Don’t Panic: The Truth About CMMC Artifact Inflation

Quick answer: CMMC Level 1 has 15 practices that break into 58 assessment objectives. Vendors inflate this to ~142 “items” by mapping each objective across three audit layers. Small businesses do not need 142 separate documents. A lean library of 8 to 12 consolidated policies, procedures, and registers can satisfy every objective, and hold up to scrutiny.

Your inbox probably looks a lot like mine: a steady stream of alarming emails from compliance software vendors. The latest one that caught my eye had a headline designed to make any small business owner spit out their morning coffee.

“Why 15 Practices Become 142 Artifacts.”

Read that once and your brain immediately pictures 142 separate Word documents and Excel spreadsheets sitting in a folder that you, a solo founder or lean team lead, now have to draft, sign, date, and update every single month. The panic sets in fast. “I thought I was almost ready for CMMC Level 1, but I only have a handful of policies. Am I missing 130 documents? Am I going to fail an assessment?”

Take a breath. You are not missing 130 documents. Here is the truth behind the marketing math, why vendors frame compliance this way, and how small GovCons can satisfy every single objective without drowning in paperwork.

The Kernel of Truth: Objective Math vs. File Count

To be fair to the vendors, they are not pulling numbers out of thin air. There is a real compliance mechanism behind the claim.

Under CMMC and NIST SP 800-171A, requirements are not evaluated as a simple yes/no checkbox. Each requirement breaks down into Assessment Objectives — discrete, evaluable conditions that assessors use to determine whether a control is actually implemented.

Here is how the math works:

  • CMMC Level 1 consists of 15 basic safeguarding requirements, derived from FAR 52.204-21.
  • When assessors evaluate those 15 practices, they apply 58 distinct assessment objectives.
  • When vendors map those objectives across three audit layers — Policy (what you decided), Procedure (how you do it), and Evidence (proof that you did it) — the “thing-to-check” count inflates to approximately 140 items.

A single control illustrates this clearly. Take basic Access Control (AC.L1-3.1.1: Limit system access to authorized users):

  • Policy layer: Do you define access rules and roles?
  • Procedure layer: Do you have documented steps for onboarding, offboarding, and authorizing devices?
  • Evidence layer: Can you show an active user list, a device inventory, approval logs, and dated access reviews?

One practice. Nine evaluation points. Multiply that decomposition across all domain practices, and you arrive at 142. The math is real. The interpretation vendors attach to it is where the problem starts.

Why Vendor-Induced Overhead Hurts Small Businesses

Here is where the marketing strategy becomes a trap for small businesses. Vendors want you to believe that 142 assessment objectives equal 142 separate files.

The reason is straightforward. If you believe you need 142 individual documents, managing them manually in Word or Excel sounds impossible. That is precisely when the vendor steps in with a $10,000-per-year platform to organize all 142 files and track every version.

The irony is that attempting to maintain 142 individual policy and procedure files creates exactly the kind of compliance failure it claims to prevent:

  • You spend more time managing document headers and revision tables than running your business or maintaining your actual security posture.
  • Version-control chaos becomes inevitable. Document 12 changes, but Document 114 does not get updated to match.
  • You fail an assessment because the assessor finds inconsistencies between documents, not because your controls are weak.

Volume is not evidence of compliance. Clarity and consistency are.

The Balanced Approach: Consolidation Over Volume

Assessors do not weigh your compliance by the megabyte. They evaluate three things: clarity, coverage, and consistency. A well-constructed, consolidated document set satisfies all three better than a fragmented folder of 142 loose files.

This is the core principle behind a Lean PAL — a Policy and Artifact Library built for small GovCons who need to be audit-ready without building a document management operation on the side.

Applied to the Access Control example from earlier, consolidation looks like this:

  • POL-AC-01 (Master Access Control Policy): One document that addresses all Policy-layer objectives for access control. Who can access what, and under what conditions.
  • SOP-AC-01 (Master Operational Procedure): One document that covers all Procedure-layer objectives. How you onboard users, how fast you revoke access when someone leaves, how you authorize hardware.
  • REG-AC-01 (Centralized Register): One living register that serves as the active evidence record — user rosters, device logs, approval dates, and quarterly review entries.

Three files instead of nine for a single control domain. Apply that consolidation logic across your full security program, and a small business can comfortably satisfy CMMC Level 1 using a streamlined set of approximately 8 to 12 master documents and active registers.

What a Lean PAL Actually Covers

A practical Lean PAL for CMMC Level 1 typically includes:

  • A Master System Security Plan (SSP) that ties your environment, scope, and controls together
  • Domain-level Master Policies (Access Control, Identification and Authentication, Media Protection, etc.)
  • Domain-level Master SOPs that describe how each control operates day-to-day
  • Active registers for users, devices, access reviews, and media handling
  • An incident log and configuration baseline document

That is it. The goal is a set of documents where every assessment objective has a clear home — and where an assessor can trace a claim from policy to procedure to evidence without hunting through a folder of 142 unconnected files.

Controls Still Matter: What Small Businesses Must Take Seriously

The point here is not to dismiss vendor emails as pure noise. The underlying message is legitimate. CMMC assessors do evaluate all 58 objectives, and your documentation needs to address each one. The lesson worth keeping is different from the one vendors want you to take away.

