CMMC Level 1 Assessment: What to Expect (2026 Guide)

CMMC Level 1 self-assessment process overview infographic showing six domains and four steps

If your company holds a Department of Defense contract, CMMC Level 1 likely applies to you.

CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification program. It applies to any organization that processes, stores, or transmits Federal Contract Information (FCI).

FCI is defined in 32 CFR § 170.4 as information provided by or generated for the government under contract. Examples include contract numbers, delivery schedules, project budgets, and proposal documents.

If your contract does not involve Controlled Unclassified Information (CUI), Level 1 is your required tier.

What Is CMMC Level 1?

Level 1 is defined in 32 CFR § 170.15 as the CMMC tier that covers the basic safeguarding of Federal Contract Information.

It requires contractors to implement 15 security requirements drawn from FAR Clause 52.204-21. These are the minimum practices needed to protect FCI in a contractor’s environment.

CMMC three-level pyramid diagram showing Level 1 FCI self-assessment, Level 2 CUI C3PAO, Level 3 DIBCAC

The Good News: CMMC Level 1 Is Self-Assessed

Unlike Level 2 and Level 3, CMMC Level 1 does not require a third-party assessor. 

You assess your own organization against 15 security requirements, submit your results in the Supplier Performance Risk System (SPRS), and have a senior official formally affirm the results.

This keeps costs manageable. It also means you control the timeline.

However, self-assessed does not mean self-reported without consequence. False attestation carries legal risk under the False Claims Act.

The 15 Requirements of CMMC Level 1: What They Cover

CMMC Level 1 is built on 15 basic safeguarding requirements from FAR Clause 52.204-21.

These 15 requirements span six security domains. Each domain targets a specific area of cyber hygiene, as defined in the CMMC Model Overview v2.13.

DomainAbbr.# of RequirementsWhat It Covers
Access ControlAC4Limit who can access FCI systems and data
Identification & AuthenticationIA2Verify the identities of users and devices
Media ProtectionMP1Protect and sanitize media containing FCI
Physical ProtectionPE1Control physical access to FCI systems
System & Communications ProtectionSC2Protect data in transit across networks
System & Information IntegritySI5Detect malware, patch systems, and monitor integrity
Total15

Access Control (4 requirements)

This domain governs who can access your FCI systems. You must limit access to authorized users only. You must also restrict what those users can do based on their assigned role.

External connections, including cloud services, fall under this domain.

Identification and Authentication (2 requirements)

Your systems must identify and authenticate all users, devices, and processes before granting access. Passwords must be cryptographically protected in storage and transit.

Media Protection (1 requirement)

This covers physical and digital media that store FCI. You must sanitize or destroy that media before disposal or reuse.

Physical Protection (1 requirement)

You must control physical access to systems holding FCI. This includes escorting visitors, maintaining access logs, and managing physical access devices like key cards.

System and Communications Protection (2 requirements)

FCI must be protected while moving across your networks. You must monitor and control communications at your system boundaries.

System and Information Integrity (5 requirements)

This is the largest domain. It covers anti-malware protections, security alerts, software updates, and basic security monitoring.

You must protect systems against malicious code and keep all software patched and up to date.

CMMC Level 1 six security domains infographic showing AC, IA, MP, PE, SC, SI with requirement counts

Step-by-Step: The CMMC Level 1 Assessment Process

Level 1 self-assessment requirements are defined in 32 CFR § 170.15. The following steps follow the official process set out in that regulation and the CMMC Assessment Guide Level 1.

  1. Define your FCI boundary (scoping)

Identify every system that processes, stores, or transmits FCI. This defines your CMMC Assessment Scope, as required by 32 CFR § 170.19(a).

According to the official CMMC Scoping Guide Level 1, all assets that touch FCI are in scope. Government Furnished Equipment (GFE) is a Specialized Asset and is excluded.

  1. Assess each requirement against your systems

Go through all 15 requirements methodically. For each one, gather evidence that the control is implemented and working.

Evidence must be final and complete. The official assessment guide states that working papers, drafts, and unofficial policies are not acceptable forms of evidence.

  1. Score each requirement as MET or NOT MET

Level 1 uses a binary scoring model. Each requirement is scored as MET, NOT MET, or NOT APPLICABLE, as defined in 32 CFR § 170.24.

