CMMC Level 1: The Federal Mandate You Can’t Ignore
On November 10, 2025, a new DoD rule took effect [1]. It implements the CMMC – Cybersecurity Maturity Model Certification program. For building automation contractors working on federal facilities, this changes contracting eligibility right now.
The short version
CMMC is a tiered cybersecurity certification framework. The DoD will require contractors to demonstrate a certification level — 1, 2, or 3 — as a condition of award.
This applies to contracts that involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The rollout is phased over four years. As of November 10, 2025, CMMC requirements began appearing in new DoD solicitations [2].
CMMC Level 1 (Foundational)
This applies to contractors handling FCI but not CUI. It implements 15 basic safeguarding practices from FAR 52.204-21. The practice families are:
- Access control
- Identification and authentication
- Media protection
- Physical protection
- System and communications protection
- System and information integrity
Compliance happens through annual self-assessment. You post results in the Supplier Performance Risk System (SPRS). In addition, you must affirm continuous compliance annually [3]. One key note: Plans of Action and Milestones (POA&Ms) are not allowed at Level 1. Every practice must be fully implemented.
CMMC Level 2 (Advanced)
This applies to contractors handling CUI. It implements the 110 practices in NIST SP 800-171. Most Level 2 contracts will require third-party assessment by a Certified Third-Party Assessor Organization (C3PAO).
CMMC Level 3 (Expert)
This applies to contractors handling CUI at the highest sensitivity. It adds practices from NIST SP 800-172. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) does the assessment.
Why this matters for building controls work
A surprising amount of BAS work on military installations touches FCI. For example: drawings, equipment lists, security-sensitive operational information, network topology diagrams.
Without CMMC certification at the right level, a contractor becomes ineligible for the contract. Period. The rule also applies through the supply chain. Prime contractors must flow down CMMC requirements to subcontractors handling FCI or CUI.
What should Facility teams do now
If you manage a federal facility, your acquisition team will write CMMC requirements into new solicitations. So talk to your contracting officer about which level applies to building controls.
For most BAS retrofit and service contracts that don’t directly touch CUI, Level 1 will be the requirement. Contractors who can’t show Level 1 self-assessment will be excluded.
What should Primes do now
If you’re a mechanical prime or GC bidding on federal work, ask your controls subcontractor where they are on CMMC. “We’re getting around to it” isn’t an answer. “We’ve completed our self-assessment and posted results in SPRS” is.
Signet’s status
We’ve delivered controls work on California’s federal installations since 2008. Specifically: Vandenberg SFB, Naval Base Ventura County, Camp Roberts, and Fort Hunter Liggett. Also USAG Stuttgart and USAG Wiesbaden internationally.
Today, Signet is pursuing CMMC Level 1 certification. This maintains DoD contracting eligibility for federal facilities and the primes who serve them. See our Federal-Ready page for details.
| Talk to Signet Controls. Planning a BAS install, retrofit, integration, or service contract in California? We work across Los Angeles, Orange County, the Inland Empire, the Central Coast, and Kern County. Reach our team at info@signetcontrols.com or call (877) 874-4638. |
References
[1] Morgan Lewis — DOD Finalizes CMMC Rules — https://www.morganlewis.com/pubs/2025/10/dod-finalizes-cmmc-rules-adding-cybersecurity-and-false-claims-act-compliance-risks
[2] Holland & Knight — CMMC Goes Live — https://www.hklaw.com/en/insights/publications/2025/09/cmmc-goes-live-new-cybersecurity-requirements
[3] CMMC Dashboard — Level 1 Requirements — https://cmmcdashboard.com/blog/cmmc-level-1-requirements-fci-compliance
[4] ISI Security — CMMC Levels Guide — https://isidefense.com/cmmc-levels