GovCon Cybersecurity | | 25 min read

CMMC Level 1 Requirements: Scope, Evidence, and Assessment


Security specialist reviewing CMMC Level 1 requirements, system scope, and assessment evidence
Photo by Risto Kokkonen on Unsplash

Key Takeaways

CMMC Level 1 is narrow in data and absolute in result

Official rule

All 15 safeguards must be MET

Level 1 has no conditional passing path. One unmet requirement prevents Final Level 1 status, and the rule does not permit a POA&M.

GS research

59 objectives sit behind the 15 safeguards

GS counted 59 determination statements in the official Level 1 guide. Boundary Protection carries the highest modeled evidence workload at 94.

Operating rule

Follow FCI through the real system

Scope follows where FCI is processed, stored, or transmitted. Email, endpoints, providers, paper, backups, and remote support all deserve an explicit decision.

CMMC Level 1 is not CMMC lite. It is an annual claim that every in scope system handling FCI meets all 15 basic safeguards.

The requirement set is smaller than Level 2. The conclusion is not softer. A Level 1 requirement is MET only when every applicable assessment objective is satisfied. One missed objective makes that requirement NOT MET. There is no POA&M path for Level 1.

That changes the work. A contractor cannot stop at a policy set, a security tool invoice, or a checklist with 15 green boxes. The company needs a defensible scope, an implementation that covers every system in that scope, evidence tied to each objective, an annual self assessment, and an annual affirmation in SPRS.

This guide explains the CMMC Level 1 requirements from contract trigger to operating proof. It connects to the CMMC Compliance hub, the companion CMMC scoping guide, the small business and subcontractor guide, and GS Consulting services for secure AI automation.

Prove the 15 safeguards in the system you actually operate.

GS Consulting helps contractors define FCI scope, map assessment objectives, repair evidence gaps, and build a repeatable annual assessment cycle.

Plan the Level 1 Review

CMMC Level 1 Requirements: The Short Answer

Six facts about CMMC Level 1 safeguards, families, objectives, protected data, assessment, and affirmation
Level 1 protects FCI through 15 safeguards, an annual self assessment, and an annual affirmation.

FAR 52.204-21 supplies the 15 basic safeguarding requirements. 32 CFR Part 170 supplies the CMMC assessment, scope, affirmation, and subcontractor rules. The DoD Level 1 Assessment Guide, version 2.13 maps the safeguards to the assessment objectives and methods.

The operating sequence is simple to state:

  1. Confirm that the governing award requires CMMC Level 1 and that performance involves FCI.
  2. Define the systems that process, store, or transmit that FCI.
  3. Implement all 15 safeguards across that scope.
  4. Assess every objective using adequate evidence.
  5. Submit the scope and result in SPRS.
  6. Have the Affirming Official submit the required affirmation.
  7. Maintain the safeguards, evidence, and scope until the next annual cycle.

Current timing needs a separate check. As of August 19, 2026, the official CMMC resources page says Phase II is suspended while Phase I self assessment requirements remain in place. That program notice does not rewrite a live award. Read the solicitation, contract, subcontract, clauses, amendments, and current direction before setting the compliance date.

CMMC Level 1 Protects FCI, Not Every Business Record

Federal Contract Information means information that is not intended for public release and is provided by or generated for the Government under a contract to develop or deliver a product or service. Public information and simple transactional information needed to process payments are excluded from that definition.

FCI can still be ordinary looking. A statement of work, nonpublic schedule, draft deliverable, technical exchange, quality record, status report, or program email may qualify when it is provided by or generated for the Government under the contract and is not intended for public release. The contract and information owner should resolve the classification. The security team should not guess from the file name.

CUI is different. CUI requires safeguarding or dissemination controls under law, regulation, or Government policy. When a system handles CUI for a DoD contract, Level 2 requirements and DFARS duties may apply. Use the CMMC levels guide to distinguish the assessment paths. Do not force CUI into a Level 1 environment merely because the Level 1 control list looks easier.

The contract review question

What exact nonpublic Government information will this team receive, create, edit, print, store, send, archive, recover, or share to perform the award?

Answer that question with the program owner, contracts lead, information owner, security lead, and system owner. Preserve the decision with the source clause, information description, owner, recipients, approved systems, and review date. That record becomes the start of scope.

CMMC Level 1 Scope Follows FCI Through the Real Workflow

The official Level 1 Scoping Guide places contractor information systems in scope when they process, store, or transmit FCI. Process includes viewing, entering, editing, generating, manipulating, and printing. Store includes memory, media, and paper. Transmit includes digital and physical movement from one asset to another.

