CMMC Level 1 · GuideSEC / GDE

Guide

Why Do CMMC Level 1 Sources Use Different Numbers and Names?

Short Answer

Because the documents come from different years. The current authority is the CMMC rule, 32 CFR Part 170, in effect since December 16, 2024. It defines Level 1 as the 15 security requirements of FAR 52.204-21(b)(1), numbered from the FAR paragraph, such as AC.L1-b.1.i. An older DoD guide from December 2021 listed 17 practices numbered from NIST, such as AC.L1-3.1.1. The objectives come from the June 2018 edition of NIST SP 800-171A, and some DoD solicitations now show the FAR clause as 52.240-93.

Why the Confusion Exists

Level 1 has been described in several official documents over several years, and each one used the language of its time. The older documents are still easy to find online, so a supplier can read two sources on the same day and see different counts, different names, and different identifiers.

The original CMMC program took effect through a DFARS interim rule on November 30, 2020, and the final rule describes it as a tiered model of practices and processes. That is where the word practice comes from.

The CMMC Self-Assessment Guide, Level 1, Version 2.0, dated December 2021, organized Level 1 as 17 practices. Each practice took its identifier from a NIST SP 800-171 number, for example AC.L1-3.1.1. The FAR item on visitors, physical access logs, and physical access devices appeared there as three separate practices, which is how 15 FAR items became 17.

What the Current Authority Says

The CMMC Program final rule was published on October 15, 2024 and took effect on December 16, 2024. Under 32 CFR 170.14(c)(2), the Level 1 security requirements are those in FAR 52.204-21(b)(1)(i) through (xv). That is 15 requirements.

The rule calls them security requirements, not practices. Under 32 CFR 170.14(c)(1), each identifier follows the format DD.L#-REQ, and for Level 1 the REQ part is the FAR paragraph number. So the first requirement is AC.L1-b.1.i. The DoD CMMC Assessment Guide, Level 1, Version 2.13, dated September 2024, uses the same numbering and lists the 15 requirements.

The 17 still appears, but only in the mapping. Table 2 to 32 CFR 170.15(c)(1)(ii) maps each Level 1 requirement to NIST SP 800-171A. One requirement, PE.L1-b.1.ix, maps to three NIST numbers, and the other 14 map to one each. The final rule explains that NIST split that one requirement into 3 parts while the other 14 align.

The assessment objectives are pinned to one edition. 32 CFR 170.15(c)(1)(i) requires the Level 1 self-assessment to use the objectives in NIST SP 800-171A, June 2018, and the rule incorporates that edition by reference. NIST published Revision 3 of SP 800-171 and SP 800-171A in May 2024. The final rule states that Revision 3 of SP 800-171 is not currently applicable to it and that DoD will amend the rule in the future to adopt a newer version. As of October 2026 the rule still names the June 2018 edition, which is the source of the 59 Level 1 assessment objectives.

The FAR clause can also carry a new number. Under DoD class deviations 2026-O0025 and 2026-O0038, effective February 1, 2026, DoD contracting officers use the revised FAR Part 40 and Part 52 from the FAR overhaul. In that text the clause appears as FAR 52.240-93, Basic Safeguarding of Covered Contractor Information Systems, and its 15 safeguarding items are word for word the same as FAR 52.204-21(b)(1). The same class deviation 2026-O0025 issues a new DFARS Part 240 for DoD contracting officers, where the prescription for the CMMC clauses appears at DFARS 240.371-5. The clause numbers stay 252.204-7021 and 252.204-7025. As of October 2026, 32 CFR 170.14(c)(2) still cites FAR 52.204-21, and identifiers such as AC.L1-b.1.i are unchanged.

What This Means

When two sources disagree, check the date and the authority behind each one. For Level 1 today, the numbers are 15 requirements, 59 assessment objectives, and 6 domains. The rule, the FAR clause, and the Version 2.13 assessment guide are the current references. Practice-based material from before the rule describes the same FAR safeguards in older terms.

If your older records use identifiers such as AC.L1-3.1.1 or count 17 practices, Table 2 to 32 CFR 170.15(c)(1)(ii) shows how each current requirement lines up with the NIST numbers. That helps when you update those records to the current identifiers.

A solicitation that cites FAR 52.240-93 points to the same 15 safeguarding items as FAR 52.204-21. Whichever number a document uses, you still assess the 15 requirements against the June 2018 objectives and record each result yourself.

Primary Sources

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Written By
AssessrLog, from the primary sources listed above

How we verify this reference

Cite This Page

“Why Do CMMC Level 1 Sources Use Different Numbers and Names?.” AssessrLog, a product of ProfytAI Pte. Ltd.. https://assessrlog.com/cmmc/guides/cmmc-level-1-terminology-changes/

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.