← Back to Library
CMMC L1

CMMC Level 1 (v2.0)

Full Name:
Cybersecurity Maturity Model Certification (CMMC) - Level 1
Acronym:
CMMC L1
Type:
US Federal Standard
Organization:
U.S. Department of Defense
Version:
2
Year Published:
2022
Popularity:
High

Overview of CMMC Level 1

Cybersecurity Maturity Model Certification (CMMC) Level 1, established under CMMC 2.0 in 2022, represents the baseline cybersecurity requirement for Department of Defense (DoD) contractors handling Federal Contract Information (FCI). Level 1 includes 17 security safeguarding requirements derived from FAR 52.204-21, focusing on fundamental cyber hygiene practices that protect basic contract information like technical specifications, proposals, and procurement-sensitive data. Unlike the more stringent Level 2 requirements for Controlled Unclassified Information (CUI), Level 1 establishes foundational protections appropriate for contractors with limited DoD information exposure.

CMMC 2.0 streamlined the original CMMC framework (which had five levels) into three levels, making Level 1 the entry point for the defense industrial base. Contractors requiring only Level 1 certification can conduct annual self-assessments rather than undergoing third-party assessments, significantly reducing compliance costs and complexity. However, self-assessments must be accurate and truthful, with senior executives affirming compliance—false attestations carry severe consequences including contract termination, suspension from DoD contracting, and potential criminal liability.

The 17 Level 1 Practices

CMMC Level 1 organizes 17 practices across multiple security domains, providing basic but essential protections for FCI.

Access Control (AC)

AC.L1-3.1.1 - Limit Information System Access: Restrict information system access to authorized users, processes acting on behalf of authorized users, or devices. Organizations must implement access controls ensuring only personnel with business need can access FCI systems and data.

AC.L1-3.1.2 - Limit Information System Access to Authorized Users: Limit system access to types of transactions and functions authorized users are permitted to execute. Implement role-based access ensuring users can perform only authorized activities, not unrestricted system administration or data modification.

Identification and Authentication (IA)

IA.L1-3.5.1 - Identify Information System Users: Identify information system users, processes acting on behalf of users, or devices. Implement unique user identifiers (no shared accounts) enabling attribution of actions to specific individuals for accountability and auditing.

IA.L1-3.5.2 - Authenticate System Users: Authenticate or verify identities of users, processes, or devices as prerequisite to system access. Implement authentication mechanisms verifying user identities before granting access to FCI.

Media Protection (MP)

MP.L1-3.8.1 - Protect Information on System Media: Protect information on system media (paper, digital) from unauthorized disclosure and modification. Implement controls for handling, marking, storing, and destroying media containing FCI.

MP.L1-3.8.2 - Limit Access to Media: Limit access to CUI on system media to authorized users. Control who can access devices, storage media, and printouts containing FCI.

MP.L1-3.8.3 - Sanitize or Destroy Media: Sanitize or destroy information system media containing FCI before disposal or release for reuse. Implement secure deletion methods preventing data recovery from disposed media.

Physical Protection (PE)

PE.L1-3.10.1 - Limit Physical Access: Limit physical access to organizational information systems, equipment, and operating environments to authorized individuals. Implement physical access controls for facilities, server rooms, and equipment storing or processing FCI.

PE.L1-3.10.3 - Escort Visitors: Escort visitors and monitor visitor activity within facilities containing FCI. Maintain visitor logs documenting who accessed facilities, when, and for what purpose.

PE.L1-3.10.4 - Maintain Audit Logs of Physical Access: Maintain audit logs of physical access and review logs periodically. Physical access logs help investigate security incidents and identify unauthorized access attempts.

System and Communications Protection (SC)

SC.L1-3.13.1 - Boundary Protection: Monitor, control, and protect communications at external boundaries and key internal boundaries of information systems. Implement firewalls and network segmentation preventing unauthorized access to FCI systems.

SC.L1-3.13.5 - Public-Access System Separation: Implement subnetworks for publicly accessible system components physically or logically separated from internal networks. Isolate DMZ systems from production networks containing FCI.

System and Information Integrity (SI)

SI.L1-3.14.1 - Identify and Manage Information System Flaws: Identify, report, and correct information system flaws in a timely manner. Implement vulnerability management and patch management addressing security flaws before exploitation.

