Cedar Ridge Machine Works, LLC
CMMC Level 1 Self-Assessment · FAR 52.204-21
- Cycle
- FY2026 Annual Affirmation
- Status
- attested
- SAM UEI
- CR7MHK9QX2P4
- CAGE code
- 9KX41
- Entity type
- Limited Liability Company
- NAICS codes
- 332710, 332721
- Generated
- June 19, 2026
- Approved
- 2026-06-15
- Affirmed
- 6/19/2026
1. System description and scope
Cedar Ridge Machine Works isolates all Federal Contract Information (FCI) inside a single Microsoft 365 Business Premium tenant, the Cedar Ridge Federal Programs enclave. Covered assets are twelve managed Windows 11 workstations, one shop floor estimating PC, the company file share in SharePoint Online, and Exchange Online mail. Quoting, drawings, and purchase orders tied to federal work live only in this tenant. The production CNC machines on the shop floor hold no FCI and are on a separate network with no inbound internet access.
2. Senior official affirmation
Raymond T. Cedar, Owner and President affirmed on June 19, 2026 that the information in this plan is accurate and that Cedar Ridge Machine Works, LLC implements all 15 CMMC Level 1 basic safeguarding requirements (FAR 52.204-21(b)(1)(i)-(b)(1)(xv); 59 NIST SP 800-171A assessment objectives) as described.
3. Implementation of the 15 safeguarding requirements
For each requirement, the narrative below describes how Cedar Ridge Machine Works, LLC implements the practice, with supporting evidence on file.
AC · Access Control
Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)
Only the five named Cedar Ridge staff who work federal jobs have accounts in the Federal Programs tenant. Accounts are created in Microsoft Entra ID by the owner, reviewed each quarter, and disabled the same day a person leaves. Shop floor machinists without a federal role have no access to this tenant.
- quarterly-access-review-q2.xlsx (6/5/2026)
Authorized users are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Processes acting on behalf of authorized users are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Devices (and other systems) authorized to connect are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
System access is limited to authorized users. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
System access is limited to processes acting on behalf of authorized users. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
System access is limited to authorized devices (including other systems). Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Limit information system access to the types of transactions and functions that authorized users are permitted to execute
Access follows least privilege. Estimators can open and edit quotes and drawings; the office admin can read but not change them; only the owner holds admin rights in Microsoft 365. Roles are documented in the access list kept in SharePoint and reviewed each quarter.
The transactions and functions authorized users are permitted to execute are defined. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
System access is limited to those defined transactions and functions. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Verify and control/limit connections to and use of external information systems
There are no public terminals or shared logins. The one shop floor estimating PC signs in with the same managed accounts and connects to the tenant over the company VPN only. No external system connects into the Federal Programs tenant.
Connections to external systems are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
The use of external systems is identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Connections to external systems are verified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
The use of external systems is verified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Connections to external systems are controlled / limited. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
The use of external systems is controlled / limited. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Control information posted or processed on publicly accessible information systems
Cedar Ridge has no public website posting area and no social accounts that publish federal work. The owner reviews the company site quarterly to confirm no drawings, quotes, or contract details are ever posted publicly.
Individuals authorized to post or process information on publicly accessible systems are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Procedures to ensure FCI is not posted or processed on publicly accessible systems are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
A review process exists prior to posting public content. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Public content is reviewed to ensure it does not include FCI. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Mechanisms exist to remove and address improper posting of FCI. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
IA · Identification & Authentication
Identify information system users, processes acting on behalf of users, or devices
Every user has a unique named account in Microsoft Entra ID. Shared or generic logins are not permitted. Devices are enrolled in Intune and identified by the company before they are allowed to connect.
System users are identified (unique IDs). Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Processes acting on behalf of users are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Devices accessing the system are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems
All accounts require a password meeting the company policy plus multi factor authentication through Microsoft Authenticator. MFA is enforced by a Conditional Access policy for every user in the tenant, verified in the admin center screenshot on file.
