CMMC Level 1 is 15 requirements you are expected to self-attest to — under penalty of the False Claims Act. Most contractors have no idea which ones they already fail. Find out in 90 seconds, before you sign something you cannot back up.
A number tells you nothing you can act on. This shows you the exact practices you miss, what each one means in plain English, and which order to fix them in — quick wins first, so you can show progress before your next contract review.
The 15 safeguarding requirements in FAR 52.204-21 map to 17 assessable practices across 6 domains: Access control, Identification & authentication, Media protection, Physical protection, System & communications protection, System & information integrity. We score the finer-grained version so you know exactly what to fix.
All 15 requirements in plain English, with a column for what counts as evidence for each one. Most people fill it out in about twenty minutes and know exactly where they stand. No call, no obligation — it is a one-page PDF.
The checklist tells you what the requirements are. This tells you which onesyou miss. Twelve questions, written for a business owner rather than an auditor, and a gap report that puts the fixes in order — quick wins first. Nothing is stored until you ask for the report.
Do you hold or bid on DoD contracts or subcontracts?
The questions contractors ask before they start.