
CMMC Level 1 asks a defense contractor that handles federal contract information (FCI) to meet 15 basic safeguarding requirements from FAR 52.204-21, covering access, identity, media, physical security, network boundaries and malware. You check yourself every year, record the result in SPRS and have a senior official affirm it. No open items are allowed.
Our CMMC compliance services set these controls up for small contractors, most of them inside Microsoft 365, Entra ID and Intune, the platform the checklist below assumes. If you also handle controlled unclassified information (CUI), you need Level 2; see CMMC Level 2 requirements. We checked the Department of War CIO's CMMC pages on October 7, 2026. This is general information, not legal advice.
Who needs CMMC Level 1?
Any contractor or subcontractor that will process, store or transmit FCI on its own systems under a DoD contract. Contracts solely for commercially available off-the-shelf items are excluded. FCI is information not intended for public release that is provided by or generated for the government under a contract, excluding information the government makes public and simple transactional information, such as what is needed to process payments. Non-public contract documents, specifications that are not marked CUI and project correspondence are typical examples.
The July 13, 2026 suspension of Phase II did not change Level 1. The Department of War CIO's CMMC page says all Phase I self-assessment requirements remain in place, and Level 1 was always a self-assessment: there is no third-party option. The CMMC glossary entry explains the levels side by side.
What are the 15 CMMC Level 1 requirements?
These are the 15 requirements in FAR 52.204-21, paragraph (b)(1), with the identifiers CMMC uses. The third column shows how we usually meet each one for a small contractor; the last column is the evidence to keep.
| Requirement | What it means | How to meet it in Microsoft 365, Entra and Intune | Evidence to keep |
|---|---|---|---|
| AC.L1-b.1.i Authorized access | Only approved people, processes and devices get in | A named Entra ID account for every user, and Conditional Access that requires a compliant, Intune-managed device | User list, Conditional Access policy export, device compliance report |
| AC.L1-b.1.ii Transaction and function control | People can do only what their job needs | Role-based groups and admin roles, with no everyday use of admin accounts | Group and role assignments, admin role list |
| AC.L1-b.1.iii External connections | Control connections to outside systems | Conditional Access that blocks unmanaged devices and unapproved locations, and a written list of approved outside services | Policy exports, approved services list |
| AC.L1-b.1.iv Control public information | Keep FCI off your website and social media | Name who may post, review content before it goes live, and limit admin access to the website | Posting procedure, approver list, review records |
| IA.L1-b.1.v Identification | Every user, process and device is identified | Unique accounts with no shared logins, devices registered in Entra ID, and service accounts with named owners | Account list, device inventory |
| IA.L1-b.1.vi Authentication | Verify identities before granting access | Passwords meet the letter of the requirement; we enforce multi-factor authentication for everyone anyway | MFA registration and enforcement report, sign-in logs |
| MP.L1-b.1.vii Media disposal | Sanitize or destroy media with FCI before disposal or reuse | An Intune wipe before a device is reissued, and drives sanitized or shredded before disposal | Wipe records, disposal certificates |
| PE.L1-b.1.viii Limit physical access | Only authorized people reach systems and equipment | A locked office and network closet, plus screen locks enforced through Intune | Key or badge list, configuration profile |
| PE.L1-b.1.ix Visitors and physical access | Escort visitors, log them, and control keys and badges | A visitor sign-in log, an escort rule and a key and badge register | Visitor log, badge register |
| SC.L1-b.1.x Boundary protection | Monitor, control and protect traffic at the network edge | A managed firewall that denies unsolicited inbound traffic, and Windows Firewall turned on by policy | Firewall configuration, rule review notes |
| SC.L1-b.1.xi Public-access separation | Keep public-facing systems apart from the internal network | The website hosted off site or on a separate network segment, and guest Wi-Fi isolated | Network diagram |
| SI.L1-b.1.xii Flaw remediation | Find and fix software flaws promptly | Intune update rings for Windows, plus patching for other applications and network devices | Patch compliance reports |
| SI.L1-b.1.xiii Malicious code protection | Protect against malware | Microsoft Defender Antivirus or another endpoint protection tool on every device, required by an Intune compliance policy | Device compliance and protection status reports |
| SI.L1-b.1.xiv Update malicious code protection | Keep protection current | A compliance policy that requires up-to-date security intelligence | Device compliance report |
| SI.L1-b.1.xv System and file scanning | Periodic scans, and real-time scans of files as they are downloaded, opened or run | Real-time protection on, plus scheduled quick or full scans | Antivirus policy, scan history |
Clause numbers are moving under the Revolutionary FAR Overhaul. GSA's class deviation for FAR part 40, for example, replaces 52.204-21 with clause 52.240-93 under the same title and keeps the basic safeguarding requirements, while the Department of War CIO's pages still cite 52.204-21. Match the requirements by title in your own contract.
How do you complete the Level 1 self-assessment?
- Confirm you handle FCI only. Check each contract and flow-down clause. Federal contract information only means Level 1; any CUI means Level 2.
