To achieve CMMC Level 1 certification, you’ll need to implement 17 foundational cybersecurity controls that protect Federal Contract Information (FCI). You must establish basic safeguarding requirements across six domains including access control, identity management, and incident response. The certification requires annual self-assessments with documentation submitted to the Supplier Performance Risk System (SPRS), affirmed by a senior company official. You’ll also need ongoing staff training and continuous monitoring to maintain compliance throughout your contract periods.
Key Takeaways
- CMMC Level 1 certification requires implementing 17 foundational cybersecurity controls to protect Federal Contract Information (FCI).
- Organizations must establish unique user identification, authentication methods, and strong password policies for accessing FCI systems.
- All assets that process, store, or transmit FCI must be identified and documented with formal evidence.
- Annual self-assessments must be conducted and affirmed by a senior company official, with results submitted to SPRS.
- Staff cybersecurity training programs and incident response capabilities for unauthorized access must be established and maintained.
Understanding CMMC Level 1 and Federal Contract Information

When your organization seeks to work with the Department of Defense, you’ll need CMMC Level 1 certification if you handle Federal Contract Information (FCI)—information the government provides or generates under contract that isn’t meant for public release.
This certification demonstrates your commitment to basic cybersecurity practices through 17 foundational controls derived from FAR 52.204-21.
CMMC Level 1 certification focuses on safeguarding sensitive information through essential security domains including access control, identification and authentication, media protection, physical protection, and system communications protection.
Compliance isn’t optional—it’s mandatory for all contractors, including small businesses, working with the DoD.
You’ll maintain certification through annual self-assessments, documenting your cybersecurity practices and submitting results to the Supplier Performance Risk System with senior official affirmation.
CMMC Level 1 Vs Level 2 Vs Level 3 Comparison
Understanding the three CMMC levels helps you determine which certification your organization needs based on the type of information you’ll handle.
CMMC Level 1 compliance focuses on basic cybersecurity hygiene for protecting Federal Contract Information (FCI) through 15 practices and a self-assessment process conducted annually.
CMMC Level 1 establishes foundational cybersecurity practices through 15 basic controls and annual self-assessments for Federal Contract Information protection.
CMMC Level 2 targets defense contractors handling Controlled Unclassified Information with 110 NIST 800-171 requirements and requires third-party assessments.
CMMC Level 3 addresses the most sensitive CUI with extensive security measures against advanced persistent threats, also requiring triennial third-party evaluations.
While Level 1 emphasizes foundational cyber hygiene, Levels 2 and 3 involve increasingly rigorous security controls.
Non-compliance consequences include contract ineligibility, making proper level determination vital for your organization’s success.
The 15 Basic Safeguarding Requirements for Level 1

Now that you know which CMMC level applies to your organization, let’s examine the specific requirements you’ll need to meet for CMMC Level 1 certification. You must comply with 15 basic safeguarding requirements outlined in FAR Clause 52.204-21, which establish fundamental cybersecurity practices for protecting Federal Contract Information.
These security requirements span six critical domains. Access Control demands unique login credentials and robust password management. Identification and Authentication requires verifying user identities before granting system access.
Physical Protection involves securing locations where FCI is stored and restricting entry to authorized personnel only. You’ll also need to address Media Protection, System and Communications Protection, and incident response capabilities.
Each requirement focuses on establishing baseline security controls that prevent unauthorized access to sensitive government information flowing through your systems.
Access Control and Identity Management Practices
Access control forms the cornerstone of your CMMC Level 1 compliance strategy, requiring you to establish robust identity management practices that verify who’s accessing your systems and what they’re allowed to see.
Robust identity management practices serve as the foundation for verifying system access and determining information visibility in CMMC compliance.
You’ll need to implement unique user identification and authentication methods for anyone accessing Federal Contract Information. This means creating strong password management policies with complexity requirements and regular password changes to prevent unauthorized access.
Your access permissions must align with job responsibilities, ensuring employees only access information necessary for their roles.
Don’t overlook physical access control measures—you’ll need locks, security badges, or monitored entry points protecting areas where FCI is stored.
Regular reviews of your access control policies are essential for maintaining compliance as your organizational structure evolves.
Media Protection and Physical Security Controls

While controlling who accesses your systems protects against digital threats, you’ll also need to secure the physical media and locations where your Federal Contract Information lives.
Media Protection requires you to establish clear rules for storage and disposal of any media containing FCI. You must mark all media appropriately, store it securely, and dispose of it properly to prevent data recovery.
Physical Protection mandates limiting access to locations storing sensitive information. You’ll need security measures like locks, surveillance systems, and access logs to monitor who enters these areas.
These controls prevent unauthorized access from personnel who shouldn’t handle FCI. Implementing both Media Protection and Physical Protection requirements creates the secure environment necessary for CMMC Level 1 certification compliance.
System and Communications Protection Standards
Although securing physical locations protects your Federal Contract Information at rest, you must also safeguard FCI as it travels across networks and communication channels.
System and Communications Protection standards under CMMC Level 1 establish critical requirements for contractors handling FCI to prevent unauthorized access during data transmission.
Your organization must implement these essential protections:
- Establish secure communication protocols that maintain FCI integrity and confidentiality across all network transmissions.
- Define and manage system boundaries clearly, restricting access to system components only to authorized users.
- Monitor communications at system perimeters continuously to detect potential breaches and unauthorized interception attempts.
- Control network access points systematically to prevent manipulation of sensitive information by malicious actors.
These standards demonstrate your capability to protect against cyber threats effectively.
Annual Self-Assessment Process and Documentation

