Hey everyone, I'm trying to figure out this CMMC thing. I run a small fastener distribution company, and we've been selling parts to DLA for a couple of years now through DIBBS. We have a dozen awards under our belt, mostly small stuff, under the simplified acquisition threshold. I just saw a new RFQ on DIBBS for some bolts, and it has a CMMC clause in it. We don't handle any drawings or anything marked as controlled; we just ship standard parts. What CMMC level applies to a parts reseller? What exactly does a Level 1 self-assessment involve? Is there a certain form I need to fill out, or is it just something internal?
What is CMMC, and do I need it if I only sell parts to DLA through DIBBS?
Ask a question- CMMC Level 1 is a self-assessment that requires you to assess and attest to your compliance with the 15 requirements of FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, and then report your CMMC status to the DoD.
- Tom is right that the CMMC Level 1 self-assessment is conducted every three years.
- The CMMC Program rule was published on October 15, 2024, and took effect on
3 answers
CMMC Level 1 is a self-assessment that requires you to assess and attest to your compliance with the 15 requirements of FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, and then report your CMMC status to the DoD. Tom is right that the CMMC Level 1 self-assessment is conducted every three years. The CMMC Program rule was published on October 15, 2024, and took effect on December 16, 2024. The DFARS CMMC acquisition rule was published on September 10, 2025, and took effect on November 10, 2025, which is when the first phase of CMMC implementation began.
CMMC is the Cybersecurity Maturity Model Certification, a program from the Department of Defense. It defines cybersecurity requirements for contractors who handle unclassified but sensitive Department of Defense information.
Your RFQ on DIBBS included a CMMC clause. That means you need to meet the requirements of that clause to bid. CMMC Level 1 is a self-assessment. It involves meeting the 15 security requirements of FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. These requirements cover things like access control, identification and authentication, and media protection. You attest to your compliance with these requirements in a system like SPRS. The CMMC Level 1 self-assessment is conducted every three years.
Jordan, you need to check the CMMC Level specified in the RFQ for that particular DIBBS solicitation, as it dictates the level of compliance required for your firm. Even for standard parts, if the contracting officer determined that the contract involves controlled unclassified information, then CMMC applies. The CMMC Level 1 self-assessment means you confirm that your company meets all 15 requirements of FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. There isn't a specific form; it's an internal process where you ensure your systems comply and then you attest to that compliance. The Department of Defense suspended Phase II of CMMC implementation on July 13, 2026, so all Phase 1 self-assessment requirements are still in place.