Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

What is CMMC Level 1?

CMMC Level 1 is the foundational cybersecurity level requiring defense contractors to implement 15 basic safeguarding practices to protect Federal Contract Information (FCI). Unlike higher CMMC levels, Level 1 allows contractors to verify compliance through annual self-assessments without third-party audits.

CMMC Level 1 establishes baseline cyber hygiene standards for any defense contractor handling non-public contract information.

According to 32 CFR 170.15, organizations must “complete and achieve a MET result for all security requirements specified in § 170.14(c)(2) to achieve the CMMC Status of Final Level 1 (Self)” Legal Information Institute. This means achieving 100% compliance—no exceptions or partial credit allowed.

This guide explains what CMMC Level 1 is, who needs it, the 15 required security practices, how to conduct your self-assessment, and the annual compliance obligations.

Understanding CMMC Level 1 Basics

What Information Does Level 1 Protect?

CMMC Level 1 focuses exclusively on protecting Federal Contract Information (FCI)—not the more sensitive Controlled Unclassified Information (CUI) that triggers Level 2 or 3 requirements.

Federal Contract Information is defined as “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments” Federal Register.

Federal Contract Information (FCI) includes contract specifications, technical drawings, pricing information, delivery schedules, and other non-public contract details.

Examples of FCI include:

  • Contract statements of work
  • Technical specifications and requirements
  • Pricing proposals and cost data
  • Delivery schedules
  • Performance reports
  • Engineering drawings for contract deliverables

Who Needs CMMC Level 1?

Any organization that processes, stores, or transmits FCI only under a Department of Defense contract or subcontract must comply with CMMC Level 1 requirements Secureframe.

Level 1 applies to:

  • Prime contractors handling only FCI (no CUI)
  • Subcontractors at all tiers with FCI-only contracts
  • Small businesses working on DoD contracts
  • All company sizes—no exemptions based on revenue or employee count

DoD estimates this will apply to approximately 63% of the Defense Industrial Base, representing roughly 220,000 companies Etactics.

Important: If your contract involves CUI, you need Level 2 or Level 3—not Level 1. Most modern DoD contracts involving technical data or sensitive information require Level 2.

The 15 CMMC Level 1 Security Requirements

CMMC Level 1 security requirements are “the 15 Level 1 requirements listed in the 48 CFR 52.204-21(b)(1)” eCFR—the Federal Acquisition Regulation clause for basic safeguarding.

FAR 52.204-21 is the federal contract clause titled “Basic Safeguarding of Covered Contractor Information Systems” that has been required in DoD contracts since 2016.

The 15 requirements are organized into six security domains:

Domain 1: Access Control (3 requirements)

  1. Limit system access to authorized users – Only approved individuals can access information systems
  2. Limit system access to authorized transactions – Users can only perform functions they’re permitted to execute
  3. Control connections to external systems – Verify and limit connections to systems outside your control

Access control means restricting who can view or use resources in a computing environment.

Domain 2: Identification and Authentication (2 requirements)

  1. Identify system users and devices – Unique identification for every user, process, and device
  2. Authenticate users, processes, and devices – Verify identities before granting access

Authentication is the process of verifying that someone or something is who or what they claim to be, typically through passwords, biometrics, or multi-factor authentication.

Domain 3: Media Protection (2 requirements)

  1. Sanitize or destroy media – Properly erase or physically destroy media containing FCI before disposal or reuse
  2. Protect FCI at rest and in transit – Safeguard information on both physical and digital media during storage and transmission

Media protection involves securing physical and digital storage devices like hard drives, USB drives, backup tapes, and removable media.

Domain 4: Physical Protection (1 requirement)

  1. Limit physical access – Restrict physical access to information systems, equipment, and operating environments to authorized personnel only

This consolidated requirement includes:

  • Escorting visitors and monitoring visitor activity
  • Maintaining audit logs of physical access
  • Controlling and managing physical access devices

Domain 5: System and Communications Protection (2 requirements)

  1. Monitor and control communications at external boundaries – Track and restrict data flowing in and out of your network
  2. Implement network segmentation – Separate publicly accessible system components from internal organizational systems

Network segmentation divides a computer network into smaller parts to improve security and performance by limiting how far threats can spread.

