Cybersecurity
CMMC Level 1 Requirements: The 15 Controls Small Contractors Need for FCI
CMMC Level 1 requires 15 basic safeguarding practices from FAR 52.204-21 and an annual self-assessment. Here is what Hampton Roads contractors handling Federal Contract Information actually need to do.
CMMC Level 1 requires 15 basic safeguarding practices drawn from FAR 52.204-21, covering access control, authentication, media handling, physical security, and basic system protection. It applies to contractors that handle Federal Contract Information rather than Controlled Unclassified Information, and it is satisfied through an annual self-assessment with no System Security Plan and no third-party assessor.
That is the short answer. If your company holds a DoD contract and isn’t sure which CMMC level applies, Level 1 is very likely where you land, and it is a much smaller project than the Level 2 process most CMMC content assumes you’re facing.
If your business supports base operations, logistics, manufacturing, or general services around Norfolk, Newport News, Portsmouth, Chesapeake, Virginia Beach, Suffolk, or Hampton, and your contract doesn’t specifically involve CUI, this is the level you should be planning for. The full CMMC overview for Hampton Roads contractors covers how the three levels fit together. This article stays on Level 1.
What is FCI?
Federal Contract Information is information the government provides to a contractor, or that a contractor generates for the government, under a contract, and that isn’t meant for public release. It’s defined at FAR 52.204-21(a), and it’s a much broader category than most small contractors expect.
FCI doesn’t require a special marking the way CUI does. There’s no banner stamped across the document. A purchase order, a delivery schedule, an internal email discussing contract performance, a spreadsheet tracking deliverables against a statement of work: all of that can be FCI if it was generated under, or provided in connection with, a federal contract and wasn’t intended for public release.
FCI explicitly excludes information the government has made public through channels like public websites, press releases, and simple transactional information needed to process payments (think invoice numbers). Everything else connected to contract performance is fair game to be FCI, which is why so many small contractors are in scope for Level 1 without realizing it.
FCI is also the lower tier of a two-tier system. CUI is the more sensitive category above it, and the two get handled very differently. If you want the full comparison, our CUI explainer covers what pushes a contractor from FCI into CUI territory, and from Level 1 into Level 2.
The CMMC Program rule itself lives at 32 CFR Part 170, which is what actually puts the FAR 52.204-21(a) safeguarding requirements into a certification framework.
The 15 CMMC Level 1 requirements
The 15 practices come straight from FAR 52.204-21(b)(1), organized here by the same control families CMMC uses at Level 2, even though Level 1 only touches six of them.
Access Control (AC)
- Limit system access to authorized users, processes, and devices.
- Limit access to the types of transactions and functions authorized users are permitted to execute.
- Verify and control connections to external systems.
- Control information posted or processed on publicly accessible systems.
Identification and Authentication (IA) 5. Identify system users, processes, and devices before allowing access. 6. Authenticate (or verify) those identities before granting access.
Media Protection (MP) 7. Sanitize or destroy media containing FCI before disposal or reuse.
Physical Protection (PE) 8. Limit physical access to organizational systems, equipment, and operating environments to authorized individuals. 9. Escort visitors and monitor visitor activity; maintain audit logs of physical access; control and manage physical access devices.
System and Communications Protection (SC) 10. Monitor, control, and protect communications at external system boundaries and key internal boundaries. 11. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
System and Information Integrity (SI) 12. Identify, report, and correct system flaws in a timely manner. 13. Provide protection from malicious code at appropriate locations. 14. Update malicious code protection mechanisms when new releases are available. 15. Perform periodic scans of systems and real-time scans of files from external sources as they’re downloaded, opened, or executed.
Read the list again and notice what isn’t there: no incident response plan, no risk assessment program, no audit logging requirement, no configuration management baseline. Those all show up at Level 2. Level 1 is deliberately narrow, and that’s by design. It’s meant to be achievable by a small business running a normal, reasonably maintained network, not a compliance program with its own budget line.
