026, the DoW describes Level 1 as requiring an annual self-assessment against 15 FAR 52.204-21 requirements, while Level 2 Self requires a self-assessment every three years against 110 NIST SP 800-171 Rev. 2 requirements, with annual affirmation.

What to CompareCMMC Level 1CMMC Level 2
Information protectedFederal Contract Information (FCI)Controlled Unclassified Information (CUI)
Security requirements15 requirements under FAR 52.204-21110 requirements from NIST SP 800-171 Rev. 2
Assessment frequencyAnnual organizational self-assessmentLevel 2 Self: every 3 years; annual affirmation required
Assessment resultsEntered into SPRSEntered into SPRS
POA&MNot permittedPermitted under defined CMMC conditions
Assessment scopeSystems handling FCISystems handling CUI and applicable security-protection assets
Compliance effortFocuses on foundational safeguarding practicesRequires a substantially broader security program
Practical questionCan we adequately safeguard FCI?Can we consistently protect CUI across the defined environment?

For a contractor deciding whether DIY compliance is realistic, this distinction matters. Level 1 has a narrower requirement set, but every requirement still needs to be satisfied for a final Level 1 status because POA&Ms are not permitted. Level 2 introduces considerably more requirements, broader scoping considerations, and a more involved assessment process.

Also Read: How to Complete Your CMMC Level 1 Self Assessment

5 Signs Your Organization Can Manage CMMC Level 1 Internally

A DIY approach can be practical when your organization already has strong visibility into its systems, FCI, security practices, and documentation. The DoW's Level 1 guidance explicitly allows organizations to perform the annual self-assessment internally or engage a third party for assistance.

Look for these five indicators before deciding to manage the process in-house:

You Have a Clearly Defined FCI Environment 

Your team knows where Federal Contract Information is created, received, stored, processed, and transmitted. You can identify the systems that fall within the assessment scope rather than treating the entire IT environment as automatically in scope. FAR 52.204-21 specifically applies to contractor information systems that process, store, or transmit FCI.

Your IT Team Understands the 15 Level 1 Requirements 

Your internal team can evaluate each of the 15 FAR 52.204-21 requirements individually, from access control and authentication to physical protection, communications protection, flaw remediation, malicious-code protection, and system scanning. A general statement that “security controls are already in place” is not enough for a defensible assessment.

You Can Produce Evidence for Your Assessment Decisions 

Your team can show how each applicable requirement is implemented and maintain the documentation needed to support its assessment conclusions. The DoW assessment guide frames an assessment around whether security requirements are implemented correctly, operating as intended, and producing the desired outcome.

You Have Someone Who Can Own the Process 

Someone internally can coordinate scope, evidence, assessment activities, remediation, SPRS reporting, and the annual affirmation. This matters because Level 1 requires an annual self-assessment and annual affirmation, and Level 1 does not permit a POA&M to carry unresolved requirements forward.

Your MSP Supports Rather Than Replaces Your Compliance Ownership 

An MSP can provide valuable technical support, but your organization should still understand what it is responsible for and what the MSP actually manages. If your MSP can clearly document its services, security responsibilities, system boundaries, and evidence, your internal team may be well positioned to manage the assessment with targeted MSP support.

A good rule of thumb: if your team can confidently answer “What FCI do we handle, where does it reside, which Level 1 requirements protect it, and what evidence proves those controls are working?”, a DIY assessment may be realistic.

When Should You Hire a CMMC Consultant or Compliance Expert?

If you need outside help, understand the difference between the two provider categories. A Registered Provider Organization (RPO) provides CMMC preparation and implementation support. A Certified Third-Party Assessment Organization (C3PAO) performs an independent assessment. These roles are not interchangeable.

If you need help identifying a CMMC provider, you can explore available providers through the Cyber AB Marketplace.

Consider bringing in a CMMC consultant or compliance specialist when:

Your FCI Scope Is Unclear 

If you cannot confidently identify which systems process, store, or transmit FCI, outside expertise can help establish a defensible assessment boundary before you evaluate controls.

Your Team Lacks CMMC Assessment Experience 

Level 1 assessment is not simply a checklist exercise. The DoW methodology uses interviews, examination, and testing to determine whether requirements are implemented and producing the intended outcomes.

Your Documentation Is Incomplete 

A consultant can help identify missing policies, procedures, system documentation, or other evidence needed to support your assessment conclusions. The DoW guidance notes that evidence can include policies, training materials, system and network diagrams, and observations of safeguards in operation.

Your MSP Handles Most of Your IT Environment 

If your internal team cannot independently explain what the MSP manages, which systems are in scope, or what evidence exists, a CMMC specialist can help separate technical responsibilities from assessment responsibilities.

You Want an Independent Readiness Review 

Even when your team performs the actual self-assessment, an external review can provide a second set of eyes before you finalize the assessment and affirmation.

Also Read: What CMMC Level 1 Requires of You

What Can an MSP Handle for CMMC Level 1?

An MSP can take much of the day-to-day technical work behind CMMC Level 1, but it does not automatically take ownership of your compliance responsibility. Level 1 requires an annual self-assessment and annual affirmation against 15 FAR 52.204-21 security requirements, and the organization remains responsible for understanding its assessment scope and determining whether those requirements are satisfied. DoW scoping guidance also requires organizations to consider external service providers that process, store, or transmit FCI when defining the Level 1 assessment scope.

