# How to Meet Every CMMC Level 1 Requirement: A Prescriptive Guide for Small Defense Contractors

> A breakdown of every CMMC Level 1 requirement in plain language so you know what to implement, which evidence to keep, and common mistakes to avoid.

canonical: https://secureframe.com/blog/cmmc-level-1-requirements

CMMC Level 1 is designed to be the foundational level of the [Cybersecurity Maturity Model Certification (CMMC)](https://secureframe.com/hub/cmmc/what-is-cmmc), verifying that small defense contractors and manufacturers have basic safeguarding requirements in place to protect contract information. The problem is that these requirements don't seem so basic, so they have to hire a consultant or C3PAO for advisory services to translate instead.

Since many don't have the budget to do so, we created this guide as a translation. It covers the four key steps in order: define your scope, decide where [Federal Contract Information (FCI)](https://secureframe.com/glossary/federal-contract-information) will live, implement all 15 requirements and 59 assessment objectives, then score and submit the result. For each [Level 1 requirement](https://www.cmmc.com/resources/level-1-requirements), we break down what it's asking in plain language, what specifically you need to do to implement it, what evidence to prove it, and the pitfall that most often causes a small contractor to fail to fully implement or maintain it.

Let's get started.

![cmmc level 1 requirements by domains and number of requirements and objectives](https://images.prismic.io/secureframe-com/HnzuGR2QKU6FWJjK_CMMCLevel1requirementsbydomain.png?auto=format,compress)

## What are the CMMC Level 1 requirements at a glance?

## What are the CMMC Level 1 requirements at a glance?

[CMMC Level 1](https://secureframe.com/blog/cmmc-level-1-compliance) is designed to verify that you have implemented the 15 basic safeguarding requirements from [FAR clause 52.204-21](https://www.acquisition.gov/far/52.204-21) (now renumbered to FAR 52.240-93), which are organized into six domains. These domains map to 6 of 14 total [NIST SP 800-171 Rev 2](https://secureframe.com/blog/nist-800-171-compliance) families. Beneath those 15 requirements sit 59 assessment objectives, the determination statements you actually assess and score yourself against.

```
<style>
#what-are-the-cmmc-level-1-requirements-at-a-glance-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table td,
#what-are-the-cmmc-level-1-requirements-at-a-glance-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table thead strong,
#what-are-the-cmmc-level-1-requirements-at-a-glance-table thead th,
#what-are-the-cmmc-level-1-requirements-at-a-glance-table thead tr {
  color: #fff;
  font-weight: bold;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table thead tr th {
  font-family: Assistant, sans-serif;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#what-are-the-cmmc-level-1-requirements-at-a-glance-table tbody tr th,
#what-are-the-cmmc-level-1-requirements-at-a-glance-table tbody tr td {
  color: #091922;
}
</style>
<table id="what-are-the-cmmc-level-1-requirements-at-a-glance-table">
<thead>
<tr><th>Domain</th><th>Requirements</th><th>Objectives</th></tr>
</thead>
<tbody>
<tr><th>Access Control (AC)</th><td>4</td><td>19</td></tr>
<tr><th>Identification and Authentication (IA)</th><td>2</td><td>6</td></tr>
<tr><th>Media Protection (MP)</th><td>1</td><td>2</td></tr>
<tr><th>Physical Protection (PE)</th><td>2</td><td>10</td></tr>
<tr><th>System and Communications Protection (SC)</th><td>2</td><td>10</td></tr>
<tr><th>System and Information Integrity (SI)</th><td>4</td><td>12</td></tr>
<tr><th><strong>Total</strong></th><td><strong>15</strong></td><td><strong>59</strong></td></tr>
</tbody>
</table>
```

Before we dive into technical implementation of these cybersecurity requirements, here's what you need to know about the [assessment requirements](https://secureframe.com/hub/cmmc/assessments) at this level:

- **You assess yourself.** Level 1 has never required a third-party assessor. No [C3PAO](https://secureframe.com/hub/cmmc/c3pao) is involved at this level.
- **It is pass or fail.** Each requirement is scored MET or NOT MET. There is no numeric score at Level 1.
- **Assess against the objectives.** A requirement is MET only when every one of its assessment objectives is satisfied.
- **There is no partial credit.** You cannot defer an unmet requirement to a [Plan of Action and Milestones (POA&M)](https://www.cmmc.com/newsroom/cmmc-poam-critical-requirements). POA&Ms are not available at Level 1 in any form.
- **NOT APPLICABLE is only allowed with contractually documented approval.** NOT APPLICABLE (N/A) is only used if you have contractually documented approvals to not have to meet that requirement. If you don't have that approval but a requirement genuinely does not apply to your environment, then you mark it MET and explain what isn't in scope for that requirement.
- **A named executive signs for it.** Your Affirming Official attests that you have implemented and will maintain the requirements, which carries liability under the [False Claims Act](https://secureframe.com/blog/false-claims-act).
- **It must be completed annually.** A Final Level 1 Self-Assessment converts to No CMMC Status one year from your assessment date, automatically and without warning. You must submit a self-assessment and affirmation every year to keep a current status.

## Recommended reading

CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2 Requirements

## Step 1: Define your scope

## Step 1: Define your scope

Every asset, person, facility, and external service provider that processes, stores, or transmits FCI is in-scope for CMMC Level 1. Everything else is out of scope and never gets assessed. Getting this right is the single most important lever in how much work Level 1 is or isn't for a small defense contractor.

FCI is information provided by or generated for the government under a contract that is not intended for public release, such as technical specifications, proposals and bids, project schedules, supplier information, and non-sensitive internal communications.

When scoping, ask yourself four questions:

1. **Which contracts bring FCI in?** Read the clauses. If FAR 52.204-21 (or FAR 52.240-93 in newer contracts) appears, you are in scope.
2. **How does FCI arrive and where does it land?** For most small contractors it arrives by email or a file-sharing link and lands in a shared folder or a local drive.
3. **Who touches it?** Name the roles, not the headcount. Estimators, project managers, and design staff usually touch FCI. Payroll and accounts receivable usually do not.
4. **Which outside parties reach it?** Your IT provider, your file-sharing service, and any [subcontractor](https://secureframe.com/blog/cmmc-requirements-for-subcontractors) you share contract or project management documents with.

For a typical small subcontractor this list is shorter than expected. As an example, take a 15-person mechanical contractor pursuing Level 1 for military housing work. They scope in the office staff who handle project files, their laptops and phones, the email and file-sharing tools those files pass through, and the on-premise drive where they land. Accounts payable, payroll, and field subcontractors who never see FCI stay out.

**Takeaway:** Every asset you can honestly leave out of scope is one less thing you need to apply 15 requirements and 59 objectives to.

