Skip to content
All frameworksCompliance Framework

CMMC Level 1

CMMC Level 1 is the tier for contractors that handle Federal Contract Information: fifteen safeguarding requirements, fifty-nine assessment objectives, an annual self-assessment submitted to SPRS, an executive affirmation behind it, and no room for a plan of action.

Compliance Guide
7 min read

What CMMC Level 1 is

The Cybersecurity Maturity Model Certification program is how the Department of Defense verifies that the companies in its supply chain actually implement the cybersecurity requirements their contracts already carry. Level 1 is the entry tier, and it applies to the most common situation in the defense industrial base: a contractor that handles Federal Contract Information but never touches Controlled Unclassified Information.

Level 1 is not a new standard. It is the fifteen basic safeguarding requirements that have sat in FAR 52.204-21 since 2016 — renumbered 52.240-93 by the FAR overhaul class deviations effective 1 February 2026, with the title and text unchanged. What CMMC added is verification: an annual self-assessment, scored requirement by requirement, submitted into a government system, and affirmed by a named executive.

That shift is the whole point. The obligation was already in the contract. What changed is that a contracting officer can now see whether you say you meet it, and an affirmation with your name on it is a representation to the government.

Who it applies to

Level 1 reaches any organization that processes, stores, or transmits Federal Contract Information under a DoD contract or subcontract, and nothing more sensitive. FCI is information provided by or generated for the government under a contract to develop or deliver a product or service, which is not intended for public release — delivery schedules, statements of work, proposal content, drawings, correspondence about contract performance. It is not classified, and it is not CUI, but it is not public either.

DoD has estimated that Level 1 covers the majority of the defense industrial base, which means it catches a great many companies that have never thought of themselves as cybersecurity organizations.

  • Suppliers and manufacturers delivering parts, materials, or equipment under a DoD contract
  • Professional services, logistics, staffing, and construction firms performing on defense contracts
  • Subcontractors at any tier who receive FCI flowed down from a prime
  • Small businesses whose only federal exposure is a single defense subcontract
  • Resellers and distributors who handle contract documentation but no technical data

The fifteen requirements, by domain

The fifteen requirements are grouped into six domains and broken out into fifty-nine assessment objectives. The objectives are what an assessment actually scores: a requirement is met only when every objective under it is met. This is where most organizations discover that a control they considered handled is partially handled.

  • Access Control — four requirements: limit system access to authorized users, limit what those users can do, control connections to external systems, and control information posted to publicly accessible systems
  • Identification and Authentication — two requirements: identify users, processes, and devices, and authenticate them before granting access
  • Media Protection — one requirement: sanitize or destroy media containing FCI before disposal or reuse
  • Physical Protection — two requirements: limit physical access to systems, equipment, and operating environments, and escort and monitor visitors
  • System and Communications Protection — two requirements: monitor and control communications at external and key internal boundaries, and separate publicly accessible systems from internal networks
  • System and Information Integrity — four requirements: identify and correct flaws in a timely manner, protect against malicious code, keep protection mechanisms current, and perform periodic and real-time scans

What the annual self-assessment actually involves

Level 1 is self-assessed. No third-party assessment organization is involved, and no assessor visits. That makes it cheaper than Level 2 and considerably easier to get wrong, because nobody corrects you before it is submitted.

Each of the fifty-nine objectives is scored MET or NOT MET. There is no partial credit and there is no Plan of Action and Milestones at Level 1 — a single unmet objective means the assessment does not pass, and a deficiency you intended to fix next quarter is not something you can carry. The result and an affirmation of continuing compliance are entered into the Supplier Performance Risk System, and both are repeated every year.

  • Scope the assessment: identify every system, service, and location where FCI is processed, stored, or transmitted
  • Assess all fifty-nine objectives against how the environment is actually configured, not how policy says it should be
  • Retain evidence for each objective — configuration exports, screenshots, logs, records, and the date each was collected
  • Submit the result in SPRS under the correct assessment scope and CAGE code hierarchy
  • Have the affirming official — a named executive with authority to bind the organization — affirm continuing compliance
  • Repeat annually, and re-affirm whenever the environment changes enough to make the last statement untrue

Where the program stands

The acquisition rule that puts CMMC into DoD contracts took effect on 10 November 2025, opening Phase 1: solicitations began requiring Level 1 and Level 2 self-assessments as a condition of award.

On 13 July 2026 the Department of War suspended Phase 2 — the milestone, set for 10 November 2026, at which third-party assessment was to become mandatory for contracts involving CUI — and stood up a reform task force to review the program. That task force delivered its recommendations to the department CIO on 13 September 2026, and the outcome had not been published as of the date on this page.

The suspension did not touch Level 1. Phase 1 self-assessment obligations, SPRS submission, the annual affirmation, and the underlying safeguarding requirements all remain in force, and the department has said it will continue to enforce them through self-assessment and government-led assessment. A contractor whose only obligation is Level 1 has nothing to wait for.

Where a Level 1 self-assessment goes wrong

Level 1 is short enough that organizations tend to treat it as a form rather than an assessment. The failures that follow are consistent and they are structural rather than technical.

  • Scope drawn too narrowly, leaving a mailbox, a file share, or a subcontractor portal that holds FCI outside the assessed boundary
  • Objectives scored against written policy rather than against the configuration in production
  • No retained evidence, so the affirmation cannot be reconstructed if it is ever questioned
  • An affirming official who signs without a record of what was assessed, on what date, and by whom
  • FCI flowed down to subcontractors with no verification that they carry the same obligation
  • A passing assessment left to age for a year while the environment changes underneath it

How Verdict helps

Verdict runs the Level 1 work as an engagement. We scope the environment, assess all fifty-nine objectives against how your systems are actually configured, close the gaps that would otherwise force a NOT MET, and assemble the evidence record that stands behind the submission and the affirmation.

We prepare, we do not attest. The self-assessment is your organization submitting a representation to the government, and the affirming official is yours. What we do is make sure that what gets affirmed is true, that the record behind it would survive a question, and that it stays true between annual cycles.

You review all of it through a client portal: which objectives are met, what evidence supports each one, what is open, who owns it, and what moved since the last submission. There is nothing for your team to install or operate.

CMMC Level 1 is part of federal authorization, the work that covers what an agency, or a company selling to one, has to satisfy before a system can operate or be bought. The same lane also covers FedRAMP, CMMC Level 2, NIST SP 800-53, and FISMA. For the mechanics of an engagement, see how we work.

If a DoD contract or a prime has put a Level 1 self-assessment in front of you, we can scope it, close the gaps, and build the evidence record your affirming official signs against.