CMMC Level 1 Self-Assessment Kit
CMMC Level 1 Self-Assessment Kit
Instant download. Editable files. One-organization licence. 5-day fit guarantee.
Couldn't load pickup availability
Not ready to buy? Get the free CMMC Level 1 self-assessment checklist
5-day fit guarantee. If it does not fit your CMMC program, ask for a refund within 5 days. Conditions.
Everything a small defense supplier needs to complete, document and affirm a CMMC Level 1 self-assessment honestly. Written for owners and office managers, not security specialists.
What you get
- Level 1 Self-Assessment Workbook (Excel): the 15 FAR 52.204-21 requirements quoted verbatim with plain-English explanations and typical evidence, all 59 assessment objectives with MET / NOT MET / N/A dropdowns, an automatic result, an SPRS worksheet, an annual affirmation checklist and a dashboard.
- Level 1 Security Policy and Procedures (Word, 7 pages): one consolidated small-business policy covering all 15 requirements, with simple procedures, roles, records and a requirement cross-reference.
- FCI Scoping and Asset Inventory (Excel): where FCI lives, in-scope people, technology and facilities, external systems and network boundary notes.
- Level 1 Records Pack (Excel): visitor log, access device register, media sanitization record, user account register with quarterly review, patch log and malware scan log.
- SPRS Submission and Affirmation Guide (PDF, 2 pages): plain-English steps for entering your result and affirming.
- Affirmation Memo Template (Word, 2 pages): an internal record of what your affirming official reviewed.
- Start Here guide (PDF): where things stand in 2026, steps and common mistakes.
How to use it
- Complete the scoping workbook (2 to 4 hours).
- Adopt the policy: fill placeholders, approve it and have staff sign (2 to 3 hours).
- Start the records pack now so you build real history.
- Self-assess every objective and fix anything NOT MET.
- Complete the SPRS worksheet and memo, then enter the result and affirm using the guide. Repeat every year.
Who it is for
Small defense suppliers (roughly 5 to 150 staff) whose contracts include FAR 52.204-21 or require CMMC Level 1, and the MSPs who support them. If you also handle CUI, Level 1 is not enough; you need the 110 NIST SP 800-171 requirements covered by our Level 2 products.
Good to know
- Instant download. Editable Excel (.xlsx) and Word (.docx), plus PDF guides. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.
- Licensed for use within one organization.
- NIST SP 800-171/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.
- These templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.
- 5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.

What every download includes
Built from the official NIST SP 800-171 Rev 2 and SP 800-171A text (US Government works). Templates help you prepare for a self-assessment or an assessment; they do not guarantee a passing score, a contract award or legal compliance.
Questions about CMMC Level 1 Self-Assessment Kit
What is in a CMMC Level 1 self-assessment?
You check each of the 15 FAR 52.204-21 requirements against its 59 assessment objectives, with evidence, and mark each MET or NOT MET. All must be met. You then enter the result in SPRS and a senior official affirms it. The workbook structures the assessment and the guide walks you through SPRS.
Why does the kit include a records pack?
Because evidence of controls running over time is more convincing than records created in one afternoon. The pack gives you a visitor log, access device register, media sanitization record, user account register with quarterly review, and patch and malware scan logs. Starting them early builds the history you need.
We use an outside IT company. Do we still need this?
Yes. The affirmation is your company's statement to the government, not your IT provider's. A common mistake is relying on the IT company without evidence. The kit helps you collect that evidence and record what your affirming official reviewed; your MSP can use the workbook with you.
Is this kit included in the Level 2 toolkit?
No. The Level 1 kit is a separate product for companies that handle FCI only. The Level 2 products cover the 110 NIST SP 800-171 requirements for companies that handle CUI. If you are unsure which applies, check your contract clauses and your prime's flowdown.
How will I receive the files?
A download button appears on the order confirmation page and the same link is emailed to you within a few minutes. Bundles arrive as one ZIP file.
Can I get a refund?
Yes. With our 5-day fit guarantee, if the files do not fit your CMMC compliance program you can ask for a full refund within 5 days of your order. It applies once per customer and organization, covers the whole product, and requires you to confirm you have deleted the files. We also refund non-delivery, defective files, wrong items and duplicate purchases within 30 days. Read the full refund policy.
Can I see the files before I buy?
Yes. The images above show real pages from the files, and the free CMMC Level 1 self-assessment checklist lets you check where you stand before you buy.
Can I use the templates with more than one company?
Each purchase is licensed to one organization. Consultants and groups need one licence per client or legal entity. See the licence agreement.
Templates that work with this one
Useful next steps for a CMMC and NIST SP 800-171 self-assessment.