## Step 2: Decide where FCI will live

## Step 2: Decide where FCI will live

At Level 1, an on-premise server, government cloud, or commercial cloud may be used to process and store FCI. What matters is that the environment satisfies the 15 requirements and 59 objectives. While an enclave approach can concentrate FCI into a smaller boundary and shrink scope, most organizations at this level opt for an enterprise or "all in" approach for operational simplicity.

For most contractors looking to store and process FCI in the cloud, [Microsoft 365 Commercial](https://secureframe.com/marketplace/microsoft/licensing-guide) or another commercial productivity suite like [Google Workspace](https://secureframe.com/blog/google-workspace-cmmc-compliance) that they're familiar with and often already paying for is acceptable. That single fact removes the largest cost item most Level 1 contractors assume they are facing.

### Do you need GCC High for CMMC Level 1?

### Do you need GCC High for CMMC Level 1?

No. Level 1 protects FCI, not [CUI](https://secureframe.com/blog/controlled-unclassified-information-cui). That means the [DFARS 252.204-7012](https://secureframe.com/blog/dfars-7012-vs-cmmc) clause that mandates cybersecurity and data residency and sovereignty requirements and drives [GCC High](https://secureframe.com/blog/is-gcc-high-required-cmmc) adoption applies at [Level 2](https://secureframe.com/blog/cmmc-level-2-compliance) and above.

Microsoft's own guidance confirms that you can demonstrate compliance with CMMC Level 1 for the protection of FCI in [Microsoft 365 Commercial as well as the government clouds](https://learn.microsoft.com/en-us/compliance/us-government/gov-cmmc). However, it notes that [Microsoft 365 Commercial was not purpose-built for US government requirements](https://techcommunity.microsoft.com/blog/publicsectorblog/understanding-compliance-between-commercial-government-dod--secret-offerings---m/4225436), and the safer long-term risk posture is adopting one of the government cloud offerings.

The deciding question is whether it's plausible your next two years of contracts will include CUI. If you expect to bid on work that flows down DFARS 252.204-7012 or CMMC Level 2 requirements, moving to [GCC High](https://secureframe.com/blog/gcc-high-business-premium) now [avoids a migration](https://secureframe.com/blog/gcc-high-migration-guide) later. If you handle FCI only, commercial is a defensible choice and the one most Level 1 contractors make.

## Recommended reading

What Is Microsoft 365 GCC High?

### Is Microsoft 365 Business Premium a good option?

### Is Microsoft 365 Business Premium a good option?

Yes, [Microsoft 365 Business Premium](https://secureframe.com/blog/gcc-high-business-premium) offers an affordable licensing tier, especially for small contractors with CMMC Level 1 requirements.

Business Premium bundles:

- Entra ID for identity
- Intune for device management
- Defender for Business for malicious code protection
- and Purview for data security and compliance.

Configured correctly, these primary and secondary services provide coverage across 14 of 15 requirements (93%) and all six domains, according to the [June 2025 Microsoft Product Placemat](https://9363439.fs1.hubspotusercontent-na1.net/hubfs/9363439/CMMC%20PDFs%20from%20Third-Party%20Sources/Microsoft%20Product%20Placemat%20for%20CMMC%20-%20LOCKED%20-%206-6-25.xlsm) (obtained directly from Microsoft's Richard Wakeman).

![Diagram listing the six CMMC Level 1 domains from NIST 800-171 Rev 2](https://images.prismic.io/secureframe-com/yaEuFEDddv4qvMxF_CMMClevel1domains-1-.png?auto=format,compress)

Note that this product placemat only maps service coverage to the high-level cybersecurity requirements, not the underlying assessment objectives.

```
<style>
#is-microsoft-365-business-premium-a-good-option-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#is-microsoft-365-business-premium-a-good-option-table td,
#is-microsoft-365-business-premium-a-good-option-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#is-microsoft-365-business-premium-a-good-option-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#is-microsoft-365-business-premium-a-good-option-table thead strong,
#is-microsoft-365-business-premium-a-good-option-table thead th,
#is-microsoft-365-business-premium-a-good-option-table thead tr {
  color: #fff;
  font-weight: bold;
}

#is-microsoft-365-business-premium-a-good-option-table thead tr th {
  font-family: Assistant, sans-serif;
}

#is-microsoft-365-business-premium-a-good-option-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#is-microsoft-365-business-premium-a-good-option-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#is-microsoft-365-business-premium-a-good-option-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#is-microsoft-365-business-premium-a-good-option-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#is-microsoft-365-business-premium-a-good-option-table tbody tr th,
#is-microsoft-365-business-premium-a-good-option-table tbody tr td {
  color: #091922;
}
</style>
<table id="is-microsoft-365-business-premium-a-good-option-table">
<thead>
<tr><th>Business Premium coverage</th><th>Definition</th><th>Service examples</th><th>Total inherited service mapping</th><th>The requirements it contributes to</th></tr>
</thead>
<tbody>
<tr><th><strong>Primary service</strong></th><td>At least one enabled Microsoft service is a primary contributor to meeting the requirement.</td><td>Entra ID, Intune, Microsoft Purview, Azure Datacenter, Microsoft Defender XDR</td><td>9 requirements (60%)</td><td>AC.L1-B.1.I, AC.L1-B.1.II, AC.L1-B.1.III, AC.L1-B.1.IV, IA.L1-B.1.V, IA.L1-B.1.VI, PE.L1-B.1.VIII, PE.L1-B.1.IX, SI.L1-B.1.XIV</td></tr>
<tr><th><strong>Secondary service</strong></th><td>At least one enabled Microsoft service supports meeting the requirement, but is not the primary contributor.</td><td>Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention</td><td>5 requirements (33%)</td><td>MP.L1-B.1.VII, SC.L1-B.1.X, SI.L1-B.1.XII, SI.L1-B.1.XIII, SI.L1-B.1.XV</td></tr>
<tr><th><strong>Available enabler</strong></th><td>At least one Microsoft service can contribute to meeting the requirement, but it is not enabled and meaningful work is required outside Microsoft as well.</td><td>Network Security Groups, Azure Firewall</td><td>1 requirement (7%)</td><td>SC.L1-B.1.XI</td></tr>
</tbody>
</table>
```

Note that Google Workspace offers comparable control coverage through its Admin console directory, endpoint management, and sharing controls.

No license or [cloud offering](https://secureframe.com/hub/cmmc/cloud) provides out-of-the-box compliance. You must still [document, configure, and implement](https://secureframe.com/blog/cmmc-shared-responsibility-model) certain controls and practices within your environment. For example, if you have a facility, printer, or other equipment that handles FCI, then you’ll need locks, visitor logs, and key management to meet requirements PE.L1-B.1.VIII and PE.L1-B.1.IX.

