Overview
If you provide security assessments, monitoring, vulnerability scanning, or compliance support to federal clients, your contracts, reports, findings, and program correspondence are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation for your own systems.
Cybersecurity is the trickiest vertical to scope honestly. If your engagement only involves FCI, you are Level 1. But security work frequently reaches into CUI: if you store, process, or administer a client's CUI systems, run a security operations function over them, or receive marked CUI in your findings, that work is Level 2, and your relevant environment is in scope for that client's Level 2 assessment as an External Service Provider.
The disciplined answer is to scope every engagement up front, keep FCI only work at Level 1, and treat any CUI touching engagement as Level 2 with a controlled enclave. Selling security is not a reason to be sloppy about your own.
Typical contracts you'll see
- Security assessments and audits for federal offices that handle FCI
- Vulnerability scanning and monitoring for FCI only environments
- Compliance and policy support engagements
- Subcontracts to a cybersecurity or IT prime where no CUI is flowed down
- Set aside security services contracts (8(a), HUBZone, SDVOSB)
What FCI actually looks like for you
Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.
Common pitfalls in this industry
- Assuming all security work is Level 2, when FCI only assessment and advisory work is Level 1.
- Missing the moment you store or administer a client's CUI, which makes your environment part of their Level 2 scope.
- Holding client findings, credentials, and scan data under shared logins, which fails FAR 52.204-21 (b)(1)(i) and (ii).
- Storing sensitive client reports in a consumer cloud drive open to the whole team, which fails (b)(1)(iii).
- Leaving testing and management tooling on weak or shared credentials.
- Letting the annual SPRS affirmation lapse while advising clients to keep theirs current.
Your Level 1 action plan
- 01Scope each engagement: FCI only or does it involve client CUI or CUI systems. Confirm in writing.
- 02Keep FCI only work at Level 1 and place any CUI touching work into a documented Level 2 boundary, recognizing your External Service Provider role.
- 03Give every consultant a named account with MFA and protect testing and management tooling with least privilege.
- 04Set report and findings access to least privilege so only the engagement team can read client data.
- 05Encrypt every laptop and protect remote access, since your tooling can reach many clients at once.
- 06Write a one to two page boundary description naming the systems that hold federal FCI and how CUI work is kept separate.
- 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.
Most common NAICS codes
Use these when searching SAM.gov, filing for set-asides, or checking size standards.
- 541519Other Computer Related Services
- 541512Computer Systems Design Services
- 541690Other Scientific & Technical Consulting Services
- 561621Security Systems Services (except Locksmiths)
- 541611Administrative Management & General Management Consulting Services
Frequently asked questions
Q.We do cybersecurity work, so are we automatically Level 2?
No. The tier depends on the data, not the field. If your federal engagement only involves Federal Contract Information, you are Level 1. You reach Level 2 when you store, process, or administer a client's marked CUI or CUI systems. Many security firms run Level 1 for FCI only advisory work and Level 2 for engagements that touch CUI.
Q.We monitor a client's CUI systems. What does that make us?
When you administer or operate systems that store or process a client's CUI, your relevant environment is in scope for that client's Level 2 assessment as an External Service Provider, and you must meet the applicable NIST SP 800-171 requirements for that work. That is separate from your own FAR 52.204-21 Level 1 obligation for FCI only work.
Q.How do we keep our own house in order at Level 1?
Apply the 15 practices to the systems that hold federal FCI: named accounts, MFA, access limited to authorized users, antivirus, patching, and basic physical and boundary protection. Then post the affirmation in SPRS. Holding yourself to the standard you sell is the point.
Q.Do I need an SSP for the Level 1 part of my work?
No. Level 1 does not require a System Security Plan under 32 CFR Part 170. The Level 2 work does require an SSP and a NIST SP 800-171 assessment. For Level 1 you need evidence the 15 practices are met, a short boundary description, and a current list of authorized users.
Related clauses
Related terms
Read more in the Library
- CMMC Level 1: All 15 FAR Safeguarding Requirements Explained in Plain English (2026 Guide)Every CMMC Level 1 safeguarding requirement, in language a non-cybersecurity founder can act on — what each control means, what evidence satisfies it, and where teams trip up.
- CMMC Level 1: The Complete 2026 Guide for Small DoD ContractorsThe single page to read first. What CMMC Level 1 is, who it applies to, what's actually required, what it costs, and the fastest honest path through it in 2026.
- CMMC Level 1 vs Level 2: Which One Do You Actually Need? (2026 Plain-English Guide)Most small defense contractors are Level 1, not Level 2 — but the wrong answer here costs you a year and tens of thousands of dollars. Here's the single question that decides it.
- CMMC vs NIST 800-171: The Difference Most Small Contractors Get Wrong (2026)CMMC and NIST 800-171 are not the same thing. The difference decides whether your weekend is 5 days of paperwork or a $50K assessment.
- CMMC Level 1 Scoping — How to Draw the Boundary (Free Worksheet) — 2026Treating the whole company as in-scope doubles your work for no compliance benefit. Here's the right way to scope CMMC Level 1.
- CUI vs FCI: What's the Difference? (With 12 Real Examples) — 2026FCI triggers CMMC Level 1. CUI triggers CMMC Level 2. Mix them up and you'll either over-spend by $20k or under-comply on a federal contract.