How Do I...?

Sell to the Government

Locations

Where We Are

Calendar

Events and Workshops

*

New DoD Level 1 CMMC Cybersecurity Rules Now in Contracts

Don’t Lose Out on Department of Defense Work 

Starting November 10th, the Department of Defense (DoD) has implemented new cybersecurity requirements that directly impact contractors across the Defense Industrial Base (DIB). Known as CMMC Level 1, these rules are now being integrated into DoD contracts, and the message is clear: if your company does not meet Level 1 standards, it will not be eligible to work on contracts that require them.

Who is Affected Now and in the Future?

CMMC Level 1 applies to 60%-70% of all DoD contractors, including prime contractors, subcontractors, and suppliers who handle Federal Contract Information (FCI). While some exemptions exist—such as companies selling Commercial-off-the-shelf (COTS) items without modification or contracts valued under $15,000—the majority of DIB organizations will need to comply. Looking ahead, adherence to these standards is expected to become increasingly critical as the DoD expands cybersecurity requirements across higher levels of CMMC, affecting more contracts and more suppliers.

Advanced CMMC Levels 2 and 3 will be phased in over 2026 and 2027 and require additional safeguards for companies that handle Controlled Unclassified Information (CUI). CUI is sensitive information that the U.S. federal government wants protected but that is not classified as Confidential, Secret, or Top Secret. In other words, it’s important information that could cause problems if it fell into the wrong hands, but it doesn’t rise to the level of classified procurements.

CUI can include a wide variety of data.

Common examples of CUI are: technical information or drawings for defense equipment or systems, contract information that includes sensitive business or pricing data, export-controlled information that has restrictions under ITAR or EAR regulations, critical infrastructure details that could impact operations if disclosed

Understanding CMMC Level 1 Requirements

CMMC Level 1 is designed to ensure basic cyber hygiene for protecting sensitive information. It consists of 17 fundamental security practices, including the use of unique user IDs, strong passwords, limiting system access, maintaining basic device configurations, and ensuring proper media handling. These practices expand into 59 specific controls that a company must address.

Compliance also requires an annual reaffirmation conducted by a senior company official, with results posted in the Supplier Performance Risk System (SPRS) so contracting officers and prime contractors can verify your status.

Steps to Achieve CMMC Level 1 Compliance

The journey to compliance begins with understanding whether your company handles Federal Contract Information (FCI). If it does, the next step is to identify all systems, emails, file shares, and design files that store, process, or transmit this information. Once the scope is established, companies must familiarize themselves with the specific requirements outlined in FAR 52.204-21.

Core domains include access control, identification and authentication, media protection, physical protection, system and communications protection, and system integrity.

Companies must document policies, configurations, access lists, and remediation steps for any gaps they identify. The final step is obtaining a senior official’s affirmation and entering the self-assessment into SPRS, completing the compliance process.

Timeline to Reach Compliance

While Level 1 is the least burdensome CMMC tier, achieving compliance still requires careful planning and documentation. For organizations with existing security measures, the process can take as little as 30 to 90 days. Small to medium-sized firms may require 4 to 8 weeks for assessment and SPRS entry, while companies that need significant new controls or cloud-based solutions should anticipate three to six months—or longer—to fully close gaps and document evidence.

Cohorts, Workshops, and Resources

Support for achieving CMMC Level 1 compliance is becoming widely available. Programs such as Washington APEX Accelerator provide guidance, workshops, and cohort-based learning opportunities to help contractors navigate requirements efficiently. Additional resources include industry guides on CMMC readiness, templates for documentation, and training sessions for affirming officials. These tools can accelerate compliance and reduce the risk of losing out on DoD contracts.

Conclusion

CMMC Level 1 is no longer a future concern—it is here, and the DoD is enforcing it through new contract requirements. Contractors who fail to meet these cybersecurity standards risk losing access to valuable work. By understanding the requirements, documenting processes, and leveraging available resources, businesses can secure compliance and maintain eligibility for contracts within the DIB. Acting now ensures you stay competitive in a landscape where cybersecurity is becoming a baseline expectation rather than an optional practice.

 

Resources

APEX Accelerator CMMC Cohorts

Project Spectrum

Get Latest News & Updates

News and announcements will be delivered straight to your inbox

Region 6 is hosted by the Thurston County Economic Development Council and serves Pierce County.

ABOUT THE THURSTON EDC

The Thurston Economic Development Council (EDC) is a private non-profit organization.  As the lead economic development organization in Thurston County our mission is to create a vital and sustainable economy throughout the county and region that supports the livelihood and values of our residents. We do this by:

·        Connecting local businesses with experts and resources that help them remain competitive

·        Creating and delivering strategic messages that attract new investment to our community

·        Working with our community partners to enhance our collective prosperity and encourage our economic future 

·        Participating regionally to ensure that Thurston County plays an appropriate role on the regional economic stage.