- entra-mfa-conditional-access.png (6/10/2026)
Each user's identity is authenticated before system access. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Each process acting on behalf of a user is authenticated before access. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Each device accessing the system is authenticated before access. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
MP · Media Protection
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse
Old drives and USB media are wiped or physically destroyed before disposal, logged on the media disposal register. Paper drawings and travelers tied to federal jobs are shredded on site. No federal media leaves the building intact.
- media-disposal-register.pdf (5/28/2026)
Media containing FCI is sanitized or destroyed before disposal. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Media containing FCI is sanitized before being released for reuse. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
PE · Physical Protection
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals
The office and server closet are locked, and only the owner and office admin hold keys. Workstations are in the controlled office area, not the open shop floor. The visitor policy keeps non employees out of areas where FCI is worked.
Authorized individuals allowed physical access are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Physical access to systems is limited to authorized individuals. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Physical access to equipment is limited to authorized individuals. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Physical access to operating environments is limited to authorized individuals. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Escort visitors and monitor visitor activity
Visitors sign in at the front office and are escorted at all times while inside. The escort requirement is posted at the entry and recorded in the visitor log kept at the front desk.
Visitors are escorted. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Visitor activity is monitored. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Maintain audit logs of physical access
The visitor log at the front desk records the name, company, date, time in, time out, and host for every visitor. The owner reviews it monthly and retains it as an audit record.
- visitor-log-may-2026.pdf (6/2/2026)
Audit logs of physical access are maintained. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Control and manage physical access devices
Physical keys are issued only to the owner and office admin and are tracked on the key register. The alarm code is changed when anyone with access leaves. Building access devices are limited to the two named staff.
Physical access devices are identified (keys, fobs, badges). Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Physical access devices are controlled. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Physical access devices are managed (issued, revoked, inventoried). Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
SC · System & Communications Protection
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems
The Federal Programs tenant sits behind Microsoft 365 boundary protection, and the office network is protected by a managed firewall. The shop floor CNC network is separated from the office network and has no inbound internet path. Remote access is only through the company VPN.
The external system boundary is defined. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Key internal system boundaries are defined. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Communications are monitored at the external boundary. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Communications are monitored at key internal boundaries. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Communications are controlled at the external boundary. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Communications are controlled at key internal boundaries. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Communications are protected at the external boundary. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Communications are protected at key internal boundaries. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks
The office guest Wi Fi is a separate network with no route to the Federal Programs systems. Publicly reachable services are not hosted on the internal network; the company website is hosted externally and holds no FCI.
Publicly accessible system components are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Publicly accessible subnetworks are physically or logically separated from internal networks. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
SI · System & Information Integrity
Identify, report, and correct information and information system flaws in a timely manner
Microsoft Defender and Windows Update for Business keep every managed workstation patched and current. Intune reports patch status, and the owner reviews the compliance dashboard weekly to confirm all covered devices are up to date.
- intune-patch-compliance.png (6/10/2026)
The time within which to identify system flaws is specified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
System flaws are identified within that time frame. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
The time within which to report system flaws is specified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
System flaws are reported within that time frame. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
The time within which to correct system flaws is specified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
System flaws are corrected within that time frame. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
Provide protection from malicious code at appropriate locations within organizational information systems
Microsoft Defender Antivirus runs on every managed workstation with real time protection on and enforced by Intune policy. The endpoint protection report on file shows all covered devices reporting healthy.
- defender-endpoint-health-report.pdf (6/10/2026)
Designated locations for malicious-code protection are identified. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Protection from malicious code at those locations is provided. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Update malicious code protection mechanisms when new releases are available
Defender definitions update automatically through Microsoft, so signatures stay current without manual work. The Intune report confirms every device has current protection updates.
Malicious-code protection mechanisms are updated when new releases are available. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed
Real time and scheduled scans run on every managed workstation, and downloads and email attachments are scanned as they arrive. Scan results feed the Defender dashboard the owner reviews weekly.
The frequency for malicious-code scans is defined. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: examine
Malicious-code scans are performed at that frequency. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: interview
Real-time scans of files from external sources are performed on download / open / execute. Confirmed during the annual self assessment and recorded in the System Security Plan.
Method: test
