CMMC Level 1 Self-Assessment: The 15 Requirements Explained
ISO Cloud Consulting editorial team
CMMC Level 1 is a yearly self-assessment against 15 basic safeguarding requirements from FAR 52.204-21, for companies that handle Federal Contract Information (FCI). Every requirement must be fully met, no POA&M is allowed, and a senior official affirms the result in the Supplier Performance Risk System (SPRS) each year.
Key facts
- 15 requirements, taken word for word from FAR 52.204-21, paragraph (b)(1).
- They map to 17 NIST SP 800-171 requirements and are tested through 59 assessment objectives in NIST SP 800-171A, reading "FCI" wherever an objective says "CUI".
- Scored met or not met overall. No points, no partial credit, no POA&M.
- Repeat the self-assessment and affirmation every year.
- Keep the evidence for six years from your CMMC status date.
- Level 1 was not affected by the July 2026 pause of third-party assessments.
Who needs a CMMC Level 1 self-assessment?
Any company whose DoD contract or subcontract requires CMMC Level 1 (Self), which applies when you process, store or transmit FCI but not CUI. Many small machine shops, fabricators and service providers fall here.
FCI is information "not intended for public release, that is provided by or generated for the Government under a contract", excluding public information and simple payment details. Think purchase orders, delivery schedules, part quantities and a customer's non-public specifications. If you also handle CUI, such as controlled technical drawings, you need Level 2, and a Level 2 (Self) status also satisfies Level 1 for the same scope.
What are the 15 CMMC Level 1 requirements?
The 15 requirements are the basic safeguarding controls in FAR 52.204-21(b)(1)(i) through (xv). They cover access control, identification and authentication, media disposal, physical protection, network boundaries and malware protection. Here is each one verbatim, with what it means in practice.
| CMMC ID | FAR 52.204-21 requirement (verbatim) | In plain English |
|---|---|---|
| AC.L1-b.1.i | Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). | Only approved people, and their approved programs and devices, can get into systems holding FCI. Keep a user and device list and remove leavers the same day. |
| AC.L1-b.1.ii | Limit information system access to the types of transactions and functions that authorized users are permitted to execute. | People can only do what their job needs. Everyday accounts are not administrators. |
| AC.L1-b.1.iii | Verify and control/limit connections to and use of external information systems. | Decide which outside systems may touch FCI (personal phones, home PCs, personal cloud storage) and enforce it. |
| AC.L1-b.1.iv | Control information posted or processed on publicly accessible information systems. | Nothing non-public goes on your website, social media or public shares. Name who approves posts. |
| IA.L1-b.1.v | Identify information system users, processes acting on behalf of users, or devices. | Every person, service account and device has its own identity. No shared shop-floor login. |
| IA.L1-b.1.vi | Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. | Verify identity before access, with strong passwords at minimum. Change default passwords on new equipment. |
| MP.L1-b.1.vii | Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. | Wipe or shred drives, USB sticks and paper holding FCI before disposal or reuse, and keep a record. |
| PE.L1-b.1.viii | Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. | Lock offices, server closets and areas where FCI lives. Only authorized people get keys or badges. |
| PE.L1-b.1.ix | Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices. | Sign in and escort visitors, keep an access log, and track who holds keys, badges and door codes. |
| SC.L1-b.1.x | Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. | A configured, monitored firewall at the internet edge and between key internal zones. |
| SC.L1-b.1.xi | Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. | Anything the public can reach, such as a web server or guest Wi-Fi, is separated from your internal network. |
| SI.L1-b.1.xii | Identify, report, and correct information and information system flaws in a timely manner. | Patch operating systems, applications and firmware on a schedule and track what is outstanding. |
| SI.L1-b.1.xiii | Provide protection from malicious code at appropriate locations within organizational information systems. | Anti-malware runs on computers, servers and email. |
| SI.L1-b.1.xiv | Update malicious code protection mechanisms when new releases are available. | Anti-malware updates automatically, and someone checks that it does. |
| SI.L1-b.1.xv | Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed. | Scheduled scans, plus real-time scanning of downloads, attachments and USB files. |
Requirement ix bundles three NIST requirements (3.10.3, 3.10.4 and 3.10.5), which is why 15 FAR requirements map to 17 NIST ones.
How is a CMMC Level 1 self-assessment scored?
Each requirement is either met or not met, and you need all 15 met to achieve Final Level 1 (Self) status. There are no points and no partial credit.
A requirement is met only when every one of its assessment objectives is satisfied with evidence in final form. Drafts, working papers and unapproved policies do not count. For example, requirement i has six objectives: users, processes and devices are identified, and access is limited to each of them. Having a user list but no device list means requirement i is not met.
A requirement can be marked not applicable when it genuinely does not apply. The CMMC rule's own example is public-access separation when there are no publicly accessible systems in scope. Not applicable counts as met, so write down the reason.
How do you complete a Level 1 self-assessment, step by step?
Most small companies can complete a Level 1 self-assessment in a few working days once the scope is clear. The steps are the same every year.
- Define the scope. List the people, computers, phones, cloud accounts, file shares and locations that store, process or transmit FCI.
- Collect evidence. User and device lists, firewall settings, antivirus status, patch records, the visitor log, key or badge records and disposal records.
- Test each requirement. Walk through all 59 objectives and mark each one met, not met or not applicable, with a note on the evidence.
- Fix every gap. Level 1 has no POA&M, so anything not met must be fixed before you affirm.
- Enter results in SPRS. Record the level, status date, assessment scope, the CAGE codes covered and the result.
- Affirm. Your Affirming Official, a senior person with authority for compliance, affirms in SPRS that all requirements are implemented and will be maintained.
- Diary the next one. Set a reminder for 11 months out, and file the evidence where you can find it for six years.
What does SPRS need for Level 1?
Under 32 CFR 170.15, the SPRS entry must include at minimum the CMMC level, the CMMC status date, the assessment scope, every CAGE code covered by that scope, and the compliance result. The affirmation is a separate step made by your Affirming Official.
Unlike Level 2, there is no numeric score to enter. The answer is simply whether every requirement is met. That makes honesty easy to judge: if one requirement is not met, you are not yet ready to affirm.
What mistakes trip up Level 1 self-assessments?
Most Level 1 gaps are small and cheap to fix. They are found by walking the building, not by reading policies.
- Shared logins. A single account for the shop-floor PC or the CNC programming station fails requirements i and v.
- Forgotten devices. Personal phones reading company email, an old laptop in a drawer, a networked printer with its default password.
- No visitor log. Visitors walk in unescorted, or the log exists but nobody fills it in.
- Undocumented disposal. Old drives recycled without being wiped or without a record that they were.
- Assuming the IT provider covers it. Your managed IT provider may run the firewall and antivirus, but you still need evidence that it happens, and you are the one affirming.
Start with the Free CMMC Level 1 Self-Assessment Checklist to see where you stand. When you are ready to document the full assessment, the CMMC Level 1 Self-Assessment Kit ($79) is built for exactly that. For how Level 1 fits alongside Level 2 and the 2026 changes, see what still applies after the Phase 2 pause and our CMMC hub. A template helps you prepare; your affirmation must rest on what you have actually implemented.
Last reviewed: 29 September 2026. CMMC rules are still moving. Check your contract, your prime's flowdown and the current rule before you rely on any date.