15 Practices, 142 Artifacts: The Anatomy of an L1 Self-Assessment With a Map
142 sounds like more work than 15. It's dramatically less โ because the thing that burns your hours isn't volume. It's ambiguity.
๐ By Rob Maupin, founder of Overwatch Tools and author of CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors
It's a Tuesday afternoon. You have fourteen browser tabs open. One is a spreadsheet you downloaded from somewhere reputable, listing all fifteen CMMC Level 1 practices, one per row, with a column headed Status. Row one says: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices.
You read it three times. You probably do that, you think. You have passwords. Not everyone can see everything. But the cursor is blinking in the Status column and you have no idea what to type, because you have no idea what "done" physically looks like. A written policy? A screenshot? A list of employees? All three? Signed by whom? Kept where?
So you close the tab. Not because you disagree that this needs doing โ we settled that in Part 1 โ but because "implement the fifteen practices" is not an instruction any human being can act on.
This article is about the thing that fixes that. Not motivation. Not a deadline. A map.
The Instruction That Isn't One
CMMC Level 1 is fifteen practices, drawn from FAR clause 52.204-21 and mapped to NIST SP 800-171. That's the entire requirement โ small enough that a 5-person shop can finish it.
But a practice is a requirement statement, not a work item. Requirement statements are written to be legally complete across every possible organization, from a two-person machine shop to a shipyard, and that generality is exactly what makes them useless as a to-do list. "Limit information system access to authorized users" is true, correct, binding โ and completely silent on what you should be doing between 2:00 and 3:30 this afternoon.
The gap between a requirement and a task is where small contractors lose months. Not because the work is hard, but because they're doing the requirement-to-task translation themselves, alone, with no way to tell whether they got it right.
The core swap this article is about
"Implement AC.L1-b.1.i" is not a task. "Complete these nine artifacts" is. One of those you can start. The other one you can only stare at.
What an Artifact Actually Is
Compliance vocabulary makes simple things sound institutional, so here's the plainest possible version.
An artifact is a thing you can point to. If someone sat down across from you and said "show me," an artifact is what you'd slide across the table. It comes in four flavors:
- A signed page. A policy or a written decision, dated, with a name on it.
- A written procedure. The steps somebody actually follows โ who does what, when, and what they record.
- A setting. A configuration in your Microsoft 365 or Google Workspace admin console, on a laptop, on a firewall โ captured as a dated screenshot or export.
- A record. A log, a roster, an inventory, an approval ticket, a receipt. Proof the procedure ran, not just that it exists.
None of those are abstract โ you can hold all four. The official CMMC Assessment Guide โ Level 1 is built on the same premise: under every practice it lists the assessment objectives ("determine ifโฆ") and then the methods and objects an assessor would examine โ policies, procedures, configuration settings and associated documentation, lists, records, logs. The guide is already telling you what the artifacts are. It just isn't organized as a checklist for your business.
Turning it into one is the job.
The Three Layers: Policy โ Procedure โ Evidence
Every artifact at Level 1 lands in one of three layers, and the layer tells you what that artifact has to accomplish.
| Layer | What it establishes | What it looks like |
|---|---|---|
| Policy | Intent. The company has decided this, and leadership signed it. | A short signed, dated statement. Two pages, not twenty. |
| Procedure | Method. Here is how the decision gets carried out, by whom. | Numbered steps naming a role, a trigger, and what gets recorded. |
| Evidence | Operation. The method actually ran, on these dates, on this system. | Screenshots, exports, logs, rosters, approvals, receipts. |
Most stalled self-assessments have a bloated first layer, a missing second layer, and nothing at all in the third. That's the signature of DIY without structure: people write policy because policy is the part that feels like compliance, then run out of energy before the part an assessor would actually credit. A policy proves you intended to. Evidence proves you did.
Three Practices, Fully Unpacked
Enough theory. Below are three of the fifteen, taken straight from the official Assessment Guide and decomposed the way a map decomposes them. Read them as the pattern rather than an exhaustive list โ but they're concrete enough that you could genuinely start on any of the three this week.
