The month CMMC Level 1 turned out to have a higher pass mark than Level 2, at 78K MRR
A composite founder diary. Everyone calls CMMC Level 1 the easy tier because it has fifteen requirements. In September 2026 I found it is the only level in the model where no plan of action is permitted at any time, so a Level 2 contractor reaches award at 0.8 while Level 1 needs every requirement MET.
Updated on September 30, 2026
In this story
“You are only Level 1. That is the easy one. Just send me your affirmation date.”
That was a program manager at a prime contractor, in a thread about a subcontract worth roughly a fifth of our year. We were at 78K MRR, eleven people, and we had never held a Department of Defense contract in our lives. I spent the next nine days finding out that the tier everybody calls the easy one is the only tier in the entire programme where you are not allowed to be partly finished.
Quick answer (2026). This is a composite founder diary. The company, the people and the timeline are invented, assembled from patterns across several small software firms. The legal material is not composite: every quotation below is from the current text of 32 CFR part 170 or 48 CFR 52.204-21, linked at the point it is used. The short version is that CMMC Level 1 has fifteen requirements where Level 2 has a much longer list, and it is also the only level in the model with no plan-of-action route. Level 2 and Level 3 both let a contractor reach award at a score ratio of 0.8 with up to 180 days to finish the rest. Level 1 permits none of that. Fourteen of fifteen is not a weaker Level 1 status. It is no status at all.
The fifteen requirements were the easy part
I started where everyone starts, with the list. CMMC Level 1 does not invent its own controls. The regulation says plainly that "The security requirements in CMMC Level 1 are those set forth in 48 CFR 52.204-21(b)(1)(i) through (xv)", and that clause is the FAR basic safeguarding rule that has existed since 2016.
Fifteen items. Limit system access to authorised users. Limit access to the kinds of transactions authorised users are permitted to perform. Control who can use external systems. Sanitise media before disposal. Update malicious code protection. None of it is exotic, and none of it costs a hundred thousand dollars. Our engineer read the list in an afternoon and said we were probably at thirteen, maybe fourteen.
I relaxed. That was the mistake, and it lasted about a day.
The sentence I read four times
Thirteen or fourteen out of fifteen sounds like a good position when you are used to security questionnaires, where a partial answer with a remediation date is a normal thing to send. So I went looking for the bit of the rule that tells you how long you have to close the gap.
There is no such bit. Section 170.15 says the contractor "must complete and achieve a MET result for all security requirements", and then, in the next sentence, without any qualification at all:
32 CFR 170.15(a)(1), verbatim: "No POA&Ms are permitted for CMMC Level 1."
A POA&M is a plan of action and milestones. It is the instrument the whole federal cybersecurity world runs on: here is what is not done, here is who is doing it, here is the date. I had assumed it was ambient, the way a grace period on an invoice feels ambient.
The dedicated POA&M section says it again, and more absolutely. Section 170.21 opens by listing the conditions under which a contractor may carry unfinished requirements, and its first condition is not a condition:
32 CFR 170.21(a)(1), verbatim: "A POA&M is not permitted at any time for Level 1 self-assessments."
At any time. Not a shorter window than Level 2, not a narrower list of eligible controls. None.
The arithmetic nobody puts side by side
Here is the part I have not seen written down anywhere, and it took reading two sections that sit six paragraphs apart.
The same section 170.21 that forbids a POA&M at Level 1 grants one at Level 2, and states the threshold as a ratio: a contractor may hold a Conditional Level 2 status if "The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8". Level 3 gets the same 0.8 treatment in the paragraph immediately below. And section 170.21(b) gives the holder of a Conditional status real time to finish: "The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date."
Now put the two next to each other.
A Level 2 contractor, handling controlled unclassified information, the sensitive tier, the one that can require an outside assessor, may go to contract award at eighty per cent, with a fifth of its obligations openly unmet, and half a year to close them.
A Level 1 contractor, handling only federal contract information, the tier with fifteen items on it, must be at one hundred per cent. Fourteen of fifteen is 93.3 per cent. It is thirteen points clear of the bar that lets a Level 2 shop win work, and it is not enough, because at Level 1 there is no bar to be clear of. There is only MET on everything or nothing.
