Serving DoD Contractors Across Missouri & Southern Illinois
CMMC Level 1 compliance for construction, logistics, and services companies that never signed up to be cybersecurity experts. Assessment and documentation delivered in 15 business days. Time to SPRS submission depends on what remediation turns up; typically 4 to 6 weeks total.
The Problem
A clause shows up in a solicitation. Or a prime sends a supplier notice with a deadline. Or a recompete comes up and suddenly there's a question on the form about your SPRS score.
You are not a technology company. You pour concrete, or you move freight, or you keep a facility running. Nobody on your payroll knows what a System Security Plan is, and your IT guy handles printers. That's the entire reason we exist.
Federal Contract Information isn't classified material. It's delivery orders. Invoices. Performance reports. Proposal responses. Site drawings the government emailed you. If any of it touches a laptop or an inbox, you're in scope.
Prime contractors are issuing their own supplier requirements regardless of what the Pentagon does next. Your contract with them binds you no matter which way the regulations move.
A senior official at your company personally affirms your compliance in a federal system. That signature carries real exposure. It should be backed by real evidence.
FAR Clause 52.204-21
CMMC Level 1 covers 15 basic safeguarding requirements pulled directly from FAR clause 52.204-21. It applies to any contractor whose systems handle Federal Contract Information but not Controlled Unclassified Information — which describes most construction, logistics, facilities, and services firms in the defense supply chain.
There's no third-party assessor and no government fee. You assess yourself, annually, and record the result in the Supplier Performance Risk System.
Plans of Action and Milestones are not permitted. All fifteen requirements must be fully met — no partial credit, no "we're working on it."
Program Status
Partly. In July 2026 the Department suspended Phase 2 — the third-party certification requirement — and stood up a task force to review the program. That was real, and it was significant.
• Level 1 and Level 2 self-assessment requirements remain in effect
• SPRS submissions and annual affirmations are still required
• DFARS 252.204-7012 obligations are untouched
• The government still runs its own assessments
• False Claims Act exposure for a bad affirmation is unchanged
With no third-party assessor standing between you and the government, the only thing backing your compliance claim is your own signature and your own documentation.
The Offer
You price your work as a lump sum. So do we. Choose the flat-fee package tailored to your compliance stage.
Tier 1
Two weeks
• We map exactly where Federal Contract Information lives in your business
• Confirm whether you're Level 1 or have Controlled Unclassified Information hiding in your scope
• Written finding with your gap count and a clear path forward
• Full credit toward a Readiness Package if you move forward
Tier 2 — Most Popular
15 business days for assessment & docs (typically 4 to 6 weeks to SPRS submission)
• Complete gap assessment against all 15 requirements
• Remediation plan, prioritized and scheduled
• Written policies and System Security Plan
• Evidence collection and organization
• SPRS submission support
• Affirmation decision package for whoever signs
Tier 3
Ongoing
• Evidence refreshed before it goes stale
• Affirmation package prepared each cycle
• Change monitoring — new systems, new vendors, new contracts
• Direct line when a prime or contracting officer asks a question
All packages are provided as transparent, flat-rate investments with zero unexpected hourly billing. Level 2 self-assessment readiness quoted separately. Companies under 25 employees, ask about reduced scope options.
Target Industries & Scope
Whether you handle basic contract info or have complex multi-vendor setups, we tailor the readiness engagement to your exact operational scope.
• General and specialty trade contractors on federal construction projects
• Freight, warehousing, and third-party logistics (3PL) firms
• Facilities, maintenance, and base operations support (BOS)
• Staffing, engineering, and professional services on DoD subcontracts
• Defense suppliers who just received a prime contractor compliance mandate
• Unsure if you have CUI? Our Scoping Diagnostic uncovers hidden Controlled Unclassified Information so you never over-spend or under-prepare.
• Already have an IT/MSP Provider? We work alongside your internal IT or MSP, handling compliance documentation while they execute technical settings.
• Urgent Solicitation Deadline? Fast-track options ensure your SPRS score and affirmation package are submitted before contract award.
Why BirdyFoot
The fifteen requirements behind CMMC Level 1 are fundamental cybersecurity best practices. Access control. Multi-factor authentication. Patching and antivirus. Media handling. Physical access. Boundary protection. I've spent twelve years designing and defending exactly these controls in enterprise environments where a failure meant the whole business stopped.
What makes federal work different isn't the technology. It's the evidence standard, the documentation, and the fact that someone at your company has to personally sign an affirmation at the end of it. That's the part we take off your plate.
Most compliance shops send you a consultant who has read about infrastructure. We've run it. When your MSP says a control can't be implemented, we know whether that's true.
BirdyFoot works with contractors across the St. Louis metro and the Metro East, supporting Scott Air Force Base, Fort Leonard Wood, Rock Island Arsenal, Whiteman, the Corps of Engineers districts, and the primes headquartered here. We show up in person. That still matters when you're asking someone to sign a federal attestation.
Level 1 is designed as a direct self-assessment, and we provide the exact evidence, policy documentation, and guidance you need to sign with complete confidence. No unnecessary fluff or overpriced add-ons. Plus, if our initial diagnostic uncovers CUI in your environment, we'll point you to the right Level 2 path and refund your diagnostic fee in full.
FAQ
Almost certainly, if you have a federal contract or subcontract. FCI is non-public information generated for or provided under a government contract — purchase orders, invoices, schedules, performance reports, proposal material. It does not need to be marked to count.
Your IT provider manages your technology. CMMC is a compliance obligation with contractual and legal consequences. Different job, different evidence, different deliverable. We work with your existing provider.
Assessment and documentation delivered in 15 business days. Time to SPRS submission depends on what remediation turns up; typically 4 to 6 weeks total.
Then you're a Level 2 organization, and we'll say so before you spend money on the wrong path. That conversation happens in the scoping diagnostic.
Yes. The self-assessment and the affirmation are annual. That's why we offer the retainer.
You become ineligible for award on contracts carrying the requirement, and you risk losing option years on work you already have.
Get Started
No pitch deck. We'll ask about your contracts, your systems, and who's been handling this so far. Fill out the form below to request a call.