← Custodia
CMMC Level 1 · Staffing services

CMMC Level 1 for staffing & workforce services firms

Staffing and staff augmentation firms placing workers on federal contracts start at CMMC Level 1 for their own environment. Contracts, candidate and placement records, timesheets, and invoices are Federal Contract Information (FCI). Where placed staff handle a client's CUI, that obligation sits in the client's scope, while the staffing firm's own systems usually remain Level 1.

Overview

If you place workers on federal contracts through staff augmentation, temporary help, or workforce services, your task orders, candidate and placement records, timesheets, labor qualification documents, and invoices are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation for your own systems.

A common point of confusion: if your placed employee works inside a client's Level 2 CUI environment, that CUI obligation lives with the client's systems, not automatically with your back office. Your own staffing systems, which hold contracts, resumes, and timesheets, are usually Level 1 unless you pull marked CUI into them.

Staffing firms run applicant tracking systems, payroll, and a lot of personal data. Level 1 covers the FCI in your federal book of business, and the personal data brings its own privacy obligations on top, but the CMMC scope is the systems that hold federal contract information.

Typical contracts you'll see

  • Staff augmentation task orders for federal agencies and primes
  • Temporary and contract to hire placements on federal programs
  • Workforce and surge support contracts
  • Recruiting and placement subcontracts under a services prime
  • Set aside staffing contracts (8(a), WOSB, SDVOSB, HUBZone)

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Task orders, modifications, and invoices tied to the staffing contract
Candidate submissions, resumes, and placement records for federal roles
Timesheets, labor category mappings, and rate documentation
Background and qualification records required by the contract
Correspondence with the contracting officer and the placing prime

Common pitfalls in this industry

  • Running recruiting and placement out of personal email and consumer drives, which fails FAR 52.204-21 (b)(1)(i) and (iii).
  • Giving every recruiter full access to all federal placement data instead of least privilege.
  • Storing resumes and timesheets for federal roles in an applicant tracking system with shared logins.
  • Assuming the client's CMMC level covers your back office. Your own FCI is your own obligation.
  • Pulling a client's marked CUI into your own systems without re-scoping to Level 2.
  • Letting the annual SPRS affirmation lapse.

Your Level 1 action plan

  1. 01Map your federal book of business and the systems that hold its FCI: applicant tracking, payroll, email, and shared drives.
  2. 02Move federal recruiting and placement onto a paid Microsoft 365 or Google Workspace tenant with MFA enforced.
  3. 03Give each recruiter a named account and scope access to only the placements they work.
  4. 04Confirm that no client CUI is being stored in your back office. If it is, scope that data as Level 2.
  5. 05Encrypt laptops and protect the applicant tracking and payroll systems with MFA and least privilege.
  6. 06Write a short boundary description naming the systems that hold federal FCI and who can access them.
  7. 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 561320Temporary Help Services
  • 561311Employment Placement Agencies
  • 561312Executive Search Services
  • 561330Professional Employer Organizations
  • 541612Human Resources Consulting Services

Frequently asked questions

Q.Our placed employees work in the client's secure environment. Are we Level 2?

Usually not for your own systems. When a placed worker handles a client's CUI inside the client's environment, that CUI obligation lives with the client's systems. Your staffing back office, which holds contracts, resumes, and timesheets, is typically Level 1, unless you also store or process that CUI yourself.

Q.Do staffing firms really need CMMC at all?

Yes, if you hold federal contracts or subcontracts. The contract paperwork, placement records, timesheets, and invoices are Federal Contract Information, and FAR 52.204-21 applies to the systems that hold them. That means a Level 1 self-assessment and an annual SPRS affirmation.

Q.We handle a lot of personal data. Does CMMC cover that?

CMMC Level 1 covers the systems that hold Federal Contract Information. Personal data carries its own privacy obligations under other laws, which are separate from CMMC. In practice the same basic protections, named accounts, MFA, access control, and encryption, help with both.

Q.Do I need an SSP for Level 1?

No. Level 1 does not require a System Security Plan under 32 CFR Part 170. You need evidence that the 15 practices are met for the systems that hold FCI, plus a short boundary description and a current list of authorized users.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
IT services & managed service providers (MSPs)
Read the it services & msps guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Management & professional services consultants
Read the professional consulting guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Engineering services firms
Read the engineering services guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Industrial machinery & equipment suppliers
Read the industrial equipment guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Medical device & instrument manufacturers
Read the medical devices guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Research, development & testing labs
Read the research & development guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)