To demonstrate Level 1 compliance, every requirement must yield a finding of MET or NOT APPLICABLE.

Important: Plans of Action and Milestones (POA&Ms) are not permitted at Level 1. Every requirement must be fully implemented before you submit.

  1. Submit results in SPRS

Enter your assessment results into the Supplier Performance Risk System (SPRS). Your score and submission date become visible to DoD contracting officers.

A current SPRS submission is a prerequisite for contract eligibility under CMMC Phase 1 requirements.

  1. Senior official provides executive affirmation

A senior company official must formally attest to compliance under 32 CFR § 170.22. This person takes legal responsibility for the accuracy of the submission.

False attestation carries potential liability under the False Claims Act.

  1. Repeat annually

Level 1 compliance is not permanent. Annual affirmation is required per 32 CFR § 170.22. You must re-assess and re-affirm every 12 months.

CMMC Level 1 self-assessment six-step process flowchart from scoping to annual affirmation

What Counts as Evidence?

Evidence is where many contractors struggle. A written policy is not sufficient on its own.

According to the CMMC Assessment Guide Level 1, evidence must show that controls are actually implemented and functioning. It must be in final, approved form.

DomainAcceptable Evidence Examples
Access Control (AC)User access list, role permission matrix, system access control configuration screenshots
Identification & Authentication (IA)Password policy document, MFA configuration records, credential audit logs
Media Protection (MP)Media sanitization log, disposal records, encryption configuration documentation
Physical Protection (PE)Visitor log, badge access records, physical access device audit trail
System & Comms Protection (SC)Firewall configuration records, network boundary documentation, encryption certificates
System & Info Integrity (SI)Anti-malware console records, patch management log, and software inventory with version data
CMMC evidence checklist showing required proof for each of the six Level 1 domains

CMMC Level 1 Assessment Timeline and Costs

How long does Level 1 take?

For organizations with some existing IT security in place, CMMC Level 1 compliance typically takes 3 to 6 months from start to SPRS submission.

If your current cyber hygiene baseline is low, allow up to 9 months.

PhaseEstimated DurationKey Activities
Scoping1-2 weeksIdentify all systems and assets touching FCI
Gap assessment2-4 weeksMap current controls against all 15 requirements
Remediation4-12 weeksImplement missing controls and gather evidence
Documentation2-4 weeksOrganize evidence, finalize policies, and records
SPRS submission1 weekSubmit score and obtain executive affirmation

What does CMMC Level 1 cost?

The DoD published official cost estimates in the CMMC Final Rule (32 CFR Part 170). These estimates are based on the DoD’s regulatory impact analysis.

Cost ItemOther-Than-Small BusinessSmall Business
Self-assessment cost (est.)~$4,000~$6,000
Annual affirmation fee (est.)~$560-$584~$560-$584
Internal staff timeVaries (several weeks)Varies (several weeks)

Internal staff time is typically the highest cost. Budget several weeks of IT and management effort across the full process.

CMMC Level 1 compliance timeline showing phases from scoping to SPRS submission across 3 to 9 months

When Does CMMC Level 1 Apply?

CMMC Phase 1 began on November 10, 2025. From that date, CMMC Level 1 self-assessment requirements began appearing in new DoD solicitations.

You cannot win a contract requiring CMMC compliance without a current SPRS submission on file.

PhaseDateWhat Happens
Phase 1Nov 10, 2025Level 1 self-assessments and some Level 2 self-assessments are required in new DoD solicitations
Phase 2Nov 10, 2026Level 2 C3PAO certification assessments begin appearing in solicitations
Phase 3Nov 10, 2027Level 3 certification required for applicable high-priority contracts
Phase 4Nov 10, 2028Full CMMC enforcement across all applicable DoD contracts
CMMC phased rollout timeline infographic showing Phase 1 through Phase 4 from November 2025 to November 2028

Source: 32 CFR Part 170 — CMMC Phased Implementation (Subpart B) 

Source: DoD CIO CMMC Program — Official Program Page

Common Mistakes to Avoid During CMMC Level 1 Assessment

  • Waiting until a solicitation arrives. By then, you may not have time to achieve compliance before the bid deadline.
  • Treating a written policy as sufficient evidence. Controls must be operational, implemented, and provable.
  • Scoping too broadly or too narrowly. Every system touching FCI is in scope, including cloud tools and third-party services.
  • Ignoring subcontractors. If you are a prime contractor, CMMC requirements must flow down to applicable subcontractors.
  • Submitting before all requirements are MET. POA&Ms are not allowed at CMMC Level 1. Every requirement must be fully implemented first.
  • Missing the annual affirmation. A lapsed affirmation ends your contract eligibility as effectively as a failed assessment.