SI.L1-3.14.2 - Provide Protection from Malicious Code: Provide protection from malicious code at appropriate locations within organizational information systems. Deploy anti-malware solutions on endpoints and servers with automatic signature updates.

SI.L1-3.14.4 - Update Malicious Code Protection: Update malicious code protection mechanisms when new releases are available. Ensure anti-malware signatures remain current to detect latest threats.

SI.L1-3.14.5 - Perform Periodic System Scans: Perform periodic scans of information systems and real-time scans of files from external sources. Implement scheduled vulnerability and malware scanning plus on-access scanning of downloads and email attachments.

Implementation and Self-Assessment

CMMC Level 1 contractors can self-assess annually rather than undergoing costly third-party assessments. Self-assessments must honestly evaluate whether organizations fully implement all 17 practices. Senior executives must affirm assessment accuracy in the Supplier Performance Risk System (SPRS), with false statements carrying serious consequences.

Conduct Honest Gap Analysis: Assess current security practices against all 17 requirements, identifying gaps requiring remediation. Many contractors discover they lack formal documentation, have implemented partial controls, or have inconsistent practices across locations. Gap analysis informs remediation priorities and implementation timelines.

Document Everything: While Level 1 doesn't require extensive documentation systems, organizations should document policies, procedures, and evidence of practice implementation. Documentation supports accurate self-assessments, enables consistent practices across personnel changes, and provides evidence if DoD questions assessment claims. Systems Security Plans (SSPs) documenting how each practice is implemented represent best practice.

Implement Basic Cyber Hygiene: Many Level 1 practices represent fundamental security measures all organizations should implement regardless of CMMC requirements. Strong authentication, access controls, malware protection, vulnerability management, and physical security provide value beyond FCI protection, defending against general cybercrime and reducing overall organizational risk.

Relationship to Other Frameworks

CMMC Level 1 practices align with basic security controls from broader frameworks. Organizations implementing CIS Controls IG1 will satisfy most Level 1 requirements, as both target fundamental cyber hygiene. Similarly, NIST Cybersecurity Framework implementations at basic maturity levels cover Level 1 practices. Organizations handling both FCI and CUI must implement CMMC Level 2, which includes all Level 1 practices plus extensive additional requirements.

Frequently Asked Questions

What is Federal Contract Information (FCI)?

FCI is information provided to contractors by or generated for the government under contract that is not intended for public release. Examples include technical specifications, engineering drawings, proposals, cost/pricing data, and procurement-sensitive information. FCI does not include Controlled Unclassified Information (CUI), which requires CMMC Level 2. Contractors should carefully classify information to determine whether Level 1 or Level 2 applies.

How do contractors determine if they need Level 1 or Level 2?

Contract solicitations specify required CMMC level. Level 1 applies to contracts involving only FCI with no CUI. Level 2 applies to contracts involving CUI (marked with "CUI" or specific distribution limitations). When uncertain, contractors should consult contracting officers or review contract clauses. Most contractors handle some CUI, making Level 2 more common than Level 1.

Can contractors self-certify Level 1 compliance?

Yes, CMMC 2.0 allows contractors to self-assess Level 1 compliance annually, affirming implementation of all 17 practices through entries in the Supplier Performance Risk System (SPRS). Self-assessment must be accurate and conducted by personnel understanding the requirements. Senior company officials must affirm assessment accuracy. While third-party assessment is not required, false attestations carry severe consequences including contract termination and suspension from federal contracting.

How long does Level 1 implementation take?

Small contractors with basic IT infrastructure can achieve Level 1 implementation in 3-6 months. Primary effort involves implementing access controls, deploying anti-malware solutions, establishing patch management processes, and documenting physical security measures. Contractors with existing cybersecurity programs may achieve compliance within weeks by documenting current practices. Organizations should not rush implementation—ensuring genuine compliance is critical given affirmation requirements and potential consequences of false statements.

What happens if DoD discovers false Level 1 self-assessments?

False attestations represent serious violations potentially resulting in contract termination, suspension or debarment from federal contracting, financial penalties through False Claims Act, and criminal prosecution for false statements. DoD may verify self-assessments through government assessments at any time. Contractors should maintain evidence supporting self-assessment claims and conduct honest evaluations rather than aspirational or optimistic assessments. When gaps exist, contractors should remediate before affirming compliance or document gaps and implementation timelines for contracting officers.