An MSP can typically support you with:

  • Access to Control & User Management: Manage user accounts, permissions, authentication settings, and access to systems containing FCI. This can help address Level 1 requirements around limiting system access to authorized users and controlling connections to external systems.
  • Network & System Security: Configure and maintain firewalls, endpoint protections, secure network settings, and other technical safeguards that help protect systems within the CMMC scope.
  • Monitoring & Threat Detection: Monitor systems for suspicious activity, support security event detection, and investigate alerts. Continuous monitoring can also help your team identify security issues that require remediation before the annual assessment.
  • Patch & Vulnerability Management: Apply operating-system and software updates, address known vulnerabilities, and maintain processes for correcting security weaknesses. This directly supports Level 1 expectations around flaw remediation and malicious-code protection.
  • Data Protection & Backups: Configure appropriate protections for FCI, maintain backups, and support recovery processes. Your MSP should be able to explain where FCI resides, how it is protected, and what happens to backup copies within the assessment environment.
  • Incident Response Support: Help detect, investigate, contain, and recover from security incidents. The MSP can provide technical assistance, while your organization retains responsibility for its compliance decisions and required reporting obligations.
  • Documentation & Technical Evidence: Provide configuration records, system information, logs, reports, and other technical evidence that can support your assessment. The DoW assessment methodology uses examination, interviews, and testing, so evidence should demonstrate that safeguards are actually implemented and operating as intended.
how-an-msp-supports-your-cmmc-level-1-requirements

 

How to Evaluate Your MSP for CMMC Level 1 Compliance

Choosing an MSP that understands CMMC requires more than checking whether “CMMC” appears on its website. Your MSP may manage critical security functions, but you need to know exactly what it manages, how those services support your CMMC Level 1 requirements, and what evidence it can provide when you complete your self-assessment. This is especially important when your MSP manages systems or services that are part of your FCI environment.

Start by reviewing your MSP's capabilities across CMMC knowledge, scope visibility, technical controls, evidence, responsibility boundaries, and ongoing support. Your organization remains responsible for its CMMC assessment and compliance decisions, so the MSP should function as a clearly defined technical partner rather than an assumed compliance owner.

Green Flag: What to Look ForRed Flag: What to Watch For
Understands the 15 CMMC Level 1 requirements and can explain how its services support themSays “we handle CMMC” without explaining which requirements or services are covered
Can identify the systems and services it manages that relate to your FCI environmentCannot clearly explain your CMMC scope
Can implement and maintain relevant security controlsProvides general cybersecurity services without mapping them to your requirements
Can provide technical evidence and documentation for the controls it managesCannot provide records, configurations, reports, or other supporting evidence
Clearly defines MSP and customer responsibilitiesSuggests that hiring the MSP transfers your CMMC responsibility
Provides ongoing security support throughout the assessment cycleTreats CMMC as a one-time compliance project
cta-banner

 

7 Questions to Ask Your MSP Before You Rely on Them for CMMC

Before you treat your MSP as a CMMC partner, move beyond a simple "Do you support CMMC?" conversation. The better approach is to ask questions that reveal whether the provider understands your Level 1 scope, can manage the technical safeguards it claims to cover, and can produce evidence to support your organization's assessment.

Which CMMC Level 1 requirements do your services directly support? 

Ask your MSP to map its services to the applicable 15 FAR 52.204-21 requirements rather than giving you a general cybersecurity overview. You should be able to see exactly which controls the MSP implements, manages, or monitors and which remain with your organization.

Which systems and services that you manage are part of our FCI environment? 

Your MSP should understand where FCI is processed, stored, or transmitted and identify the systems and services it manages that fall within the relevant assessment scope. DoW Level 1 scoping guidance specifically addresses external service providers when determining the assessment boundary.

What evidence can you provide for the controls you manage? 

Ask for examples of technical and administrative evidence such as configuration records, access information, vulnerability or patch reports, security logs, and relevant procedures. The objective is to establish whether the MSP can support your assessment with evidence rather than simply state that a control is “covered.”

Who is responsible when a CMMC requirement involves both our team and your MSP? 

Shared responsibilities can easily create gaps. Define who implements the safeguard, who monitors it, who maintains the evidence, who approves changes, and who addresses identified deficiencies.

How do you manage changes that could affect our CMMC scope? 

Ask what happens when you add a cloud service, replace endpoints, change network architecture, move FCI, or modify an MSP-managed service. Scope should remain aligned with the environment actually used to process, store, or transmit FCI.

How will you support us during our annual Level 1 self-assessment? 

Your MSP should explain what assessment support it can provide, including access to technical evidence, system information, configuration details, and knowledgeable personnel for questions about managed controls. Your organization remains responsible for the self-assessment and affirmation, so clarify the MSP's role before assessment activities begin.

What happens if one of the controls you manage stops meeting the requirement? 

CMMC readiness is not a one-time configuration exercise. Ask how the MSP detects issues, communicates them, assigns remediation ownership, tracks corrective action, and confirms that the control is restored.

Also Read: CMMC Level 1 vs Level 2, Which Applies to You?

Frequently Asked Questions

Back
to Top