CMMC Level 1 vs. CMMC Level 2: Key Differences

Understanding where Level 1 ends and Level 2 begins is essential for any DoD contractor.

FactorCMMC Level 1CMMC Level 2
Data type protectedFederal Contract Information (FCI)Controlled Unclassified Information (CUI)
Governing regulation32 CFR § 170.1532 CFR § 170.16 / 170.17
Source requirements15 (FAR 52.204-21)110 (NIST SP 800-171 Rev 2)
Assessment typeAnnual self-assessmentC3PAO third-party or self-assessment
POA&Ms allowedNoYes, with conditions (max 180 days)
Estimated cost (DoD est.)$4,000-$6,000$31,000-$150,000+
SPRS submissionRequired annuallyRequired (C3PAO submits for cert. assessments)

Source: 32 CFR § 170.15 (Level 1) and 32 CFR § 170.16-170.17 (Level 2) 

Records Retention

You must retain records of each self-assessment for at least 6 years after the date of submission.

This includes your evidence binder, scoring documentation, and the affirmation record. Keep these organized and accessible in case of a future audit or contract dispute.

The DoD retains the right to conduct its own assessment under the DFARS clause. If its findings show non-compliance, that determination takes precedence.

Frequently Asked Questions

Do I need CMMC Level 1 if I am a subcontractor?

Yes. If you handle FCI at any tier of the supply chain, CMMC Level 1 applies. Under 32 CFR § 170.23, prime contractors must flow CMMC requirements down to applicable subcontractors.

Can I use a consultant to help with CMMC Level 1 self-assessment?

Yes. External assistance is permitted. However, the executive affirmation and legal responsibility remain with your senior company official. The DoD does not certify or accredit Level 1 consultants.

What happens if I miss the annual affirmation?

You lose CMMC status and become ineligible for contracts requiring Level 1 compliance. A lapsed affirmation has the same effect as a failed assessment.

Do cloud tools count as in-scope systems?

Yes, if they process, store, or transmit FCI. External service providers in that role are considered External Service Providers (ESPs) under 32 CFR § 170.4 and must be included in your assessment scope.

Summary: What to Do Next

  1. Confirm whether your contract involves FCI or CUI. This determines your required CMMC level.
  2. Identify all systems that touch FCI. This is your CMMC Assessment Scope under 32 CFR § 170.19(a).
  3. Run a gap assessment. Compare your current controls against all 15 requirements of FAR 52.204-21.
  4. Implement any missing controls and gather final, approved evidence for each requirement.
  5. Submit your score to SPRS and obtain executive affirmation under 32 CFR § 170.22.
  6. Calendar your annual re-assessment. Set a reminder 3 months before the 12-month mark.
 CMMC Level 1 six-step readiness checklist with completion status indicators

Official Sources and Further Reading

All sources below are official U.S. Government and DoD publications.

Source: DoD CIO — CMMC Program Home (https://dodcio.defense.gov/CMMC/)

Source: DoD CIO — CMMC Resources and Documentation (all official guides) (https://dodcio.defense.gov/CMMC/Documentation/)

Source: CMMC Model Overview v2.13 (Official PDF) (https://dodcio.defense.gov/Portals/0/Documents/CMMC/ModelOverviewv2.pdf)

Source: CMMC Assessment Guide Level 1 v2.13 (Official PDF) (https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL1v2.pdf)

Source: CMMC Scoping Guide Level 1 v2 (Official PDF) (https://dodcio.defense.gov/Portals/0/Documents/CMMC/ScopingGuideL1v2.pdf)

Source: 32 CFR Part 170 — CMMC Program Final Rule (eCFR) (https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170)

Source: FAR Clause 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems (https://www.acquisition.gov/far/52.204-21)

Source: SPRS — Supplier Performance Risk System (DoD/DISA) (https://www.sprs.csd.disa.mil/)

Source: Federal Register — CMMC Program Final Rule (Oct 15, 2024) (https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program)

Scroll to Top