In this article:

CMMC Level 1 Requirements: The 15 Practices and the Annual Self-Assessment

Compliance
/
August 6, 2026
CMMC Level 1 Requirements: The 15 Practices and the Annual Self-Assessment

CMMC Level 1 requires a defense contractor to implement 15 basic safeguarding requirements drawn from FAR 52.204-21, verify them with an annual self-assessment, and post the result in SPRS with an affirmation signed by a senior company official. It applies to companies that handle Federal Contract Information and no Controlled Unclassified Information. No third party assessor is involved at any point: there is no C3PAO, no certificate, and no assessment invoice. There is also no partial credit and no deferral. The program rule at 32 CFR 170.15 prohibits POA&Ms at Level 1, so all 15 requirements must be MET on the day you self-assess or there is no Level 1 status to post. For most small contractors, the work behind that signature runs $5,000 to $25,000 the first time through.

Where the 17 practices went

Older CMMC material described Level 1 as 17 practices, and the number still circulates in checklists and slide decks. The final rule counts 15. Nothing was removed: the requirements are the 15 basic safeguarding requirements of FAR 52.204-21(b)(1), and earlier CMMC versions had split some of them into separate practices. The final rule identifies each requirement by its FAR paragraph, running from AC.L1-b.1.i through SI.L1-b.1.xv, so the CMMC count now matches the source regulation. If a resource you are using says 17, it predates the rule. The substance is unchanged, and the work is the same either way.

What the 15 requirements cover

The set is basic hygiene, spread across six control families. Four access control requirements: limit system access to authorized users, limit users to the transactions and functions their role needs, verify and control connections to external systems, and control what gets posted on publicly accessible systems. Two identification and authentication requirements: identify your users and authenticate them before granting access. One media protection requirement: sanitize or destroy media containing FCI before disposal or reuse. Two physical protection requirements: limit physical access to authorized individuals, and manage the mechanics of that limit, meaning escorted visitors, physical access logs, and controlled keys and badges. Two system and communications protection requirements: monitor and protect communications at the network boundary, and separate publicly accessible components such as a web server from internal networks. Four system and information integrity requirements: correct system flaws in a timely manner, run malicious code protection, keep it updated, and scan files arriving from external sources.

The list reads as trivial. Assessed properly, it often is not. The requirements apply to every system that stores, processes, or transmits FCI, which in a small company usually means email, file storage, and the laptop of everyone touching the contract. A shared login on the shop floor fails the user identification requirement. A firewall nobody has reviewed since installation is a weak answer on boundary protection. Project drives discarded without wiping fail the media disposal requirement, and that one has ended up in incident reports more than once.

Scope: FCI and nothing more

Federal Contract Information is information provided by or generated for the government under contract and not intended for public release: statements of work, delivery schedules, contract correspondence, performance data. Nearly every DoD contract produces some, which is why Level 1 is the floor of the program. Level 1 scoping is deliberately simpler than Level 2: identify the systems that handle FCI and assess those, with no asset categories to argue over and no formal boundary document required. Write down what you decided anyway, because next year's self-assessment starts from that record, and so does any future question about what the affirmation covered. The moment CUI enters the picture, technical drawings, export controlled specifications, program data, you are planning at the wrong level, and the jump is large: CMMC Level 2 means 110 requirements and a different scale of effort entirely.

How the self-assessment and affirmation work

The cycle is annual. You assess the environment against the 15 requirements using the assessment objectives DoD maps to them, record a MET or NOT MET result for each, and enter the result in SPRS through the PIEE portal against your CAGE code, with the assessment date and scope. There is no minus 203 to positive 110 score at Level 1; that scoring methodology belongs to the 110-requirement standard. The Level 1 entry records that all 15 requirements are met. A senior company official, the rule calls this person the Affirming Official, then affirms the result in SPRS and re-affirms every year. Keep the evidence behind each MET result: 32 CFR 170.15 requires retaining self-assessment artifacts for six years.

Do the assessment at the objective level rather than the requirement level. DoD maps each of the 15 requirements to assessment objectives drawn from NIST SP 800-171A, and a requirement is only MET when every one of its objectives holds on every in-scope system. Authenticating users, for example, breaks into objectives covering users, processes, and devices, and the device part is the one small companies miss. Work from a worksheet with one row per objective and a column for the evidence that proves it. The worksheet costs an afternoon more than a gut check, and it is the difference between an affirmation you can defend and one you hope nobody ever examines.

Treat the affirmation as what it is, a signed representation to the federal government. The Department of Justice has settled False Claims Act cases over misrepresented cybersecurity compliance, and an affirmation that all 15 requirements are met, filed while the company runs on one shared administrator password, is exactly the kind of gap a whistleblower can monetize. Affirm what you can evidence, and fix the rest first.

What Level 1 does not require

No C3PAO and no third party of any kind: certification assessments exist only at Levels 2 and 3, and no Level 1 contract will ever ask for one. No POA&M, ever. At Level 2 a narrow set of low-weight gaps can ride through an assessment on a remediation plan; at Level 1 the rule permits none, so a single NOT MET means fixing it before you post the status. No formal System Security Plan is mandated, though a short one is worth writing because it turns next year's assessment into a review instead of a rebuild. No three-year certification cycle: Level 1 status lasts one year and renews by self-assessment and affirmation. And no SPRS score under DFARS 252.204-7019, which applies to contractors handling covered defense information under the 110-requirement standard, a population that is by definition beyond Level 1.

What it costs a small contractor

For a company under 50 people running mainstream cloud services, readiness typically runs $5,000 to $15,000: assessing the 15 requirements against how the environment actually operates, closing the gaps that fall out, and assembling the documentation behind the affirmation. A shop with legacy equipment, no written policies, and shared accounts sits closer to $15,000 to $25,000, and remediation there can cost more than the assessment did, usually on identity cleanup and boundary work. Internal time is the quiet line: plan on 40 to 120 hours in the first year across whoever owns IT, contracts, and facilities. Renewal years are cheaper if the evidence habit survives, because the next self-assessment starts from artifacts instead of memory. The full cost picture across both levels, including where Level 2 money actually goes, is in what CMMC certification costs.

The mistake that invalidates everything else

The most common Level 1 failure is not among the 15 requirements. It is the level determination itself. Companies self-assess at Level 1 because nobody handed them a document stamped CUI, while export controlled drawings sit on the file server. If DoD or a prime later concludes you were handling CUI, the Level 1 status does not cover you, and the affirmation you posted ages very badly. Before affirming at Level 1, check your contracts for DFARS 252.204-7012, ask your primes what they believe they send you, and look at what your engineers actually receive. The FCI and CUI distinction, and how it drives the levels, is covered in what is CMMC.

Getting it done

Level 1 involves no assessor, but a second set of eyes before a senior official signs a federal affirmation is cheap relative to what the signature carries. A CMMC gap assessment scoped to Level 1 confirms the level determination, tests all 15 requirements against their objectives, and leaves you the evidence file that supports the affirmation. On independence, the boundary is worth stating even here: BD Emerson is not a C3PAO and does not certify anyone at any level. At Level 2, a separate certified assessor performs the certification assessment and we do the preparation. That separation means the advice carries no stake in the outcome, which is exactly what you want from the people telling you whether you are ready to sign.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director