← Custodia
CMMC Level 1 · Professional consulting

CMMC Level 1 for management & professional services consultants

Small management, program support, and professional services firms that consult for federal agencies usually start at CMMC Level 1. Contract documents, deliverables, schedules, and program correspondence are Federal Contract Information (FCI). You move to Level 2 only when you store, process, or transmit marked Controlled Unclassified Information (CUI) for the client.

Overview

If you provide management consulting, program and project support, administrative support, or analysis for federal agencies, your task orders, deliverables, schedules, meeting notes, and program correspondence are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation.

Professional services work stays at Level 1 as long as the information you hold is FCI. It becomes Level 2 when the agency gives you marked CUI to work with, or when you access or store CUI as part of the engagement, for example pulling controlled data into your own analysis environment.

Consulting firms tend to run on a single cloud tenant, a lot of documents, and staff working from anywhere. That is workable at Level 1, but it requires named accounts with MFA, controlled document sharing, and a clear boundary so a reviewer can see exactly where federal FCI lives.

Typical contracts you'll see

  • Management and program support task orders for civilian and defense agencies
  • Administrative and operational support services
  • Acquisition, financial, and analytic support contracts
  • Subcontracts under a professional services prime
  • 8(a), WOSB, SDVOSB, and HUBZone set asides for support services

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Task orders, modifications, and invoices
Deliverables, briefings, and reports prepared for the agency
Project schedules, status reports, and meeting minutes
Staffing rosters and labor qualification records tied to the contract
Correspondence with the contracting officer and program office

Common pitfalls in this industry

  • Running engagements out of personal email and consumer file sharing, which fails FAR 52.204-21 (b)(1)(i) and (iii).
  • Sharing deliverable folders with the whole company instead of the project team, which fails (b)(1)(iii).
  • Letting subcontractor consultants use personal, unencrypted laptops with no MFA.
  • Pulling marked CUI into the engagement without re-scoping to Level 2.
  • Publishing client work, logos, or award details before the agency clears them, which fails (b)(1)(iv).
  • Treating the SPRS affirmation as a one time task instead of an annual obligation by a senior official.

Your Level 1 action plan

  1. 01Decide, per engagement, whether you will ever hold marked CUI. If yes, scope that work as Level 2 with a controlled environment.
  2. 02Move all federal work onto a paid Microsoft 365 or Google Workspace tenant with MFA enforced on every account.
  3. 03Give each consultant a named account and set deliverable and document access to least privilege per project.
  4. 04Encrypt every laptop used for federal work and require a passcode on phones.
  5. 05Keep a short list of which projects, folders, and people touch federal FCI.
  6. 06Write a one page boundary description: which tenant, which folders, who has access, how it is separated from marketing and personal systems.
  7. 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 541611Administrative Management & General Management Consulting Services
  • 541618Other Management Consulting Services
  • 541612Human Resources Consulting Services
  • 541990All Other Professional, Scientific & Technical Services
  • 561110Office Administrative Services

Frequently asked questions

Q.We just write reports and give advice. Do we need CMMC?

Yes, once you hold a federal contract or subcontract. The task orders, your deliverables, your invoices, and your program correspondence are Federal Contract Information, and FAR 52.204-21 applies to the systems that hold them. The 15 practices are basic protections on your cloud tenant and laptops.

Q.When does a consulting engagement become Level 2?

When you store, process, or transmit CUI for the client, or the agency flows marked CUI under DFARS 252.204-7012 into your environment. Working only with FCI keeps you at Level 1. If a single engagement involves CUI, scope just that work as Level 2 and keep the rest of the firm at Level 1.

Q.Our consultants work from home and coffee shops. Is that allowed at Level 1?

Yes, if the systems are controlled. FAR 52.204-21 requires identified, authenticated users, access limited to authorized people, and basic protection of the systems. Remote work is fine when every consultant uses a named company account with MFA, an encrypted laptop, and controlled access to federal documents.

Q.Do I need an SSP for Level 1?

No. Level 1 does not require a System Security Plan under 32 CFR Part 170. You need evidence that each of the 15 practices is met across the systems that handle FCI, plus a short boundary description and a current list of authorized users.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
IT services & managed service providers (MSPs)
Read the it services & msps guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Staffing & workforce services firms
Read the staffing services guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Engineering services firms
Read the engineering services guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Industrial machinery & equipment suppliers
Read the industrial equipment guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Medical device & instrument manufacturers
Read the medical devices guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Research, development & testing labs
Read the research & development guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)