What Is Required for CMMC Level 1? The Complete Playbook
By Christina Sentry · September 17, 2026 · 1 view
Nobody talks about Level 1. There's no C3PAO, no certificate to frame, no six figure readiness budget, so all the noise in this space goes to Level 2 and Level 1 gets treated like a checkbox.. CMMC Level 1 explained: the 15 required safeguards, who needs it, how the annual self-assessment and SPRS affirmation work, and the mistakes that turn a simple level into a liability.
Nobody talks about Level 1. There's no C3PAO, no certificate to frame, no six figure readiness budget, so all the noise in this space goes to Level 2 and Level 1 gets treated like a checkbox.
Level 1 is easy to meet and even easier to misrepresent without realizing you've done it, don't be a contractor that get's it wrong, or falls victim to greedy companies.
Who actually needs Level 1?
If you hold a DoD contract, you're handling Federal Contract Information. FCI is basically any information the government gives you or that you generate for them under the contract that isn't meant for public release. This can include Statements of work, Contract emails, Deliverables, Performance details, Cost, etc. Sometimes this may even fall under CUI categories.
Almost everyone in the DIB encounters FCI, which makes Level 1 the real floor of this whole program. If FCI is all you touch, Level 1 is your requirement. If CUI shows up anywhere in your world, you're a Level 2 shop, and we broke that down in a separate post.
The 15 safeguards, controls, practices. What are they?
Level 1 is the 15 basic safeguarding requirements out of FAR 52.204-21. If you've been around a while you might remember this as 17 practices. Same substance, the count got consolidated to 15. They fall across six families:
Access Control. Only authorized users get in, they can only do what they're authorized to do, you control connections to outside systems, and you watch what goes on your public-facing stuff.
Identification and Authentication. Know who your users and processes are, and make them prove it before they get access.
Media Protection. Wipe or destroy media with FCI on it before it gets tossed or reused.
Physical Protection. Locked doors, escorted visitors, logs of who came in, and control over your keys and badges.
System and Communications Protection. Watch and control traffic at your boundary, and keep public-facing components separated from your internal network.
System and Information Integrity. Patch your flaws, run protection against malicious code, keep it updated, and scan.
The bar is low on purpose. Read that list again. Firewalls, antivirus, patching, user accounts, locked doors, shredded drives. This is cyber hygiene your IT person has probably been doing for years.
How you prove it
Annual self-assessment. You check your own environment against the 15 requirements, and then a senior official at your company affirms compliance in SPRS every year.
Now, two things about that affirmation, and this is the part of the post I actually care about.
First: all 15 or nothing. Level 1 doesn't allow POA&Ms. There's no "we're working on it" and no partial credit. If one requirement isn't met, you can't truthfully affirm, full stop.
Second: that affirmation is a signed representation to the federal government with a real name attached to it. DOJ has already gone after contractors under the False Claims Act for cybersecurity attestations that didn't match reality. That's what the Civil Cyber-Fraud Initiative is. So no, nobody's auditing your Level 1 self-assessment. The accountability didn't disappear. It just moved entirely onto your own signature, which is arguably worse.
And before anyone asks: yes, this all still applies. The Phase II suspension in July paused the third party certification rollout. Phase I self-assessments, which is where Level 1 lives, never went anywhere. We wrote up what the suspension does and doesn't change if you want the full picture.
Where this goes sideways
A few patterns we see constantly.
The scoping-by-assumption problem. Level 1 covers every asset that processes, stores, or transmits FCI. Contractors assess the office network and forget the PM's laptop, the shared drive, and the inbox where the FCI actually lives.
The autopilot affirmation. Year one, somebody does the assessment carefully. Years two and three get affirmed from memory while the environment quietly changed underneath. It's an annual requirement because environments drift annually.
No paper trail. Level 1 doesn't make you submit evidence, so plenty of contractors keep none. Then a prime or a contracting officer asks how you reached your affirmation and there's nothing to show them. A simple record of what you checked, when, and who checked it turns that conversation into a nothing.
And the big one: treating Level 1 like the finish line. If CUI is in your contracts or coming, Level 1 is your warm up. The contractors who build honest habits here, real scoping, real assessment, evidence they can put their hands on, walk into Level 2 with the hard part already done.
Bottom line
Fifteen basic safeguards, an honest annual look at your own environment, and an executive signature in SPRS. That's Level 1. Treat the signature like the legal statement it is and keep evidence you never have to scramble for, and this level stays what it was designed to be: simple.
Not sure your Level 1 affirmation would hold up if someone asked you to show your work? That's a short conversation with us before it's a long one with someone else. Cipher Sentinel reviews are CCA led and built for small contractors. Reach out.
Last edited by Christina Sentry · September 19, 2026 at 9:27 PM
Ready to get compliant?
Talk to a CCA today about your specific environment.