← Custodia
CMMC Level 1 · IT services & MSPs

CMMC Level 1 for it services & managed service providers (msps)

Small IT services firms and managed service providers that support federal offices or sit under a DoD prime usually start at CMMC Level 1. Help desk tickets, asset inventories, network diagrams, and contract paperwork are Federal Contract Information (FCI). The line to watch is the moment you store, process, or administer systems that hold marked Controlled Unclassified Information (CUI), because that pushes you to Level 2 and into External Service Provider territory.

Overview

If you run a small IT shop or MSP and your federal work is break/fix, help desk, hardware refresh, cabling, or basic systems support, the information you touch (tickets, asset lists, contract POs, network drawings) is Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment, affirmed annually in SPRS by a senior official.

The hard part for IT firms is honest scoping. The instant you administer, store, or process a client's marked CUI (for example, you manage the file server where a manufacturer keeps DFARS 252.204-7012 technical data), you are no longer Level 1 for that work. You become a Level 2 obligation and, in CMMC terms, an External Service Provider whose own environment is in your client's assessment scope.

The practical answer for most small MSPs is to keep the federal book of business clean: serve FCI only clients at Level 1, and carve a separate, documented enclave (often GCC High) for any client whose data is marked CUI. Knowing which side of that line each contract sits on is the single most valuable thing you can document.

Typical contracts you'll see

  • Help desk, desktop support, and managed IT task orders for small federal offices
  • Hardware, peripherals, and network gear resale under GSA Schedule or SEWP
  • Structured cabling and network installation on federal facilities
  • IT subcontracts to a systems integration prime where no CUI is flowed down
  • Microsoft 365 or Google Workspace setup and administration for FCI only clients

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Help desk tickets, asset inventories, and license counts tied to a federal contract
Network diagrams, IP schemes, and configuration baselines that are not marked CUI
Purchase orders, statements of work, and invoices from the agency or prime
Service level reports and performance metrics submitted to the contracting officer
User rosters and onboarding lists for the systems you support

Common pitfalls in this industry

  • Assuming all federal IT work is Level 2. Plenty of help desk and hardware work is FCI only and sits at Level 1.
  • Missing the moment you cross into CUI. Administering a client system that stores marked CUI makes your own shop part of that client's Level 2 scope.
  • Running client work out of a shared technician login with no per person account, which fails FAR 52.204-21 (b)(1)(i) and (ii).
  • Storing client network documentation and credentials in a personal password manager or a consumer cloud drive.
  • Reusing one global admin account across the whole team instead of named, MFA protected admin identities.
  • Skipping the annual SPRS affirmation, which DoD now treats as False Claims Act exposure under the Civil Cyber-Fraud Initiative.

Your Level 1 action plan

  1. 01Classify every federal contract: FCI only or CUI involved. Confirm in writing with each client and prime whether any marked CUI is in play.
  2. 02Separate the two books of business. Keep FCI only clients at Level 1 and stand up a documented CUI enclave for anything marked.
  3. 03Give every technician a named company account with MFA, and replace shared admin logins with individual privileged identities.
  4. 04Inventory the systems that hold federal FCI: your ticketing tool, your documentation platform, your email tenant, and your remote management tooling.
  5. 05Lock down remote access (RMM, VPN, jump hosts) with MFA and least privilege, since that is the path an attacker uses to reach every client at once.
  6. 06Write a one to two page boundary description naming the systems that touch FCI and how they are kept separate from public facing and personal systems.
  7. 07Run the 15 FAR 52.204-21 practices, document the evidence, then have a senior official post and affirm the score in SPRS and calendar the annual re-affirmation.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 541512Computer Systems Design Services
  • 541513Computer Facilities Management Services
  • 541519Other Computer Related Services
  • 541511Custom Computer Programming Services
  • 517311Wired Telecommunications Carriers
  • 423430Computer & Peripheral Equipment Merchant Wholesalers

Frequently asked questions

Q.I run an MSP for a defense manufacturer. Am I Level 1 or Level 2?

It depends on what data lives on the systems you manage. If your client only handles FCI and you support their general IT, you are Level 1. The moment your client stores marked CUI under DFARS 252.204-7012 on a system you administer, store, or back up, that work is Level 2, and your own environment becomes part of your client's assessment scope as an External Service Provider. Many MSPs run a clean Level 1 practice for FCI only clients and a separate enclave for CUI clients.

Q.Does selling hardware to a federal office require CMMC?

If you hold a federal contract or subcontract to supply and support that hardware, the contract paperwork, POs, and any asset or user information are FCI, so FAR 52.204-21 and a Level 1 self-assessment apply. Pure catalog resale with no ongoing access to federal information is a lighter footprint, but the safe assumption once you have a contract is Level 1.

Q.What is an External Service Provider and does it apply to my IT firm?

An External Service Provider (ESP) is an outside company that handles a contractor's covered information or security functions. If you manage systems that process or store a client's CUI, the CMMC rules treat your relevant environment as in scope for that client's Level 2 assessment. For Level 1 FCI only work there is no formal ESP assessment, but you still owe your own FAR 52.204-21 self-assessment.

Q.Do I need an SSP for Level 1 as an IT provider?

No. The 32 CFR Part 170 rule does not require a System Security Plan for Level 1. You need evidence that each of the 15 practices is met across the systems that touch FCI. A short boundary description plus a current list of authorized users and admins is enough.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Management & professional services consultants
Read the professional consulting guide →
Staffing & workforce services firms
Read the staffing services guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Engineering services firms
Read the engineering services guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Industrial machinery & equipment suppliers
Read the industrial equipment guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Medical device & instrument manufacturers
Read the medical devices guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Research, development & testing labs
Read the research & development guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)