← Custodia
CMMC Level 1 · Medical devices

CMMC Level 1 for medical device & instrument manufacturers

Manufacturers of medical instruments, devices, and surgical appliances supplying the VA and military health systems sit at CMMC Level 1 for the common case. Contracts, specifications, drawings, and delivery records are Federal Contract Information (FCI). Patient health information carries separate privacy obligations, and CUI under a DFARS 252.204-7012 flow-down is uncommon for device supply.

Overview

If you manufacture medical instruments, devices, or surgical appliances for the VA, military treatment facilities, or other federal health buyers, your contracts, item specifications, drawings, and delivery records are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation.

Device supply is usually Level 1. The data you hold for a typical order, the contract, the specification, the drawing, the delivery record, is FCI, not CUI. Protected health information, where it appears, brings its own privacy obligations that sit alongside CMMC rather than changing the CMMC tier.

Device makers run an ERP or quality system, engineering and production stations, and an email tenant. Level 1 covers the systems that hold federal contract and design information, which means named accounts, MFA, controlled access, and a clear boundary.

Typical contracts you'll see

  • Medical and surgical device contracts for the VA and military treatment facilities
  • Subcontracts to a medical device prime
  • Instrument and equipment supply under federal supply schedules
  • DLA Troop Support medical materiel buys
  • Set aside medical device contracts (8(a), WOSB, SDVOSB)

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Contracts, delivery orders, and modifications
Device specifications, drawings, and bills of material that are not marked CUI
Quality records, first article inspections, and acceptance documents
Delivery schedules, packing slips, and DD-250 acceptance documents
Correspondence with the contracting officer and ordering facility

Common pitfalls in this industry

  • Storing device drawings and specs on an open share readable by everyone, which fails FAR 52.204-21 (b)(1)(iii).
  • Running the quality or ERP system on a shared login, which fails (b)(1)(i) and (ii).
  • Emailing contracts and specs from personal accounts, which fails (b)(1)(iii).
  • Confusing privacy obligations for health data with CMMC scope, and addressing neither.
  • Assuming device supply is too simple to be in scope. The FCI in the contracts and drawings is what triggers CMMC.
  • Letting the annual SPRS affirmation lapse.

Your Level 1 action plan

  1. 01Inventory the systems that hold federal FCI: ERP or quality system, engineering and production stations, email, and shared drives.
  2. 02Move contract and design exchange onto a paid Microsoft 365 or Google Workspace tenant with MFA enforced.
  3. 03Give each engineer and order user a named account and set drawing and contract access to least privilege.
  4. 04Keep any protected health information handling aligned with its own privacy obligations, separate from but alongside CMMC.
  5. 05Separate program systems from public web browsing and the company website.
  6. 06Write a short boundary description naming the systems that hold federal contract and design information.
  7. 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 339112Surgical & Medical Instrument Manufacturing
  • 339113Surgical Appliance & Supplies Manufacturing
  • 334510Electromedical & Electrotherapeutic Apparatus Manufacturing
  • 339114Dental Equipment & Supplies Manufacturing
  • 423450Medical, Dental & Hospital Equipment & Supplies Merchant Wholesalers

Frequently asked questions

Q.We make medical instruments for the VA. Do we need CMMC?

Yes, once you hold a federal contract or subcontract. The contracts, specifications, drawings, and delivery records are Federal Contract Information, and FAR 52.204-21 applies to the systems that hold them. That means a Level 1 self-assessment and an annual SPRS affirmation.

Q.Does handling patient or health data change my CMMC level?

Not by itself. Protected health information carries its own privacy obligations that are separate from CMMC. CMMC Level 1 covers the systems that hold Federal Contract Information. The same basic protections, named accounts, MFA, access control, and encryption, help satisfy both.

Q.Could a device contract be Level 2?

It is uncommon. You would reach Level 2 only if the contract flowed down DFARS 252.204-7012 and you received marked Controlled Unclassified Information, such as controlled technical data for a defense specific device. Ordinary medical device supply is Level 1.

Q.Do I need an SSP at Level 1?

No. Level 1 does not require a System Security Plan under 32 CFR Part 170. You need evidence the 15 practices are met for the systems that hold FCI, plus a short boundary description and a current list of authorized users.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
IT services & managed service providers (MSPs)
Read the it services & msps guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Management & professional services consultants
Read the professional consulting guide →
Staffing & workforce services firms
Read the staffing services guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Engineering services firms
Read the engineering services guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Industrial machinery & equipment suppliers
Read the industrial equipment guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Research, development & testing labs
Read the research & development guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)