CMMC Level 1 · New Mexico small contractors

Not sure what CMMC means for your business?

If a prime or a federal customer is asking you about cybersecurity or CMMC, start here. Miclyn helps New Mexico small contractors find out what actually applies, secure what needs protecting, and prepare for CMMC Level 1 — without turning your business into an IT project.

Free qualification Local, Albuquerque-based ✓ We tell you if you don’t need it

In about 5 minutes, find out:

?
Does CMMC even apply to your business?
?
Is it Level 1, Level 2, or neither?
?
What information you’re responsible for protecting
?
What it would take — and roughly what it costs
Start the Free CMMC Check →

Read this first

Not every federal contractor needs CMMC.

A lot of small contractors get a cybersecurity questionnaire from a prime and assume the worst. Sometimes CMMC applies. Sometimes it doesn’t. And sometimes what looks like Level 1 is actually the bigger Level 2 requirement. We help you figure out which — before anyone spends money on compliance.

CMMC Level 1 may be required when your federal or defense contract calls for Level 1 and your systems process, store, or transmit Federal Contract Information (FCI). Government-adjacent work by itself doesn’t automatically mean you have a current CMMC requirement. Not sure whether it applies to you? We check first — for free.

You do federal or defense work

Directly, or as a sub to a prime — even single jobs or work orders at a base.

You handle non-public info

Work orders, project instructions, non-public files tied to the contract.

Someone asked about CMMC

A clause, a questionnaire, or a prime saying “you’ll need to be compliant.”

If those sound familiar, the free check is worth 5 minutes. If they don’t, you’ll likely find out you have nothing to do here — which is worth knowing too.

Plain English

What CMMC Level 1 actually is

CMMC is the government’s way of confirming that contractors protect certain non-public information tied to federal work. Level 1 is the entry level. It’s built on 15 basic safeguards — most of which have been in federal contracts since 2016 — plus a yearly self-check and a sign-off.

15 basic safeguards

Common-sense protections, not exotic security.

You check your own work

Level 1 is a yearly self-assessment — a third-party (C3PAO) assessment is not required.

A yearly cycle

You keep it current and confirm it each year in the government’s system (SPRS).

The distinction that changes everything

FCI vs. CUI — and why we check

Level 1

FCI — Federal Contract Information

Non-public information tied to a federal job:

  • Non-public work orders and purchase orders
  • Statements of work, schedules, instructions
  • Non-public project emails and reports
Level 2 — we stop and look separately

CUI — Controlled Unclassified Information

A tighter category that points to a bigger requirement:

  • Documents actually marked “CUI”
  • Controlled or export-controlled drawings/data
  • Information requiring special handling

If we see a sign of CUI, we pause the Level 1 path and look at it properly. We’d never push a business into the wrong requirement because it’s the easier sale. A drawing or blueprint isn’t automatically CUI — it depends on the markings and the contract.

What Level 1 asks you to do

Fifteen safeguards, five simple ideas

1

Right people only

Only the right people get into your systems and information.

2

Accounts & devices protected

Everyone uses their own account — no shared logins. Miclyn adds stronger sign-in like MFA as part of our security standard.

3

Network & info protected

Business information stays separated and protected.

4

Updated & guarded

Systems stay current and protected from malware.

5

Physical & paper handled

Equipment, printouts, and old devices handled safely.

That’s the whole idea

Sensible protection for the information that matters.

Built for small

Home office? Two people? That works.

You don’t need a commercial office or an IT department. A home office doesn’t rule out Level 1 — we just help keep the business side separate from the family and smart-home side.

Separate the business computer and Wi-Fi from the family side.
Everyone uses their own account — Miclyn adds stronger sign-in (like MFA) as our standard.
Project files in a protected, backed-up place.
Printed job info locked up or shredded.

How Miclyn helps

We handle the technical work — and stay

Find out if it applies (free).
Secure what needs protecting, right-sized.
Document it and gather the evidence.
Help you complete the yearly self-assessment.
Manage it after — one local partner you can call.

What you probably don’t need

We won’t sell you the heavy stuff

For an FCI-only Level 1 business, these are usually unnecessary — and we’ll say so:

A move to GCC High (that’s a CUI/Level 2 concern).
A FedRAMP cloud stack for Level 1.
A giant consulting engagement or 300-page binder.
Enterprise gear a two-person shop will never use.

How it works

A clear path — starting at the free end

STEP 1 · FREE

Qualify

Find out if it applies.

STEP 2

Assess

What’s missing + a plan.

STEP 3

Secure

We implement the safeguards.

STEP 4

Self-assess

You record it in SPRS.

STEP 5

Maintain

Kept current, reviewed yearly.

Pricing, honestly

Simple and separated, so nothing surprises you

We don’t bundle everything into one scary number, and we don’t sell fear. Qualification is free. If Level 1 applies, there are two simple CMMC numbers — a one-time Foundation and a flat yearly renewal — with your SecureIT security billed separately.

Free · Qualification
Free
Find out if it even applies.
CMMC Level 1 Foundation
$1,995
One time. Gets you ready and through your first self-assessment.
CMMC Level 1 Assurance
$995/yr
Begins at your first annual renewal.
SecureIT Protect+
Separate
Your managed security, based on your users.

This is our standard price for a typical small, FCI-only business. Unusual setups — multiple sites, on-premise servers, or special software — are quoted separately after we look. Any hardware, licensing, or out-of-scope remediation is discussed and approved separately before work begins.

Why Miclyn

A local partner who can actually do the work

Local

Albuquerque-based. We know New Mexico’s federal and defense ecosystem.

Right-sized

We fix only what the work requires, and tell you what you don’t need.

We do it, not just advise

A consultant says “segment your network.” We design, install, and manage it.

We stay

Ongoing management and next year’s self-assessment — not a one-time binder.

Miclyn is a managed technology and cybersecurity partner based in Albuquerque, New Mexico, serving small businesses that do federal and defense work.

Questions people actually ask

CMMC Level 1, answered plainly

What is CMMC Level 1?
It’s the entry level of the government’s Cybersecurity Maturity Model Certification. It applies when your business handles Federal Contract Information (FCI), and it’s built on 15 basic safeguards from a rule called FAR 52.204-21, plus a yearly self-assessment you record and affirm.
Who needs it?
Businesses that do federal or defense work — directly or as a subcontractor — and handle non-public information tied to that work. It’s not about company size; a one- or two-person shop can be in scope, and a large company might not be. That’s what the free qualification sorts out.
What is FCI?
Federal Contract Information: non-public information provided by or created for the government under a contract — things like non-public work orders or project instructions. Public information and simple payment/invoice information don’t count.
What is CUI, and how is it different?
Controlled Unclassified Information is a tighter category — for example, documents marked “CUI” or controlled technical drawings. All CUI is FCI, but not all FCI is CUI. CUI points to the bigger Level 2 requirement, not Level 1 — so if we see it, we pause and look at it separately.
Do I need GCC High or a special government cloud?
For an FCI-only Level 1 business, generally no. Microsoft’s own guidance positions commercial Microsoft 365 as able to support Level 1; GCC High is aimed at CUI (Level 2/3) situations. We won’t move you there unless your information actually requires it.
Can my office be in my home?
Yes. A home office doesn’t disqualify you. We’d help keep the business side of your computers and internet separate from the family and smart-home side, and keep the plan realistic for your size.
How much does Level 1 cost?
Qualification is free. If Level 1 applies, there are two simple CMMC numbers: a one-time Foundation of $1,995 that gets you ready and through your first self-assessment, then a flat $995 a year that begins at your first annual renewal to keep you current. Your SecureIT managed security is billed separately, based on your users. That standard price covers a typical small FCI-only business; unusual setups are quoted separately after we look.
How long does it take?
For a small shop, the assessment is quick, and remediation is usually a matter of a few weeks depending on what needs to change. We’ll give you a realistic timeline with your plan.
Can Miclyn certify me?
Level 1 isn’t certified by an outside party — it’s a self-assessment you record and affirm each year. Miclyn implements, manages, documents, and helps you prepare the self-assessment. Your authorized official makes the final affirmation; we don’t do that on your behalf.
What if I discover I have CUI?
We stop the Level 1 path and scope the Level 2 requirement separately. We’d never try to squeeze a CUI situation into Level 1 because it’s the simpler sale — getting that right protects you.
What happens every year?
Level 1 is a yearly cycle. We keep the safeguards current, watch for anything that drifts out of place, and help you complete and affirm your annual self-assessment.

Free · No obligation

Find out what applies

Answer a few plain-English questions and a local Miclyn specialist will review your result with you. You’ll get a one-page CMMC Qualification Snapshot to keep — whatever you decide.

  • Takes about 5 minutes — no technical knowledge needed.
  • We review it before recommending anything paid.
  • If it doesn’t apply to you, we’ll tell you.

By continuing you’ll start the free qualification. We’ll email your Snapshot and a specialist will follow up. No spam, no pressure.