CMMC · Level 1
CMMC Level 1
CMMC Level 1 is a self-assessment that a small defense supplier performs on its own systems to protect Federal Contract Information. It is not a certification and no third-party assessor is involved.
What Level 1 Covers
Level 1 protects Federal Contract Information (FCI), the information a company receives or creates under a federal contract that is not intended for public release. It is scoped to FCI only. Controlled Unclassified Information (CUI) and the larger Level 2 world are out of scope.
The work is a count of resolved objectives, not a grade. There is no numeric score and no plan-of-action-and-milestones at Level 1. Each objective is determined MET, NOT MET, or N/A by a person, and the results are affirmed annually in SPRS by a senior company official. Assessment records are retained for 6 years.
The Numbers
- Requirements
- 15 (FAR 52.204-21(b)(1))
- Assessment Objectives
- 59 (NIST SP 800-171A)
- Domains
- 6
- Determinations
- MET · NOT MET · N/A
- Affirmation
- Annual, in SPRS, by a senior official
- Retention
- 6 years
The Six Domains
Common Questions
- Is CMMC Level 1 a certification?
- No. Level 1 is an annual self-assessment. You assess your own systems against the fifteen requirements, record each result, and affirm them each year in SPRS. No certificate is issued and no third-party assessor is involved. The word certified does not apply at Level 1.
- Do I need a C3PAO or a third-party audit for Level 1?
- No. Level 1 is self-assessed. A third-party assessment by a C3PAO applies to Level 2. You may bring in a consultant or a managed IT provider to help, and it remains your self-assessment. Your own senior official still signs the affirmation.
- Is there a Level 1 score, like the 110-point NIST score?
- No. Level 1 has no numeric score. Each of the 59 assessment objectives is determined MET, NOT MET, or N/A, and the overall result is MET or NOT MET. The 110-point score belongs to the Level 2 world.
- Do I need a System Security Plan or a POA&M for Level 1?
- Neither is required at Level 1. Many suppliers still write a short plan because it helps, but it is not a requirement. A plan of action and milestones is not permitted at Level 1 either. Every one of the fifteen requirements has to be MET or N/A. There is no partial pass.
- I entered my results in SPRS. Is that everything?
- Not quite. Entering the results and affirming them are two separate steps. The affirmation is a separate action completed in SPRS by your senior Affirming Official. Without a current affirmation you are not considered to have a Level 1 status.
- How much does CMMC Level 1 cost and how long does it take?
- The Department of Defense estimates about $5,977 a year in labor for a small business, much of it optional outside help, with nothing attributed to the fifteen safeguards themselves. The SPRS entry itself takes only minutes. The real time goes into gathering and keeping the evidence that backs each result.
Explore the Reference
Sources
- FAR 52.204-21(b)(1)
- NIST SP 800-171A
- 32 CFR § 170.15
- 32 CFR § 170.22
- 32 CFR § 170.24
How This Reference Is Maintained
Every requirement and objective here is taken directly from the primary sources: FAR 52.204-21, NIST SP 800-171A, and 32 CFR Part 170. Identifiers, official text, and assessment procedures are reproduced from those authorities and pinned to a specific published version, then checked against the DoD CMMC Assessment Guide for Level 1. Each page shows the framework version, its effective date, and when the content was last verified. When a source changes, the affected pages are re-verified before they are updated.
