Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
Your L1 Self-Assessment Starts This Week (Here's the First 30 Minutes) | Overwatch Tools
Do It With a Map · Part 1 of 6

Your L1 Self-Assessment Starts This Week (Here's the First 30 Minutes)

By Rob Maupin · Founder, Overwatch Tools · Author of CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors

Nothing is due right now. No assessor is coming. That's not a reason to wait — it's the best starting conditions you will ever get.

Published August 6, 2026. This article reflects the Department of War announcement of July 13, 2026 and reporting available at the time of writing. The CMMC Reform Task Force is expected to deliver findings roughly mid-September 2026, and guidance may change. We will update this article as the situation develops.

If you've been reading along since July, you already know the argument. The Department of War suspended CMMC Phase II — the third-party audit machinery — but it did not suspend your obligations. DFARS 252.204-7012 still binds your contracts. NIST SP 800-171 is still the standard. Phase I self-assessment requirements remain firmly in place, primes are still gating awards on compliance, and select government-led assessments continue. We made that case in detail across our Self-Assessment Era series, and if you're here, we'll assume it landed.

So here's the uncomfortable question: if you agree the self-assessment matters, why haven't you started?

We'd bet it isn't disagreement. It isn't even busyness, exactly. It's that the work has no shape. "Do a CMMC Level 1 self-assessment" is not a task anyone can put on a Tuesday calendar. There's no obvious first step, no sense of what order things go in, and — worst of all — no picture of what "done" actually looks like. Faced with a shapeless project, reasonable people do the reasonable thing: they wait for it to become clearer.

This article is the end of the waiting. It's the first piece in a six-part series called Do It With a Map, and its job is simple: to walk you through the literal first 30 minutes of your self-assessment — this week — and show you what comes out the other side. Not a pep talk. A starting point.

You're Not Procrastinating. You're Un-Mapped.

Let's be honest about the stall, because naming it correctly is half of fixing it.

You are not stalled because you doubt the requirement. You're stalled because every time you sit down to start, the project presents as a blank page. You open the official documentation and find 15 security practices written in assessment-objective language. You google "CMMC Level 1 checklist" and find forty of them, all different, none of which tell you what a finished self-assessment physically contains. Most DIY attempts we hear about begin the same way: three weekends of research that produce a folder of bookmarks and zero completed work.

That's not a character flaw. That's what happens when required work arrives without a map. The blank page is doing exactly what blank pages do — absorbing your momentum before you've taken a single concrete step.

The fix isn't more willpower. It's a first step small enough to actually take, that produces something useful enough to make the second step obvious. That first step exists, it's free, and it takes about half an hour. We'll walk it in a moment.

The Quiet Window: Why Right Now Is the Cheapest This Will Ever Be

First, the timing — because it matters more than most contractors realize.

Between now and roughly mid-September, when the CMMC Reform Task Force is expected to deliver its findings, the entire defense industrial base is in a holding pattern. Nothing new is due. No assessor is scheduling visits. Most of your competitors have interpreted "suspension" as "permission to stop thinking about this." The industry is, functionally, standing still.

That stillness is not a reason to wait. It's the opportunity.

Four reasons the quiet window works in your favor

  1. The work is required either way. Phase I self-assessment requirements remain firmly in place. Whatever the Task Force decides about the program's future, the self-assessment you owe today doesn't change between now and then.
  2. It has never been easier to do it. No looming assessment date, no scramble, no premium-priced consultants booked out for months. You can work at a sane pace, on your own schedule, with room to do it right the first time.
  3. Primes are still gating awards. Contracting officers and prime contractors didn't stop checking Supplier Performance Risk System (SPRS) scores on July 13. A current score and a completed self-assessment win work today — during the very window your competitors have gone quiet.
  4. Government-led assessments continue. The suspension removed the third-party audit apparatus, not government scrutiny. If your program is selected for a government-led assessment, your documentation is the only thing in the room. Better to build it in the calm than assemble it under a deadline.

And there's a fifth reason that outlasts all of them: a completed NIST SP 800-171-based self-assessment serves you in every possible Task Force outcome. If the program continues, you're ahead. If it's reformed, your documentation maps to whatever replaces it, because the underlying standard isn't going anywhere. If it's cancelled outright, DFARS 252.204-7012 still requires exactly what you just built. We walked the full four-outcome logic in the final installment of the Self-Assessment Era series — the short version is that finishing now is the rare move that's right no matter what mid-September brings.

