
CMMC Level 1 Compliance: Requirements + Self-Assessment Guide
Anna Fitzgerald
Senior Content Marketing Manager
Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
CMMC Level 1 requirements are in effect today. Phase 1 of the CMMC rollout took effect November 10, 2025, and it is still the current phase: applicable Department of Defense contracts require a Level 1 self-assessment and an annual affirmation from a senior company official as a condition of award.
Level 1 is also the part of CMMC least affected by the Department's ongoing program review. While that review is underway, requiring activities may designate only Level 1 (Self) and Level 2 (Self) statuses, which leaves the Level 1 path exactly where it has been since Phase 1 began.
For smaller defense contractors and subcontractors, Level 1 still adds up to real work: 15 cybersecurity requirements, 58 assessment objectives, and no partial credit. This guide covers what Level 1 requires, who it applies to, how to complete the self-assessment and affirmation, and what to look for in the tooling that supports it.
Recommended reading
CMMC Phase 2 on Hold: What the DoW and Primes Still Require
What is CMMC Level 1 compliance?
CMMC Level 1 is the foundational level of cybersecurity requirements set by the Department of Defense (DoD) in 32 CFR 170.14(c)(2)\(2\)) for contractors working with federal contract information (FCI).
As the lowest of the three CMMC certification levels a defense contractor or subcontractor can be required to meet, Level 1 consists of 15 basic cyber hygiene practices specified in Federal Acquisition Regulation (FAR) Clause 52.204-21(b)(1)\(1\)\(i\)) for protecting FCI.
Under the 2026 FAR overhaul class deviation, FAR 52.204-21 was renumbered to FAR 52.240-93. The 15 safeguarding requirements themselves are unchanged, and both clause numbers are still in circulation across solicitations and guidance.
See our guide to the DFARS and FAR clauses behind CMMC for the full picture.
*A note on naming: The Department is now commonly referred to by its official secondary title, the Department of War (DoW). Because existing CMMC rules, contract clauses, and source documents still read "Department of Defense (DoD)," we continue to use the statutory name or "the Department" as well as DoW.*
Who needs CMMC Level 1 certification?
Any organization that processes, stores, or transmits FCI only under a Department of Defense contract or subcontract must comply with CMMC Level 1 requirements. If they don't, they won't be eligible for DoD contracts involving FCI.
According to DoD estimates in the 32 CFR rule, 63% of the Defense Industrial Base (DIB) will ultimately fall into this category and need to achieve CMMC Level 1.
That includes:
- Prime contractors that work directly with the DoD and handle FCI.
- Subcontractors that process, store, or transmit FCI in performance of a subcontract.
- Managed service providers (MSPs) and other vendors that manage IT systems or perform services where FCI may be accessed or stored.
In short, if your work touches FCI in any way, you're in scope for Level 1.
Note that the level is set by the information you handle, not by your size or your tier in the supply chain. Primes carry legal responsibility for verifying a subcontractor's CMMC status before work begins, so many contractors first hear about Level 1 from a customer rather than a contracting officer.
Let's take a closer look at what FCI is, and what it isn't, before diving deeper into Level 1 requirements.
Recommended reading
Who Needs CMMC? DoD Contractor Requirements in 2026
What is Federal Contract Information (FCI)?
Federal contract information is information provided by or generated for the Government under a contract to develop or deliver a product or service to the Government that is not intended for public release, as defined in 48 CFR 4.1901.
Examples of FCI are:
- Technical specifications
- Proposals and bids
- Project schedules or progress reports
- General supplier information
- Non-sensitive internal communications
Examples that aren't considered FCI are:
- Information provided by the Government on public websites
- Simple transactional information that's needed to process payments
- Controlled unclassified information (CUI)
Let's take a closer look at the difference between the two major categories of information CMMC is designed to protect below.

FCI vs CUI
Both FCI and CUI are types of sensitive, unclassified data created or owned by the government, or created on behalf of the government. Any organization that handles FCI or CUI must achieve the CMMC level specified in their contract to be eligible to do defense-related work.
However, unlike FCI, CUI is designated by the federal government as sensitive enough to require safeguarding and may also be subject to dissemination controls in accordance with laws, regulations, or government-wide policies, as defined in 32 CFR 2002.4(h)).
If an organization handles CUI, they must comply with CMMC Level 2 or Level 3. That means organizations handling CUI must achieve a more advanced level of cyber hygiene than Level 1 contractors.