Do not measure readiness by document count. Having 50 documents does not mean you are compliant. It may just mean you are disorganized. A document that no one maintains and no one follows is not evidence of control — it is a liability.

Respect the assessment objectives when you write. A Master Access Control SOP that says “We limit access” will not pass. The SOP needs to explain specifically how you approve new users, how quickly you revoke access when someone leaves, and how you authorize hardware to connect to your environment. Specificity is what assessors are looking for.

Keep your data boundaries clear and documented. If you run a dual-environment setup — for example, Microsoft GCC High for government FCI and CUI alongside Google Workspace for commercial business development — your policies need to state explicitly where government data is allowed to live and where it is strictly prohibited. While full FedRAMP Moderate equivalency is legally driven by DFARS 252.204-7012 for CUI at Level 2, defining clean FCI boundaries right now at Level 1 prevents data spillage and simplifies your audit scope. Ambiguity in data boundaries is one of the most common assessment findings for small GovCons.

Make evidence collection a habit, not an event. Under CMMC Level 1, there are no POA&Ms allowed to defer missing controls; you must be 100% compliant. While the CMMC Assessment Process (CAP v2.0) allows a strict 10-business-day window during the assessment to cure minor deficiencies, relying on a last-minute scramble is a recipe for failure. A living Excel register updated on a defined quarterly cadence will outperform a chaotic folder of 100 loose screenshots every single time. Structured, dated, consistently formatted evidence signals an operating habit, not panic.

CMMC Level 1 Compliance Without the Drama

Small and micro-businesses in the defense supply chain have a real advantage when it comes to compliance: agility. A 200-person company may need months to align stakeholders and update 142 documents across three departments. A lean team can review and update 10 consolidated documents in an afternoon.

The goal is a security program that is lean, traceable, and consistently maintained. That means:

  • Clear ownership for each document and register
  • A defined review cadence (quarterly works well for most Level 1 controls)
  • Policies that match your actual operations, not a generic template
  • Evidence that accumulates naturally from daily work rather than being staged before an assessment

Compliance vendors sell complexity because complexity sells software. That is not cynicism — it is a business model. Your job as a small GovCon is to extract the useful signal from their messaging without buying into the overhead it implies.

Know your 58 assessment objectives. Consolidate your documentation into a lean, auditable library. Keep your registers current. You do not need 142 artifacts to pass CMMC Level 1. You need a program that works, and documentation that proves it.

Frequently Asked Questions

What is CMMC artifact inflation, and why does it happen?
Artifact inflation refers to the gap between the actual number of CMMC practices (15 for Level 1) and the number of documentation items vendors suggest you need (approximately 142). It happens because vendors decompose each practice into assessment objectives and then map those objectives across three audit layers — policy, procedure, and evidence — treating each layer as a separate document requirement. The math is technically grounded, but the document-per-item interpretation is a sales framing, not an assessment requirement.

How many documents does a small business actually need for CMMC Level 1?
A lean, well-structured library of approximately 8 to 12 master documents and active registers can satisfy all 58 assessment objectives under CMMC Level 1. The key is consolidation: one master policy per control domain, one master SOP per domain, and one active register per evidence category. Each document should be specific enough that an assessor can trace a claim from policy to procedure to proof without gaps.

What do CMMC assessors actually evaluate during a Level 1 assessment?
Assessors evaluate 58 assessment objectives derived from the 15 basic safeguarding requirements in FAR 52.204-21. For each objective, they look for three things: a documented policy decision (what you decided), a documented procedure (how you implement it), and traceable evidence (proof that you actually do it). Clarity, coverage, and consistency across those three layers matter more than document volume.

What is a System Security Plan (SSP) and do small businesses need one?
Yes. The SSP is a foundational document that describes your environment, the scope of your controlled information, and how each CMMC control is implemented. For small businesses, the SSP does not need to be a long or complex document. It needs to accurately reflect your actual environment and control implementation. Assessors use the SSP as a reference point for the entire assessment.

What are the most common CMMC compliance mistakes small GovCons make?
The most common mistakes include writing policies that do not match actual operations, assuming Level 1 permits Plans of Action & Milestones (POA&Ms) for missing controls (it does not — all 15 practices must be MET), leaving data boundaries undefined between commercial and gov tools, and over-engineering documentation to the point where version control becomes unmanageable. A lean, consistently maintained document set avoids all four. 

Is CMMC compliance software worth the cost for a small business?
It depends on your team size, contract scope, and document management discipline. For most small and micro-businesses pursuing CMMC Level 1, a well-organized set of 8–12 consolidated documents maintained in a secure, access-controlled environment (such as Microsoft GCC High or SharePoint) is completely sufficient. While FedRAMP Moderate or equivalent external cloud hosting becomes mandatory when handling CUI at CMMC Level 2, enterprise compliance management platforms add little value at Level 1 and often create unnecessary software overhead.

What does “audit-ready documentation” mean in practice?
Audit-ready documentation means your policies, procedures, and evidence records are current, consistent, and traceable without requiring last-minute updates or explanations. An assessor should be able to follow a control from your policy to your SOP to your evidence register without finding contradictions or gaps. Quarterly reviews and a defined update cadence are the most reliable way to maintain that standard over time.

Recent Blogs

WORK WITH OUR EXPERTS

Partner with an experienced team that combines discipline and innovation to deliver results.

Human Computing Volunteers & Supports