**Bottom line:** At CMMC Level 1 especially, you can evaluate and buy licenses based on capability, not the highest compliance watermark. For FCI-only work, Microsoft 365 Commercial and Google Workspace are sufficient and can significantly reduce the burden of implementation and maintenance of the underlying cybersecurity requirements.

*As a Microsoft reseller, Secureframe offers competitive pricing on Microsoft 365 licenses, including Business Premium for Microsoft 365 Commercial, GCC, and GCC High. [Browse licenses on our Marketplace](https://secureframe.com/marketplace/microsoft).*

## Recommended reading

CMMC Shared Responsibility Model: You vs. Microsoft vs. Your MSP

## Step 3: Implement all 15 requirements

## Step 3: Implement all 15 requirements

Each domain opens with a reference table you can scan, followed by implementation detail for each requirement. For the full objective-level breakdown or to track your control implementation, download our [CMMC Level 1 compliance checklist](https://secureframe.com/compliance-resources/cmmc-level-1-compliance-checklist).

### Access control (AC): 4 requirements, 19 objectives

### Access control (AC): 4 requirements, 19 objectives

```
<style>
#access-control-ac-4-requirements-19-objectives-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#access-control-ac-4-requirements-19-objectives-table td,
#access-control-ac-4-requirements-19-objectives-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#access-control-ac-4-requirements-19-objectives-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#access-control-ac-4-requirements-19-objectives-table thead strong,
#access-control-ac-4-requirements-19-objectives-table thead th,
#access-control-ac-4-requirements-19-objectives-table thead tr {
  color: #fff;
  font-weight: bold;
}

#access-control-ac-4-requirements-19-objectives-table thead tr th {
  font-family: Assistant, sans-serif;
}

#access-control-ac-4-requirements-19-objectives-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#access-control-ac-4-requirements-19-objectives-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#access-control-ac-4-requirements-19-objectives-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#access-control-ac-4-requirements-19-objectives-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#access-control-ac-4-requirements-19-objectives-table tbody tr th,
#access-control-ac-4-requirements-19-objectives-table tbody tr td {
  color: #091922;
}
</style>
<table id="access-control-ac-4-requirements-19-objectives-table">
<thead>
<tr><th>Requirement</th><th>What it means in plain terms</th><th>What to do</th><th>What not to do</th></tr>
</thead>
<tbody>
<tr><th><strong>AC.L1-B.1.I</strong>: Limit system access</th><td>You know who is allowed on your systems, and which devices can connect, and have policies and configurations in place so only those get on to the company network</td><td>Keep track of and put policies and configuration settings in place to limit access based on user and device</td><td>Allow shared accounts</td></tr>
<tr><th><strong>AC.L1-B.1.II</strong>: Limit transactions and functions</th><td>People get access to the apps, functions, and data their job requires, not to everything</td><td>Assign roles or groups and set up policies and configurations to limit access based on those roles and responsibilities</td><td>Assign overly permissive defaults</td></tr>
<tr><th><strong>AC.L1-B.1.III</strong>: Control external connections</th><td>You know which outside systems or devices can connect to your network, and have documented and enforced how they can do so</td><td>Identify what external systems are authorized to connect (and/or how and when) and implement controls such as policies, firewalls, and connection allow/deny lists to verify and limit those connections</td><td>Allow remote workers to use personal devices or cloud storage that isn't approved for FCI</td></tr>
<tr><th><strong>AC.L1-B.1.IV</strong>: Control public information</th><td>Whatever you publish publicly gets reviewed first, so FCI never ends up on it</td><td>Designate and train individuals that can publicly post information and set up a review process</td><td>Mark as N/A if you have social media</td></tr>
</tbody>
</table>
```

#### AC.L1-B.1.I: Limit system access to authorized users, processes, and devices

#### AC.L1-B.1.I: Limit system access to authorized users, processes, and devices

**Objectives:** [a] through [f]

##### What satisfies it

- Documentation of the users, processes initiated on their behalf (such as automatic updates or vulnerability scans), system accounts, and devices that can access the company network and information systems containing FCI
- Proof that these lists have been reviewed and reflect current employees, accounts, and devices
- Policies, procedures, and/or configuration settings in place that define and enforce how access is limited
- A record showing that account requests are authorized before system access is granted

##### Evidence to prove it may include

- Current user and asset inventory
- A record of your most recent user access review
- An [access control policy](https://secureframe.com/blog/access-control-policy)
- Configuration settings or logs showing how your login systems work
- A log of additions, deletions, and modifications of user accounts based on access requests or changes in JIRA or a similar ticketing system

##### Common gap

- **Shared accounts**: A single "office" login used by four people fails [a] and [d] at once, because you cannot identify authorized users individually.

#### AC.L1-B.1.II: Limit access to permitted transactions and functions

#### AC.L1-B.1.II: Limit access to permitted transactions and functions

**Objectives:** [a] and [b]

##### What satisfies it

- Role-based permissions that are clearly defined and enforced
- Implementation of the principle of least privilege (ie. denying access by default and allowing it by exception)
- A record showing how functional access or permissions is formally requested, approved, and removed when roles change or employees onboard or leave

##### Evidence to prove it may include

- An access control policy that defines which roles are permitted access to systems and apps containing FCI and to which functions (create/ read/ delete / update)
- A stand-alone role-based access control matrix (RBAC) or an export/screenshot of RBAC settings from Microsoft Entra ID or a similar tool
- A log of additions, deletions, and modifications to user roles, functional access, or permissions in JIRA or a similar ticketing system

##### Common gap

- **Overly permissive defaults**: An access control policy that doesn't clearly define permitted functions by role or mandate regular reviews of roles and permissions may assign overly permissive defaults or drift toward those over time, failing both objectives.

#### AC.L1-B.1.III: Verify and control connections to external systems

#### AC.L1-B.1.III: Verify and control connections to external systems

**Objectives:** [a] through [f]

##### What satisfies it

- Documentation of in-scope external systems and whether each is permitted to access corporate networks and how (ie. only certain employees may be allowed to connect to outside systems using a VPN, or only for certain windows of time)
- Policies, procedures, and/or configuration settings in place that define and enforce how external connections are limited
- Tools like firewalls, connection allow/deny lists, and VPNs

##### Evidence to prove it may include

- An access control policy that defines which external systems can connect and which can't (for example, it may require employees to use company laptops, not personal laptops, when working remotely on contract work involving FCI)
- List of external system connections with date of last review and approval
- Terms and conditions that address the types of applications that can be accessed from external systems at a minimum (also known as "Terms of Service")
- A record of your most recent network configuration review, including firewall rules, VPN configurations, and network architecture
- Log of any changes completed as identified during review (such as a screenshot of updated configurations or an incident ticket)

##### Common gap

- **Personal cloud storage**: Someone syncing project files containing FCI to a personal cloud or email account breaks [e] and [f], although it may be an unintentional violation. Ideally, that's why the use of external connections should be limited by a policy and a physical control.

