← Custodia
CMMC Level 1 · Research & development

CMMC Level 1 for research, development & testing labs

Small R&D firms and testing laboratories on federal research contracts often start at CMMC Level 1. Contracts, progress reports, and unmarked research data are Federal Contract Information (FCI). Because research can drift into marked or export controlled data, scoping matters: marked Controlled Unclassified Information (CUI) moves that work to Level 2.

Overview

If you perform research, development, or testing for federal agencies and labs, your contracts, progress reports, test data, and program correspondence are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation. SBIR and STTR Phase I work is almost always Level 1.

Research and development sits near the CUI line because results, test data, and technical approaches can become marked or export controlled, especially in later phases or hardware programs. Work that involves only FCI is Level 1. When the agency marks deliverables as CUI under DFARS 252.204-7012, that work is Level 2.

R&D firms and labs run data and analysis systems, lab instruments and workstations, and an email tenant. Level 1 covers the systems that hold federal research FCI, which means named accounts, MFA, controlled access, and a clear boundary.

Typical contracts you'll see

  • Federal research and development contracts and grants with FAR clauses
  • SBIR and STTR awards (Phase I is almost always Level 1)
  • Testing and evaluation laboratory contracts
  • Subcontracts under a research or engineering prime
  • Agency lab support and analysis task orders

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Contracts, award documents, and modifications
Progress reports and final reports that are not marked CUI
Test data and analysis files produced under the contract
Schedules, status briefings, and correspondence
Invoices and acceptance documents

Common pitfalls in this industry

  • Running research out of personal email and consumer drives, which fails FAR 52.204-21 (b)(1)(i) and (iii).
  • Sharing lab and analysis system logins across the team, which fails (b)(1)(i) and (ii).
  • Storing research data on an open share readable by everyone, which fails (b)(1)(iii).
  • Continuing at Level 1 after the agency marks deliverables as CUI, which is Level 2.
  • Publishing results or technical approaches before the agency clears them, which fails (b)(1)(iv).
  • Letting the annual SPRS affirmation lapse.

Your Level 1 action plan

  1. 01Scope each award: FCI only or will deliverables be marked CUI. Confirm in writing, and re-scope before later phases.
  2. 02Keep FCI only research at Level 1 and place any CUI marked work into a controlled enclave.
  3. 03Move federal research onto a paid Microsoft 365 or Google Workspace tenant with MFA enforced.
  4. 04Set data and analysis access to least privilege and give every researcher a named account.
  5. 05Encrypt workstations and laptops used for research and protect lab systems and remote access with MFA.
  6. 06Write a one to two page boundary description naming the systems that hold research FCI and how CUI work is kept separate.
  7. 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 541715R&D in the Physical, Engineering & Life Sciences (except Biotechnology & Nanotechnology)
  • 541714R&D in Biotechnology (except Nanobiotechnology)
  • 541713R&D in Nanotechnology
  • 541380Testing Laboratories
  • 541720R&D in the Social Sciences & Humanities

Frequently asked questions

Q.We won a federal research contract. Are we Level 1 or Level 2?

If the work involves only Federal Contract Information, you are Level 1, and SBIR or STTR Phase I work is almost always Level 1. You reach Level 2 when the agency marks deliverables as CUI under DFARS 252.204-7012, which is more common in later phases and hardware programs. Scope each award up front and re-scope before later phases.

Q.Our research is unclassified and open. Do we still need CMMC?

Yes. Unclassified is not the same as unrestricted. The award documents, your reports, your invoices, and your correspondence are Federal Contract Information regardless of how open the research is, and FAR 52.204-21 applies to the systems that process them.

Q.How do I know when research data becomes CUI?

CUI is explicitly marked by the agency with a CUI banner and category, or flows from a -7012 marked package. Export controlled data is often treated as CUI for safeguarding. If you expect markings but do not see them, ask the contracting officer rather than guessing.

Q.Do I need an SSP for the Level 1 part of my work?

No. Level 1 does not require a System Security Plan under 32 CFR Part 170. The Level 2 work does. For Level 1 you need evidence the 15 practices are met, a short boundary description, and a current list of authorized users.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
IT services & managed service providers (MSPs)
Read the it services & msps guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Management & professional services consultants
Read the professional consulting guide →
Staffing & workforce services firms
Read the staffing services guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Engineering services firms
Read the engineering services guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Industrial machinery & equipment suppliers
Read the industrial equipment guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Medical device & instrument manufacturers
Read the medical devices guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)