That definition reaches beyond the main application. Email may transmit FCI. A laptop may process and store it. A printer may create a paper copy. A backup service may store it. A support provider may administer a system that handles it. A conference room, home office, or facility may become part of the operating story through people and physical records.

The rule also identifies two important limits. An endpoint that runs a virtual desktop client and permits no FCI processing, storage, or transmission beyond keyboard, video, and mouse interaction can be out of scope.

Specialized assets that can handle FCI but cannot be fully secured are not part of the Level 1 assessment scope under the stated rule. Examples include certain operational technology, Government furnished equipment, restricted systems, and test equipment. These are narrow treatments, not convenient labels. Validate the actual configuration and contract context.

The Level 1 guide says there are no formal documentation requirements for in scope, out of scope, or specialized assets. That does not make undocumented scope wise. A contractor still has to submit the assessment scope in SPRS and support its conclusion. A short inventory, data flow, and decision log reduce the chance that the annual result rests on memory.

For a complete boundary method, use the companion CMMC scoping guide. It covers Level 1, Level 2 asset categories, provider services, subcontractors, and boundary tests.

Original Research: The GS CMMC Level 1 Evidence Workload Index

Fifteen requirements do not create fifteen equal work packages. Broad technical controls need more evidence coordination.

GS Consulting counted 59 determination statements across the official Level 1 guide. We then scored each safeguard across five factors. Objective count carries 35 percent. System reach carries 25 percent. Operator spread and recurring evidence demand each carry 15 percent. Live test demand carries 10 percent.

The objective count is normalized against the largest Level 1 objective count. The four remaining inputs are GS ratings from one to five.

GS CMMC Level 1 Evidence Workload Index ranking all 15 safeguards
The index orders evidence planning effort inside the GS model. It does not grade compliance or predict an official assessment result.

Boundary Protection scores 94.0, the highest result. It has eight objectives and reaches gateways, network paths, external connections, remote access, and monitoring behavior. Authorized Access Control and Flaw Remediation each score 88.3. External Connections scores 85.3. These safeguards deserve early attention because they depend on broad inventories, live configuration, recurring records, and tests that cross several owners.

The lower scores do not mean optional. Media Disposal scores 47.8 because it has two objectives and a narrower operating surface in the stated model. It still must be MET. A weak disposal process can block Final Level 1 status just as surely as a weak firewall rule.

The sensitivity test moves five percentage points from objective count to recurring evidence demand. The same four safeguards remain at the top. No score moves by more than 4.4 points. That supports a practical sequence: start with the controls that touch the most systems and require the most continuing proof, then close every remaining objective before submission.

The full model, source register, input ratings, formulas, sensitivity analysis, figure data, and caveats are preserved in the repository research workbook and companion CSV files.

The 15 CMMC Level 1 Requirements, in Plain Language

Six CMMC Level 1 families with safeguard and assessment objective counts
Access Control contains 19 of the 59 determination statements counted by GS, while four System and Information Integrity safeguards contribute another 12.

The official wording governs. The descriptions below translate the operating intent and common proof questions. They do not replace FAR 52.204-21, 32 CFR Part 170, the assessment guide, or a contract review.

  1. Authorized Access Control. Limit system access to identified and authorized users, devices, and processes. Prove account approval, device decisions, removal, reviews, and tests against the real FCI environment.
  2. Transaction and Function Control. Limit each authorized user to the transactions and functions the role is allowed to perform. Prove role design, access assignment, restrictions, and a test using a representative account.
  3. External Connections. Verify and control connections to outside systems. Include vendor links, remote access, personal devices, integrations, and other networks that can reach the covered system.
  4. Control Public Information. Identify people allowed to publish, review proposed releases, and remove FCI from public systems when discovered. Prove the approval chain and the response path.
  5. Identification. Identify users, devices, and processes that act in the system. Shared or anonymous access creates an evidence problem when the organization cannot tell who or what is acting.
  6. Authentication. Verify those identities before granting access. Prove the mechanism for users, devices, and processes and test the path used by the assessed system.
  7. Media Disposal. Sanitize or destroy media containing FCI before disposal or release for reuse. Cover paper, drives, removable media, devices, and provider managed disposal.
  8. Limit Physical Access. Restrict physical access to systems, equipment, and operating environments to authorized people. Include offices, server areas, workspaces, and remote work conditions.
  9. Manage Visitors and Physical Access. Escort and monitor visitors, maintain access logs, and control physical access devices. Prove the process works at every relevant facility.
  10. Boundary Protection. Monitor, control, and protect communications at external and key internal boundaries. Prove the boundary, approved paths, configuration, monitoring, and tests.
  11. Public System Separation. Separate publicly accessible system components from internal components. Prove the logical or physical separation and test that the public path cannot reach the protected environment outside approved rules.
  12. Flaw Remediation. Identify, report, and correct system flaws within defined time frames. Prove inventories, intake, priority, ownership, deployment, exceptions, and closure records.
  13. Malicious Code Protection. Deploy protection against malicious code at appropriate locations. Cover endpoints, servers, email, and other relevant entry points.
  14. Update Malicious Code Protection. Update protection mechanisms when new releases are available. Prove the update configuration, coverage, exceptions, and recent status.
  15. System and File Scanning. Run periodic system scans and real time scans of files from external sources as they are downloaded, opened, or executed. Prove both schedules and actual results.