What a small business usually already has covered
Most contractors we talk to are further along on Level 1 than they think. Unique user logins instead of a shared “office” account, antivirus that updates itself, a locked server closet, a guest Wi-Fi network that’s separate from the internal one: those cover a good chunk of the 15 practices without anyone having called it CMMC.
Where the gaps tend to show up:
- Media sanitization. Old laptops and drives get handed off, sold, or thrown out without anyone wiping them first. Practice 7 requires a real process here, not “we deleted the files.”
- Visitor logs. Small offices rarely track who came in, when, and who they met with. Practice 9 asks for that, even if it’s a paper sign-in sheet.
- External connections. Remote access tools, vendor VPNs, and cloud file shares often get set up without anyone documenting or reviewing what’s actually connecting into the network. Practice 3 covers this.
- Network segmentation. If a guest network or public-facing system sits on the same flat network as everything else, practice 11 isn’t met, and this is the one most likely to need an actual configuration change rather than a policy update.
None of these are expensive fixes on their own. The work is mostly identifying what’s missing, documenting what’s already in place, and being consistent about it going forward, which is exactly what a readiness checklist is built to walk through, scaled down for Level 1’s much shorter list.
The Level 1 self-assessment process
Level 1 is always self-assessed. There is no C3PAO involved, no SPRS score to calculate, and no System Security Plan required. That puts it in a different category from Level 2, where self-assessment is only an option for some contracts and a numeric SPRS score is always part of the picture.
What the process actually involves:
- Evaluate your environment against all 15 practices. Go through the list above and determine, honestly, whether each one is implemented. There’s no partial credit; either the practice is in place or it isn’t.
- Fix what isn’t in place. Unlike Level 2, there’s no POA&M option at Level 1. All 15 practices need to be implemented before you affirm compliance, not scheduled for later.
- Have a senior company official submit the affirmation. A senior official, someone with the authority to speak for the organization’s compliance posture, affirms in the Supplier Performance Risk System (SPRS) that all 15 practices are implemented. This isn’t a formality. A false affirmation carries potential False Claims Act exposure, the same as it does at Level 2.
- Reaffirm annually. The affirmation is valid for one year. After that, you go through the process again, which is a lot faster the second time if you kept your documentation instead of starting from memory.
That’s the whole process. No third-party auditor walks your floor, no formal report gets filed with a certification body, and there’s no waiting period for a certificate to be issued. The affirmation itself is the record.
CMMC Level 1 vs Level 2
| Level 1 | Level 2 | |
|---|---|---|
| Protects | FCI | CUI |
| Requirements | 15 (FAR 52.204-21) | 110 (NIST SP 800-171 Rev 2) |
| Assessment | Annual self-assessment only | Annual self-assessment OR triennial C3PAO |
| SSP required | No | Yes |
| POA&M allowed | No | Yes, for limited items |
| SPRS submission | Affirmation, no score | Numeric score plus affirmation |
The gap between the two levels is the reason so much CMMC content skips past Level 1 entirely: it’s a smaller, less interesting problem to write about than Level 2’s 110 controls. But if your contract doesn’t involve CUI, that smaller problem is the only one you actually have to solve. Read CMMC Level 2 Requirements if you want the full picture of what changes once CUI enters the environment, and CMMC vs NIST 800-171 if you want to see how the two frameworks line up more broadly.
What Level 1 costs and how long it takes
For a contractor with a reasonably maintained network, Level 1 readiness is typically weeks, not months. The 15 practices are narrow enough that a gap review, a short remediation list, and the affirmation itself can often happen inside a single engagement. Contractors starting from a genuinely neglected network, no antivirus policy, no access controls, physical security that’s an afterthought, will take longer, but still nowhere near the 6 to 24 month range that Level 2 involves.
Cost follows the same pattern. There’s no C3PAO fee at Level 1, since third-party assessment isn’t part of the process. Most of the cost is the labor to review, document, and close whatever gaps the review finds, plus any tooling you’re missing (antivirus licensing, a proper media sanitization process, network segmentation if your guest and internal traffic aren’t already separated).
