
CMMC Level 1
CMMC Level 1 Has 15 Requirements, Not 17 Controls
Why you see 15, 17, 49, and 61 for CMMC Level 1, and the correct answer. Fifteen requirements, fifty-nine objectives, six domains, and no score.
Search for the size of CMMC Level 1 and you get four different answers. Some pages say 15 requirements, others say 17 controls, and forum threads throw around 49 or 61 objectives. When guides, MSPs, and even other vendors disagree on the count, it is hard to trust anything else they say. Here is the correct answer and why the confusion exists.
The short version. CMMC Level 1 has 15 requirements, broken into 59 assessment objectives, across 6 domains. It exists to protect Federal Contract Information. There is no numeric score at Level 1 and no Plan of Action and Milestones. If a page tells you 17 controls or gives you a percentage score, it is working from the wrong source.
Why You See "17" and Why the Answer Is 15
The 15 requirements come from a federal rule, FAR 52.204-21, at paragraph (b)(1). They are lettered i through xv, which is where the 15 comes from. These are the requirements the government points to for basic safeguarding of Federal Contract Information.
The 17 comes from mapping those requirements to NIST SP 800-171, where one of them (physical protection) expands into three separate practices, which is how the total reaches 17. Both numbers describe the same set of protections. The requirement count is 15, and that is the number tied to the actual rule you are being held to. This is why you will see older or copied pages say "17 practices" or "17 controls." They are not entirely wrong about the mapping, but the count that matters for Level 1 is 15 requirements.
One more habit worth dropping. At Level 1 these are requirements, not controls. Calling them controls is how the "17 controls" phrasing spreads. Say 15 requirements and 59 objectives.
The 15 CMMC Level 1 Requirements
Here are the 15 requirements with their canonical identifiers and plain descriptions.
- AC.L1-b.1.i, limit system access to authorized users
- AC.L1-b.1.ii, limit access to permitted transactions and functions
- AC.L1-b.1.iii, verify and control connections to external systems
- AC.L1-b.1.iv, control information posted to publicly accessible systems
- IA.L1-b.1.v, identify system users, processes, and devices
- IA.L1-b.1.vi, authenticate users before granting access
- MP.L1-b.1.vii, sanitize or destroy media before disposal or reuse
- PE.L1-b.1.viii, limit physical access to systems and equipment
- PE.L1-b.1.ix, escort visitors, log physical access, and manage devices
- SC.L1-b.1.x, monitor and control communications at the boundary
- SC.L1-b.1.xi, separate publicly accessible systems from internal networks
- SI.L1-b.1.xii, identify, report, and correct system flaws
- SI.L1-b.1.xiii, protect against malicious code
- SI.L1-b.1.xiv, keep malicious code protection current
- SI.L1-b.1.xv, perform periodic and real-time scans
The 59 Objectives Across 6 Domains
Each requirement breaks into smaller assessment objectives, which come from NIST SP 800-171A. There are 59 of them, and they group into six domains. The counts are exact.
- Access Control: 19 objectives
- Identification and Authentication: 6 objectives
- Media Protection: 2 objectives
- Physical Protection: 10 objectives
- System and Communications Protection: 10 objectives
- System and Information Integrity: 12 objectives
Those add to 59. When you see 49 or 61, it is an older or miscounted figure. The number is 59, and it is the level of detail you actually assess against.

What CMMC Level 1 Does Not Have
Getting the count right also means getting rid of three things that belong to other levels.
- No numeric score. Level 1 is not scored. You do not get a percentage or a points total. Every applicable objective is either MET or N/A, and you affirm the whole thing. Anyone showing you a Level 1 "readiness score" is showing you a number that does not exist.
- No Plan of Action and Milestones. You cannot affirm Level 1 with open items to fix later. Everything applicable has to be resolved first.
- No certification. Level 1 is a self-assessment, not a certification. No third party certifies you. You assess, you affirm, and a senior official records it in SPRS.
Built Around These Exact Numbers
AssessrLog is built around exactly these numbers. It scopes your Federal Contract Information, walks all 59 objectives across the 15 requirements, and logs each determination as MET, NOT MET, or N/A with its evidence attached. No invented score, no plan-of-action fiction, just the real structure of Level 1 kept in one place. You can see that structure on the product overview.
Frequently Asked Questions
Is CMMC Level 1 15 or 17 controls? It is 15 requirements. They come from FAR 52.204-21(b)(1), lettered i through xv. They map to 17 NIST SP 800-171 practices, but the count that applies to Level 1 is 15 requirements.
How many assessment objectives are in Level 1? 59, across six domains, from NIST SP 800-171A. Not 49 and not 61.
Is there a CMMC Level 1 score? No. Level 1 is not scored. Each applicable objective is MET or N/A, and you affirm the result. There is no percentage or points total.
Are they called controls or requirements? At Level 1 they are requirements, 15 of them, broken into 59 objectives. "Controls" is a habit carried over from other frameworks.
What is Level 1 protecting? Federal Contract Information, or FCI. The more sensitive Controlled Unclassified Information belongs to Level 2, which is a different and heavier standard.
