Here's the question almost every small contractor asks first, usually phrased something like: "The compliance stuff only applies to the two of us who actually open the government files, right?" It's a reasonable guess. It's also the single most common scoping mistake at Level 1, and getting it wrong quietly leaves a chunk of your business outside a boundary that's supposed to include it.
The short answer: no. CMMC Level 1 isn't scoped by how many people touch Federal Contract Information (FCI). It's scoped by system. This guide explains what that actually means, why 11 of the 15 requirements have nothing to do with headcount, and how to draw a boundary that's honest without swallowing your whole company.
The clause scopes by "covered contractor information system"
The requirements come from FAR 52.204-21, and the clause is explicit about what it protects: a covered contractor information system - any information system that is owned or operated by a contractor and that processes, stores, or transmits Federal Contract Information. Notice what defines the boundary there. Not people. Systems. If a laptop, a phone, a file server, an email account, or a stack of paper travelers holds FCI, that thing is in scope, regardless of how many hands it passes through.
This is why "it's just the office manager and me" doesn't shrink the requirement the way owners hope. Two people can generate FCI across a dozen systems and a whole building. The count of people is close to irrelevant; the count of systems and places is what defines the work.
The 4-of-15 breakdown
The cleanest way to see it: walk the 15 requirements and ask which ones are actually about users. Only four are.
| USER-SCOPED (4 of 15) | SYSTEM- AND FACILITY-SCOPED (11 of 15) |
|---|---|
| 1. Limit access to authorized users 2. Limit access to what the job needs 5. Identify users 6. Authenticate before access | 3. Control external connections 4. Control what goes public 7. Sanitize media before disposal 8. Limit physical access 9. Escort visitors, keep logs 10. Control the internet boundary 11. Separate public systems 12. Fix flaws timely 13-14. Malware protection, updated 15. Scan periodically and in real time |
The four on the left are the ones where "which people" matters - who's authorized, what each person can reach, whether everyone has their own login, whether they authenticate. The eleven on the right are about your equipment and your building. A firewall, a patch routine, a visitor log, a media-wipe habit - none of those get smaller because only two employees open contract files. They apply to the systems and the facility, full stop. The complete plain-English walk-through of all 15 is in the requirements guide.
Why Requirement 9 applies to your building even with two FCI users
Requirement 9 - escort visitors, log visits, track who holds keys and door codes - is the one that makes the point cleanest. It doesn't ask how many people use FCI. It asks whether your facility, the place where FCI-bearing systems and paper live, is controlled. A two-person shop with a server in the back room and a front door that any vendor can wander through has a Requirement 9 gap, and the headcount has nothing to do with it. The building is in scope because the systems are in the building.
The field-work trap
This is where field-heavy businesses - restoration, construction, logistics, facilities services, installation - get caught, and it's worth spelling out because the exposure is invisible until someone names it.
Picture a small commercial installation company - the kind that mounts equipment and fixtures on government sites. Two people in the office handle the contract paperwork. But the field crews get their work orders, site photos, punch lists, and delivery schedules pushed to their phones and tablets - and a lot of that is government job information. Every one of those devices is now a system that processes and stores FCI. They're inside the boundary. The owner, picturing "the two of us in the office," has a scope that's actually a dozen phones spread across three counties.
If job information for government work reaches phones, tablets, or laptops in the field, those devices are in scope until you deliberately build them out of it. The field isn't automatically outside the boundary - it's inside by default, and it takes real decisions to change that.
How to actually shrink the boundary
The good news is that scope isn't fixed - you can make it smaller on purpose, which makes the whole assessment easier. Three moves do most of the work:
- Restricted libraries. Put FCI in specific, permission-controlled folders or SharePoint sites instead of letting it spread across every shared drive. When FCI lives in one defined place, the systems around it that never see FCI can be argued out of scope.
- Defined groups. Give FCI access to named roles, not "everyone who's logged in." This is Requirement 2, and it's also a scoping tool - the tighter the group, the cleaner the boundary.
- Deliberate exclusion. Decide, in writing, that certain systems don't handle FCI - and then actually keep FCI off them. A field-crew app that only ever gets your own internal instructions, never government-provided drawings or scopes, can sit outside the boundary. But that only holds if the exclusion is real and enforced, not just hoped for.
Why the Requirement 2 fix and the scoping fix are the same fix
Here's the part that ties it together. When you scope FCI into restricted libraries with defined access groups, you're doing two things at once: you're satisfying Requirement 2 (people reach only what their job needs), and you're drawing a tight boundary that keeps the other systems out of scope. The permission architecture is the scope decision. Get it right and you close a requirement and shrink your assessment in the same afternoon. Get it wrong - FCI mixed in with everything, everyone able to open everything - and you've both failed Requirement 2 and pulled your entire environment into scope. One fix, two payoffs. It's the highest-leverage move at Level 1.
Want a fast read on where your boundary stands today? The free 5-question check samples the 15 and gives you a grade in about three minutes, no email to start. If you're not even sure Level 1 is your level, start with Level 1 vs Level 2; if you know it is, the five most common gaps are where most shops find their scope problems hiding.
Where does your shop stand right now?
Five yes/no questions, instant grade, no email required. Know before you're asked.
Take the free 5-question check