CMMC Level 1 · GuideSEC / GDE

Guide

Do I Need GCC High or a FedRAMP Cloud for CMMC Level 1?

Short Answer

CMMC Level 1 does not require FedRAMP authorization or any particular government cloud. In the CMMC rule, 32 CFR Part 170, the FedRAMP Moderate condition appears only in the Level 2 and Level 3 sections, for cloud services that process, store, or transmit CUI. DFARS 252.204-7012 sets its FedRAMP condition for covered defense information. FAR 52.204-21, the source of the 15 Level 1 requirements, names no cloud authorization. The rule still asks you to consider any provider that handles your FCI when you set your scope.

Why the Confusion Exists

Much of what is written about CMMC and the cloud comes from the Level 2 world. A supplier that keeps Controlled Unclassified Information in the cloud must use an offering that is FedRAMP Moderate or equivalent, and that advice is easy to repeat without the condition attached. Read without the condition, it sounds like a rule for every CMMC level.

Two separate authorities carry FedRAMP conditions, and both are about CUI. One is the DFARS clause on covered defense information. The other is the set of Level 2 and Level 3 sections in the CMMC rule. Neither is written for a supplier whose work involves only Federal Contract Information.

The preamble to the final rule can add to the confusion. In one response to comments on external service providers, it discusses providers that handle FCI or CUI in a sentence that also mentions FedRAMP Moderate (89 FR 83136). The conditions themselves are set in the codified text of 32 CFR Part 170, and there the FedRAMP condition appears only in sections about CUI.

What the Current Authority Says

Under 32 CFR 170.14(c)(2), the Level 1 security requirements are the 15 items in FAR 52.204-21(b)(1)(i) through (xv). None of the 15 mentions cloud services, FedRAMP, or the authorization of any provider.

The Level 1 self-assessment procedures are in 32 CFR 170.15, and Level 1 scoping is in 32 CFR 170.19(b). Neither contains a FedRAMP condition. 32 CFR 170.19(b)(3) asks a supplier scoping a Level 1 self-assessment to consider the people, technology, facilities, and External Service Providers within its environment that process, store, or transmit FCI.

The FedRAMP condition appears where CUI is involved. 32 CFR 170.16(c)(2) allows a cloud service to process, store, or transmit CUI for a Level 2 self-assessment when the offering is FedRAMP Authorized at the Moderate baseline or higher, or meets equivalent security requirements. 32 CFR 170.17(c)(5) and 170.18(c)(5) set the same kind of condition for the Level 2 and Level 3 assessments performed by outside assessors. Table 4 to 32 CFR 170.19(c)(2)(i) points a cloud provider that handles CUI to the FedRAMP requirements in DFARS 252.204-7012.

DFARS 252.204-7012(b)(2)(ii)(D) applies when a contractor intends to use an external cloud service provider to store, process, or transmit covered defense information. The contractor must ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline. The clause defines covered defense information by reference to the CUI Registry.

None of these texts names a vendor or a specific cloud product.

What This Means

For work that involves only FCI, no Level 1 authority requires a FedRAMP authorized cloud, a government cloud offering, or a particular vendor. You may still choose one for your own reasons. Level 1 does not require it.

The cloud services you use for FCI still matter. Under 32 CFR 170.19(b)(1), information systems that process, store, or transmit FCI are in scope for Level 1. The DoD CMMC Assessment Guide, Level 1, Version 2.13, says a requirement can be MET when adequate evidence shows that an External Service Provider, which can include a cloud service provider, implements the requirement objectives. Which services you include is the scoping decision you make.

If your work involves CUI or covered defense information, the FedRAMP conditions above apply to the cloud services that handle it, and that is the Level 2 world rather than Level 1. FAR 52.204-21(b)(2) also notes that the clause does not relieve a contractor of other safeguarding requirements an agency specifies, so read each contract for its other clauses.

Primary Sources

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Written By
AssessrLog, from the primary sources listed above

How we verify this reference

Cite This Page

“Do I Need GCC High or a FedRAMP Cloud for CMMC Level 1?.” AssessrLog, a product of ProfytAI Pte. Ltd.. https://assessrlog.com/cmmc/guides/do-i-need-fedramp-or-gcc-high-for-cmmc-level-1/

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.