Authorized Access Control
"Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)."
Unpacks into 9 artifacts across 3 layersPolicy โ 2 artifacts
- Access Control Policy โ signed and dated by the owner, stating that access to company systems is granted only to identified, authorized users, processes, and devices.
- Role and access definitions โ the conditions for group and role membership. Who is in "Contracts," what "Contracts" can reach, and who decides.
Procedure โ 3 artifacts
- Account provisioning procedure โ who requests an account, who approves it before access is granted, and where that approval is recorded.
- Account removal procedure โ the trigger events (separation, transfer, termination) and the step that disables the account, with a stated timeframe.
- Device authorization procedure โ how a new laptop, phone, or network printer gets approved onto the network before it connects.
Evidence โ 4 artifacts
- Authorized user roster โ every active account with the name of the individual associated with it and their role.
- Authorized device inventory โ the devices and systems permitted to connect, including the shared printer somebody added last spring.
- Account approval records โ tickets, emails, or a simple approval log showing authorization happened before access.
- Access review record โ a dated periodic review of the roster with the reviewer's name, plus records of accounts disabled for departures.
Authentication
"Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems."
Unpacks into 7 artifacts across 3 layersPolicy โ 1 artifact
- Identification & Authentication Policy โ signed and dated; states that every user, process, and device is verified before it is allowed access.
Procedure โ 2 artifacts
- Authenticator management procedure โ issuing credentials to a new hire, resetting them, and revoking them when access ends, including temporary access.
- Default credential procedure โ the step that changes the factory username and password on any new device before it goes into service. The Assessment Guide calls this out directly; default credentials are well known and easily discovered.
Evidence โ 4 artifacts
- Password policy configuration capture โ the actual dated screenshot from your Microsoft 365 or Google Workspace admin console showing what's enforced, not what you meant to enforce.
- Multi-factor enrollment export โ a report showing MFA status per account, including the owner's account and any admin accounts.
- Default credential change records โ for the router, the firewall, the network printer, the NAS in the closet.
- Credential issuance and revocation log โ dated entries tying each event to a person.
Media Disposal
"Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse."
Unpacks into 5 artifacts across 3 layersPolicy โ 1 artifact
- Media Protection Policy โ signed and dated; states that media holding Federal Contract Information (FCI) is sanitized or destroyed before it is thrown out or handed to anyone else.
Procedure โ 2 artifacts
- Sanitization and destruction procedure โ the method for each media type you actually own: paper, laptop drives, USB sticks, phones, and the hard drive inside the copier. NIST SP 800-88 is the reference for methods.
- Reuse procedure โ what must happen to a laptop before it's reassigned to another employee, which is the case people forget because nothing is being thrown away.
Evidence โ 2 artifacts
- Sanitization and destruction log โ date, item, method, and who performed it.
- Certificates of destruction or vendor receipts โ from the shredding service or the e-waste recycler.
๐ก The plain-English version of every practice
Each of the fifteen gets a full chapter in the book โ what the practice actually requires, what evidence proves it, and where small contractors reliably over-build. This article shows the pattern on three of them; the book runs the pattern on all fifteen.
Not sure which of the fifteen you've already got?
The free CMMC Assessment Tool walks all fifteen Level 1 practices in plain-language questions, takes under 30 minutes, and gives you an instant gap report with a prioritized remediation roadmap. No credit card.
Run the Free Assessment โWhy Counting Artifacts Gives You a Finish Line
Run that decomposition across all fifteen practices and you land at roughly 142 artifacts. Some practices carry a dozen; a couple carry four or five.
The number isn't the point โ the granularity is. Here's what it buys:
- A real percentage complete. "4 of 15 practices" is nearly meaningless, because practices don't finish evenly. "61 of 142" is a number you can put in front of a prime โ or a spouse who wants to know when the evenings end.
- Parallel work. 142 items can be split across three people. Fifteen ambiguous requirements can't be split across anyone.