Domain 6: System and Information Integrity (5 requirements)

  1. Identify and manage system vulnerabilities – Timely detection, reporting, and correction of information system flaws
  2. Deploy malware protection – Provide anti-malware protection at appropriate system locations
  3. Update malware protections – Keep malware protection mechanisms current
  4. Perform periodic malware scans – Conduct regular scans of information systems
  5. Monitor security alerts and advisories – Act on security alerts and patch critical vulnerabilities promptly

CMMC Level 1 Assessment Objectives

Each of the 15 requirements contains multiple assessment objectives that break down exactly what must be implemented.

Level 1 includes “15 requirements and 58 assessment objectives” that must all be fully implemented Secureframe.

Assessment objectives are specific, testable statements describing how to evaluate whether a security requirement has been properly implemented.

The Level 1 self-assessment must be performed “using the objectives defined in NIST SP 800-171A Jun2018 (incorporated by reference) for the security requirement that maps to the CMMC Level 1 security requirement” eCFR.

For example, the requirement “Limit system access to authorized users” contains multiple objectives:

  • Verify access authorizations are documented
  • Confirm account management procedures exist
  • Validate that accounts are reviewed periodically
  • Check that access is removed when no longer needed

Critical Point: Since each of the 15 Level 1 requirements and 58 assessment objectives must be fully implemented to achieve a CMMC Status of Final Level 1 (Self), there is no Plan of Action and Milestones (POA&M) allowed at this level Secureframe.

This means you cannot achieve Level 1 status with any unmet requirements—everything must be fully implemented before your self-assessment.

How CMMC Level 1 Self-Assessment Works

Unlike Level 2 and Level 3, Level 1 does not require third-party certification—you assess yourself.

Self-Assessment Process

The OSA must conduct a Level 1 self-assessment scored in accordance with the CMMC Scoring Methodology. No POA&Ms are permitted for CMMC Level 1. The OSA must conduct a self-assessment and submit assessment results in SPRS Legal Information Institute.

OSA stands for Organization Seeking Assessment—the company conducting the CMMC evaluation.

Step 1: Define Your Assessment Scope

Identify all systems that process, store, or transmit FCI:

  • Computers and workstations
  • Servers and data storage
  • Network equipment
  • Mobile devices
  • Cloud services
  • Email systems

Step 2: Evaluate Each Requirement

To conduct the self-assessment, you must assess each of the 15 requirements and 58 assessment objectives and determine whether each has been MET, NOT MET, or is NOT APPLICABLE Secureframe.

For each assessment objective, you determine:

  • MET: The objective is fully satisfied with documented evidence
  • NOT MET: The objective is not satisfied
  • NOT APPLICABLE: The objective doesn’t apply to your environment

Step 3: Achieve 100% Compliance

All 15 requirements must be MET. A single NOT MET finding means you haven’t achieved Level 1 status and cannot submit your assessment to SPRS.

Step 4: Document Your Evidence

The artifacts used as evidence for the assessment must be retained by the OSA for six (6) years from the CMMC Status Date eCFR.

Artifacts are documented evidence demonstrating that security controls have been implemented, such as policies, procedures, configuration screenshots, logs, or test results.

Keep evidence including:

  • Security policies and procedures
  • Configuration screenshots
  • Access control lists
  • Malware scan logs
  • Patch management records
  • Training records

Submitting Results to SPRS

Once you’ve achieved 100% compliance, you submit your results to the Supplier Performance Risk System.

SPRS (Supplier Performance Risk System) is the DoD’s authoritative database where contractors report cybersecurity assessment results and CMMC status.

Prior to award of any contract or subcontract with a requirement for the CMMC Status of Level 1 (Self), OSAs must both achieve a CMMC Status of Level 1 (Self) and have submitted an affirmation of compliance into SPRS for all information systems within the CMMC Assessment Scope Legal Information Institute.

Submission requirements:

  • Upload your Level 1 self-assessment results
  • Report MET status for all requirements
  • Include all applicable CAGE codes
  • Submit executive affirmation of compliance

CAGE Code (Commercial and Government Entity Code) is a unique identifier assigned to suppliers doing business with the federal government.

The Affirming Official Requirement

A senior company official must affirm your compliance.

Affirmation of the Level 1 (Self) CMMC Status is required for all Level 1 self-assessments. Affirmation procedures are set forth in § 170.22 Legal Information Institute.

Affirming Official is a senior-level representative with authority to attest to your organization’s continuing compliance with CMMC requirements.

The Affirming Official:

  • Must be a senior executive with authority
  • Personally certifies compliance
  • Assumes responsibility for accuracy
  • Faces potential False Claims Act liability for false attestations

Annual Compliance Requirements for Level 1

CMMC Level 1 is not a one-time certification—it requires ongoing maintenance.