A product can support several safeguards. It does not inherit the assessment result. The contractor must show that the product is configured, deployed, monitored, and operated across the full scope. A license without coverage evidence proves little.

The Annual Self Assessment Has an Absolute Passing Rule

Five stage CMMC Level 1 self assessment path from contract and scope through submission and maintenance
Assessment starts with the contract and boundary, not with an evidence upload.

32 CFR 170.15 requires the organization to achieve a MET result for all Level 1 security requirements to obtain Final Level 1 status. The organization performs the assessment annually and submits the result in SPRS. The minimum submission includes the CMMC level, status date, assessment scope, associated industry CAGE codes, and compliance result.

The Affirming Official then attests to continuing compliance through the required affirmation process. That role should have enough authority and knowledge to make the statement. Security can prepare the evidence. Information technology can operate controls. Contracts can interpret the award. The official still needs a defensible basis for the affirmation.

A third party may help perform the work. The official guide is clear that assistance does not turn Level 1 into a certification. Accountability stays with the organization seeking assessment.

No POA&Ms are permitted for Level 1. If one requirement is NOT MET, fix the condition, gather current proof, and retest it before submitting a passing result. Do not convert an open gap into a footnote and call the assessment complete.

Evidence Must Match Examine, Interview, and Test

Six qualities of credible CMMC Level 1 evidence covering records, scope, ownership, period, method, and result
Credible evidence links an approved rule to the scoped system, responsible people, current records, a proof method, and a reproducible conclusion.

The Level 1 guide uses the NIST assessment methods of examine, interview, and test. Examine reviews specifications, mechanisms, activities, and records. Interview asks responsible people to explain the implementation. Test exercises a mechanism or process under defined conditions and compares the result with what should happen.

The methods should agree. A policy may say terminated accounts are disabled promptly. The account record should show that action. The identity administrator should explain the trigger and exception path. A sample test should confirm that the disabled account cannot enter the covered system. When those pieces conflict, the assessment conclusion becomes fragile.

A system security plan is recommended at Level 1 but not required by the official guide. A concise plan is still useful. It can record the scope, environment, safeguard implementation, owner, provider role, evidence location, and open operating decision. Keep it accurate. A polished plan that describes another system is worse than a short plan that matches reality.

Use an objective crosswalk as the index. For every objective, record the safeguard, implementation statement, evidence item, method, system, owner, review period, location, result, and reviewer. Keep source records in the systems that create them where practical. The crosswalk should point to authoritative proof rather than create a second uncontrolled archive.

CMMC Level 1 Flows to Subcontractors That Handle FCI

32 CFR 170.23 says CMMC requirements apply through the supply chain when a prime contractor or subcontractor processes, stores, or transmits FCI or CUI on contractor systems for contract performance. A subcontractor that handles only FCI, not CUI, requires Level 1 under the stated rule. A subcontractor that handles CUI requires at least the applicable Level 2 status.

DFARS 252.204-7021, when included, adds contract administration duties concerning current status, annual affirmation, CMMC unique identifiers, and subcontract awards. FAR 52.204-21 also includes a subcontract flow requirement for covered contractor information systems, with the stated COTS exception. Read the actual instruments. Do not rely on a supplier questionnaire as a substitute for the governing terms.

The best burden reduction is information minimization. If the lower tier does not need FCI, do not send it. If it does need FCI, name the data, approved transfer path, system boundary, status expectation, evidence exchange, and change notice in the subcontract operating record.

A Practical 30 Day Level 1 Implementation Plan

Days 1 through 5: settle applicability and ownership. Collect the solicitation, award, clauses, subcontracts, data descriptions, deliverables, and customer direction. Name the executive sponsor, Affirming Official, assessment lead, system owners, program owner, contracts lead, and provider contacts.

Days 6 through 10: trace FCI and set scope. Map entry, users, processing, storage, email, print, backup, recovery, remote access, support, providers, and exits. Record in scope, out of scope, and specialized asset decisions. Test any claimed virtual desktop restriction.

