Guide
Does CMMC Level 1 have 15 or 17 requirements?
Short Answer
CMMC Level 1 has 15 requirements, 59 assessment objectives, and 6 domains. The 15 come from FAR 52.204-21(b)(1). They map to 17 NIST SP 800-171 practices, which is where the 17 comes from, but Level 1 is counted and stated as 15 requirements.
Where the 17 comes from
Some sources say 17 because they count the underlying NIST SP 800-171 practices instead of the FAR requirements. One requirement, on managing visitors and physical access, maps to three NIST practices, so 15 requirements line up with 17 practices. The requirement count is still 15.
The full breakdown
15 requirements from FAR 52.204-21(b)(1), broken into 59 assessment objectives from NIST SP 800-171A, organized under 6 domains. The domains are Access Control, Identification and Authentication, Media Protection, Physical Protection, System and Communications Protection, and System and Information Integrity.
Related Definitions
Related Questions
Primary Sources
Build the Record Behind This
AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.
