CMMC Level 1 readiness · Mobile, AL & the Gulf Coast

Get ready for CMMC Level 1 without the consultant runaround.

Fixed-fee readiness for small defense suppliers: shipyard vendors, machine shops, fabricators, and logistics companies. We close the gaps, write the policies, and build the evidence so your affirmation holds up.

How it works

Step 1

Free 5-minute scorecard

Answer 15 plain-English questions and see exactly which Level 1 requirements you'd fail today.

Step 2

Fixed-fee Readiness Sprint

We close the gaps with you or your IT provider, write right-sized policies, and build your evidence binder. Usually 2–4 weeks.

Step 3

Affirm with confidence

Your senior official submits the SPRS affirmation knowing all 15 requirements are actually met and documented.

Step 4

Stay ready every year

Level 1 requires a new self-assessment and affirmation annually. Annual Care keeps you current without starting over.

What the Readiness Sprint includes

  • Scoping: where Federal Contract Information lives, including people, devices, cloud, and paper
  • Hands-on remediation of every gap, alongside your team or existing IT provider
  • Written policies and procedures sized for your company, not a 200-page binder
  • An evidence binder organized by requirement, ready when a prime asks
  • A readiness report and a walkthrough of the SPRS affirmation with your Affirming Official

The 15 Level 1 requirements

Level 1 is pass/fail: every one must be met before your affirmation. There’s no partial credit.

  1. AC.L1Authorized Access Control
  2. AC.L1Transaction & Function Control
  3. AC.L1External Connections
  4. AC.L1Control Public Information
  5. IA.L1Identification
  6. IA.L1Authentication
  7. MP.L1Media Disposal
  8. PE.L1Limit Physical Access
  9. PE.L1Manage Visitors & Physical Access
  10. SC.L1Boundary Protection
  11. SC.L1Public-Access System Separation
  12. SI.L1Flaw Remediation
  13. SI.L1Malicious Code Protection
  14. SI.L1Update Malicious Code Protection
  15. SI.L1System & File Scanning

Simple, fixed pricing

No hourly surprises. You know the cost before we start.

Readiness Sprint

Up to 25 employees

$2,500

Gap assessment, remediation, policies, evidence binder, and affirmation walkthrough.

Readiness Sprint

26–75 employees

$4,500

Same scope, sized for more users, devices, and sites.

Annual Care

After your sprint

$250/mo

Quarterly check-ins, onboarding and offboarding reviews, and the yearly re-assessment and affirmation packet.

Why Pathfinder

Pathfinder’s founder, Patrick Rivers, is a systems and cloud administrator with hands-on CMMC Level 1 readiness experience in a multi-site logistics environment. He holds CCNA and CompTIA Security+ certifications and works day to day in Microsoft 365, Entra ID, and network security.

Before IT, he spent more than ten years in Gulf Coast chemical plants and industrial transportation. He knows how a shop floor actually runs, what’s realistic to ask of a small team, and how to explain compliance without jargon.

Common questions

What is CMMC Level 1?+

It's the baseline cybersecurity requirement for DoD contractors and subcontractors that handle Federal Contract Information (FCI). Level 1 has 15 security requirements, drawn from FAR 52.204-21, and requires an annual self-assessment plus an affirmation by a senior company official in SPRS.

Does my company need it?+

If you hold or bid on DoD contracts or subcontracts that involve FCI, very likely yes. DoD began phasing CMMC requirements into solicitations in November 2025, and prime contractors are flowing the requirement down to their suppliers. If you're not sure, the scorecard and a short call will tell you.

Can you certify us?+

Level 1 is a self-assessment, so no outside party certifies it. Your company's Affirming Official signs. Our job is to make sure that signature is backed by real controls and real evidence, because the affirmation carries legal weight.

We handle CUI. Is Level 1 enough?+

No. Controlled Unclassified Information generally requires Level 2, which has 110 requirements based on NIST SP 800-171 and often a third-party assessment. We'll tell you plainly which level applies and whether we're the right fit.

Do you replace our IT provider?+

No. We work alongside your current IT provider or in-house person, handle the compliance side, and hand technical fixes back to them where it makes sense. If you don't have IT support, Pathfinder's systems services can fill that gap.

Find out where you stand in 5 minutes.

Level 1 is a self-assessment. The affirmation is made by your company’s senior official. Pathfinder prepares you and your evidence; we do not certify.