Examples of CUI are:
- Personally identifiable information
- HIPAA-protected data
- Law enforcement records
- Export controlled information
- Critical infrastructure and defense information
The distinction matters commercially, not just technically. Level 1 is 15 requirements and a self-assessment. Level 2 is 110 requirements from NIST SP 800-171, a much larger documentation burden, and usually an infrastructure decision about where CUI will live.
Recommended reading
How to Determine Your CMMC Certification Level
CMMC Level 1 vs Level 2 vs Level 3
The CMMC model is structured in three levels, with each representing an increasing degree of cybersecurity maturity.
Note: Level 2 C3PAO certification requirements and Level 3 DIBCAC certification requirements are suspended in new DoD solicitations during the current program review, but we’ve preserved those assessment requirements as a record of the CMMC program as codified in the 32 CFR rule.

Level 1 (Foundational)
- Who: required for any defense contractor and subcontractor that handles FCI. DoD estimates this will be 63% of the DIB.
- What: basic cyber hygiene practices focused on protecting FCI, such as access control.
- Based on existing regulation: based on 15 requirements in FAR 52.204-21 (now 52.240-93).
- Assessment: annual self-assessment and affirmation of compliance by a senior company official.
Level 2 (Advanced)
- Who: required for most defense contractors and subcontractors that handle CUI. DoD estimates this will be 37% of the DIB.
- What: practices aligned with higher data protection requirements, suitable for those handling CUI.
- Based on existing regulation: based on 110 requirements in NIST 800-171.
- Assessment: as codified in 32 CFR Part 170, a triennial assessment performed by a C3PAO plus annual affirmation for most Level 2 contractors, and annual self-assessment and affirmation for contractors handling non-critical national security information.
Level 3 (Expert)
- Who: required for defense contractors that handle the most sensitive CUI and face advanced persistent threats (APTs). DoD estimates this will be less than 1% of defense contractors.
- What: practices aligned with advanced security requirements designed to protect critical national security information and address APTs.
- Based on existing regulation: based on 110 requirements in NIST 800-171 and 24 from NIST 800-172.
- Assessment: triennial assessment by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, and annual affirmation of compliance with the 24 NIST 800-172 requirements. Must achieve CMMC Level 2 first.
One clarification worth making: the three-level model in 32 CFR Part 170 is unchanged. What has changed is which statuses can be designated in new contracts while the Department's program review runs: only Level 1 (Self) and Level 2 (Self). Level 1 is unaffected either way, because it has always been a self-assessment.
The DoD contracts you're bidding on or currently involved with will likely specify the required CMMC level. If they don't, understanding the distinctions between levels can help you determine which you need, and our guide to what type of CMMC assessment you need walks through the decision. You can also use the decision tree below as an aid.

Recommended reading
CMMC Self-Assessment Guide: Level 1 and Level 2 Process
CMMC Level 1 compliance requirements
CMMC Level 1 presents a baseline of 15 cybersecurity requirements that all contractors must meet to win or continue working on DoD contracts involving federal contract information (FCI). These requirements are organized around six core areas or domains. They are as follows:
| Domain | Requirement statement |
|---|---|
| Access Control (AC) | 1. Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). |
| 2. Limit information system access to the types of transactions and functions that authorized users are permitted to execute. | |
| 3. Verify and control/limit connections to and use of external information systems. | |
| 4. Control information posted or processed on publicly accessible information systems. | |
| Identification and Authentication (IA) | 5. Identify information system users, processes acting on behalf of users, or devices. |
| 6. Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. | |
| Media Protection (MP) | 7. Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. |
| Physical Protection (PE) | 8. Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. |
| 9. Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices. | |
| System and Communications Protection (SC) | 10. Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. |
| 11. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. | |
| System and Information Integrity (SI) | 12. Identify, report, and correct information and information system flaws in a timely manner. |
| 13. Provide protection from malicious code at appropriate locations within organizational information systems. | |
| 14. Update malicious code protection mechanisms when new releases are available. | |
| 15. Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed. |
To ensure organizations are fully implementing these safeguards, they must meet all assessment objectives for each requirement. The 15 requirements in Level 1 have between 1 and 8 assessment objectives each, for a total of 58 assessment objectives.
How Level 1 requirements map to NIST 800-171
The 15 Level 1 requirements come from FAR 52.204-21, but they aren't a separate standard. CMMC domains map to the security requirement families in NIST SP 800-171 Rev 2, as specified in 32 CFR 170.14(b), and the six Level 1 domains are six of the 14 families in that standard.
