Reference Center
CMMC, in Plain English
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program, set out in 32 CFR Part 170, for safeguarding federal information across the defense supply chain. This reference center covers Level 1.
Where Level 1 Fits
CMMC has tiers. Level 1 applies to companies that handle Federal Contract Information (FCI) and is met by an annual self-assessment. The higher levels apply to Controlled Unclassified Information (CUI) and involve more requirements and, above Level 1, third-party assessment. This reference center is built for the Level 1 world: 15 requirements and 59 assessment objectives across 6 domains.
Start Here
What Level 1 covers, the numbers behind it, the six domains, and how the self-assessment and annual affirmation work.
RequirementsAll 15 Level 1 security requirements from FAR 52.204-21(b)(1), each with its official text and assessment objectives.
Assessment ObjectivesThe 59 assessment objectives from NIST SP 800-171A, each with the official examine, interview, and test procedures.
GuidesDirect answers to the most common Level 1 questions: is it a certification, do I need a C3PAO, FCI vs CUI, cost, and how to submit in SPRS.
GlossaryPlain-English definitions of the Level 1 terms, from FCI and CUI to SPRS, the Affirming Official, POA&M, and determinations.
Sources
- 32 CFR Part 170
- FAR 52.204-21(b)(1)
- NIST SP 800-171A
- DoD CMMC Assessment Guide, Level 1
How This Reference Is Maintained
Every requirement and objective here is taken directly from the primary sources: FAR 52.204-21, NIST SP 800-171A, and 32 CFR Part 170. Identifiers, official text, and assessment procedures are reproduced from those authorities and pinned to a specific published version, then checked against the DoD CMMC Assessment Guide for Level 1. Each page shows the framework version, its effective date, and when the content was last verified. When a source changes, the affected pages are re-verified before they are updated.