Maintaining CMMC Level 1 compliance isn’t a one-time achievement—it requires ongoing verification through annual self-assessments that demonstrate your organization’s continued adherence to the 15 basic safeguarding requirements outlined in FAR Clause 52.204-21.
During your annual self-assessment, you’ll document your security measures, policies, procedures, and safeguards to prove CMMC Level 1 compliance. You must identify all assets that process, store, or transmit Federal Contract Information to confirm they meet requirements.
Your findings necessitate formal documentation with evidence for each requirement you’ve satisfied. These results must be submitted to the Department of Defense’s Supplier Performance Risk System.
Importantly, a senior company official must affirm your self-assessment findings, accepting liability under the False Claims Act to guarantee accountability and compliance verification.
Submitting Compliance Evidence to SPRS
Once you’ve completed your annual self-assessment, you must submit your compliance evidence to the Department of Defense’s Supplier Performance Risk System (SPRS) to maintain your CMMC Level 1 certification status.
Your compliance documentation must demonstrate adherence to all 15 security requirements outlined in FAR 52.204-21.
When preparing your SPRS submission, guarantee you include:
- Supporting evidence for each self-assessment finding that verifies compliance with security requirements
- Formal affirmation from a senior company official, making your organization liable under the False Claims Act
- Assessment scope details specifying which assets process, store, or transmit Federal Contract Information
- Annual submission timeline to avoid penalties related to noncompliance with DoD contract requirements
This submission process guarantees your organization maintains compliance and protects Federal Contract Information effectively.
Maintaining Continuous Compliance and Monitoring

Submitting your compliance evidence to SPRS represents just the beginning of your CMMC Level 1 obligations. You must establish continuous compliance through regular monitoring of your 15 security controls outlined in FAR 52.204-21.
Conduct annual self-assessments to evaluate your cybersecurity practices’ effectiveness and document findings in SPRS.
Implement Continuous Control Monitoring to automate evidence collection and identify compliance gaps before they become critical issues. You’ll need real-time updates on your compliance status to maintain your cybersecurity posture effectively.
Don’t overlook training programs—they’re essential for keeping staff informed about their cybersecurity roles. This creates a culture supporting risk management and ongoing compliance.
Your monitoring process should consistently update security measures as threats evolve, ensuring you maintain CMMC certification requirements throughout your contract periods.
Frequently Asked Questions
Can You Self Certify for CMMC Level 1?
Yes, you can self-certify for CMMC Level 1.
You’ll conduct an annual self-assessment demonstrating compliance with 17 cybersecurity practices from FAR 52.204-21. The certification process requires documenting your security controls, risk assessment, and audit procedures.
You must submit compliance documentation to SPRS with senior official affirmation. Unlike higher CMMC requirements, Level 1 standards don’t need third-party assessment, making self-certification accessible for defense contractors implementing basic cybersecurity practices.
What Is the Difference Between Level 1 and Level 2 CMMC?
Think of CMMC levels as building blocks – Level 1 is your foundation.
You’ll follow 15 basic cybersecurity practices through self-assessment for Federal Contract Information protection.
Level 2 requires you to climb higher with 110 NIST SP 800-171 security controls, demanding third-party validation every three years for Controlled Unclassified Information.
Your compliance requirements, assessment methodology, and documentation standards become considerably more rigorous as you advance through these certification processes and implementation strategies.
How to Become CMMC Certified?
To become CMMC certified, you’ll need to understand the certification process and specific CMMC requirements for your target level.
Start by reviewing security controls and creating a compliance checklist. Implement necessary documentation needs and security measures following industry standards and best practices.
Develop implementation strategies, utilize training resources, and establish your assessment timeline.
You’ll undergo evaluation by authorized assessors who’ll verify your organization meets all required controls before granting certification.
How Much Does CMMC Level 1 Cost?
You’re likely wondering about the financial commitment lurking behind CMMC Level 1—and it’s more complex than you’d expect.
Your CMMC costs start with certification expenses of $4,000-$6,000 for self-assessment, but that’s just the beginning.
Budgeting for compliance requires financial planning beyond initial certification fees. Your cost breakdown includes implementation expenses, ongoing maintenance, and potential third-party expertise.
Smart investment analysis and cost management reveal compliance isn’t optional—non-compliance costs far more.
Conclusion
You’ve built your CMMC Level 1 foundation like constructing a house—you wouldn’t skip the basic electrical wiring, would you? With 88% of small defense contractors still unprepared for CMMC requirements, you’re ahead of the curve by implementing these 15 safeguarding practices. Your annual self-assessment isn’t just paperwork; it’s your quality inspection ensuring every security control functions properly. Stay vigilant with continuous monitoring, because your compliance house needs ongoing maintenance to protect those valuable federal contracts.