CMMC requirements are also cumulative: each level includes everything from the level below. Level 2 keeps all 15 Level 1 requirements and adds 95 more, for the full 110 in NIST 800-171 Rev 2 across all 14 families.
The table below shows how the 15 Level 1 requirements sit inside the 110 at Level 2, across all 14 domains. Because the levels stack, the Level 2 column counts only what gets added on top of Level 1:
| CMMC domain | Level 1 requirements | Additional Level 2 requirements |
|---|---|---|
| Access Control | 4 | 18 |
| Audit and Accountability | - | 9 |
| Awareness and Training | - | 3 |
| Configuration Management | - | 9 |
| Identification and Authentication | 2 | 9 |
| Incident Response | - | 3 |
| Maintenance | - | 6 |
| Media Protection | 1 | 8 |
| Personnel Security | - | 2 |
| Physical Protection | 2 | 4 |
| Risk Assessment | - | 3 |
| Security Assessment | - | 4 |
| System and Communications Protection | 2 | 14 |
| System and Information Integrity | 4 | 3 |
| Total | 15 | 110 |
That means, the work you do for Level 1 won't have to be repeated if a government or prime contract later requires Level 2. You are building in six domains you would expand rather than replace, and the eight domains with no Level 1 requirements are what gets added.
For the full picture, see our breakdown of CMMC requirements across all domains and levels.
For a more detailed overview of Level 1 requirements and the CMMC controls that satisfy them, download our checklist below or refer to the DoD's CMMC Level 1 Self-Assessment Guide.
CMMC Level 1 compliance checklist
For some organizations in the DIB, CMMC Level 1 compliance will involve re-evaluating existing practices, while others will need to establish entirely new security measures.
To help contractors meet Level 1 requirements no matter where they are in the readiness process, we created this checklist to cover all 15 requirements and 58 assessment objectives. Use it as a streamlined way to track that you've implemented each requirement fully and monitor ongoing compliance.

CMMC Level 1 Compliance Checklist
Download this checklist with all the requirements and assessment objectives for CMMC Level 1 to help guide your compliance efforts and assessment preparations.
More free tools are in our library of CMMC compliance checklists and CMMC documentation templates.
How do you get CMMC Level 1 certification?
Getting CMMC Level 1 certification takes seven steps: confirm you handle FCI, scope your environment, run a gap assessment, implement and document controls, perform the self-assessment, submit your results and affirmation to SPRS, and repeat annually. There is no third-party assessment and no waiting on a C3PAO, so the timeline is yours to control.
Step 1: Determine if you handle FCI.
Review your contracts and environment to identify if and where Federal Contract Information exists. If any employees, systems, vendors, or other assets handle FCI, you're required to meet CMMC Level 1 and must conduct a self-assessment.
Step 2: Scope your assessment.
Before you actually conduct a Level 1 self-assessment, you must specify scope. Scope is the set of all assets, including the people, technology, facilities, and external service providers, that store, process, or transmit FCI and therefore must be assessed against the Level 1 security requirements.
Clearly scoping your environment prevents unnecessary work and costs. To ensure you get this step right, consult the DoD's CMMC Level 1 Scoping Guidance.
Step 3: Conduct a gap assessment.
Compare your existing security practices to the 15 Level 1 requirements. Identify any gaps, such as missing access controls, outdated antivirus software, or lack of audit logs, and prioritize remediation.
While you can do this step manually with spreadsheets, automation can significantly speed up the control mapping process and reduce the chance of human error. Our guide to running a CMMC gap analysis covers what to look at and in what order.
Step 4: Implement missing controls and document your practices.
Put CMMC controls in place to meet each requirement and provide evidence that demonstrates how you're meeting them.
Once controls and tests are in place, document your implementation of all Level 1 requirements and assessment objectives in your System Security Plan (SSP). You'll likely have to provide other documentation as well, such as:
- policy, process, and procedure documents
- training materials
- plans and planning documents
- system, network, and data flow diagrams
Our guide to what CMMC documentation is required breaks down each artifact, and our CMMC training roundup covers the awareness training side.
Step 5: Perform your self-assessment.
To conduct the self-assessment, you must assess each of the 15 requirements and 58 assessment objectives and determine whether each has been MET, NOT MET, or is NOT APPLICABLE.
For Level 1, no requirements can be unmet and included on a Plan of Action and Milestones (POA&M) to be remediated later. So you have to score the self-assessment as MET or NOT MET in its entirety, rather than using a numerical value.