Pierce County services are primarily provided virtually. 

This location is funded, in part, through a partnership with Pierce County through the Navigator Program

General Contact: pierce@washingtonapex.org

Clallam and Jefferson counties

Tri-City Regional Chamber of Commerce

Tri City Regional Chamber of Commerce

Region 8 is hosted by the Tri-City Regional Chamber of Commerce and serves Benton, Columbia, Franklin, Grant, Klickitat, Walla Walla, and Yakima counties.

About the Tri-City Regional Chamber

The Tri-City Regional Chamber of Commerce is the leading business advocate for nearly 1,000 private, public, and non-profit member firms in the Tri-Cities region. The fifth largest chamber in Washington, the Tri-City Regional Chamber advocates for a strong business community and supports the interests of its members. The Regional Chamber is a catalyst for business growth, a convener of leaders and influencers, and a champion for a strong community.

Address

7130 W Grandridge Blvd, Suite C
Kennewick, WA. 99336

Email: tricity@washingtonapex.org

GREATER SPOKANE INC

Region 7 is hosted by Greater Spokane Inc and serves Spokane, Adams, Asotin, Douglas, Ferry, Garfield, Lincoln, Okanogan, Pend Oreille, Stevens and Whitman counties.

ABOUT GREATER SPOKANE INC

Greater Spokane Incorporated (GSI) is the Spokane region’s business development organization, focused on leading transformative business and community initiatives to build a robust regional economy. GSI is a nonprofit organization that serves as the Spokane Regional Chamber of Commerce and Economic Development Organization that supports the success of businesses of all sizes across the Inland Northwest. GSI is dedicated to creating a vibrant Spokane region by advocating at the local, state, and federal levels, driving strategic economic growth, and championing a talented workforce. Learn more at GreaterSpokane.org.

Address

801 West Riverside Avenue, Suite 200
Spokane, WA 99201

Contact: spokane@washingtonapex.org

Green River College

Region 5 is hosted by the Green River College serves King County.

ABOUT THE GREEN RIVER COLLEGE

The mission of Green River College is to ensure student success through comprehensive programs and support services responsive to our diverse communities.

ADDRESS

1221 D St NE
Suite 210 C
Auburn, WA 98002

Email: king@washingtonapex.org

Economic Alliance Snohomish County

Region 4 is hosted by the Economic Alliance Snohomish County and serves Snohomish, Skagit, Island, San Juan and Whatcom counties.

ABOUT THE EASC

The Economic Alliance Snohomish County (EASC) is a nonprofit serving as a combined economic development organization and a countywide chamber of commerce. We bring together private-public partners to create a unified voice for Snohomish County.

Address

808 134th St. SW, Suite 101
Everett, WA 98204

Email: snohomish@washingtonapex.org

Columbia River Economic Development Council

Region 3 is supported by the Columbia River Economic Development Council and serves the counties of Clark, Cowlitz and Skamania. 

Columbia River Economic Development Council 

Address

805 Broadway St, Suite 412
Vancouver WA 98660

Email: swwa@washingtonapex.org

Thurston County Economic Development Council

Region 2 is hosted by the Thurston County Economic Development Council and serves Thurston, Lewis, Mason, Grays Harbor, Pacific, Wahkiakim, Chelan and Kittatas counties.

This center is also the main center for Washington APEX Accelerator Statewide

ABOUT THE THURSTON EDC

The Thurston Economic Development Council (EDC) is a private non-profit organization.  As the lead economic development organization in Thurston County our mission is to create a vital and sustainable economy throughout the county and region that supports the livelihood and values of our residents. We do this by:

  • Connecting local businesses with experts and resources that help them remain competitive
  • Creating and delivering strategic messages that attract new investment to our community
  • Working with our community partners to enhance our collective prosperity and encourage our economic future
  • Participating regionally to ensure that Thurston County plays an appropriate role on the regional economic stage.

Address
4220 6th Ave
Lacey, WA 98503

General Contact: thurston@washingtonapex.org

Kitsap Economic Development Alliance

Region 1 is hosted by the Kitsap Economic Development Alliance and serves the counties of Kitsap and North Mason.  

ABOUT KEDA

The Kitsap Economic Development Alliance (KEDA) is a 30+ year old public/private nonprofit 501 (c) (6) corporation founded in June 1983. Our goal is to attract and retain jobs and investments in this community that generate wealth, enhance the quality of life and embrace future generations.

Address
2021 NW Myhre Rd, Suite 100
Silverdale WA 98383

Email:  kitsap@washingtonapex.org