CMMC Level 1 · GuideSEC / GDE

Guide

Does CMMC Level 1 have 15 or 17 requirements?

Short Answer

CMMC Level 1 has 15 requirements, 59 assessment objectives, and 6 domains. The 15 come from FAR 52.204-21(b)(1). They map to 17 NIST SP 800-171 practices, which is where the 17 comes from, but Level 1 is counted and stated as 15 requirements.

Where the 17 comes from

Some sources say 17 because they count the underlying NIST SP 800-171 practices instead of the FAR requirements. One requirement, on managing visitors and physical access, maps to three NIST practices, so 15 requirements line up with 17 practices. The requirement count is still 15.

The full breakdown

15 requirements from FAR 52.204-21(b)(1), broken into 59 assessment objectives from NIST SP 800-171A, organized under 6 domains. The domains are Access Control, Identification and Authentication, Media Protection, Physical Protection, System and Communications Protection, and System and Information Integrity.

Primary Sources

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.