Step 6: Submit results and affirmation.
Once you've completed your CMMC assessment, upload your results and score to the Supplier Performance Risk System (SPRS) and submit an executive affirmation of compliance to achieve a CMMC Status of Final Level 1 (Self).
A current CMMC status is a condition of award on any contract that includes the CMMC clause. Subcontractors are often asked earlier, through prime flowdown, rather than waiting for a government milestone.
Step 7: Maintain your status.
To maintain compliance, you must assess your controls and submit these results, along with an affirmation of compliance, in SPRS at least annually to prove you're still meeting all CMMC Level 1 requirements.
That annual affirmation is a legal statement about your current state, not a memory of last year's project. It needs an operational record behind it: control test results from across the year, a log of environment changes and what you determined about them, and an SSP that still describes the system you are actually running. Our guide to maintaining CMMC compliance between assessments covers how to build that record.
This step-by-step overview shows that CMMC compliance is a rigorous and ongoing process. The right tooling can automate much of it, from scoping and gap analysis to evidence collection and continuous monitoring, so you can get secure faster and stay compliant year-round.
Recommended reading
SPRS Scoring: How to Get a Current CMMC Status and Stay Eligible for DoD Contracts
What CMMC Level 1 compliance software does, and what it doesn't
Compliance management software automates the documentation and monitoring side of CMMC: gap analysis, evidence collection, policy and SSP management, risk assessments, and continuous control monitoring. That is the governance, risk, and compliance (GRC) layer. It is one layer of CMMC, not the whole requirement.
The other layer is the environment itself. Several Level 1 requirements are satisfied by how systems are configured, not by what you write down about them.
| Level 1 domain | Example requirement | What actually satisfies it |
|---|---|---|
| Access Control (AC) | Verify and control connections to external systems | Identity and conditional access configuration in your cloud tenant |
| Identification and Authentication (IA) | Authenticate users, processes, and devices before granting access | MFA and device enrollment enforced tenant-wide |
| System and Communications Protection (SC) | Separate publicly accessible components onto subnetworks | Network architecture and boundary design |
| System and Information Integrity (SI) | Update malicious code protection and run periodic and real-time scans | Endpoint policy enforced on every device that touches FCI |
| Media and Physical Protection (MP, PE) | Sanitize media before disposal, control physical access | Device lifecycle process and facility controls |
A GRC tool can tell you a requirement is unmet. It cannot enroll the laptop, configure the tenant, or segment the network. That gap is why contractors who buy a GRC platform alone often find themselves two months later with a clean dashboard and an environment that still fails the objective.
The SSP is where both layers meet
Your System Security Plan has to describe the system as it is actually configured, requirement by requirement, and stay accurate as the environment changes. A template-driven SSP describes an environment someone intended to build. A generated SSP describes the one you are running.
For Level 1 that distinction matters more than it looks. No requirement can sit unmet on a POA&M, so you score MET or NOT MET on all 15, and your documentation has to hold up to the same standard. The documentation requirements do not get easier at Level 1, they just get shorter.
When FCI turns into CUI
Most Level 1 contractors are one contract away from Level 2. The moment CUI enters scope, the question stops being "which tool tracks our controls" and becomes "where does CUI live."
That is an infrastructure decision, and it drives most of the cost:
- A CUI enclave to contain scope rather than pulling your whole tenant into the assessment boundary. Our enclave architecture guide covers how to build and configure one.
- A FedRAMP-authorized environment to host it, usually Microsoft 365 GCC High or Google Workspace. GCC High is not automatically required, as we cover in does CMMC require GCC High and our comparison of GCC High alternatives.
- Managed device enrollment and virtual desktops for the users who need access, so scope stays contained to the people who actually touch the data.
Scoping that boundary well is the single biggest cost lever in CMMC, as our breakdown of CMMC certification costs and our guide to CMMC in the cloud both show. It is also a decision no GRC platform makes for you.
As an authorized AOS-G reseller, Secureframe offers competitive pricing on Microsoft 365 GCC High licenses, including Business Premium, G3, and G5. Browse licenses on our Marketplace.
What to look for when you evaluate
The GRC layer:
- Gap analysis: identifies gaps in current practices against all 15 Level 1 requirements and 58 objectives.
- Evidence collection: pulls evidence automatically from your stack instead of by screenshot.
- Documentation management: generates and maintains the SSP, policies, and procedures from your live configuration.
