CMMC Level 1 is the floor of the Cybersecurity Maturity Model Certification: fifteen security requirements, self-assessed once a year, with an affirmation in SPRS and no Plan of Action and Milestones allowed. It applies to any Department of Defense contractor or subcontractor whose information systems process, store or transmit Federal Contract Information, which is most of the defense industrial base, and it is the one CMMC level the July 2026 suspension did not touch — Phase 1 self-assessment requirements remain in force. This guide sets out the fifteen requirements as 32 CFR Part 170 lists them, how each maps to NIST SP 800-171A, what the self-assessment and affirmation involve, and why a single NOT MET result fails the whole thing.

Who needs CMMC Level 1
The CMMC program rule at 32 CFR 170.3 applies to all DoD contract and subcontract awardees that will process, store or transmit information meeting the standards for FCI or CUI on contractor information systems. Level 1 is the status for FCI: information provided by or generated for the government under contract that is not intended for public release, which the FAR defines at 52.204-21. If a contract involves CUI, Level 2 applies instead. A contractor with FCI-only systems needs Level 1; a contractor with a mixed environment may scope Level 1 to the FCI systems and Level 2 to the CUI systems.
The status is required before award. Under 32 CFR 170.15(b), “prior to award of any contract or subcontract with a requirement for the CMMC Status of Level 1 (Self), OSAs must both achieve a CMMC Status of Level 1 (Self) and have submitted an affirmation of compliance into SPRS for all information systems within the CMMC Assessment Scope”. Subcontractors carry the same obligation when FCI flows down to them. Our guide to CMMC compliance and the phased rollout covers where Level 1 sits in the timeline.
The 15 CMMC Level 1 requirements
Level 1 incorporates the fifteen basic safeguarding requirements of FAR 52.204-21(b)(1). The CMMC rule numbers them by family and FAR paragraph, and 32 CFR 170.15(c)(1)(ii) maps each to the NIST SP 800-171 requirement whose 800-171A assessment objectives are used to assess it — with FCI substituted wherever the objective says CUI.
| CMMC ID | Requirement (FAR 52.204-21(b)(1)) | Assessed with 800-171A objectives for |
|---|---|---|
| AC.L1-b.1.i | Limit system access to authorized users, processes acting on their behalf, and devices | 3.1.1 |
| AC.L1-b.1.ii | Limit access to the types of transactions and functions authorized users are permitted to execute | 3.1.2 |
| AC.L1-b.1.iii | Verify and control connections to and use of external information systems | 3.1.20 |
| AC.L1-b.1.iv | Control information posted or processed on publicly accessible systems | 3.1.22 |
| IA.L1-b.1.v | Identify users, processes and devices | 3.5.1 |
| IA.L1-b.1.vi | Authenticate the identities of those users, processes and devices before allowing access | 3.5.2 |
| MP.L1-b.1.vii | Sanitize or destroy media containing FCI before disposal or reuse | 3.8.3 |
| PE.L1-b.1.viii | Limit physical access to systems, equipment and operating environments to authorized individuals | 3.10.1 |
| PE.L1-b.1.ix | Escort visitors and monitor visitor activity; maintain audit logs of physical access; control and manage physical access devices | 3.10.3, 3.10.4, 3.10.5 |
| SC.L1-b.1.x | Monitor, control and protect communications at external boundaries and key internal boundaries | 3.13.1 |
| SC.L1-b.1.xi | Implement subnetworks for publicly accessible components, separated from internal networks | 3.13.5 |
| SI.L1-b.1.xii | Identify, report and correct information system flaws in a timely manner | 3.14.1 |
| SI.L1-b.1.xiii | Provide protection from malicious code at appropriate locations | 3.14.2 |
| SI.L1-b.1.xiv | Update malicious code protection mechanisms when new releases are available | 3.14.4 |
| SI.L1-b.1.xv | Perform periodic scans of systems and real-time scans of files from external sources | 3.14.5 |
Note the ninth requirement. The FAR wrote visitor escort, physical access logs and physical access devices as one clause; NIST split it into three requirements when 800-171 was written, so PE.L1-b.1.ix is assessed against three sets of objectives. There are fifteen CMMC requirements but seventeen 800-171 requirements behind them, which is why older material sometimes says “17 practices”.
How the CMMC Level 1 self-assessment works
Scope first
32 CFR 170.19(b) requires the assessment scope to be specified before the self-assessment. Systems that process, store or transmit FCI are in scope. Two categories are out: systems that do not handle FCI at all, including an endpoint running a VDI client that allows nothing beyond keyboard, video and mouse; and Specialized Assets — IoT, IIoT, OT, government-furnished equipment, restricted information systems and test equipment — which can handle FCI but are unable to be fully secured, and are excluded from Level 1 scope entirely. There are no documentation requirements for out-of-scope assets at Level 1, but the scope statement itself goes into SPRS. Our guide to CMMC scoping covers the Level 2 categories, which are more demanding.