- An actual definition of done. An artifact is binary. The policy is signed or it isn't. The export is dated or it isn't. There is no "mostly."
- A stopping point. Without a map, contractors don't just under-build โ they over-build, writing enterprise documentation for a fifteen-practice requirement because nobody told them where the edge was.
Ambiguity Is the Labor Multiplier
When the Department of War suspended CMMC Phase II on July 13, 2026, the Small Business Administration's supporting statement put numbers on what compliance had been costing small firms. They're worth reading carefully, because they're almost always quoted wrong.
The SBA figures, stated properly
The SBA described total compliance cost per certification for small firms as reaching approximately $593,800 where a third-party assessment was required, and approximately $388,600 for firms eligible for self-assessment.
Both are upper bounds on total compliance cost โ what costs can reach, not a typical invoice. And critically, they are not assessor fees: they include remediation, tooling, platform changes, documentation, and internal labor.
Sit with the second figure. $388,600 with no third-party assessor involved at all. No audit in that number. No C3PAO. Nobody sent a bill for an assessment.
So where does it come from? Labor and rework. Months of evenings. Documentation written, discarded, rewritten. Scoping decided wrong at the start and discovered late. Consultants brought in to translate. Enterprise templates bought and then adapted line by line to a company one-fortieth the size.
The expensive part of compliance was never the assessment. It was doing it without a map.
Ambiguity is the multiplier. Every hour spent deciding what counts is an hour not spent producing anything. Structure doesn't add work โ it deletes the deciding.
The Rework Tax: Writing It Three Times
Most contractors who do this without a map write the same material three times.
- Once wrong. The first draft is a policy downloaded from a search result. It's written for an organization with a security team and a change advisory board โ half of it describes controls you don't have, the other half is silent on the two systems you actually use.
- Once incomplete. The rewrite is right-sized but stops at intent. Policies, no procedures, no evidence. It reads well and proves nothing. This is the version most people submit against.
- Once finally right. The third pass adds the layer that was always the actual requirement โ records, exports, rosters, logs โ and forces a partial rewrite of the first two, because now the procedure has to describe what the evidence shows.
That isn't a discipline failure, it's a sequencing failure. When you know the artifact list up front, you write the policy knowing which procedure it supports and which record proves it. One pass.
Generic Templates Are Where Rework Comes From
One more source of the tax, and the one people underestimate most: an artifact list for Microsoft 365 and an artifact list for Google Workspace are not the same document. The requirement is identical; the evidence isn't. The policy layer barely changes between platforms, but the procedure and evidence layers change substantially โ different consoles, different names for things, different exports, different places the setting lives.
| Artifact | Microsoft 365 | Google Workspace |
|---|---|---|
| Authentication configuration capture | Entra ID authentication methods and policy blades | Admin console security and 2-step verification settings |
| MFA status per account | Entra ID sign-in and authentication methods report | Admin console 2-step verification enrollment report |
| External sharing controls | SharePoint and OneDrive sharing settings | Drive sharing settings by organizational unit |
| Account and role listing | Users and role assignments export | Users list and admin roles export |
A generic template hands you a blank labeled "capture your MFA report." A platform-specific one names the console, the path, and what the finished capture should show. The first costs an hour of searching and a decent chance of grabbing the wrong screen โ multiply by the number of evidence artifacts and you've found a meaningful slice of that $388,600.
โ ๏ธ A Level 1 note worth saving you money on
Microsoft 365 commercial editions are sufficient for Level 1. GCC High is a Level 2 conversation, not a Level 1 one โ and it is one of the most common places small contractors get sold something the requirement never asked for.
๐ From the Author
CMMC Level 1: A Practical Guide for Small to Medium GovCon ContractorsAll fifteen practices in plain English, mapped to their FAR 52.204-21 and NIST SP 800-171 origins โ plus scoping, FCI versus CUI, the platform decision, building a system description, and the self-assessment and annual affirmation in the Supplier Performance Risk System (SPRS), step by step. Written for the 5- to 50-employee contractor with a real contract on the line.