- Automated risk assessments: runs the risk workflow for risks associated with FCI.
- Continuous monitoring: watches controls and configurations and flags drift between assessments.
The layers GRC alone doesn't cover:
- Environment provisioning: stands up a compliant cloud environment and enclave rather than documenting one you have to build yourself.
- Device and endpoint management: enforces the required configurations on the laptops and workstations in scope.
- Scoping guidance: helps you draw the boundary before you buy licenses or migrate data.
- Assessment output: produces the SPRS score and the artifact package a self-assessment and a prime review both ask for.
Buying the GRC layer alone means assembling the rest from an MSP, a cloud reseller, and a readiness consultant, then reconciling their work yourself. Our guide to when you need a CMMC consultant covers what that route costs. Buying a platform that covers both layers means one system of record for what your environment does and what your documentation claims it does.
Recommended reading
Introducing Secureframe Defense: A Complete, End-to-End Solution for CMMC Compliance
Why Secureframe Defense is more than a GRC solution for CMMC Level 1
Secureframe Defense covers all three layers of CMMC: the environment where FCI and CUI live, the documentation that describes it, and the proof you hand to a contracting officer or a prime. Most tools in this category cover the middle one.
Deploy a secure environment
- Automated Cloud Provisioning: a Microsoft GCC High or Google Workspace environment preconfigured with the controls required for handling CUI, rather than a checklist telling you to go build one.
- Virtual Desktops: auto-provisioned Azure virtual desktops for CUI access, so you are not managing physical hardware for a handful of users.
- FedRAMP Moderate Authorized MDM: enrolls existing laptops and workstations and enforces CMMC configurations on them, including the AC, IA, and SI objectives Level 1 depends on.
Document and manage the program
- Defense Navigator: an AI workflow that walks you through scoping, integration setup, and CUI access configuration step by step, while tracking your progress.
- Automated Documentation: policies, SSP, and POA&Ms generated and maintained from your actual environment, not blank templates. Templates and policies are written by former federal auditors and fully customizable.
- Comply Platform: continuous evidence collection, control monitoring, risk management, and vendor tracking for flowdown, in one tool.
- Out-of-the-box CMMC frameworks: all three CMMC levels ship as native frameworks, with automated gap assessments mapped directly to Level 1 requirements and controls, plus in-platform training that meets the Level 1 awareness and insider threat requirements.
Prove it
- Real-time SPRS scoring: watch your score move as you implement each requirement, and close gaps before they affect an award.
- Assessment-Ready Package: evidence, documentation, and artifact exports built for a self-assessment and for prime review.
- Expert support: CMMC Registered Practitioners who have been through Level 2 assessments, guiding you from scoping to SPRS submission. Our team includes former CMMC, FISMA, and FedRAMP auditors and consultants.
- Trust Center: show your CMMC status and monitoring controls in real time. Here's ours.
Be prepared for what comes next
Level 1 is rarely the end state. Intelligent cross-mapping carries your Level 1 work forward into CMMC Level 2 and into other federal frameworks, including NIST 800-53 and FedRAMP, so you don't start from scratch when a contract changes what's required of you.
The Phase 2 suspension did not remove the requirement, and it did not remove the affirmation you sign every year. Primes are still enforcing flowdown on their own schedule, and the reason the Department is pushing on DIB cybersecurity has not changed either.
This post was originally published in November 2024 and has been updated for accuracy and comprehensiveness.
Get certified. Stay compliant.
FAQs
What is CMMC Level 1?
CMMC Level 1 is the foundational level of CMMC. It presents a baseline of 15 cybersecurity requirements that all contractors must meet to win or continue working on DoD contracts involving federal contract information (FCI).
When is CMMC Level 1 compliance required?
CMMC Level 1 compliance has been a condition of award on applicable Department of Defense contracts since November 10, 2025, when Phase 1 of the CMMC rollout took effect. Phase 1 is still the current phase.
Phase 1 implements DFARS 252.204-7021, which requires a CMMC status as a condition for contract award. The Phase 2 transition to third-party assessments, originally scheduled for November 10, 2026, was suspended in July 2026 pending a program review. That suspension does not change Level 1: self-assessment and annual affirmation continue to apply, and Level 1 (Self) remains one of only two statuses that can be designated during the review.
Does the CMMC Phase 2 suspension affect Level 1?
