Integrators and managed-service firms usually pass the technical requirements comfortably and fail the documentation ones. Level 1 does not ask whether you are competent — it asks whether you can produce evidence for 15 specific requirements when someone asks.
FCI is the ordinary, non-public material the government or a prime hands you so you can perform the contract. It is not classified and it is not exotic. For IT and systems-integration firms, it usually looks like this:
You are bidding a federal task order and the solicitation asks for your safeguarding posture as a submission requirement. That is the moment this stops being theoretical.
Three requirements this trade tends to miss — not because the work is hard, but because nobody was ever asked to write it down.
The assessment scores all 17 assessable practices, not just these three. These are simply the ones that come up most often.
All 15 requirements in plain English, with a column for what counts as evidence for each one. Most people fill it out in about twenty minutes and know exactly where they stand. No call, no obligation — it is a one-page PDF.
The checklist tells you what the requirements are. This tells you which onesyou miss. Twelve questions, written for a business owner rather than an auditor, and a gap report that puts the fixes in order — quick wins first. Nothing is stored until you ask for the report.
Do you hold or bid on DoD contracts or subcontracts?
Same assessment, written for a different shop floor.