CMMC Level 1 Made Clear and Manageable
One flat-fee engagement. Seven structured deliverables. Your SPRS self-assessment submitted. Your compliance owned — not rented.
$5,000 flat fee. 59 objectives. 4–8 weeks. Everything you need.
Understanding Level 1
What Is CMMC Level 1?
CMMC Level 1 is the baseline cybersecurity compliance tier for Department of Defense contractors who handle Federal Contract Information (FCI) — information provided by or generated for the government under a contract that is not intended for public release.
What You Get
7 Structured Deliverables. Complete Coverage.
Every deliverable is audit-ready, organized in your Cavalry GRC Tool, and designed to hold up to a DoD spot check.
Scope Definition
We help you identify exactly which systems, processes, contracts, and people fall under CMMC Level 1. Nothing gets over-scoped. Nothing that should be in scope gets missed.
Policy & Procedure Development
We draft or refine the documentation that supports every Level 1 practice — written in clear, audit-ready language that holds up to a DoD review.
Gap Analysis
We compare your current practices against all 59 assessment objectives and document exactly where each practice is Met or Not Met.
Evidence Guidance & Organization
We guide you on exactly what proof to gather (screenshots, logs, configurations) and help you organize it in your GRC Tool, so the right documentation lands in the right places and stays audit-ready.
SPRS Submission Support
We guide your team through the complete SPRS submission process, ensuring your self-assessment is accurate, defensible, and properly recorded.
Remediation Planning
Any gaps identified during the engagement get a prioritized remediation plan, with timelines and owners, so every practice reaches Met before your self-assessment is finalized.
Continuous Monitoring Guidance
We establish simple, practical routines your team can follow year-round to maintain your Level 1 posture — with built-in review dates for policies and procedures.
Pricing
Flat Fee. Full Scope. No Surprises.
Complete Level 1 Self-Assessment Package
Flat fee covering all 7 deliverables. No hourly rates. No scope creep. No unexpected invoices. You know exactly what you’re getting and what it costs before you sign anything.
- Scope definition
- Policy & procedure development
- Full gap analysis
- Evidence guidance & organization
- SPRS submission support
- Remediation planning
- Monitoring guidance
Common Questions
Frequently Asked Questions
Typically 4–8 weeks, depending on your organization’s size, existing documentation, and responsiveness during the evidence collection phase.
Level 1 works differently than Level 2 here: there is no POA&M option, and all 59 assessment objectives must be met before your self-assessment and affirmation are submitted. When we find gaps, we build a prioritized remediation plan with timelines and owners, and we do not consider the engagement complete until every objective is Met.
If your contracts involve FCI but not CUI, Level 1 is likely your requirement. If you’re handling CUI, you’re looking at Level 2. Not sure? Schedule a discovery call and we’ll determine scope together.
Yes — Compliance Cavalry serves defense contractors across the entire country. All engagements are fully remote-capable.
You own everything. All documentation, evidence, and compliance tracking lives in your GRC Tool. You maintain your posture independently using the continuous monitoring routines we establish. No forced retainers.
Ready to Get Level 1 Right the First Time?
Schedule a free discovery call and we’ll walk you through exactly what your Level 1 engagement looks like, what your timeline should be, and what we’ll need from your team.