#### AC.L1-B.1.IV: Control information posted on publicly accessible systems

#### AC.L1-B.1.IV: Control information posted on publicly accessible systems

**Objectives:** [a] through [e]

##### What satisfies it

- Documentation of who is allowed to post to your website or social accounts
- An established review process before anything goes up
- Procedures to remove FCI if it is accidentally published to the public

##### Evidence to prove it may include

- An access control policy that clearly defines roles and responsibilities for publishing, reviewing, and when necessary deleting publicly accessible content
- Security awareness training materials or records for authorized posters
- Export of permissions in your content management system (CMS)
- Logs of access attempts or changes in CMS or reviews and approvals for published content

##### Common gap

- **Social media accounts**: If you have no website, this requirement can be assessed as NOT APPLICABLE if you have contractually documented approval or IMPLEMENTED with an explanation for what’s not in scope. But any public presence at all, including a company page on a social platform or press releases, makes it applicable.

## Recommended reading

How to Write an Access Control Policy: Best Practices + Templates

### Identification and authentication (IA): 2 requirements, 6 objectives

### Identification and authentication (IA): 2 requirements, 6 objectives

```
<style>
#identification-and-authentication-ia-2-requirements-6-objectives-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table td,
#identification-and-authentication-ia-2-requirements-6-objectives-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table thead strong,
#identification-and-authentication-ia-2-requirements-6-objectives-table thead th,
#identification-and-authentication-ia-2-requirements-6-objectives-table thead tr {
  color: #fff;
  font-weight: bold;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table thead tr th {
  font-family: Assistant, sans-serif;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#identification-and-authentication-ia-2-requirements-6-objectives-table tbody tr th,
#identification-and-authentication-ia-2-requirements-6-objectives-table tbody tr td {
  color: #091922;
}
</style>
<table id="identification-and-authentication-ia-2-requirements-6-objectives-table">
<thead>
<tr><th>Requirement</th><th>What it means in plain terms</th><th>What to do</th><th>What not to do</th></tr>
</thead>
<tbody>
<tr><th><strong>IA.L1-B.1.V</strong>: Identification</th><td>Every person, service account, and device has a distinct identity on your systems</td><td>Issue unique identifiers to authorized users and devices such as usernames and IP addresses</td><td>Use generic logins like "shopfloor" or "frontdesk"</td></tr>
<tr><th><strong>IA.L1-B.1.VI</strong>: Authentication</th><td>Identities get verified before access is granted</td><td>Create and enforce policy requiring changing default credentials, minimum password length, etc.</td><td>Assume MFA is required</td></tr>
</tbody>
</table>
```

#### IA.L1-B.1.V: Identify users, processes, and devices

#### IA.L1-B.1.V: Identify users, processes, and devices

**Objectives:** [a] through [c]

##### What satisfies it

- Documentation of the unique identifiers of every user that accesses company systems (i.e., usernames) and every device (i.e., IP address)
- Policies, procedures, and/or configuration settings in place that define and enforce how users, devices, and service accounts are identified and differentiated during registration or login

Ensuring that every user, process, and device has a vetted and trusted identity makes the access control requirement AC.L1-B.1.I possible.

##### Evidence to prove it may include

- A password policy defining procedures for assigning and tracking user, device, or service account identities
- List of personnel, service, and root accounts including their access keys, key count, and when the keys were last used

##### Common gap

- **Generic logins**: This is among the easiest requirements to satisfy and can be done with a [password policy](https://secureframe.com/blog/password-policy) that mandates default usernames be changed (among other requirements). The entire Identification and Authentication domain is basic account hygiene. If every person has their own login and has to enter a password, you are close to done.

#### IA.L1-B.1.VI: Authenticate identities before granting access

#### IA.L1-B.1.VI: Authenticate identities before granting access

**Objectives:** [a] through [c]

##### What satisfies it

- Defined password requirements, including minimum length
- Defined requirements if using other authenticator type, like requiring a one-time password be used within a certain time window
- Proof of how authentication is enforced for users, service accounts, and devices

##### Evidence to prove it may include

- Password policy defining requirements for length, complexity, and changing factory/default passwords
- Export or screenshot of authentication settings, including passwords and trusted devices
- Records of devices enrolled in Intune or similar MDM solution
- Records of MFA enrollment for users can be provided (although not required)

##### Common gap

- **Overengineering**: The most common way to verify identity at this level is using a username and a hard-to-guess password. Level 1 does not require [multi-factor authentication](https://secureframe.com/blog/cmmc-level-2-compliance). That is [NIST SP 800-171](https://secureframe.com/blog/nist-800-171-compliance) requirement 3.5.3 and applies at CMMC Level 2 or higher. You may choose to enable it anyway because credential compromise is one of the most common ways small contractors get breached and you will need it if you move up, but it is not required to reach a MET result at Level 1.

## Recommended reading

Best Password Practices for 2026: Latest NIST Guidelines, Policy Template + Checklist

### Media protection (MP): 1 requirement, 2 objectives

### Media protection (MP): 1 requirement, 2 objectives

```
<style>
#media-protection-mp-1-requirement-2-objectives-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#media-protection-mp-1-requirement-2-objectives-table td,
#media-protection-mp-1-requirement-2-objectives-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#media-protection-mp-1-requirement-2-objectives-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#media-protection-mp-1-requirement-2-objectives-table thead strong,
#media-protection-mp-1-requirement-2-objectives-table thead th,
#media-protection-mp-1-requirement-2-objectives-table thead tr {
  color: #fff;
  font-weight: bold;
}

#media-protection-mp-1-requirement-2-objectives-table thead tr th {
  font-family: Assistant, sans-serif;
}

#media-protection-mp-1-requirement-2-objectives-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#media-protection-mp-1-requirement-2-objectives-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#media-protection-mp-1-requirement-2-objectives-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#media-protection-mp-1-requirement-2-objectives-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#media-protection-mp-1-requirement-2-objectives-table tbody tr th,
#media-protection-mp-1-requirement-2-objectives-table tbody tr td {
  color: #091922;
}
</style>
<table id="media-protection-mp-1-requirement-2-objectives-table">
<thead>
<tr><th>Requirement</th><th>What it means in plain terms</th><th>What to do</th><th>What not to do</th></tr>
</thead>
<tbody>
<tr><th><strong>MP.L1-B.1.VII</strong>: Media disposal</th><td>Drives, USB sticks, and paper with FCI get wiped, redacted, or destroyed before disposal or reuse</td><td>Define a sanitization or destruction method for every media type that holds FCI, including paper, and record each time you use it</td><td>Recycle, donate, or reassign a device with FCI without wiping it first</td></tr>
</tbody>
</table>
```