- Define the scope. 32 CFR 170.19 asks you to consider the people, technology, facilities and external service providers that process, store or transmit FCI. IoT devices, operational technology and test equipment are specialized assets outside the Level 1 scope.
- Meet the 15 requirements. Put each basic safeguarding requirement in place, using the table above.
- Collect final evidence. Save final policies, configuration exports, screenshots and logs for each requirement. Drafts do not count.
- Score the self-assessment. All 15 requirements must be met. Level 1 allows no plan of action and milestones, so a single gap means no Level 1 status until it is fixed.
- Enter the results in SPRS. Record the level, date, scope, CAGE codes and result in the Supplier Performance Risk System.
- Affirm compliance. Your Affirming Official, a senior person with authority for CMMC compliance, affirms continuing compliance in SPRS.
- Repeat every year. Reassess and reaffirm annually, and keep the evidence for six years from the status date.
The self-assessment uses the NIST SP 800-171A objectives for the matching requirements, with FCI substituted wherever an objective mentions CUI. A contract that requires Level 1 needs both the status and the affirmation in SPRS before award.
What evidence counts for a Level 1 self-assessment?
The CMMC Level 1 Self-Assessment Guide lists three ways to check a requirement: examine documents, interview the people involved, and test that the safeguard works. Documents must be in final form. Common evidence includes policies and procedures, training materials, plans, and system, network and data flow diagrams, but a demonstration is often the strongest proof: signing in as a user to show MFA, or opening a device's compliance status in Intune. Date every export and screenshot, and store them where the Affirming Official can review them before affirming.
What is the difference between CMMC Level 1 and Level 2?
| Level 1 | Level 2 | |
|---|---|---|
| Information protected | Federal contract information | Controlled unclassified information |
| Requirements | 15, from FAR 52.204-21 | 110, from NIST SP 800-171 Rev. 2 |
| Assessment today | Self-assessment every year | Self-assessment every three years; no contract may require a C3PAO assessment during the suspension |
| Open items allowed | None | A limited POA&M, closed within 180 days |
| Affirmation | Every year | At each assessment and every year |
| Cloud rule | None in FAR 52.204-21 itself | FedRAMP Moderate or equivalent for cloud services that hold CUI |
Frequently asked questions
Is CMMC Level 1 a certification?
No. Level 1 is a self-assessment that you record in SPRS and a senior official affirms. No outside assessor is involved, and none can certify you at Level 1, so a claim of Level 1 certification can only mean the self-assessment and affirmation are done.
Can we use commercial Microsoft 365 for CMMC Level 1?
Usually yes. FAR 52.204-21 sets no cloud authorization requirement; the FedRAMP Moderate rule in DFARS 252.204-7012 applies to covered defense information, a category of CUI. What matters at Level 1 is meeting the 15 requirements: commercial Microsoft 365 with Entra ID and Intune covers the technical ones, and the physical ones are handled at the office. If you will also receive CUI, plan the environment for Level 2 instead.
What happens if we miss a Level 1 requirement?
You cannot claim Level 1 status until it is fixed, because Level 1 allows no plan of action. Fix the gap, update the evidence and complete the self-assessment before you enter the result in SPRS. Contracts that require Level 1 need the status and the affirmation in place before award.
Who should sign the Level 1 affirmation?
The Affirming Official: under 32 CFR 170.22, the senior person responsible for the company's CMMC compliance with the authority to affirm it. Because the affirmation is a statement to the government, that person should review the evidence first rather than sign on someone else's word.
Do subcontractors need Level 1?
Yes, if they will have FCI on their systems. FAR 52.204-21 requires primes to include the clause in subcontracts where the subcontractor may have FCI, and 32 CFR 170.23 makes Level 1 (Self) the requirement for a subcontractor that handles FCI but not CUI.
Sources and further reading
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems: the 15 requirements, the FCI definition and the flow-down, checked October 7, 2026.
- Department of War CIO: About CMMC: Level 1 annual self-assessment, SPRS entry and affirmation, checked October 7, 2026.
- Department of War CIO: Cybersecurity Maturity Model Certification: the Phase II suspension notice, checked October 7, 2026.
- 32 CFR Part 170, CMMC Program, eCFR: Level 1 scoping, scoring, affirmation and six-year evidence retention, checked October 7, 2026.
- CMMC Level 1 Self-Assessment Guide, version 2.13 (PDF): assessment methods and evidence, checked October 7, 2026.
- GSA class deviation for FAR part 40 (PDF): clause 52.240-93 replacing 52.204-21, checked October 7, 2026.
- Microsoft Learn: Configure CMMC Level 1 controls: Entra ID guidance for the access and identification requirements, checked October 2026.
- Microsoft Learn: Windows compliance settings in Intune: antivirus, security intelligence and real-time protection settings, checked October 2026.
- Microsoft Learn: Manage Windows update ring policies, and Wipe devices with Microsoft Intune, checked October 2026.
- Microsoft Learn: Scheduled quick or full Microsoft Defender Antivirus scans, checked October 2026.
Discuss cmmc 2.0 compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



