HomeBlogCompliance

CMMC Level 1 Checklist: The 15 Requirements Explained

Illustration of a friendly robot in a brick-walled office, plugging a network cable into a server rack while holding a tablet

CMMC Level 1 asks a defense contractor that handles federal contract information (FCI) to meet 15 basic safeguarding requirements from FAR 52.204-21, covering access, identity, media, physical security, network boundaries and malware. You check yourself every year, record the result in SPRS and have a senior official affirm it. No open items are allowed.

Our CMMC compliance services set these controls up for small contractors, most of them inside Microsoft 365, Entra ID and Intune, the platform the checklist below assumes. If you also handle controlled unclassified information (CUI), you need Level 2; see CMMC Level 2 requirements. We checked the Department of War CIO's CMMC pages on October 7, 2026. This is general information, not legal advice.

Who needs CMMC Level 1?

Any contractor or subcontractor that will process, store or transmit FCI on its own systems under a DoD contract. Contracts solely for commercially available off-the-shelf items are excluded. FCI is information not intended for public release that is provided by or generated for the government under a contract, excluding information the government makes public and simple transactional information, such as what is needed to process payments. Non-public contract documents, specifications that are not marked CUI and project correspondence are typical examples.

The July 13, 2026 suspension of Phase II did not change Level 1. The Department of War CIO's CMMC page says all Phase I self-assessment requirements remain in place, and Level 1 was always a self-assessment: there is no third-party option. The CMMC glossary entry explains the levels side by side.

What are the 15 CMMC Level 1 requirements?

These are the 15 requirements in FAR 52.204-21, paragraph (b)(1), with the identifiers CMMC uses. The third column shows how we usually meet each one for a small contractor; the last column is the evidence to keep.

RequirementWhat it meansHow to meet it in Microsoft 365, Entra and IntuneEvidence to keep
AC.L1-b.1.i Authorized accessOnly approved people, processes and devices get inA named Entra ID account for every user, and Conditional Access that requires a compliant, Intune-managed deviceUser list, Conditional Access policy export, device compliance report
AC.L1-b.1.ii Transaction and function controlPeople can do only what their job needsRole-based groups and admin roles, with no everyday use of admin accountsGroup and role assignments, admin role list
AC.L1-b.1.iii External connectionsControl connections to outside systemsConditional Access that blocks unmanaged devices and unapproved locations, and a written list of approved outside servicesPolicy exports, approved services list
AC.L1-b.1.iv Control public informationKeep FCI off your website and social mediaName who may post, review content before it goes live, and limit admin access to the websitePosting procedure, approver list, review records
IA.L1-b.1.v IdentificationEvery user, process and device is identifiedUnique accounts with no shared logins, devices registered in Entra ID, and service accounts with named ownersAccount list, device inventory
IA.L1-b.1.vi AuthenticationVerify identities before granting accessPasswords meet the letter of the requirement; we enforce multi-factor authentication for everyone anywayMFA registration and enforcement report, sign-in logs
MP.L1-b.1.vii Media disposalSanitize or destroy media with FCI before disposal or reuseAn Intune wipe before a device is reissued, and drives sanitized or shredded before disposalWipe records, disposal certificates
PE.L1-b.1.viii Limit physical accessOnly authorized people reach systems and equipmentA locked office and network closet, plus screen locks enforced through IntuneKey or badge list, configuration profile
PE.L1-b.1.ix Visitors and physical accessEscort visitors, log them, and control keys and badgesA visitor sign-in log, an escort rule and a key and badge registerVisitor log, badge register
SC.L1-b.1.x Boundary protectionMonitor, control and protect traffic at the network edgeA managed firewall that denies unsolicited inbound traffic, and Windows Firewall turned on by policyFirewall configuration, rule review notes
SC.L1-b.1.xi Public-access separationKeep public-facing systems apart from the internal networkThe website hosted off site or on a separate network segment, and guest Wi-Fi isolatedNetwork diagram
SI.L1-b.1.xii Flaw remediationFind and fix software flaws promptlyIntune update rings for Windows, plus patching for other applications and network devicesPatch compliance reports
SI.L1-b.1.xiii Malicious code protectionProtect against malwareMicrosoft Defender Antivirus or another endpoint protection tool on every device, required by an Intune compliance policyDevice compliance and protection status reports
SI.L1-b.1.xiv Update malicious code protectionKeep protection currentA compliance policy that requires up-to-date security intelligenceDevice compliance report
SI.L1-b.1.xv System and file scanningPeriodic scans, and real-time scans of files as they are downloaded, opened or runReal-time protection on, plus scheduled quick or full scansAntivirus policy, scan history

Clause numbers are moving under the Revolutionary FAR Overhaul. GSA's class deviation for FAR part 40, for example, replaces 52.204-21 with clause 52.240-93 under the same title and keeps the basic safeguarding requirements, while the Department of War CIO's pages still cite 52.204-21. Match the requirements by title in your own contract.

