The 15 CMMC Level 1 Requirements, Explained in Plain Language
CMMC Level 1 has a reputation problem in both directions. Half the defense industrial base treats it as a checkbox (“we have a firewall, we’re fine”), and the other half has been sold a compliance project with a five-figure invoice. The truth sits in between: Level 1 is 15 requirements — the basic safeguarding requirements of FAR 52.204-21, adopted wholesale by 32 CFR § 170.14(c)(2) — assessed against 59 specific objectives that a small business owner can genuinely read, understand, and answer honestly in an afternoon.
This guide goes domain by domain through all fifteen. For each requirement you get the official statement and the assessment objectives translated into the plain question an assessor is actually asking. The plain-language phrasings below are the ones we use in our own free CMMC Level 1 self-assessment and document generator; the official objective texts come from the CMMC Assessment Guide, Level 1, v2.13.
What CMMC Level 1 is — and isn’t
Level 1 is the CMMC tier for contractors who handle Federal Contract Information (FCI) but not CUI. It is verified entirely by self-assessment: you assess your own systems annually, enter the result in SPRS, and a senior official affirms it — the mechanics, exact button labels included, are in our SPRS score submission walkthrough. There is no third-party assessor and no certificate at this level, which is why nobody can truthfully claim to be “CMMC Level 1 certified.”
If your contracts involve CUI, Level 1 is your foundation but not your destination — that’s CMMC Level 2 and the 110 controls of NIST SP 800-171 behind it. And note the current landscape: since the July 13, 2026 suspension of CMMC Phase II, self-assessed postures — Level 1 (Self) and Level 2 (Self) — are the only CMMC levels a contracting officer may currently designate.
Scope matters before any control does. The Level 1 assessment scope is the set of your information systems that process, store, or transmit FCI (32 CFR § 170.19(b)(1)). Specialized Assets — IoT and IIoT devices, operational technology, Government-Furnished Equipment, Restricted Information Systems, and Test Equipment — are not part of the Level 1 CMMC Assessment Scope and are not assessed against the requirements (§ 170.19(b)(2)(ii)).
How the 15 requirements are assessed
Four rules govern every finding, and they’re worth internalizing before you read a single control:
- Three findings exist: MET, NOT MET, and NOT APPLICABLE (32 CFR § 170.24). Each of a requirement’s objectives gets one.
- One NOT MET objective fails the entire requirement. A requirement is MET only when every one of its objectives is MET or N/A.
- N/A is equivalent to MET — the rule imposes no justification precondition, though recording why the objective doesn’t apply is the Assessment Guide’s best practice, and it’s ours: an unexplained N/A is the first thing anyone reviewing your self-assessment will poke.
- All 15 requirements must be MET to achieve the Final Level 1 (Self) status — and no POA&M is permitted at any time for Level 1 (§ 170.21(a)(1)). Two findings-level accommodations exist: enduring exceptions described, with mitigations, in a system security plan are assessed MET, as are temporary deficiencies appropriately addressed in operational plans of action (§ 170.24(b)(1)(i)–(ii)) — and an operational plan of action is legally distinct from a POA&M.
Evidence must be in final form — working papers, drafts, and unofficial or unapproved policies don’t count — and retained for six years from the CMMC Status Date (§ 170.15(c)(2)). An SSP is recommended but not required at Level 1, except that claiming an enduring exception requires one.
Now, the requirements — grouped by their six domains, with each objective as the plain question it amounts to.
Access Control (AC) — 4 requirements
AC.L1-b.1.i — Authorized Access Control (SP 800-171: 3.1.1). Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). The six objectives, plainly:
- Do you keep a current list of who is authorized to use your systems?
- Have you identified the service accounts and automated processes that act on behalf of users?
- Have you identified which devices (and other systems) are allowed to connect?
- Is system access actually limited to those authorized users?
- Is access limited to those identified processes and service accounts?
- Is access limited to those authorized devices?
AC.L1-b.1.ii — Transaction & Function Control (3.1.2). Limit information system access to the types of transactions and functions that authorized users are permitted to execute. Two objectives:
- Have you defined what each user or role is allowed to do (view, edit, admin)?
- Is access actually limited to those defined permissions?
AC.L1-b.1.iii — External Connections (3.1.20). Verify and control/limit connections to and use of external information systems. Six objectives:
- Have you identified the external systems that connect to yours (client portals, partner systems)?
- Have you identified where your people use external systems (personal cloud, outside tools)?
- Do you verify external connections before allowing them?
- Do you verify the external systems your people use?
- Do you control or limit connections to external systems?
- Do you control or limit the use of external systems (e.g., no FCI in personal accounts)?
AC.L1-b.1.iv — Control Public Information (3.1.22). Control information posted or processed on publicly accessible information systems. Five objectives:
- Is there a defined list of people allowed to post to your website and social accounts?
- Do you have procedures to keep FCI off public systems?
- Is content reviewed before it is posted publicly?
- Is public content checked to confirm it contains no FCI?