📣 One deadline that IS real: the RFI closes Friday, August 14

While nothing is due on the compliance side, there is one date on the calendar this month: the Department of War's Request for Information supporting the CMMC Reform Task Force closes at 12:00 PM ET on Friday, August 14, 2026. This is the mechanism through which the Task Force hears from industry — and historically, small contractors are the least-heard voice in these processes. The large primes and industry associations will file comments. If the reformed program is going to reflect what compliance actually costs a 5-person shop, that perspective has to come from 5-person shops.

If the past year of CMMC has cost you time, money, or contracts, say so — briefly and specifically. Details on the RFI are available through the SBA Office of Advocacy. It doesn't need to be long. It needs to exist.

The First 30 Minutes, Walked Step by Step

Here is the entire first step of your self-assessment. It requires no preparation, no purchase, no credit card, and no IT background. It's our free CMMC Assessment Tool, and it exists specifically to kill the blank page.

What actually happens in those 30 minutes

1

Answer plain-language questions

The tool walks all 15 CMMC Level 1 practices as questions about how your business actually operates — who has access to what, how devices are handled, what happens when someone leaves. No assessment-objective jargon to decode.

~25 minutes
2

Get your instant gap report

The moment you finish, you see exactly where you stand: which of the 15 practices you already satisfy (most shops are further along than they think), and which have gaps that need work.

Instant
3

Receive a prioritized roadmap

Not just a list of gaps — an ordered one. What to fix first, what can wait, and whether anything in your operation suggests Level 2 may apply to you.

Instant

Run the Free 30-Minute Assessment

That's it. Thirty minutes ago, your self-assessment was a shapeless obligation. Now it's a document with your company's name on it that says: here's where you stand, here's what needs work, and here's the order to work in.

Why a prioritized roadmap beats every checklist you've bookmarked

The difference between the gap report and the generic checklists you've already collected comes down to one word: order.

A requirements spreadsheet tells you everything that must eventually be true. It says nothing about your situation. It can't tell you that you already satisfy six practices through how your Microsoft 365 or Google Workspace tenant is configured, that two of your gaps are fifteen-minute fixes, and that one item genuinely needs planning. So every item looks equally urgent, which means none of them do — and the spreadsheet joins the bookmark folder.

Priority order is what turns a compliance standard into a work plan. It's the difference between "here are 15 things" and "start here, then here, then here." That single transformation is why the assessment is the first 30 minutes and not the checklist — and it's the germ of everything this series will show you.

Kill the Blank Page in the Next Half Hour

Free gap analysis across all 15 Level 1 practices. Instant report. Prioritized roadmap. No credit card, no obligation — just a map where the blank page used to be.

Run the Free Assessment

What "Done" Actually Looks Like at Level 1

The second thing that keeps contractors stalled — right behind not knowing where to start — is not knowing where the finish line is. So let's put it in plain sight. A completed CMMC Level 1 self-assessment isn't a feeling of confidence or a folder of good intentions. It's a specific set of deliverables:

15 → 142 All 15 L1 practices, broken down into 142 specific, checkable artifacts — policies, procedures, configurations, and evidence
1 SPRS score, calculated and submitted — the number primes and contracting officers actually check
100% Packaged and date-stamped — a self-assessment record that proves what was true, and when
  • Every practice documented as artifacts. Not "we do that" — a thing you can point to. A written policy, a procedure your team follows, a screenshot of a setting, a record that proves it. (Part 2 of this series unfolds the full 15-to-142 map, artifact by artifact.)
  • Evidence collected as you go. Configurations captured at the moment they're made, filed where you can find them — because a setting you can't prove is a setting that doesn't count. (Parts 3 and 4 cover configuration and evidence in depth.)
  • An SPRS score submitted. The self-assessment produces a score; the score goes into the government's Supplier Performance Risk System; that's what award decisions reference.
  • A date-stamped package. The whole assessment — documentation, evidence, score — assembled into a single dated record. If a prime asks, if a government-led assessment selects you, if the Task Force's reformed program wants history: you hand over the package.

That's the finish line. It's real, it's finite, and — this is the part that surprises people — with structure, most of our clients get there in 2–4 weeks of part-time work. Timelines vary with your existing infrastructure and how quickly your team can act, but this is a weeks-scale project, not a months-scale one. The contractors who spend months on it are almost always the ones working without a map.

If you want that entire finish line walked end to end — the system description, the evidence behind each practice, the self-assessment, and the annual affirmation filed in SPRS — it's exactly what CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors was written to do, chapter by chapter, for the contractor doing this work themselves.