Days 11 through 17: map the 59 objectives. Create the crosswalk. For each objective, name the implementation, evidence, method, owner, and result. Mark gaps as implementation gaps, evidence gaps, scope gaps, or ownership gaps. The distinction matters because each needs a different repair.

Days 18 through 24: fix and prove. Repair coverage, approve final documents, collect current records, conduct interviews, and run tests. Retest any failed result. Keep the evidence period explicit.

Days 25 through 30: review and submit. Run an independent internal review of scope and objective coverage. Resolve every NOT MET condition. Prepare the SPRS inputs and affirmation basis. Submit only after the result and supporting record agree.

Common Level 1 Failure Modes

  • Treating Level 1 as a product bundle. Tools do not prove configuration, coverage, operation, or scope.
  • Ignoring ordinary systems. Email, collaboration, printers, backups, and support paths often touch FCI.
  • Using Level 1 for CUI. CUI can trigger Level 2 and additional contract duties.
  • Assessing only the 15 labels. The official guide contains underlying objectives that determine whether each safeguard is MET.
  • Keeping draft evidence. Unapproved intent does not prove the operating rule.
  • Submitting with an open gap. Level 1 does not permit a POA&M.
  • Forgetting providers. An external provider can perform an objective, but the contractor still needs adequate evidence.
  • Letting scope drift. A new application, integration, employee, facility, backup, or subcontractor can change the assessed system.

Minimum CMMC Level 1 Evidence Packet

Eight item CMMC Level 1 evidence packet covering contract, scope, objectives, controls, result, and affirmation
The packet is an index to operating proof, not a substitute for the source systems and people behind it.

Keep the packet controlled and current. At minimum, include the contract and FCI determination, scope inventory and data flow, objective crosswalk, access and identity evidence, boundary and public system evidence, physical and media records, flaw and malicious code records, and the final assessment and affirmation record.

Add a change log. Record new systems, providers, users, facilities, data paths, subcontracts, and contract modifications. Give each change an owner and a scope review date. Annual assessment works only when the organization preserves the evidence between annual dates.

Sources, Method, and Caveats

The research package uses primary public sources: FAR 52.204-21, DFARS 252.204-7021, 32 CFR Part 170, the DoD Level 1 Assessment Guide, the DoD Level 1 Scoping Guide, and the current CMMC resources page. Public facts and GS analyst assumptions are separated in the source register and model inputs.

The GS CMMC Level 1 Evidence Workload Index is a derived planning tool. It is not an official CMMC score, legal opinion, contract interpretation, certification result, or compliance determination. The actual contract, information, system, implementation, assessment record, and current Government direction control.

Frequently Asked Questions About CMMC Level 1 Requirements

What are the CMMC Level 1 requirements?

CMMC Level 1 uses the 15 basic safeguarding requirements in FAR 52.204-21. They cover access, permitted functions, external connections, public information, identity, media, physical protection, network boundaries, flaw repair, malicious code protection, updates, and scanning.

Who needs CMMC Level 1?

A contractor or subcontractor generally needs the required Level 1 status when the governing award requires it and performance involves FCI on contractor information systems. Verify the actual contract and current implementation direction.

Is CMMC Level 1 a self assessment?

Yes. The organization conducts the assessment annually and submits the result in SPRS. Outside assistance does not turn the work into a certification. The required affirmation also remains the responsibility of the organization.

Can Level 1 use a POA&M?

No. All 15 requirements must be MET for Final Level 1 status. Fix and retest a gap before submitting a passing result.

Is a system security plan required at Level 1?

The official guide recommends one as a useful practice but says it is not required to obtain a Level 1 self assessment. A concise, accurate plan still makes scope, implementation, ownership, and evidence easier to maintain.

What evidence should support Level 1?

Use final documents, current records, responsible interviews, and repeatable tests. Map each item to the objective, system, owner, review period, and result. Evidence quality matters more than file count.

Make Every MET Result Reproducible

Do not treat Level 1 as the easy tier. Treat it as the exact tier. Name the FCI. Draw the real boundary. Prove every objective. Fix every gap. Submit only what the operating record supports.

The standard is simple: all 15 safeguards, every year, across the system that actually handles the work.

Build a Level 1 result you can defend.

GS Consulting can help your team settle scope, organize evidence, test the safeguards, and prepare the annual review and affirmation basis.

Discuss CMMC Level 1

© GS Consulting, LLC . All Rights Reserved | For more information, contact us at info@gsconsultingllc.com. Image credit: ©iStock.com/Vertigo3d. Privacy Policy | Terms of Use