No. The suspension applies to Phase 2, which would have required third-party C3PAO assessments for many Level 2 contractors. Level 1 has always been a self-assessment, Phase 1 remains in effect, and Level 1 (Self) is one of only two CMMC statuses that can be designated while the review is underway. Contractors handling FCI still need a current status, an annual self-assessment, and an executive affirmation in SPRS. Our full breakdown of the Phase 2 pause covers what changed and what didn't.
Why do some resources say CMMC Level 1 has 17 requirements?
When CMMC 2.0 was first announced in 2021, CMMC Level 1 consisted of 17 requirements derived from FAR 52.204-21. In an earlier version of the DoD's CMMC Level 1 Self-Assessment Guide (version 2.0, released December 2021), there were four Physical Protection (PE) requirements. In the latest guide (version 2.13, released September 2024), three PE requirements were merged into one: PE.L1-B.1.IX, Manage Visitors and Physical Access \[FCI Data\]. That consolidation brought the total from 17 down to 15, as confirmed in the official CMMC rule (32 CFR)\(2\)).
Is "CMMC Level 1 certification" the right term?
Not strictly, no. Level 1 status is earned through a self-assessment, not a certification assessment. When you complete the process, the Department records a CMMC Status of Final Level 1 (Self) in SPRS. No certificate is issued, and no C3PAO is involved. Only Level 2 (C3PAO) and Level 3 statuses come from an assessment performed by an outside body.
In practice, "CMMC Level 1 certification" is how most contractors, primes, and even some solicitations refer to it, so we use the term throughout this guide for clarity. If you're filling out a supplier questionnaire or answering a prime, the precise answer is that you hold a current Final Level 1 (Self) status in SPRS with a senior official's annual affirmation on record.
How does CMMC Level 1 certification work?
CMMC Level 1 requires an annual self-assessment, which involves reviewing and documenting that you've met all 15 cybersecurity practices defined in FAR 52.204-21. All requirements must be met in full, with no exceptions or POA&Ms allowed at this level. Organizations then score themselves as MET or NOT MET, like a pass or fail, and submit these assessment results and scores in the Supplier Performance Risk System, along with an executive affirmation of compliance, to achieve a CMMC Status of Final Level 1 (Self). They must repeat this process every year to maintain that status.
Does Level 1 CMMC require a third-party audit?
CMMC Level 1 does not require a third-party assessment like the higher levels as codified in the 32 CFR rule. It requires a self-assessment to verify the implementation of all 15 security requirements and 58 assessment objectives. However, organizations can engage a third party to assist with their self-assessment, as noted in the DoD's CMMC Level 1 Self-Assessment Guide.
What are the CMMC Level 1 domains?
CMMC Level 1 presents a baseline of 15 cybersecurity requirements for protecting FCI, organized into six domains that map directly to the NIST 800-171 Rev. 2 control families. The CMMC Level 1 domains are:
- Access Control: control who can access FCI, ensuring employees use unique login credentials and strong password management.
- Identification and Authentication: verify the identities of users accessing FCI through authentication measures.
- Media Protection: protect both physical and digital media used to store FCI, with rules around handling, storage, and disposal.
- Physical Protection: limit physical access to locations storing FCI, implementing badge systems or secured entry points.
- System and Communications Protection: protect the edges of a system and ensure that devices that work together are managed safely, using secure communication protocols and network segmentation.
- System and Information Integrity: ensure systems are secure and up to date, using antivirus software and security patches.
What happens if I fail to meet CMMC Level 1 requirements?
Failing to meet all CMMC Level 1 requirements will result in a "No CMMC Status" in SPRS and disqualification from defense contracts involving FCI, both existing and new. Regular self-assessments and a proactive approach to cybersecurity help mitigate the risks of non-compliance, which include loss of contracts as well as legal and financial penalties.
What's the cost of CMMC Level 1 compliance?
The cost of CMMC Level 1 compliance is at least $4,000 to $6,000, which is the DoD's estimate for the Level 1 self-assessment only. Level 1 is the least costly due to its self-assessment and minimal security requirements. The DoD estimates the cost of a Level 2 self-assessment at $37,000 to $49,000, for comparison. Actual cost varies based on company size, current cybersecurity posture, and whether additional headcount or software is required. You can find a more detailed breakdown of costs by level here.
How many controls are in CMMC Level 1?
Typically, an organization will need to implement around 50 controls on average for CMMC Level 1. The exact number you implement to meet the 15 requirements and 58 assessment objectives may vary depending on your assessment scope and the complexity of your infrastructure and organization.

Anna Fitzgerald
Senior Content Marketing Manager
Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.