#### MP.L1-B.1.VII: Sanitize or destroy media containing FCI before disposal or reuse

#### MP.L1-B.1.VII: Sanitize or destroy media containing FCI before disposal or reuse

**Objectives:** [a] and [b]

##### What satisfies it

- Documentation of the types of media that carry FCI in your environment (laptops, external drives, USB sticks, CDs, mobile devices, paper, etc.)
- Established procedures for disposing of each type, such as remote wipe for laptops, physical destruction for removable drives, and crosscut shredding for paper
- A record of every time media is disposed of or reassigned

##### Evidence to prove it may include

- Media protection policy or procedure defining approved sanitization methods by media type
- A log of every disposal with the date, asset identifier, method, and who performed the action (i.e., a remote wipe record in Intune)
- Vendor agreements if third-party destruction services are used

##### Common gap

- **Unsanitized reuse**: Most contractors handle disposal and forget reassignment, which fails objective [b] on its own. Handing a laptop from a departing employee to a new hire counts even though the device never leaves the building. Paper is a close second, since printed drawings and submittals routinely end up in a recycling bin instead of a shredder.

### Physical protection (PE): 2 requirements, 10 objectives

### Physical protection (PE): 2 requirements, 10 objectives

No software satisfies this domain. It is where a fully cloud-based contractor still has work to do, and the domain small contractors most often skip.

```
<style>
#physical-protection-pe-2-requirements-10-objectives-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#physical-protection-pe-2-requirements-10-objectives-table td,
#physical-protection-pe-2-requirements-10-objectives-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#physical-protection-pe-2-requirements-10-objectives-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#physical-protection-pe-2-requirements-10-objectives-table thead strong,
#physical-protection-pe-2-requirements-10-objectives-table thead th,
#physical-protection-pe-2-requirements-10-objectives-table thead tr {
  color: #fff;
  font-weight: bold;
}

#physical-protection-pe-2-requirements-10-objectives-table thead tr th {
  font-family: Assistant, sans-serif;
}

#physical-protection-pe-2-requirements-10-objectives-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#physical-protection-pe-2-requirements-10-objectives-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#physical-protection-pe-2-requirements-10-objectives-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#physical-protection-pe-2-requirements-10-objectives-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#physical-protection-pe-2-requirements-10-objectives-table tbody tr th,
#physical-protection-pe-2-requirements-10-objectives-table tbody tr td {
  color: #091922;
}
</style>
<table id="physical-protection-pe-2-requirements-10-objectives-table">
<thead>
<tr><th>Requirement</th><th>What it means in plain terms</th><th>What to do</th><th>What not to do</th></tr>
</thead>
<tbody>
<tr><th><strong>PE.L1-B.1.VIII</strong>: Limit physical access</th><td>You know who is allowed into the spaces where FCI lives, and other people cannot get in</td><td>Limit and control physical access to specific individuals with locks, badges, and/or secured rooms</td><td>Rely on a locked front door alone</td></tr>
<tr><th><strong>PE.L1-B.1.IX</strong>: Manage visitors and physical access</th><td>You don't let visitors wander, write down who came in, and keep track of keys and badges</td><td>Use logs, physical access points, and devices like badges to monitor and restrict access of employees and visitors</td><td>Giving out physical access devices without inventorying or managing them</td></tr>
</tbody>
</table>
```

#### PE.L1-B.1.VIII: Limit physical access to systems, equipment, and operating environments

#### PE.L1-B.1.VIII: Limit physical access to systems, equipment, and operating environments

**Objectives:** [a] through [d]

##### What satisfies it

- Documentation of individuals authorized for physical access to information systems, equipment, and operating environments
- Mechanisms like locks or badge readers to limit physical access to the office, network or server closet, cabinets, safes, or any sensitive areas

##### Evidence to prove it may include

- Physical security policy defining who is authorized and what is secured
- Photos or a floor plan marking secured areas and access points
- Record of badge assignments, key issuances, or revocation in the event of a termination or role change

##### Common gap

- **Unsecured network equipment**: A locked front door may satisfy the requirement for the environment [d] but not the rest if the switch, router, and backup drive sit in an open hallway or an unlocked utility closet.

#### PE.L1-B.1.IX: Escort visitors, maintain physical access logs, and manage physical access devices

#### PE.L1-B.1.IX: Escort visitors, maintain physical access logs, and manage physical access devices

**Objectives:** [a] through [f]

##### What satisfies it

- Established procedures for escorting and monitoring visitors, including general contractors, vendors, and delivery drivers, while in areas where FCI is processed or stored
- A visitor log or sign-in sheet at the front desk capturing name, company, date, time in and out, and who escorted them
- An inventory of physical access devices that's updated and maintained when an employee leaves or changes roles

##### Evidence to prove it may include

- Physical security policy and/or training materials that include visitor management procedures
- Completed visitor log from the front desk capturing name, company, date, time in and out, and who escorted them
- An up-to-date list of key, badge, and fob holders with date of last review
- An offboarding checklist including collection of physical access devices

##### Common gap

- **Key inventory**: Objectives [d], [e], and [f] cover identifying, controlling, and managing physical access devices, and small contractors may not maintain who holds which key, badge, or key card or even have written it down in the first place.

### System and communications protection (SC): 2 requirements, 10 objectives

### System and communications protection (SC): 2 requirements, 10 objectives

```
<style>
#system-and-communications-protection-sc-2-requirements-10-objectives-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table td,
#system-and-communications-protection-sc-2-requirements-10-objectives-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table thead strong,
#system-and-communications-protection-sc-2-requirements-10-objectives-table thead th,
#system-and-communications-protection-sc-2-requirements-10-objectives-table thead tr {
  color: #fff;
  font-weight: bold;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table thead tr th {
  font-family: Assistant, sans-serif;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#system-and-communications-protection-sc-2-requirements-10-objectives-table tbody tr th,
#system-and-communications-protection-sc-2-requirements-10-objectives-table tbody tr td {
  color: #091922;
}
</style>
<table id="system-and-communications-protection-sc-2-requirements-10-objectives-table">
<thead>
<tr><th>Requirement</th><th>What it means in plain terms</th><th>What to do</th><th>What not to do</th></tr>
</thead>
<tbody>
<tr><th><strong>SC.L1-B.1.X</strong>: Boundary protection</th><td>You know where your network ends, and traffic crossing that edge is watched, controlled, and protected</td><td>Define your external boundary and your key internal boundaries, then monitor, control, and protect traffic at both</td><td>Think encryption creates logical separation</td></tr>
<tr><th><strong>SC.L1-B.1.XI</strong>: Public-access system separation</th><td>Anything the public can reach does not sit on the same network as your internal systems</td><td>Identify publicly accessible system components, then place them on a separate subnet or DMZ</td><td>Assume this is a firewall question rather than an inventory question</td></tr>
</tbody>
</table>
```