Available on Amazon โ Kindle, paperback, and hardcover.
You Can Absolutely Build This Map Yourself
Let's be straight about what's proprietary here, because it isn't the information. Everything above is derivable from public documents: the Assessment Guide lists the objectives and assessment objects under every practice, NIST SP 800-171 gives the underlying discussion, FAR 52.204-21 is the source clause, NIST SP 800-88 covers media sanitization. All free, all authoritative, all sitting on federal websites right now.
What you'd be buying isn't access. It's the weeks.
Building your own artifact map means reading several hundred pages, deciding for each objective what a defensible artifact looks like for a company your size, resolving every place the guidance says "as appropriate," and translating each evidence item into the specific screen in your specific admin console. Entirely doable. It takes weeks of evenings, and the first version won't be right โ the rework tax, arriving on schedule.
Some contractors should do exactly that: the ones who want to own the methodology and have the time. That's who the book is for. Others want the artifact list to already exist on Monday morning. That's what the package is.
The Turnkey Level 1 Package is this map, complete
- All 15 practices decomposed into 142 defined artifacts โ every one identified, so nothing is invented and nothing is over-built
- Platform-specific templates for Microsoft 365 or Google Workspace โ not a generic pack you translate yourself
- All 8 device and network configuration guides, plus implementation procedures and workflows
- Evidence Locker and SPRS report, with date-stamped self-assessment documentation
- 8 bi-weekly expert consultation sessions โ the thing that keeps a part-time project from stalling in week three
- $2,495/year (limited time โ save $500 off the regular $2,995). Most clients complete their Level 1 assessment in 2โ4 weeks, varying with existing infrastructure and responsiveness.
What's Next: Roughly Half of This Is Settings
Something becomes obvious once the artifact list is laid out: a large share of the technical evidence isn't paperwork at all. It's configuration โ laptop, phone, router and firewall, admin console โ captured as proof.
That's good news, because settings are fast. A configuration change takes minutes where a policy takes an afternoon. But it comes with a rule that catches people out: a setting you can't prove is a setting nobody can credit you for. Configure it, capture it immediately, file it, move on. Part 3 covers exactly that โ the device and network configuration guides, per device type, and how to capture proof as you go instead of reconstructing it three weeks later from memory.
In the meantime, the window is still quiet. Nothing is due, no assessor is scheduled, and the Task Force isn't expected to report until roughly mid-September. Whatever it decides, a completed self-assessment built on NIST SP 800-171 serves you in every outcome โ and the underlying obligations never went anywhere. This is the cheapest, calmest stretch you'll get to do required work. Most of your competitors are using it to wait.
Want the map instead of building one?
Thirty minutes with Rob. We'll walk your platform, your scope, and which of the 142 artifacts you already have sitting in a folder somewhere โ most contractors have more than they think. No pressure, no six-figure quotes.
Book a Free 30-Minute Consultation โ Run the Free AssessmentAbout the Author
Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small to medium defense contractors, and the author of CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors (available on Amazon in Kindle, paperback, and hardcover). He works with 5- to 50-employee GovCon firms on right-sized compliance. He's based in the Kansas City area.
Sources & Further Reading
- DoD CIO โ CMMC Assessment Guide, Level 1 (Version 2.13) โ practice statements, assessment objectives, and assessment methods and objects quoted above
- NIST SP 800-171 Rev. 2 โ the underlying requirements and discussion
- U.S. Department of War โ "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026)
- U.S. Small Business Administration โ statement on the suspension of CMMC Phase II (July 13, 2026) โ source of the total compliance cost figures
- SBA Office of Advocacy โ DoW Requests Information for CMMC Reform Task Force
Artifact counts and the three-layer breakdown reflect the Overwatch Tools Level 1 taxonomy, not a federal requirement โ the government defines practices and assessment objectives, not artifact counts. This article is provided for informational purposes and does not constitute legal advice. Contractors should review their specific contract terms and DFARS clauses with qualified counsel.
