CMMC Level 1: Foundational
17 basic safeguarding practices covering Federal Contract Information. Annual self-assessment with senior official affirmation, no third-party C3PAO required.
CMMC Level 1 is the entry-level certification, covering only Federal Contract Information (FCI) — information not intended for public release that is provided or generated in the performance of a federal contract. Level 1 does not cover CUI. If your DoD contract involves CUI, you need Level 2.
17 Level 1 practices
The 17 Level 1 practices are drawn directly from FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems). They cover fundamental cyber hygiene practices:
- ✓Limit system access to authorized users and the types of transactions they can perform
- ✓Identify information system users and authenticate their identity before granting access
- ✓Sanitize or destroy media containing FCI before disposal or reuse
- ✓Limit physical access to organizational systems to authorized individuals
- ✓Escort visitors and monitor visitor activity
- ✓Maintain audit logs of system activity
- ✓Identify, report, and correct information and information system flaws in a timely manner
- ✓Scan for malicious code and update detection mechanisms
- ✓Update malicious code protection mechanisms when new releases are available
- ✓Perform periodic scans of information systems and real-time scans of files from external sources
Assessment and affirmation
Level 1 requires an annual self-assessment — no C3PAO or third-party assessor is needed. The organization self-scores against the 17 practices, posts the score to the Supplier Performance Risk System (SPRS), and a senior official must affirm the accuracy of the score. False affirmations can result in False Claims Act liability.
Who this affects most
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in The Framework