The lowest tier in the model has the highest pass mark in the model. I read it three times before I believed it, and I still think it is the single least intuitive thing in the regulation.
The scoring section is quietly consistent with this. It says the methodology "designed to credit partial implementation only in limited cases", and Level 1 is not one of them.
Then I read who signs it
I had also been treating self-assessment as a synonym for nobody being really on the hook. That survived until I reached section 170.22.
The affirmation is not a checkbox on a portal. It is filed by an Affirming Official, defined as "the senior level representative from within each Organization Seeking Assessment" who has authority to affirm continuing compliance. The filing carries that person's name, title and contact information. And the statement they are signing is not a report that we assessed ourselves. It is an "Affirmation statement attesting that the OSA has implemented and will maintain implementation of all applicable CMMC security requirements".
Implemented, and will maintain. Present and future tense, annually, by a named human being.
Section 170.15(b) then ties it to money: "Prior to award of any contract or subcontract with a requirement for the CMMC Status of Level 1 (Self), OSAs must both achieve a CMMC Status of Level 1 (Self) and have submitted an affirmation of compliance into SPRS". Both. The assessment alone buys nothing.
In a company our size the senior level representative with authority over compliance is me. There is no one else it could be.
It reaches you through somebody else's contract
The last thing I checked was whether any of this applied to us at all, since we are not a defence contractor and have never bid on anything. Section 170.23 settles that: the requirements apply "throughout the supply chain at all tiers", and it is specific about the bottom of the chain. "If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor."
Federal contract information is a low bar. It is non-public information provided by or generated for the government under a contract. If a prime sends you a statement of work and you store it, you are probably in scope. Nobody negotiates this with you. It arrives in a flow-down clause in somebody else's paperwork.
What I got wrong
Three things, and the third is the one I would want back.
I assumed the fifteen requirements were the hard part. They are the easy part. The pass rule is the hard part, and the pass rule is one sentence long and sits in a section most summaries skip.
I assumed a self-assessment has no teeth. Section 170.15(b) makes award conditional on both the status and the affirmation being filed, and section 170.22 puts a named senior person's signature on it annually.
And I went hunting for a small-business carve-out. I was confident I would find one, because a rule that lands on an eleven-person company with no federal experience surely has a threshold in it somewhere. It does not. I searched the full text of part 170 for the usual escape hatches and got nothing: zero occurrences of small business, zero of small entity, zero of de minimis, zero of exempt. That hypothesis was simply wrong, and finding it wrong was more useful than finding it right would have been, because it ended a week of looking.
I also checked for the other thing that normally softens a rule like this, which is a state-of-mind tier. Most regimes grade you on whether you tried. Part 170 contains no occurrence of willful, negligent, reckless, good faith or safe harbor. There is no gradient in the text at all. You are MET or you are NOT MET.
What actually happened
Scroll to see more
| What I assumed | What the text says |
|---|---|
| Level 1 is the entry tier, so it is the forgiving one | "No POA&Ms are permitted for CMMC Level 1" (170.15(a)(1)) |
| A remediation plan buys time at any level | "A POA&M is not permitted at any time for Level 1 self-assessments" (170.21(a)(1)) |
| The higher tier must have the higher bar | Level 2 and Level 3 reach award at a ratio "greater than or equal to 0.8"; Level 1 must be MET on everything |
| Self-assessment means nobody signs anything | An Affirming Official, "the senior level representative", files name, title and contact, annually |
| We are not a defence contractor, so none of it applies | Flow-down runs "throughout the supply chain at all tiers"; FCI alone triggers Level 1 |
| Effort counts for something if you fall short | Part 170 has no occurrence of willful, negligent, reckless, good faith or safe harbor |
We closed the last two items in about three weeks. It was not expensive. It was only expensive to discover, and I lost nine days to an assumption that the small number meant the soft rule.
Limits
This is a composite, so treat the company details as illustrative and the citations as the real content.
Two things I did not verify and am not claiming. First, I read the regulation itself rather than the CMMC Assessment Guide for Level 1, so I have nothing to say about the mechanics of how you evidence each item in practice. Second, and more importantly, the absence I reported above is an absence in part 170 specifically. I am saying that the programme rule contains no state-of-mind language and no small-business exemption. I am not saying there are no consequences for a wrong affirmation, because what happens to a false certification is governed somewhere other than part 170 and I did not check it. That distinction matters and I do not want to be read as having proved the stronger claim.