📘 From Overwatch Press

CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors

All fifteen practices, the evidence behind them, and the self-assessment — written for the 5- to 50-employee contractor. Plain English, no jargon, no six-figure engagement.

Available on Amazon in Kindle, paperback, and hardcover.

Your Actual Plan for This Week

Not a metaphorical "this week." This one. Here's the whole thing — about two hours, total, spread across three days:

Day 1 · 30 minutes

Run the free assessment

Block half an hour, run the free gap assessment, and get your report. Do it with coffee. Do it tonight. The only requirement is that it happens.

Day 2 · 1 hour

Read the roadmap with your team

Sit down with whoever touches this — a partner, your office manager, the person who "does the computers" — and walk through the gap report together. You're not fixing anything yet. You're just agreeing on what the map says: what's already done, what's quick, what needs planning. Most teams leave this hour genuinely relieved.

Day 3 · 30 minutes

Book the free kickoff consultation

Bring your gap report to a free 30-minute kickoff consultation and talk through it with us. What's realistic for your shop, what order makes sense, whether anything in your contracts points at Level 2. No pitch required to get value from it — you'll leave with a clearer plan than you walked in with.

By Friday, you will have gone from "we should really deal with CMMC" to a documented gap analysis, a prioritized roadmap, a team that's seen it, and a conversation on the calendar. That's not symbolic progress. That's the actual start of the assessment.

The Map Is Free. The Guided Version Is Optional.

A word about where we stand in all this, because we'd rather be plain about it.

The free assessment gives you the map, and the map is genuinely yours. You can take your gap report and roadmap and do the entire self-assessment yourself using the official guides — contractors do, and this series will keep showing you how the work is structured either way. If that's you, we mean it: run the tool, take the roadmap, go build.

The Turnkey CMMC Level 1 Compliance Package is the guided version of walking the same map. For $2,495/year (a limited-time $500 savings off the regular $2,995), it's the full method: all 15 practices broken into their 142 required artifacts, platform-specific templates for Microsoft 365 or Google Workspace, all 8 device and network configuration guides, the Evidence Locker for organized proof, SPRS reporting, your self-assessment packaged and date-stamped — plus 8 bi-weekly expert sessions so momentum never dies in week two. It's the difference between having a trail map and hiking with the person who drew it.

Which route you take matters less than this: the first 30 minutes are identical either way. Run the assessment. Everything else follows from the map.

Start With the Map. Add the Guide If You Want One.

Run the free assessment first — then bring your gap report to a free 30-minute kickoff and we'll help you turn it into a plan.

Run the Free Assessment Book a Free 30-Minute Kickoff

This Is Part 1 of 6. Here's Where the Series Goes.

The stall ends with a starting point — that was this piece's job. The next five show, concretely, how the rest of the work gets done:

  1. Your L1 Self-Assessment Starts This Week — you are here.
  2. 15 Practices, 142 Artifacts — the anatomy of an L1 self-assessment with a map: how vague requirements become a checkable task list.
  3. The Settings Are the Evidence — the device and network configuration half of L1, and why you don't need an IT department for it.
  4. From Folder Chaos to a Date-Stamped Package — how the finished assessment comes together, and what "done" looks like in your hands.
  5. The Part-Time CUI Enclave — for contractors who handle CUI: how small businesses approach Level 2 without enterprise IT.
  6. Finish Before the Report — the sprint plan that's right in every Task Force outcome.

One piece every few days between now and the Task Force report. By the time the industry wakes back up, you'll have seen the entire method — and if you started this week, you may simply be done.

The quiet won't last. Use it.

About the Author

Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small to medium defense contractors, and the author of CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors (available on Amazon in Kindle, paperback, and hardcover). He works with 5- to 50-employee GovCon firms on right-sized compliance. He's based in the Kansas City area.

Sources

  • Department of War, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026) — war.gov
  • U.S. Small Business Administration, statement on the CMMC Phase II suspension (July 13, 2026) — sba.gov
  • SBA Office of Advocacy, "DoW Requests Information for CMMC Reform Task Force" (July 20, 2026) — advocacy.sba.gov
  • NIST SP 800-171 Rev. 2, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" — csrc.nist.gov

Overwatch Tools · CMMC Compliance Specialists · Chesapeake, Virginia · info@overwatchtools.com

Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
60 Days Out: The Move That&#82...
60 Days Out: The Move That's Right No Matter What the Task Force Decides
15 Practices, 142 Artifacts: The Anatomy of an L1 Self-Assessment With a Map
15 Practices, 142 Artifacts: T...

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool