Scope and data flow
Map where FCI lives and how it moves — the storage server, office workstations, the firewall and switches, printers, and remote access paths.
A working tool for getting through CMMC Level 1: document the scope, inventory the assets that touch FCI, track the 15 requirements, keep evidence notes, and print clean reports for review.
This tool organizes the work. It does not certify the company, submit to SPRS, or stand in for the annual affirmation — those steps stay with you.
Built around how this environment handles data
Map where FCI lives and how it moves — the storage server, office workstations, the firewall and switches, printers, and remote access paths.
Keep a list of every system that stores, processes, transmits, or reaches FCI. Anything you are unsure about stays flagged until you settle it.
Work through all 15 FAR 52.204-21 safeguarding requirements, and tie each one back to the assets, scope, and evidence that support it.
Print what management needs to see: scope, readiness, open gaps, the evidence register, and the SPRS and affirmation checklists.
Unclassified does not mean it is not CUI. Check government documents for CUI markings, contract clauses, distribution statements, controlled technical information, and export-control flags before assuming they are clear.
External regulation
Official government source
The current CMMC program rule, straight from the electronic Code of Federal Regulations.
Open sourceExternal regulation
Official government source
The FAR clause that spells out the basic safeguards for Federal Contract Information.
Open sourceExternal regulation
Official government source
DoD's official Level 1 assessment guide — use it when you are deciding whether a requirement is actually met.
Open sourceExternal regulation
Official government source
DoD's official Level 1 scoping guide — for drawing the line around systems, assets, and access paths.
Open source