Tuesday Journey | Beginner Path · Compliance Lead
Level 1 Looks Easy. That’s the Trap.
Fifteen controls instead of a hundred and ten, and no outside assessor. Level 1 is genuinely simpler than Level 2, but the weight behind the signature is exactly the same.
Level 1 is supposed to be the easy one. Fifteen controls instead of a hundred and ten, a self-assessment instead of an outside auditor. So here’s the question I keep coming back to: if it’s so easy, why do good companies still get into trouble with it?
Because they do. Every so often I hear about another capable, well-run contractor that did what it was told, self-assessed, filed the affirmation, felt good about it, and still ended up somewhere it never expected. Fifteen controls. How does that go wrong?
The answer isn’t in the controls. It’s in what the signature underneath them actually means.
The moment it stopped being an IT task
When I owned our CMMC program as the compliance lead, the affirmation was the moment that changed how I thought about all of it. Up to that point it had felt like a technical project: evidence, screenshots, policies, checklists. Then it came time to actually sign, to put a name behind a statement to the federal government that said, plainly, this is true. That is a different kind of moment. It stops being an IT deliverable and becomes a question of whether the organization is ready to stand behind what it’s claiming.
I think about a company here, a composite of patterns that show up again and again. A thirty-person shop, a couple-million-dollar subcontract. Two years earlier someone had told them, you’re Level 1, fifteen controls, easy. So they self-assessed, the owner signed, and everyone moved on. Eighteen months later a former employee pointed out that three of those controls had gaps on the day they signed, and there was an email trail showing the company had known. The controls were never the problem. The signature was. They had put their name behind something the record didn’t support, and it cost them far more than getting it right would have.
The mistake isn’t carelessness
Here’s the mistake, and it isn’t usually carelessness. It’s misunderstanding what the affirmation actually represents. It happens when the affirmation gets treated like paperwork, a form to complete and file, instead of what it really is: a business decision, a statement the whole organization has to be willing to stand behind.
Level 1 has fewer controls, not less accountability. It is genuinely simpler than Level 2: fifteen items instead of a hundred and ten, and no outside assessor. But the weight behind the signature is exactly the same. Fewer things to check. The same responsibility when you put your name to them.
A new stop every Tuesday and Thursday.
Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.
This is a leadership question, not a legal one
A Level 1 self-assessment deserves the same discipline as any other decision the business makes, because your signature represents the organization, not the IT department.
The danger in Level 1 was never the fifteen controls. It’s that “simpler” quietly gets read as “lower stakes,” and the whole thing gets handed down to whoever runs IT and then filed away. Remember, no one outside ever checks your work at Level 1. There’s no C3PAO walking your floor. That isn’t a break. It means the discipline has to come from inside, from the business deciding it’s ready, not from an assessor forcing the question.
Yes, there’s a legal reality underneath all of this. A false affirmation is treated as a false claim to the government, and the penalties are serious enough that I don’t need to dramatize them. But executives don’t lie awake worrying about the finer points of the False Claims Act. They worry about something simpler and more human: putting their name on something they can’t defend. That’s the real risk here. It’s also the one you can do something about.
Who actually owns the affirmation
One thing I learned during certification is that the affirmation was never just an IT milestone. It was a business decision. IT gathered the evidence. Compliance validated it. Leadership decided whether the organization was ready to stand behind it. That’s exactly how it should work: the business decides, IT enforces. When the affirmation gets treated as a form for IT to submit, that structure quietly breaks, and the accountability ends up sitting with someone who was never meant to carry it.
This is very much within reach
Now the part I most want you to hear, because the point of all this is not to scare you. Level 1 is absolutely achievable, and for most companies it’s closer than it feels. The fifteen controls are basic hygiene. Limit who has access. Know who your users are. Lock screens when people walk away. Wipe old drives before they leave the building. You almost certainly do most of this already. The work is usually proving it, not inventing it from scratch.
When our team went through certification, what protected us wasn’t a big budget or a clever tool. It was being able to show our work and being honest about what was and wasn’t finished yet. That is available to a company of any size. The companies that get there aren’t the ones with the most security staff or the deepest pockets. They’re the ones whose leadership treats the decision as theirs to own. The ones that struggle usually treated it as a formality and pushed it down to whoever had a spare afternoon.
So if you’re reading this and feeling behind, you’re probably not as far off as you think. You don’t need everything perfect before you can move. You need to know the truth about where you stand, and be willing to stand behind it. That is a starting point any company can reach, and it’s the same starting point the successful ones used.
What I would do if I were in your seat
Treat the affirmation as a decision the business makes
Not a form IT files. Put it on a leader’s desk with the evidence in front of them, and let them decide the company is ready.
Do an honest one-hour evidence check against the fifteen controls
For each one, can we show it’s true today? Not planned, not in progress. Today.
Make sure the person signing can speak for the company
And knows that’s what they’re doing. At a small shop that’s the owner or an officer, not the IT lead, and not you by default because you prepared it.
If a control isn’t there yet, don’t paper over it
Note it honestly and fix it. An honest gap you’re working on is defensible. A signature over a gap you hid is not.
Level 1 really is the simpler path. It was just never the lower-stakes one. Fewer controls, the same accountability, and a signature that speaks for everyone in the building.
So here’s the question I’d sit with before the next affirmation comes due: if our CEO signed it tomorrow, would I be comfortable standing behind every answer in it? If you can say yes without flinching, you’re in good shape. If you hesitate, that isn’t a reason to panic. It’s simply where the work is, and now you know where to start.
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
A few sources
- FAR 52.240-93 (formerly FAR 52.204-21): the fifteen basic safeguarding requirements and the Level 1 self-assessment
- 32 CFR Part 170: the CMMC Program, the annual affirmation, and the Affirming Official’s role
- False Claims Act, 31 U.S.C. §§ 3729-3733, and the DOJ Civil Cyber-Fraud Initiative (October 2021): the enforcement behind a false affirmation