#### SC.L1-B.1.X: Monitor, control, and protect communications at system boundaries

#### SC.L1-B.1.X: Monitor, control, and protect communications at system boundaries

**Objectives:** [a] through [h]

##### What satisfies it

- Defined external system boundary and key internal boundaries
- Firewalls, web proxies, gateways, and other protections in place to monitor, control, and protect the flow of data passing between boundaries
- A default-deny inbound rule with defined exceptions for all network boundaries

##### Evidence to prove it may include

- Network security policy
- An architecture and network diagram and/or data flow diagram including the system components and tools supporting the flow of data
- Export or screenshots of firewall configuration settings, record of last review, and any changes
- Firewall, network, or IPS logs and alerts configured to monitor traffic and detect anomalies

##### Common gap

- **Architectural controls**: A common mistake is to think encryption protects boundaries. It doesn't. It protects data. Logical separation requires architectural controls such as firewalls, VLANs, routing rules, and network enforcement mechanisms.

## Recommended reading

DoD CMMC FAQ: Answers to the Most Common Questions

#### SC.L1-B.1.XI: Separate publicly accessible components from internal networks

#### SC.L1-B.1.XI: Separate publicly accessible components from internal networks

**Objectives:** [a] and [b]

##### What satisfies it

- Documentation of any publicly accessible system components
- A dedicated VLAN, isolated cloud environment, security groups, or subnetworking that physically or logically separates any systems that you do host publicly
- A default-deny inbound rule from those subnetworks to your internal network containing FCI

##### Evidence to prove it may include

- The list of publicly accessible components, or a documented statement that you have none
- A network diagram showing physical or logical separation of public-facing systems
- Switch or firewall configuration settings showing access is restricted between public and internal systems

##### Common gap

- **Undocumented inventory**: Objective [a] is inventory, not configuration. Mapping firewall evidence here without ever identifying your publicly accessible components leaves [a] unsatisfied, and it is a common mapping error in compliance tooling as well as in self-assessments.

### System and information integrity (SI): 4 requirements, 12 objectives

### System and information integrity (SI): 4 requirements, 12 objectives

```
<style>
#system-and-information-integrity-si-4-requirements-12-objectives-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table td,
#system-and-information-integrity-si-4-requirements-12-objectives-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table thead strong,
#system-and-information-integrity-si-4-requirements-12-objectives-table thead th,
#system-and-information-integrity-si-4-requirements-12-objectives-table thead tr {
  color: #fff;
  font-weight: bold;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table thead tr th {
  font-family: Assistant, sans-serif;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#system-and-information-integrity-si-4-requirements-12-objectives-table tbody tr th,
#system-and-information-integrity-si-4-requirements-12-objectives-table tbody tr td {
  color: #091922;
}
</style>
<table id="system-and-information-integrity-si-4-requirements-12-objectives-table">
<thead>
<tr><th>Requirement</th><th>What it means in plain terms</th><th>What to do</th><th>What not to do</th></tr>
</thead>
<tbody>
<tr><th><strong>SI.L1-B.1.XII</strong>: Flaw remediation</th><td>You have decided how fast you patch, and you patch that fast</td><td>Write down timeframes for identifying, reporting, and correcting flaws, then set up policies and configurations to patch within them</td><td>Rely on automatic updates without documented timeframes or reviews</td></tr>
<tr><th><strong>SI.L1-B.1.XIII</strong>: Malicious code protection</th><td>You decided where antivirus needs to run, and it runs there</td><td>Identify the locations that need malicious code protection and deploy it to all of them</td><td>Leave in-scope endpoints out of the deployment</td></tr>
<tr><th><strong>SI.L1-B.1.XIV</strong>: Update malicious code protection</th><td>Your EDR or antivirus solution updates itself</td><td>Enable automatic updates and keep records</td><td>Build a manual process where an automated setting would do</td></tr>
<tr><th><strong>SI.L1-B.1.XV</strong>: Periodic and real-time scans</th><td>You decided how often to scan, you scan that often, and files from outside get scanned as they arrive</td><td>Define a scan frequency, schedule scans to match it, and enable real-time scanning of files from external sources</td><td>Leave the frequency undefined and assume defaults count</td></tr>
</tbody>
</table>
```

#### SI.L1-B.1.XII: Identify, report, and correct system flaws in a timely manner

#### SI.L1-B.1.XII: Identify, report, and correct system flaws in a timely manner

**Objectives:** [a] through [f]

##### What satisfies it

- Documented timeframes for identifying, reporting, and correcting flaws (can be as simple as "critical patches within 14 days, all others within 30 days")
- A mechanism that performs the patching, such as Windows Update for Business, Intune update rings, or a managed service provider's patching service
- Proof that servers and user devices actually meet the timeframe

##### Evidence to prove it may include

- Vulnerability and patch management policy containing timeframes and defined process for reviewing vendor notifications and updates
- Patch compliance reports showing current status of servers and devices
- Ticketing or tracking records showing when flaws were reported and corrected

##### Common gap

- **Overreliance on automatic updates**: Contractors may patch diligently and never write the timeframe down, which fails half the requirement. Automatic updates alone cannot satisfy [a], [c], or [e], because those objectives ask whether the timeframe is specified, not whether patching happens.

## Recommended reading

A Step-by-Step Guide to the Vulnerability Management Process [+ Policy Template]

#### SI.L1-B.1.XIII: Provide protection from malicious code at appropriate locations

#### SI.L1-B.1.XIII: Provide protection from malicious code at appropriate locations

**Objectives:** [a] and [b]

##### What satisfies it

- Documentation of the designated locations where malicious code protection is needed
- Endpoint protection deployed at all of them, such as an EDR tool like Microsoft Defender for Business or an anti-virus software
- Coverage that matches your scope, including mobile devices, email gateways, shop-floor machines, and any shared workstation that touches FCI
- Non-traditional mechanisms (i.e., secure coding and configuration management controls) if you have custom-built software

##### Evidence to prove it may include

- Malware protection policy identifying designated locations, including both system entry and exit points
- An endpoint deployment, coverage, and/or monitoring report or dashboard
- Export or screenshot of endpoint protection configuration settings
- Logs of actions initiated by the protection mechanisms (such as email filtering logs) and by personnel to address false positives (such as incident reports)

##### Common gap

- **Endpoints missing from deployment**: Usually it's a shop-floor machine, a shared workstation, or a tablet nobody counted as in scope. The gap is a scoping failure more often than a tooling failure.