Assess every requirement against the 800-171A objectives
The self-assessment is performed “using the objectives defined in NIST SP 800-171A” for the mapped requirement. Each objective is MET, NOT MET or, where the requirement genuinely does not apply, NOT APPLICABLE. A requirement is MET only when all of its objectives are. The Level 1 assessment is scored under the CMMC scoring methodology in 170.24, but the scoring is binary in effect: 170.15(a)(1) says the OSA “must complete and achieve a MET result for all security requirements” to achieve Final Level 1 (Self).
No POA&M, ever
Section 170.21(a)(1) is one sentence: “A POA&M is not permitted at any time for Level 1 self-assessments.” There is no Conditional Level 1. A single NOT MET means the organization does not have the status and cannot affirm it; fix it, re-assess, then submit.
Submit to SPRS and affirm
The results go into the Supplier Performance Risk System with, at minimum, the CMMC level, the CMMC Status Date, the assessment scope, all CAGE codes associated with the in-scope systems, and the compliance result. A senior official then affirms continuing compliance under 170.22. Both the self-assessment and the affirmation repeat annually; the status lapses if either is missed.
Keep the artifacts
The rule requires the OSA to retain the artifacts used as evidence for the self-assessment for six years from the CMMC Status Date. Screenshots, configuration exports, policy documents and the completed objective-by-objective worksheet are the record a DCMA DIBCAC review would ask for under DFARS 252.204-7020, which the rule reserves the right to conduct.
Where CMMC Level 1 self-assessments go wrong
- Treating the fifteen as fifteen. Assessed properly there are dozens of 800-171A objectives behind them. PE.L1-b.1.ix alone has three requirements’ worth. Assess the objectives, not the headings.
- Scoping by convenience. FCI lives in email, shared drives and project tools, not only in the “contract system”. If FCI reaches a laptop, the laptop is in scope.
- Marking a requirement NOT APPLICABLE to avoid a NOT MET. SC.L1-b.1.xi (a DMZ for public-facing components) is NOT APPLICABLE only if there are no publicly accessible system components; a public web server hosted internally makes it applicable.
- Forgetting the affirmation. Submitting results without the senior official’s affirmation leaves the organization ineligible for award under 170.15(b).
- Assuming Level 1 is enough for CUI. Any contract involving CUI requires Level 2, which is the same 110 requirements as NIST SP 800-171 Rev 2 and which the CMMC vs NIST 800-171 guide explains.
What the 2026 suspension changed for Level 1
Nothing. On 13 July 2026 the Department of War suspended the transition to Phase 2 — the point at which C3PAO certification would have entered Level 2 contracts — and launched a review of the program. The suspension memo is explicit that “DFARS 252.204-7012 and CMMC Phase I self-assessment requirements remain unaffected”, and Cyber AB confirmed that all program elements remain operational. Level 1 self-assessments, SPRS submissions and annual affirmations continue on the Phase 1 basis that has applied since 10 November 2025. Our guide to the CMMC Phase 2 suspension covers what was paused and what was not.
Frequently asked questions
How many requirements does CMMC Level 1 have?
Fifteen, taken from FAR 52.204-21(b)(1), in six families: access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. They are assessed with the NIST SP 800-171A objectives for seventeen mapped 800-171 requirements.
Is a third-party assessment required for Level 1?
No. Level 1 is always a self-assessment, submitted to SPRS with an annual affirmation by a senior official. There is no Level 1 (C3PAO) status.
Can we have a POA&M at Level 1?
No. 32 CFR 170.21(a)(1) prohibits a POA&M at any time for Level 1. Every requirement must be MET before the status can be claimed.
How often is the Level 1 self-assessment repeated?
Annually. Both the self-assessment results in SPRS and the affirmation must be renewed each year to maintain Final Level 1 (Self).
Did the July 2026 suspension pause Level 1?
No. The suspension covers the Phase 2 transition and future implementation milestones. Phase 1 self-assessment requirements, including Level 1, remain in force.
Where this leaves you
CMMC Level 1 is small but unforgiving: fifteen requirements, all MET, assessed against the 800-171A objectives on a properly scoped set of FCI systems, submitted to SPRS and affirmed every year with six years of evidence behind it. Do it that way once and the annual repeat is a review. Do it as a checkbox and the first DIBCAC question exposes it.
References
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification Program — The CMMC program rule: §170.14 model, §170.15 Level 1 requirements, §170.19 scoping, §170.21 POA&Ms.
- 48 CFR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems — The fifteen FAR requirements Level 1 incorporates.
More on CMMC
- CMMC Level 1 — you are here
- CMMC compliance: the phased rollout
- CMMC vs NIST 800-171
- CMMC scoping: the five asset categories
- CMMC Level 2 certification cost
- SPRS score: the scoring rules
The CMMC Gap Analysis Workbook, the Assessment Scope Determination Procedure and the policies and procedures behind all fifteen Level 1 requirements — and the 110 at Level 2 — are in the CMMC Documentation Toolkit, or start with the free templates.