CMMC Level 1: What Ohio Suppliers Actually Need
If your company sells to a prime defense contractor, or to anyone who does, you have probably received an email in the last year asking about CMMC. For most Ohio suppliers the email arrives with no explanation, a deadline, and the implication that something expensive is now required.
Usually it is not. Most small suppliers fall under CMMC Level 1, which is a self-assessment against fifteen basic requirements. It is not an audit, there is no certification body, and it is not a six-figure project. The trouble is that Level 1 gets described using the same vocabulary as Level 2, which is a serious undertaking, and the confusion costs people either money they did not need to spend or a contract they did not know they were about to fail.
Here is the practical version.
First: which level actually applies to you
The dividing line is the kind of government information you handle.
Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Delivery schedules, purchase orders, statements of work. If you hold FCI and nothing more sensitive, you are Level 1.
Controlled Unclassified Information (CUI) is a defined category with specific markings: technical drawings, specifications, and similar. Handling CUI puts you at Level 2, which is a materially larger obligation.
A large share of small Ohio machine shops, fabricators, and component suppliers hold FCI only. If nobody has ever sent you documents marked CUI, that is a strong signal, though it is worth confirming with your prime rather than assuming.
What changed in July 2026, and what did not
This is where a lot of current confusion comes from, so it is worth stating precisely.
On July 13, 2026, the transition to Phase 2 was paused. The pause covers outside assessments: Level 2 by an authorized third-party assessor (C3PAO), and Level 3 by DIBCAC, the Defense Contract Management Agency’s assessment center. While it lasts, DoD may not designate either one for new requirements. An existing contract that already carries one is to be modified to remove it; until then, the contract as awarded still contains it. DoD revised its contracting rules to carry out the pause, and a later revision dated September 3, 2026 repeats the same CMMC direction word for word. None of it touched Level 1.
Level 1 has always been a self-assessment, and it remains fully in force in contracts. Phase 1 began November 10, 2025. It was scheduled to give way to Phase 2 on November 10, 2026, but that transition is exactly what the July pause suspended, so for now Phase 1 continues with no announced end date, and applicable contracts still require Level 1 (Self) or Level 2 (Self) before award. During the pause, the only CMMC levels DoD may designate for new requirements are Level 1 (Self) and Level 2 (Self).
So if you heard “CMMC got delayed” and concluded there was nothing to do, that conclusion is wrong for Level 1 suppliers. If anything, the pause has made it easier to overlook an obligation that is still live.
The fifteen requirements
CMMC Level 1 maps to the fifteen basic safeguarding requirements in FAR clause 52.204-21. Since February 2026, DoD has written contracts under the FAR overhaul, a rewrite of the Federal Acquisition Regulation, the rulebook for federal contracts. Where federal contract information may pass through a contractor’s systems, those contracts carry the same fifteen, word for word, as FAR 52.240-93. The fifteen are genuinely basic. Grouped by what they actually ask you to do:
Control who gets in
- Limit system access to authorized users and devices
- Limit what those users can do to what their role requires
- Verify and control connections to external systems
- Control information posted publicly
Know who did what
- Identify users and devices
- Authenticate them before granting access
Handle media safely
- Sanitize or destroy media containing FCI before you dispose of it or reuse it: drives, laptops, USB media, and the hard drives inside leased copiers and multifunction printers
Protect the physical space
- Limit physical access to systems and equipment
- Escort visitors, keep physical access logs, and control keys, badges, and fobs
Protect the network
- Monitor and control communications at system boundaries
- Separate publicly accessible systems from internal ones
Keep systems healthy
- Identify and correct flaws in a timely way
- Protect against malicious code
- Keep malicious-code protection updated
- Scan periodically, and scan external files as they arrive
Read that list again with your own shop in mind. Most companies already do a majority of it. What they usually lack is the documentation proving the control exists.
What the self-assessment actually involves
Three steps, and each is more procedural than technical.
- Assess yourself against all fifteen requirements. Pass or fail, per requirement. There is no partial credit at Level 1 and no plan-of-action mechanism to defer a failing item. You either meet it or you do not.
- Submit the results in SPRS, the Supplier Performance Risk System. This is the government’s record that you did it.
- Have a named senior official affirm continuous compliance. A real person attaches their name to the claim.
Then repeat annually.
That third step deserves attention. Affirmation is a personal attestation by a named official, which means overstating your posture is a representation to the federal government. Treat the assessment honestly for that reason alone.
The failures we would expect to see in a small shop
If you self-assess candidly, these are the requirements most likely to come back as “no”:
Physical access logs and visitor escorting. Plenty of shops have a door that locks and a visitor who signs in on a clipboard that nobody reviews. The requirement asks you to maintain logs and actually escort. This is usually a process fix, not a purchase.