#### SI.L1-B.1.XIV: Update malicious code protection mechanisms when new releases are available

#### SI.L1-B.1.XIV: Update malicious code protection mechanisms when new releases are available

**Objectives:** [a]

##### What satisfies it

- Defined frequency for malicious code protection mechanisms to be updated
- Logs or records of those updates

##### Evidence to prove it may include

- A configuration screenshot showing automatic updates are enabled
- Update logs from your EDR platform console
- Alerting records of any update failures and tickets tracking remediation

##### Common gap

- **Manual process**: This requirement is one of the easiest to meet thanks to automatic updates. Relying on a manual process increases the risk of failed or untimely updates.

#### SI.L1-B.1.XV: Perform periodic and real-time scans

#### SI.L1-B.1.XV: Perform periodic and real-time scans

**Objectives:** [a] through [c]

##### What satisfies it

- A defined scan frequency in writing, which is objective [a]
- Scheduled scans configured to match that frequency
- Real-time protection enabled so files from external sources are scanned as they are downloaded, opened, or executed

##### Evidence to prove it may include

- Malware protection policy stating the scan frequency
- Scan history or logs showing scans ran at that frequency
- Real-time protection configuration settings

##### Common gap

- **Default schedule**: The same pattern as flaw remediation. Your endpoint protection ships with a default schedule that may suit your needs, but it must be evaluated first and then documented to satisfy objective [a].

## Recommended reading

CMMC Gap Analysis: How to Find What You're Missing

## What CMMC Level 1 does not require

## What CMMC Level 1 does not require

Most of the cost and anxiety at Level 1 comes from assuming Level 2 work is required. But Level 1 is a foundational level that [rolls up to CMMC Level 2](https://secureframe.com/hub/cmmc/certification-levels).

![](https://images.prismic.io/secureframe-com/tTBvvCBrsdgTiQ3x_CMMCLevelscomparedbynumberofsecurityrequirements.png?auto=format,compress)

Implementing the underlying cybersecurity requirements at this level provides a headstart for Level 2 and other more advanced frameworks. None of the following is required to reach a MET result at Level 1:

```
<style>
#what-cmmc-level-1-does-not-require-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}

#what-cmmc-level-1-does-not-require-table td,
#what-cmmc-level-1-does-not-require-table th {
  padding: 1rem;
  border: 1px solid #fff;
}

#what-cmmc-level-1-does-not-require-table thead {
  background-color: #0CAB6B;
  color: #fff;
}

#what-cmmc-level-1-does-not-require-table thead strong,
#what-cmmc-level-1-does-not-require-table thead th,
#what-cmmc-level-1-does-not-require-table thead tr {
  color: #fff;
  font-weight: bold;
}

#what-cmmc-level-1-does-not-require-table thead tr th {
  font-family: Assistant, sans-serif;
}

#what-cmmc-level-1-does-not-require-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}

#what-cmmc-level-1-does-not-require-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}

#what-cmmc-level-1-does-not-require-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}

#what-cmmc-level-1-does-not-require-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}

#what-cmmc-level-1-does-not-require-table tbody tr th,
#what-cmmc-level-1-does-not-require-table tbody tr td {
  color: #091922;
}
</style>
<table id="what-cmmc-level-1-does-not-require-table">
<thead>
<tr><th>Requirement at Level 2</th><th>What's actually required at Level 1</th></tr>
</thead>
<tbody>
<tr><th><a href="https://secureframe.com/blog/cmmc-ssp">System Security Plan (SSP)</a></th><td>While the <a href="https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL1.pdf">DoD's Level 1 Assessment Guide</a> recommends an SSP as a <a href="https://secureframe.com/compliance-resources/cmmc-ssp-template">best practice</a>, it explicitly states it is not required to obtain a Level 1 self-assessment.</td></tr>
<tr><th><a href="https://secureframe.com/hub/cmmc/documentation">POA&amp;M</a></th><td>Prohibited at Level 1 since all 15 requirements in FAR 52.204-21 must be MET.</td></tr>
<tr><th><a href="https://secureframe.com/hub/cmmc/c3pao">C3PAO assessment</a></th><td>Only self-assessments are required at Level 1.</td></tr>
<tr><th><a href="https://secureframe.com/blog/cmmc-level-2-compliance">Multi-factor authentication</a></th><td>Mandated by an Identification and Authentication requirement for CMMC Level 2 and higher only (3.5.3 from NIST 800-171 Rev 2).</td></tr>
<tr><th><a href="https://secureframe.com/blog/cmmc-level-2-compliance">FIPS-validated encryption</a></th><td>Required by multiple Access Control and System and Communications Protection requirements at CMMC Level 2 and higher only.</td></tr>
<tr><th><a href="https://secureframe.com/hub/cmmc/training">Security awareness training</a></th><td>CMMC Level 1 does not contain any requirements or practices from the Awareness &amp; Training domain, but security awareness training records and materials can be evidence for certain Level 1 requirements.</td></tr>
<tr><th><a href="https://secureframe.com/blog/cmmc-incident-response-plan">Incident response plan</a></th><td>CMMC Level 1 does not contain any requirements or practices from the Incident Response domain, but incident response procedures or tickets can be evidence for certain Level 1 requirements.</td></tr>
<tr><th><a href="https://secureframe.com/blog/vulnerability-management">Risk assessment and vulnerability remediation</a></th><td>CMMC Level 1 does not contain any requirements or practices from the Risk Assessment domain, although risk assessment and remediation is foundational to Level 1 requirements.</td></tr>
<tr><th><a href="https://secureframe.com/compliance-resources/nist-800-171-compliance-checklist">Audit logging and review</a></th><td>CMMC Level 1 does not contain any requirements or practices from the Audit &amp; Accountability domain, although audit logs can be evidence for certain Level 1 requirements.</td></tr>
</tbody>
</table>
```

## CMMC Level 1 Evidence Collection Spreadsheet

This spreadsheet maps all 15 requirements and 59 objectives assessed at CMMC Level 1 to examples of controls and evidence you need to prove you've met each. Use it to understand what each objective is asking, how to implement it, what evidence to collect, and then track it to assess if you're ready to submit or defend your self-assessment in SPRS.

## Step 4: Score, submit, and affirm

## Step 4: Score, submit, and affirm

Once every requirement is implemented, you run a readiness check, score the assessment, and record it in the [Supplier Performance Risk System (SPRS)](https://secureframe.com/blog/cmmc-sprs) through the Procurement Integrated Enterprise Environment (PIEE) portal, and your Affirming Official signs the affirmation.

The overall result is MET only if all 15 requirements and 59 objectives are satisfied (or marked as NOT APPLICABLE with contractually documented approval). Only a status of Final Level 1 Self-Assessment makes you eligible for awards carrying the Level 1 requirement, and it expires one year from your assessment date. [Primes](https://secureframe.com/blog/prime-contractor-cmmc-compliance) cannot see your SPRS record directly, so expect to be asked for a screenshot.

