CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification program. It covers 15 basic security requirements derived from FAR Clause 52.204-21. If your contract specifies a CMMC Level 1 assessment and you only handle FCI across all contracts, then you fall under Level 1. Here’s what you need to know.
Key Takeaways
- CMMC Level 1 requires annual self-assessment and SPRS affirmation against 15 security controls from FAR 52.204-21.
- It applies to any contractor whose information system processes, stores, or transmits Federal Contract Information.
- Level 1 does not permit Plans of Action and Milestones. All 15 requirements must be completely met to achieve CMMC status.
Table of Contents
What CMMC Level 1 Protects
CMMC Level 1 protects Federal Contract Information (FCI) – non-public information provided by or generated for the government under a contract to develop or deliver a product or service. FCI is defined in FAR Clause 52.204-21 and is broader than many contractors assume.
FCI is not the same as Controlled Unclassified Information (CUI). CUI is the higher-sensitivity category that triggers CMMC Level 2 and Level 3 obligations. However, FCI still represents information the government does not intend for public release, and mishandling it creates both contractual and legal exposure under the False Claims Act.
CMMC Phase 1 implementation began on November 10, 2025, and runs through November 9, 2026. During this phase, DoD solicitations are incorporating Level 1 self-assessment requirements directly into contract language under DFARS clause 252.204-7021. If your system handles FCI, you are likely already in scope.
Who Needs to Comply with CMMC Level 1
Any DIB contractor or subcontractor whose information system processes, stores, or transmits FCI is subject to the safeguarding requirements of FAR 52.204-21. These requirements apply across the supply chain and must be flowed down to subcontractors that handle FCI.
When a DoD contract (or subcontract) includes DFARS 252.204-7021 with a CMMC Level 1 requirement, those organizations must complete a Level 1 self-assessment and affirm compliance with those same controls.
However, if your company delivers a service, produces custom work product, or manages data under a government contract, you likely handle FCI and must implement the 15 safeguarding requirements in FAR 52.204-21. If a CMMC Level 1 requirement is included in your contract, you must assess and affirm compliance against those controls.
15 CMMC Level 1 Requirements
The 15 Level 1 security requirements come directly from FAR clause 52.204-21 (Nov 2021). They are organized across six practice areas:
Access Control (AC)
- Only let authorized people log into your systems.
- Make sure people can only do the things on your systems they’re supposed to do. No one should have more access than their job requires.
- Only let approved devices connect to your network.
- Keep public-facing systems (like a website) separate from the systems where you store government information.
Identification and Authentication (IA)
- Make sure every user has a unique identity before they can access your systems.
- Require passwords or other authentication to verify who someone is before granting access.
Media Protection (MP)
Properly wipe or destroy hard drives, USB drives, or any media that holds government information before throwing it away or repurposing it.
Physical Protection (PE)
- Control who can physically walk into areas where government information is stored or processed.
- Escort visitors in those areas and keep a log of who comes and goes.
- Track and manage physical access badges or keys.
System and Communications Protection (SC)
- Monitor and control what data flows in and out of your network at the boundary. This is typically handled by a firewall.
System and Information Integrity (SI)
- Fix known security vulnerabilities in your systems in a timely way (e.g., patch your software).
- Have antivirus or anti-malware protection running on your systems.
- Keep your antivirus / anti-malware software up to date.
- Run regular scans on your systems, and scan files coming from outside your network before opening them.
What Happens if You Don’t Meet One of These Requirements?
All 15 must be met. There is no partial credit. One failure means you are not compliant, which can affect your ability to win or keep government contracts.
Do You Need to Hire Someone to Meet CMMC Level 1 Requirements?
You can do it yourself, or you can bring in a third party, like Teal CMMC, to help you.
Either way, it’s still a self-assessment and does not result in a formal certification. The accountability stays with you.
How Does the CMMC Level 1 Self-assessment Process Work?
Level 1 is assessed by your own team, not an independent assessor. Per 32 CFR § 170.15, the process has three required steps:
1. Assess.
Review your information systems against all 15 FAR 52.204-21 controls. Every requirement must be fully MET or documented as NOT APPLICABLE. There is no partial credit and no POA&M option.
2. Enter results in SPRS.
Your assessment results must be entered into the Supplier Performance Risk System. SPRS is the DoD’s official repository for contractor cybersecurity status data.
3. Affirm.
A senior company official must affirm continuous compliance in SPRS after each assessment and annually thereafter. If the annual self-assessment and affirmation are not maintained, the organization’s CMMC Level 1 status will expire, which may affect contract eligibility.
CMMC Level 1 Requires Ongoing Diligence
CMMC Level 1 is the floor of DoD contract cybersecurity compliance, and its annual cycle means there is no safe moment to treat it as a one-time project.
Contractors handling FCI should confirm their assessment is current, their SPRS affirmation is active, and their systems genuinely meet all 15 controls.
If you’re looking for assistance in meeting Level 1 requirements, Teal CMMC can help.
We provide CMMC managed services that can help you meet the requirements and stand ready to support you with CMMC compliance consulting if you decide to take on contracts that require CMMC Level 2 certification.