One more. Level 2's requirement count lives in a NIST publication that part 170 incorporates by reference rather than restating, so I have quoted the 0.8 ratio and deliberately not quoted a number of controls. And the eCFR section links above redirect to longer canonical paths; the links here are the destinations, not the short forms.
The one thing I would tell you
When a compliance tier is described to you as the easy one, do not check how many requirements it has. Check what happens when you miss one.
The number of obligations and the strictness of the pass rule are independent, and in this regulation they run in opposite directions. Fifteen items with no partial credit is a harder thing to satisfy than a long list where eighty per cent gets you to award with six months to finish. The person who told me Level 1 was the easy one was not lying to me. He had counted the requirements, the way I would have.
Written by
Anya PetrovaFrequently asked questions
Is this a real founder's diary?
It is a composite. These diaries are built from patterns across several small software companies, with the numbers, names and timeline changed, so no single story here is any one real company. The legal material is not composite: every provision quoted is from the current text of 32 CFR part 170 and 48 CFR 52.204-21, and each is linked at the point it is used.
Can you self certify CMMC Level 1?
Yes. Level 1 is a self-assessment and no outside assessor is involved, but self does not mean informal. Under 32 CFR 170.15 the results go into SPRS, and under 170.22 an Affirming Official, defined as the senior level representative of the organisation, files a separate affirmation carrying their name, title and contact information, at completion and annually thereafter. Section 170.15(b) makes contract award conditional on both the assessment and the affirmation being submitted.
Is CMMC Level 1 easier than CMMC Level 2?
It has far fewer requirements and needs no third-party assessor, so in workload terms it is lighter. Its pass rule is stricter. Section 170.21 lets a Level 2 or Level 3 contractor hold a Conditional status at an assessment score ratio of 0.8 or better, with up to 180 days to close the gap. The same section states that a plan of action and milestones is not permitted at any time for Level 1 self-assessments, so Level 1 requires every requirement to be MET.
What happens if you meet 14 of the 15 CMMC Level 1 requirements?
You do not hold a CMMC Level 1 status. Section 170.15(a)(1) requires a MET result for all security requirements and states that no POA&Ms are permitted for CMMC Level 1, so there is no partial or conditional Level 1 to fall back to. Fourteen of fifteen is 93.3 per cent, which is above the 0.8 ratio that would let a Level 2 contractor reach award, and it is still not a Level 1 status.
Who signs a CMMC Level 1 affirmation?
An Affirming Official, which 32 CFR 170.22 defines as the senior level representative from within the organisation who is responsible for its compliance and has authority to affirm it. The affirmation records that person's name, title and contact information, and the statement attests that the organisation has implemented and will maintain implementation of all applicable requirements. In a very small company this is usually a founder, because there is nobody else it can be.
Does CMMC Level 1 apply to subcontractors?
Yes. Section 170.23 applies CMMC throughout the supply chain at all tiers, and states that a subcontractor which will only process, store or transmit federal contract information, and not controlled unclassified information, needs a CMMC Status of Level 1 (Self). The obligation typically arrives through a flow-down clause in a prime contractor's paperwork rather than through any direct dealing with the government.
More stories
The month CMMC Level 2 was suspended and I kept the half I sign myself, at 69K MRR
A composite founder diary. The July 2026 suspension of CMMC Phase II cancelled the certification a third party performs on you and left the self-assessment you sign yourself, along with a contract clause whose own deadline had passed 3,116 days earlier.
The month FedRAMP turned out to have an expiry date at 77K MRR
A composite founder diary. Everyone treats FedRAMP as a property of your product. In September 2026 I found that only the buying agency may decide whether it applies, and that every section of the FedRAMP Authorization Act carries a note repealing itself on 23 December 2027.
The month my bank was allowed not to read the name, at 82K MRR
A composite founder diary at 82K MRR. When a payment order names one person and numbers another, the receiving bank may pay on the number and need not check the name. The escape the statute gives a non bank originator is deleted by a signature, and the right to chase the stranger follows the loss.