FAR 52.204-21 - Level 1
Get CMMC Level 1 done in an afternoon.
17 basic safeguarding controls, one guided questionnaire, and an officer-ready affirmation letter. No C3PAO, no long engagement, no six-figure consulting fee.
One-time payment. Includes the affirmation letter and evidence bundle.
Who this is for
- Subcontractors on DoD or federal awards that touch FCI (not CUI)
- Suppliers whose prime asked for a Level 1 affirmation
- Small teams who want to graduate to Level 2 without starting from scratch
Two ways to finish Level 1
Self-Serve
$500one-time
Do it yourself with our guided flow. Best for teams with an in-house IT lead.
- 17-control guided questionnaire
- Evidence upload with templates
- Auto-generated affirmation letter (PDF)
- Downloadable evidence bundle (.zip)
- 1-year workspace access + refresh
- Email support (48h SLA)
Recommended
Advisor-Assisted
$1,500one-time
A Symbiosis advisor reviews your evidence, joins one working session, and signs off before you affirm.
- Everything in Self-Serve
- 60-min working session with a GRC advisor
- Evidence review and gap callouts
- Advisor-reviewed affirmation letter
- Priority support (same-business-day)
- $500 credit toward the CMMC L2 package
The 17 controls we cover
FAR 52.204-21 basic safeguarding3.1.1
Limit system access to authorized users
3.1.2
Limit system access to permitted transactions and functions
3.1.20
Verify and control external system connections
3.1.22
Control CUI posted or processed on publicly accessible systems
3.5.1
Identify system users, processes acting on behalf of users, and devices
3.5.2
Authenticate users, processes, or devices before allowing access
3.8.3
Sanitize or destroy media containing CUI before disposal or reuse
3.10.1
Limit physical access to systems, equipment, and operating environments
3.10.3
Escort visitors and monitor visitor activity
3.10.4
Maintain audit logs of physical access
3.10.5
Control and manage physical access devices
3.13.1
Monitor, control, and protect communications at system boundaries
3.13.5
Implement subnetworks for publicly accessible system components
3.14.1
Identify, report, and correct system flaws in a timely manner
3.14.2
Provide protection from malicious code at designated locations
3.14.4
Update malicious code protection mechanisms when new releases are available
3.14.5
Perform periodic scans of the system and real-time scans of files from external sources
Ready for Level 2?
Handle CUI? You need Level 2 - and a C3PAO assessment.
Every dollar you spend on L1 with Symbiosis credits toward the L2 readiness package. Same workspace, same evidence, no data migration.