Annual Self-Assessment Requirement

“To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS” Legal Information Institute.

This means every year you must:

  1. Re-evaluate all 15 requirements and 58 assessment objectives
  2. Verify continued compliance (all MET)
  3. Submit updated results to SPRS
  4. Submit fresh affirmation of compliance

Timeline: Your annual self-assessment is due one year from your CMMC Status Date (the date you first achieved Level 1 status).

Maintaining Continuous Compliance

Between annual assessments, you must continuously maintain your security controls:

  • Keep malware protections updated
  • Monitor and patch vulnerabilities
  • Maintain access controls
  • Document any changes to systems
  • Retain evidence for 6 years

If you lose compliance during the year (a control fails), you must remediate immediately to maintain your CMMC Status.

CMMC Level 1 vs Level 2: Key Differences

Understanding the difference between Level 1 and Level 2 helps determine which level you need.

Critical Decision Point: If your contract involves CUI (technical data, export-controlled information, etc.), you need Level 2, not Level 1. Most contractors working on weapon systems, research, or sensitive programs require Level 2.

Common CMMC Level 1 Implementation Challenges

While Level 1 is the “basic” level, contractors still face implementation challenges.

Challenge 1: Identifying FCI Throughout Your Environment

Many contractors struggle to identify all locations where FCI exists:

  • Email attachments
  • Shared drives
  • Employee laptops
  • Cloud storage accounts
  • Backup systems

Solution: Conduct a comprehensive data flow analysis mapping where FCI enters, moves through, and exits your organization.

Challenge 2: No POA&M Flexibility

No POA&Ms are permitted for CMMC Level 1 Legal Information Institute—you cannot achieve certification with any unmet requirements.

This means you must fully implement all controls before submitting your assessment, unlike Level 2 where you can achieve Conditional Status with a plan to fix deficiencies.

Challenge 3: Annual Compliance Burden

Repeating the full assessment every year requires ongoing effort:

  • Staff time for annual evaluation
  • Evidence collection and retention
  • Documentation updates
  • SPRS submission process

Challenge 4: Artifact Retention Requirements

Artifacts used as evidence must be retained for six (6) years from the CMMC Status Date eCFR. This creates long-term storage and organization requirements.

When Level 1 Compliance is Required

CMMC Level 1 becomes a contract requirement under the phased implementation timeline.

Phase 1 of the CMMC rollout commenced November 10, 2025, when DoD began including requirements for Level 1 (Self) or Level 2 (Self) for applicable DoD solicitations and contracts as a condition of contract award Etactics.

Starting November 10, 2025:

  • New contracts with FCI requirements include Level 1 clause
  • Cannot be awarded without valid CMMC Status in SPRS
  • Subcontractors must also achieve Level 1 for flow-down
  • Option period exercises may require Level 1

Third-Party Assistance with Level 1

Although Level 1 is a self-assessment, you can get help.

OSAs can choose to perform the annual self-assessment internally or engage a third party to assist. Use of a third party to assist is still considered a self-assessment and does not result in a certification Cmmcwiki.

Third parties can help with:

  • Gap assessments to identify deficiencies
  • Implementation guidance for security controls
  • Policy and procedure development
  • Evidence collection and organization
  • SPRS submission assistance

CMMC Registered Provider Organizations (RPOs) are companies authorized by the Cyber Accreditation Body to provide CMMC preparation and advisory services.

Key Takeaways: What is CMMC Level 1?

CMMC Level 1 establishes fundamental cybersecurity standards for defense contractors handling Federal Contract Information:

15 basic security requirements from FAR 52.204-21
58 assessment objectives that must all be MET
Annual self-assessment—no third-party certification required
100% compliance required—no POA&Ms allowed
Submit to SPRS with executive affirmation
Applies to ~63% of DIB (contractors handling FCI only)
Required starting November 10, 2025 for new contracts
6-year evidence retention requirement

CMMC Level 1 may be “basic,” but achieving and maintaining compliance requires serious commitment to implementing cybersecurity fundamentals and annual verification of continued compliance.


Related Articles:

Official Sources: This article is based on 32 CFR 170.15 “CMMC Level 1 self-assessment and affirmation requirements,” FAR 52.204-21 “Basic Safeguarding of Covered Contractor Information Systems,” and the DoD CMMC Level 1 Self-Assessment Guide, published by the Department of Defense Chief Information Officer.

Table of Contents