CMMC Guide · Level 1
CMMC Level 1: Requirements, Self-Assessment and Affirmation
CMMC Level 1 applies to companies that handle Federal Contract Information (FCI) but no CUI. It requires the 15 basic safeguarding requirements of FAR 52.204-21, a self-assessment every year with results entered in SPRS, and an annual affirmation by a senior official. Every requirement must be met; there is no partial credit.
Level 1 at a glance
- Who needs it
- Contractors and subcontractors that handle FCI only
- Requirements
- 15, from FAR 52.204-21(b)(1)
- Assessment
- Self-assessment by your company, every year
- To pass
- All 15 requirements met; no plan of action allowed
- Reporting
- Results and affirmation in SPRS before contract award
- Evidence
- Keep for six years
What are the 15 Level 1 requirements?
They are basic cyber hygiene, grouped here by the six security areas they belong to:
| Area | What you must do |
|---|---|
| Access control (4) | Allow only authorized users, processes and devices; limit what each user can do; control connections to outside systems; control what is posted on public systems. |
| Identification and authentication (2) | Identify every user, process and device, and verify their identity before granting access. |
| Media protection (1) | Sanitize or destroy media holding FCI before disposal or reuse. |
| Physical protection (2) | Limit physical access to authorized people; escort visitors, keep access logs and manage keys, badges and other access devices. |
| System and communications protection (2) | Monitor and protect your network boundaries; keep public-facing systems separate from internal networks. |
| System and information integrity (4) | Fix flaws promptly; use malware protection, keep it updated and scan files from outside sources. |
Why some sources say 17: the physical access requirement is assessed as three separate items, so older materials counted 17 “practices.”
How does the Level 1 self-assessment work?
Define the scope
List the systems, people and locations that store, process or transmit FCI.
Assess each requirement
Check every requirement against the objectives in NIST SP 800-171A and collect the evidence that shows it is met.
Fix any gaps first
All 15 must be met. Unlike Levels 2 and 3, Level 1 does not allow a plan of action for open items.
Record and affirm in SPRS
Enter the result, scope and CAGE codes in SPRS. Your Affirming Official, a senior representative of the company, confirms continuing compliance.
Repeat every year
Reassess and affirm annually, and keep the assessment evidence for six years.
Questions about CMMC Level 1
Does Level 1 require an outside assessor?
No. Level 1 is always a self-assessment performed by your company. You can use outside help to prepare, but the result is your company’s own representation to the government.
What if we cannot meet one of the 15 requirements?
You cannot claim Level 1 until all 15 are met, and a contract requiring Level 1 cannot be awarded without it. Fix the gap, then complete the self-assessment and affirmation.
Who signs the Level 1 affirmation?
The Affirming Official: a senior representative responsible for the company’s CMMC compliance who has the authority to attest to it. The affirmation is entered in SPRS every year.
Handle FCI? Let’s make Level 1 simple.
CMMCMARK helps small and mid-size contractors meet Level 1 quickly and keep it current every year.
Prefer the phone? Call +1 (202) 867-8444.
Sources
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- 32 CFR Part 170 (§ 170.15 Level 1 self-assessment, § 170.22 affirmation)
- Supplier Performance Risk System (SPRS)