## Recommended reading

How to Submit Your CMMC Self-Assessment to SPRS

## Step 5: Keep your Level 1 status current

## Step 5: Keep your Level 1 status current

The affirmation is what turns Level 1 from an annual project into an [ongoing obligation](https://secureframe.com/hub/cmmc/continuous-compliance). You are attesting not just that you met the requirements on assessment day, but that you are maintaining them.

That distinction is where most contractors get into trouble. Access reviews stop happening, a laptop leaves without being wiped, a former employee keeps a key, antivirus falls off a machine. None of it is dramatic, and all of it makes a signed affirmation [inaccurate](https://secureframe.com/blog/false-claims-act). Build the recurring habits now: a quarterly access and key review, a disposal log you actually fill in, and a check that endpoint protection still covers every in-scope device.

## Recommended reading

How to Maintain CMMC Compliance Between Assessments: Navigating the Next Phase of Enforcement

## Get secure and stay CMMC compliant with Secureframe

## Get secure and stay CMMC compliant with Secureframe

CMMC Level 1 requires you to assess your implementation of 15 requirements and 59 objectives, and for a small contractor with a tight scope, most of them are satisfied by the right configurations of tools you already own plus decisions you just need written down.

The three things that will save you the most time are scoping honestly so you assess only what's necessary, choosing a cloud solution and license for what it does rather than for its compliance label, and finding an affordable and scalable way to [implement and maintain](https://secureframe.com/hub/cmmc/manual-vs-automated) the underlying Level 1 requirements that are foundational to compliance with NIST 800-171, DFARS 7012, CMMC Level 2, and other cybersecurity frameworks.

You do not need a [consultant](https://secureframe.com/hub/cmmc/consultant), an [RPO](https://secureframe.com/blog/cmmc-rpo), or an advisory [C3PAO](https://secureframe.com/hub/cmmc/c3pao) to do this necessarily. You need an accurate mapping of the 15 requirements and 59 objectives to the controls you need in place and the tests to ensure they're operating effectively, an honest look at your environment and what touches FCI (and whether it touches any CUI), and the operational discipline to keep it current between assessments.

[Secureframe Defense](https://secureframe.com/blog/announcing-secureframe-defense-for-cmmc) automatically maps controls and collects evidence for all Level 1 requirements and objectives that apply to your environment, and [monitors them between assessments](https://secureframe.com/hub/cmmc/automation) so the affirmation you sign every year reflects your actual environment.

[Request a demo](https://secureframe.com/cmmc) to see how we help contractors of all sizes stand up and manage a NIST 800-171 and CMMC cybersecurity program to keep their contracts and operations running.

### Get certified. Stay compliant.

### How many requirements are in CMMC Level 1?

CMMC Level 1 assesses whether a defense contractor has implemented 15 requirements focused on protecting Federal Contract Information (FCI). These are the basic safeguarding requirements from FAR Clause 52.204-21. Note that when CMMC 2.0 was announced in 2021, Level 1 had 17 requirements, including four Physical Protection requirements but three of those were merged into one, PE.L1-B.1.IX, bringing the final total to 15. The current count is confirmed in 32 CFR 170.14(c)(2).

### How many assessment objectives are in CMMC Level 1?

CMMC Level 1 has 59 assessment objectives spread across the 15 requirements, with between one and eight objectives each.

### How long does it take to get CMMC Level 1?

It depends almost entirely on how much documentation you already have, not on the technology. The Department estimates roughly 28 labor hours for a Level 1 self-assessment, but that covers only assessing, reporting, and affirming, not implementing the requirements or closing gaps. A contractor already running a commercial productivity suite with unique user accounts, managed devices, and endpoint protection is mostly writing decisions down and collecting evidence, which is weeks rather than months. A contractor with shared logins, an unlocked network closet, no written patch timeframes, and no key inventory has real remediation work first. There's no waiting period for an assessor, because Level 1 is self-assessed, so your timeline is entirely within your control.

### What is the difference between CMMC Level 1 and Level 2?

Level 1 protects Federal Contract Information and Level 2 protects Controlled Unclassified Information. That single distinction drives everything else. Level 1 is 15 requirements from FAR 52.204-21 with 59 assessment objectives, drawn from 6 of the 14 NIST SP 800-171 families. Level 2 is all 110 NIST SP 800-171 requirements across all 14 families. Level 1 is self-assessed and scored pass or fail, with no partial credit and no POA&M. Level 2 is scored numerically, allows a POA&M for some requirements, and was codified in the 32 CFR rule as requiring a C3PAO assessment rather than a self-assessment for most contractors. The practical consequences are large: MFA, FIPS-validated encryption, audit logging, incident response, security awareness training, and an SSP all enter at Level 2 and none are required at Level 1.

### Can you self-certify CMMC Level 1?

Yes, though the correct term is self-assessment rather than self-certification. Level 1 has never required a C3PAO or any third-party assessor. You assess your own environment against the 15 requirements and 59 objectives, record the result in SPRS through the PIEE portal, and a named Affirming Official signs the affirmation. That affirmation is what distinguishes this from older self-attestation models. It's a formal statement to the government that you have implemented and will maintain the requirements, and an inaccurate one can carry liability under the False Claims Act.

### How much does it cost to get CMMC Level 1?

The Department estimates $4,000 to $6,000 annually for assessing, reporting, and affirming CMMC Level 1 compliance, though that assumes you have already implemented the underlying cybersecurity costs. Realistically, your costs also include remediation for whatever you don't currently meet, licensing for a commercial productivity suite and endpoint protection (which you may already pay for), physical security items like locks and a visitor log, and consulting or additional labor hours internally. That brings the total cost between $5,000-$20,000 on average. Several costs commonly quoted for CMMC don't apply here at all: a CUI enclave, GCC High licensing, SIEM tooling, and FIPS-validated encryption are all Level 2 concerns. See the CMMC certification cost breakdown for the full picture across levels, and what CMMC costs smaller contractors.

### Do I need GCC High for CMMC Level 1?

No. Level 1 covers FCI, not CUI, and Microsoft confirms Commercial can be used to demonstrate Level 1 compliance for FCI. But Microsoft also notes that Commercial was not purpose-built for US government requirements and that the government clouds are the safer long-term posture, so the deciding factor is whether you expect CUI work in the next couple of years (does CMMC require GCC High?).

### Does CMMC Level 1 require multi-factor authentication?

No. Level 1 requires authentication before access, which passwords can satisfy. MFA enters at Level 2. Enabling it is still recommended at Level 1, however.

### Do I need a System Security Plan for Level 1?

No. The DoD's Level 1 Assessment Guide recommends developing an SSP as a best practice but states explicitly that it is not required to obtain a Level 1 self-assessment.

### Can I use a POA&M at Level 1?

No. Every requirement must be MET (or marked NOT APPLICABLE with contractually documented approval) to achieve a passing result.