Subcontractors and flowdown
If you’re a subcontractor rather than a prime, your CMMC obligation depends on what the prime flows down to you, not on the size of your role in the project. A subcontractor handling only FCI, no CUI, generally sits at Level 1 even when the prime above them is working toward Level 2. Our guide for subcontractors covers how that flowdown actually works in practice, including what to ask your prime when the contract language is vague.
Why Helix Stax for Level 1 readiness
Level 1 is a smaller job than Level 2, but it’s still worth getting right the first time. An affirmation that doesn’t match reality is a liability, not a shortcut, and the gaps that trip up small contractors, media sanitization, visitor logs, network segmentation, are easy to overlook without someone walking the environment specifically to check.
Helix Stax works with small Hampton Roads contractors on cybersecurity compliance, including Level 1 readiness reviews for companies that only need to clear the FCI bar. We also support the broader government contracting IT needs that come with holding a DoD contract in the first place.
If you’re not sure which level applies to you, the free Helix Score gives you a directional read in about three minutes. If you want someone to walk your environment against the 15 practices directly, book the free 60-minute assessment and get a clear answer before your prime asks for one.
Read more
Cybersecurity
NIST 800-171 Checklist: The 14 Control Families and How Scoring Works
A working NIST 800-171 checklist covering all 14 control families, the SPRS scoring formula, Rev 2 vs Rev 3 changes, and where NIST SP 800-172 fits. Built for Hampton Roads defense subcontractors.
Cybersecurity
IT Disaster Recovery Plan Template (With RTO/RPO and Site Comparison)
A free IT disaster recovery plan template covering RTO, RPO, hot vs. warm vs. cold site recovery, testing cadence, and how it maps to NIST SP 800-34. Copy it and fill in your own numbers.
Cybersecurity
6 Phishing Email Examples Your Staff Will Actually See (And How to Train Against Them)
Real-world phishing email examples: fake invoices, MFA fatigue, payroll redirects, vendor bank-change scams, and more. What gives each one away, plus how to run simulation training.
Frequently asked questions about Helix Stax managed IT services
CMMC Level 1 is the entry tier of the Cybersecurity Maturity Model Certification program. It requires 15 basic safeguarding practices drawn from FAR 52.204-21 and applies to contractors that handle Federal Contract Information (FCI) but not Controlled Unclassified Information. Contractors self-assess annually and affirm the results; no System Security Plan or third-party assessment is required.
The 15 requirements cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. They come directly from FAR 52.204-21(b)(1) and include practices like limiting system access to authorized users, using antivirus protection, and sanitizing media before disposal.
Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release. It is not classified and, unlike CUI, does not carry special markings. Nearly any DoD contract, even a small purchase order, can generate FCI.
Level 1 protects FCI with 15 basic safeguarding practices and a self-assessment. Level 2 protects CUI with all 110 NIST SP 800-171 practices, a System Security Plan, and either a self-assessment or a third-party C3PAO assessment depending on the contract. Level 1 is a fraction of the Level 2 workload.
No. Level 1 is always self-assessed. The contractor evaluates its own environment against the 15 practices, and a senior company official submits an annual affirmation. There is no SPRS score to calculate and no C3PAO involved at Level 1.
Annually. A senior official must affirm, at least once every 365 days, that the 15 practices are in place. There is no separate certificate; the affirmation itself, submitted through the Supplier Performance Risk System, is the record the DoD checks.
Often, yes. Most of the 15 practices describe things a reasonably maintained small business network is already doing: unique logins, antivirus, locked doors, and basic access limits. The gaps tend to show up in documentation and consistency, not in needing entirely new tools.
Through the Supplier Performance Risk System (SPRS), the same DoD system used for Level 2 scores. Level 1 does not produce a numeric score; the submission is a yes/no affirmation that all 15 practices are implemented.