How do you complete the Level 1 self-assessment?

  1. Confirm you handle FCI only. Check each contract and flow-down clause. Federal contract information only means Level 1; any CUI means Level 2.
  2. Define the scope. 32 CFR 170.19 asks you to consider the people, technology, facilities and external service providers that process, store or transmit FCI. IoT devices, operational technology and test equipment are specialized assets outside the Level 1 scope.
  3. Meet the 15 requirements. Put each basic safeguarding requirement in place, using the table above.
  4. Collect final evidence. Save final policies, configuration exports, screenshots and logs for each requirement. Drafts do not count.
  5. Score the self-assessment. All 15 requirements must be met. Level 1 allows no plan of action and milestones, so a single gap means no Level 1 status until it is fixed.
  6. Enter the results in SPRS. Record the level, date, scope, CAGE codes and result in the Supplier Performance Risk System.
  7. Affirm compliance. Your Affirming Official, a senior person with authority for CMMC compliance, affirms continuing compliance in SPRS.
  8. Repeat every year. Reassess and reaffirm annually, and keep the evidence for six years from the status date.

The self-assessment uses the NIST SP 800-171A objectives for the matching requirements, with FCI substituted wherever an objective mentions CUI. A contract that requires Level 1 needs both the status and the affirmation in SPRS before award.

What evidence counts for a Level 1 self-assessment?

The CMMC Level 1 Self-Assessment Guide lists three ways to check a requirement: examine documents, interview the people involved, and test that the safeguard works. Documents must be in final form. Common evidence includes policies and procedures, training materials, plans, and system, network and data flow diagrams, but a demonstration is often the strongest proof: signing in as a user to show MFA, or opening a device's compliance status in Intune. Date every export and screenshot, and store them where the Affirming Official can review them before affirming.

What is the difference between CMMC Level 1 and Level 2?

Level 1Level 2
Information protectedFederal contract informationControlled unclassified information
Requirements15, from FAR 52.204-21110, from NIST SP 800-171 Rev. 2
Assessment todaySelf-assessment every yearSelf-assessment every three years; no contract may require a C3PAO assessment during the suspension
Open items allowedNoneA limited POA&M, closed within 180 days
AffirmationEvery yearAt each assessment and every year
Cloud ruleNone in FAR 52.204-21 itselfFedRAMP Moderate or equivalent for cloud services that hold CUI

Frequently asked questions

Is CMMC Level 1 a certification?

No. Level 1 is a self-assessment that you record in SPRS and a senior official affirms. No outside assessor is involved, and none can certify you at Level 1, so a claim of Level 1 certification can only mean the self-assessment and affirmation are done.

Can we use commercial Microsoft 365 for CMMC Level 1?

Usually yes. FAR 52.204-21 sets no cloud authorization requirement; the FedRAMP Moderate rule in DFARS 252.204-7012 applies to covered defense information, a category of CUI. What matters at Level 1 is meeting the 15 requirements: commercial Microsoft 365 with Entra ID and Intune covers the technical ones, and the physical ones are handled at the office. If you will also receive CUI, plan the environment for Level 2 instead.

What happens if we miss a Level 1 requirement?

You cannot claim Level 1 status until it is fixed, because Level 1 allows no plan of action. Fix the gap, update the evidence and complete the self-assessment before you enter the result in SPRS. Contracts that require Level 1 need the status and the affirmation in place before award.

Who should sign the Level 1 affirmation?

The Affirming Official: under 32 CFR 170.22, the senior person responsible for the company's CMMC compliance with the authority to affirm it. Because the affirmation is a statement to the government, that person should review the evidence first rather than sign on someone else's word.

Do subcontractors need Level 1?

Yes, if they will have FCI on their systems. FAR 52.204-21 requires primes to include the clause in subcontracts where the subcontractor may have FCI, and 32 CFR 170.23 makes Level 1 (Self) the requirement for a subcontractor that handles FCI but not CUI.

Sources and further reading

CMMC 2.0 Compliance Services

Discuss cmmc 2.0 compliance services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore CMMC 2.0 Compliance Services 845-203-3914