Limiting access by role. Small companies often give everyone access to everything because it is simpler. The requirement wants access limited to what a role needs.
Controlling external connections. Personal laptops, an employee’s home machine used for quoting, a vendor with a remote-access tool from a previous project.
Timely flaw remediation. “Timely” is not defined, which means you need to define it and then actually follow your own definition. An undefined standard is a failing one.
Separating public systems. A shop network where the guest Wi-Fi and the machine network are the same network fails this.
Media sanitization. The classic miss. Traded-in laptops, retired drives, USB sticks in a drawer, and, the one almost nobody thinks about, the hard drive inside a leased copier that goes back to the vendor at end of term with years of scanned documents on it. This is a process fix rather than a purchase, which is why it belongs on this list.
What this should cost
Level 1 is not a large project for most small suppliers, and anyone quoting you as though it were Level 2 is either misreading your situation or selling past it.
The honest breakdown is usually: some hours of assessment and documentation, a small number of genuine gaps to close, and then an annual cadence to keep it current. The recurring cost is mostly discipline, not licensing.
Where it does get expensive is when a supplier discovers mid-bid that they need Level 2 after all, or when documentation has to be reconstructed from memory under deadline pressure. Both are avoidable by starting before a contract depends on it.
A reasonable order of operations
- Confirm with your prime whether you handle FCI only, or CUI. This determines everything else.
- Work the fifteen requirements honestly, marking each pass or fail.
- Fix the failures, starting with the ones that are process rather than technology.
- Write down what you did, with dates. The documentation is the deliverable.
- Submit in SPRS and have your senior official affirm.
- Put a recurring annual reminder in the calendar, because this is not a one-time exercise.
Where we fit
Compliance work is what our virtual CISO service is built around, and CMMC is one of the frameworks it covers alongside SOC 2 and ISO 27001. For a Level 1 supplier that usually looks like a structured gap assessment, help closing the handful of real failures, and setting up the documentation so next year’s affirmation is a review rather than a scramble.
CMMC is rarely the only thing on the list. If the same plant also runs controllers that will never take another patch, or an office network sharing a broadcast domain with the line, what we do for Columbus manufacturers covers how that work sits alongside the compliance side.
If you are not sure which level applies to you, that is the right first question and it is a short conversation. Tell us what your prime has asked for and we will tell you honestly whether this is a small project or a real one.
Sources
- DoW CIO: About CMMC
- DoW CIO memo suspending CMMC Phase 2 (July 13, 2026)
- DoW acquisition memo implementing the suspension (July 13, 2026)
- DoD Class Deviation 2026-O0025, Revision 3 (September 3, 2026)
- 32 CFR Part 170: the CMMC Program rule
- FAR overhaul Part 52, including clause 52.240-93
- CMMC Level 1 Self-Assessment Guide (2026)
- CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2
Requirements and timelines described here reflect published guidance as of September 12, 2026. CMMC implementation has changed repeatedly; verify current status against your contract and your contracting officer before relying on any deadline.
Questions this post answers
How do I know if my company needs CMMC Level 1 or Level 2?
Your CMMC level depends on the government information you handle. If you hold only Federal Contract Information (FCI), like purchase orders and delivery schedules, you are Level 1. If you handle Controlled Unclassified Information (CUI), such as marked technical drawings, you are Level 2, a much larger obligation. If nobody has ever sent you documents marked CUI, that is a strong sign you hold FCI only. Confirm it with your prime contractor. TTS Cyber is not a law firm; this is not legal advice.
Is CMMC Level 1 still required after the July 2026 pause?
The July 2026 pause did not touch CMMC Level 1. On July 13, 2026, the transition to CMMC Phase 2 was paused. The pause covers outside assessments: Level 2 by an authorized third-party assessor (C3PAO) and Level 3 by DIBCAC. Level 1 is a self-assessment, and it remains fully in force in contracts. This status reflects published guidance as of September 12, 2026, so check your contract and contracting officer before relying on any deadline. TTS Cyber is not a law firm; this is not legal advice.
Does CMMC Level 1 require an outside audit?
No. CMMC Level 1 is a self-assessment against fifteen basic requirements, with no audit and no certification body. You mark each requirement pass or fail, with no partial credit. You submit the results in SPRS, the Supplier Performance Risk System, and a named senior official affirms continuous compliance. Then you repeat it every year. Because a real person attaches their name, overstating your posture is a representation to the federal government. TTS Cyber is not a law firm; this is not legal advice.
What Your Cyber Insurance Renewal Is Actually Asking For
MFA, EDR, tested backups: what each renewal question really means, what evidence underwriters now want, and why answering optimistically can cost you…