CMMC Guide · Level 1

CMMC Level 1: Requirements, Self-Assessment and Affirmation

CMMC Level 1 applies to companies that handle Federal Contract Information (FCI) but no CUI. It requires the 15 basic safeguarding requirements of FAR 52.204-21, a self-assessment every year with results entered in SPRS, and an annual affirmation by a senior official. Every requirement must be met; there is no partial credit.

Level 1 at a glance

Who needs it
Contractors and subcontractors that handle FCI only
Requirements
15, from FAR 52.204-21(b)(1)
Assessment
Self-assessment by your company, every year
To pass
All 15 requirements met; no plan of action allowed
Reporting
Results and affirmation in SPRS before contract award
Evidence
Keep for six years

What are the 15 Level 1 requirements?

They are basic cyber hygiene, grouped here by the six security areas they belong to:

AreaWhat you must do
Access control (4)Allow only authorized users, processes and devices; limit what each user can do; control connections to outside systems; control what is posted on public systems.
Identification and authentication (2)Identify every user, process and device, and verify their identity before granting access.
Media protection (1)Sanitize or destroy media holding FCI before disposal or reuse.
Physical protection (2)Limit physical access to authorized people; escort visitors, keep access logs and manage keys, badges and other access devices.
System and communications protection (2)Monitor and protect your network boundaries; keep public-facing systems separate from internal networks.
System and information integrity (4)Fix flaws promptly; use malware protection, keep it updated and scan files from outside sources.

Why some sources say 17: the physical access requirement is assessed as three separate items, so older materials counted 17 “practices.”

How does the Level 1 self-assessment work?

  1. Define the scope

    List the systems, people and locations that store, process or transmit FCI.

  2. Assess each requirement

    Check every requirement against the objectives in NIST SP 800-171A and collect the evidence that shows it is met.

  3. Fix any gaps first

    All 15 must be met. Unlike Levels 2 and 3, Level 1 does not allow a plan of action for open items.

  4. Record and affirm in SPRS

    Enter the result, scope and CAGE codes in SPRS. Your Affirming Official, a senior representative of the company, confirms continuing compliance.

  5. Repeat every year

    Reassess and affirm annually, and keep the assessment evidence for six years.

Questions about CMMC Level 1

Does Level 1 require an outside assessor?

No. Level 1 is always a self-assessment performed by your company. You can use outside help to prepare, but the result is your company’s own representation to the government.

What if we cannot meet one of the 15 requirements?

You cannot claim Level 1 until all 15 are met, and a contract requiring Level 1 cannot be awarded without it. Fix the gap, then complete the self-assessment and affirmation.

Who signs the Level 1 affirmation?

The Affirming Official: a senior representative responsible for the company’s CMMC compliance who has the authority to attest to it. The affirmation is entered in SPRS every year.

Handle FCI? Let’s make Level 1 simple.

CMMCMARK helps small and mid-size contractors meet Level 1 quickly and keep it current every year.

Prefer the phone? Call +1 (202) 867-8444.

Sources