- Could you quickly remove FCI if it were ever posted?
Identification & Authentication (IA) — 2 requirements
IA.L1-b.1.v — Identification (3.5.1). Identify information system users, processes acting on behalf of users, or devices. Three objectives:
- Does every user have a unique login — no shared accounts?
- Are service accounts and automated processes individually identified?
- Are the devices that access your systems identified (inventoried)?
IA.L1-b.1.vi — Authentication (3.5.2). Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. Three objectives:
- Must every user log in (password, and ideally MFA) before getting access?
- Do service accounts and processes authenticate (keys/tokens) before access?
- Do devices authenticate or get verified before connecting?
Media Protection (MP) — 1 requirement
MP.L1-b.1.vii — Media Disposal (3.8.3). Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. Two objectives:
- Are drives, laptops, USBs, and paper with FCI wiped or destroyed before disposal?
- Is media wiped before being reused or reassigned?
Physical Protection (PE) — 2 requirements
PE.L1-b.1.viii — Limit Physical Access (3.10.1). Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. Four objectives:
- Do you know exactly who is allowed physical access to your workspace?
- Is physical access to your systems limited to those people?
- Is physical access to equipment (laptops, network gear, printers) limited?
- Is access to the operating environment (offices, closets) limited?
PE.L1-b.1.ix — Manage Visitors & Physical Access (3.10.3 / 3.10.4 / 3.10.5). Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices. One FAR sentence carrying three NIST requirements — six objectives:
- Are visitors escorted in non-public areas?
- Is visitor activity monitored while on site?
- Do you keep logs of physical access (visitor log, badge logs)?
- Are your keys, badges, and fobs inventoried?
- Are they controlled — issued and returned with a record?
- Are they managed — deactivated or rekeyed when lost or when someone leaves?
System and Communications Protection (SC) — 2 requirements
SC.L1-b.1.x — Boundary Protection (3.13.1). Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. The biggest requirement in the set — eight objectives:
- Have you defined your external boundary (firewall/router, cloud tenant edges)?
- Have you defined key internal boundaries (e.g., FCI areas vs. guest/general)?
- Are communications monitored at the external boundary (logs/alerts)?
- Are communications monitored at key internal boundaries?
- Are communications controlled at the external boundary (default-deny inbound)?
- Are communications controlled at internal boundaries (segmentation, access rules)?
- Are communications protected at the external boundary (TLS/VPN)?
- Are communications protected at internal boundaries?
SC.L1-b.1.xi — Public-Access System Separation (3.13.5). Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Two objectives:
- Have you identified any publicly accessible components inside your scope (self-hosted website, public server)?
- Are any such components separated from your internal network (or externally hosted)?
This is the Assessment Guide’s own example of a legitimate NOT APPLICABLE: if no publicly accessible system components exist in your scope — your website lives with an external host, nothing self-hosted faces the internet — the requirement can be assessed N/A, which counts as MET.
System and Information Integrity (SI) — 4 requirements
SI.L1-b.1.xii — Flaw Remediation (3.14.1). Identify, report, and correct information and information system flaws in a timely manner. Six objectives — and notice the pattern: three ask whether you defined a timeframe, three ask whether you hit it:
- Have you specified how quickly flaws must be identified (a defined timeframe)?
- Are flaws actually identified within that timeframe (auto-updates, advisories)?
- Have you specified how quickly flaws must be reported internally?
- Are flaws reported within that timeframe?
- Have you specified how quickly flaws must be corrected (e.g., critical in 14 days)?
- Are flaws corrected within that timeframe?
SI.L1-b.1.xiii — Malicious Code Protection (3.14.2). Provide protection from malicious code at appropriate locations within organizational information systems. Two objectives:
- Have you designated where malware protection runs (every laptop, email, web filtering)?
- Is protection actually installed and running at those locations?
SI.L1-b.1.xiv — Update Malicious Code Protection (3.14.4). Update malicious code protection mechanisms when new releases are available. The single-objective requirement:
- Does your malware protection update itself automatically when new releases ship?
SI.L1-b.1.xv — System & File Scanning (3.14.5). Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed. Three objectives:
- Have you defined how often full scans run (e.g., weekly)?
- Do those periodic scans actually run on that schedule?
- Is real-time scanning on — files from outside scanned as they are downloaded, opened, or executed?
What to do with a gap
If any objective above made you wince, the sequence matters: at Level 1 you cannot submit a NOT MET finding with a promise to fix it later — no POA&Ms, no conditional status. Implement the control, gather final-form evidence, then assess and submit. For most small businesses the gaps cluster in the same few places (written patch timeframes, media-disposal logs, visitor logs, and unexplained N/As), and most are policy-and-habit fixes, not purchases.
The fastest way to find yours: run the free CMMC Level 1 self-assessment. It asks all 59 objectives in the plain language above, applies the exact MET/NOT MET/N/A gate rules from the rule text, and hands you either the complete Level 1 document package or a prioritized gap report — entirely in your browser, and your answers never leave it.