CMMC Level 1 requires meeting all 15 basic safeguarding practices in FAR clause 52.204-21, then completing an annual self-assessment with results submitted to SPRS and affirmed by a senior company official. There's no partial credit here: every practice must be scored MET or Not Applicable. Plans of Action and Milestones, the fallback many contractors use at higher CMMC levels, don't exist at Level 1. You either meet the requirement or you don't hold the contract.
TL;DR:
- Ensuring all 15 basic safeguarding practices are met and documented with concrete evidence is critical for successful self-assessment and compliance.
- The scope must only include assets that process, store, or transmit federal contract information, excluding operational technology and outside equipment.
- Evidence should be straightforward, final-form documents retained for six years, and clearly linked to specific practices and assets.
- Common pitfalls include mis-scoping assets, incomplete evidence collection, and neglecting proper documentation or retention procedures.
- Small contractors often underestimate the effort needed, but even simple gaps like outdated antivirus or shared credentials can block certification.
Table of Contents
- What Are CMMC Level 1 Requirements?
- How Do You Scope a CMMC Level 1 Assessment?
- How Do You Complete a Level 1 Self-Assessment?
- What Counts as Evidence, and How Long Do You Keep It?
- Level 1 Readiness Checklist: What Trips Up Small Contractors
- Why Small Contractors Underestimate Level 1
- Get Help Meeting CMMC Level 1 Requirements in Oklahoma
- Sources
What Are CMMC Level 1 Requirements?
Level 1 exists for one reason: protecting Federal Contract Information, or FCI, the non-public information the government shares with contractors to perform a contract. It's not classified data, and it's not Controlled Unclassified Information (that's Level 2 territory). It's things like contract deliverables, technical drawings, or internal correspondence about a government project that shouldn't end up on a public server.
The 15 requirements come directly from FAR 52.204-21, and they map to NIST SP 800-171A assessment objectives for anyone who wants to research a specific control further. Here's the practical breakdown:
- Limit system access to authorized users (maps to NIST 3.1.1). Maintain a current list of who has login credentials to systems touching FCI.
- Limit access by transaction and function type (3.1.2). Not everyone with a login needs administrator rights.
- Control connections to external systems (3.1.20). Document what vendors or partners connect to your network and why.
- Control information posted publicly (3.1.22). Someone should review website content and social posts before they go live.
- Identify and authenticate users (3.5.1 and 3.5.2). Unique logins, no shared passwords.
- Sanitize media before disposal or reuse (3.8.3). Wiping a hard drive before it goes to e-waste counts.
- Control physical access (3.10.1). Locked doors, badge access, or a sign-in sheet for visitors.
- Escort visitors and monitor activity (3.10.3).
- Maintain audit logs of physical access (3.10.4).
- Control and manage physical access devices (3.10.5), like keys and badges.
- Monitor and protect organizational communications at network boundaries (3.13.1).
- Implement subnetworks for publicly accessible components where applicable (3.13.5).
- Identify, report, and correct system flaws in a timely manner (3.14.1), meaning patching.
- Provide malicious code protection (3.14.2), antivirus or endpoint protection.
- Update malicious code protection when new releases are available (3.14.4), and perform periodic scans (3.14.5).
Many of these requirements are physical security controls, not technical. A locked filing cabinet and a visitor log satisfy real requirements just as much as a firewall rule does.
How Do You Scope a CMMC Level 1 Assessment?
Scoping determines what actually needs to meet these 15 practices, and getting it wrong in either direction causes problems. Scope too broadly and you're securing systems that never touch FCI, burning time and budget. Scope too narrowly and you leave an in-scope asset unassessed, which becomes a compliance gap the moment someone checks.
The CMMC Scoping Guide for Level 1 defines in-scope assets as anything that processes, stores, or transmits FCI. That includes:
- Workstations and laptops where employees open contract documents.
- Shared drives or cloud folders holding deliverables.
- Email accounts receiving contract correspondence.
- Networked printers or copiers used for contract paperwork.
- Physical filing cabinets storing printed FCI.
Specialized assets, think IoT devices, operational technology, government-furnished equipment, and dedicated test equipment, are generally excluded from the Level 1 assessment scope. A smart thermostat on the office network almost never touches FCI, and the scoping guide doesn't require you to secure it as though it does.
Pro Tip: Build your scope with an asset-type inventory grouping assets by category (laptops, servers, shared drives, physical storage) and confirm each category's relationship to FCI once. This approach is faster and holds up better under review.
Re-scope whenever something material changes: a new cloud tenant, a merger, or a network expansion. Routine changes like adding one more laptop to an existing setup don't trigger a fresh assessment.
How Do You Complete a Level 1 Self-Assessment?
The process breaks into three phases, and skipping the first one is where most contractors get into trouble.
Phase one: preparation.
- Finalize your asset scope using the approach above.
- Collect evidence for each in-scope asset and each applicable practice.
- Decide your assessment method for each practice: examine (review documents or configurations), interview (talk to the person responsible), or test (verify the control actually works). The CMMC Assessment Guide for Level 1 and NIST SP 800-171A both describe these methods in detail.
Phase two: execution. Score every one of the 15 practices as MET or N/A. There's no third option. Document the finding with the specific evidence that supports it, not just a note that says "compliant."
Phase three: submission.
- Enter your results into the Supplier Performance Risk System (SPRS).
- Have a senior company official sign the affirmation attesting the assessment is accurate.
- Repeat this annually, and immediately after any significant change to your scope, per 32 CFR § 170.15.
If you want a walkthrough tailored to smaller organizations, this Level 1 self-assessment guide covers the SPRS mechanics step by step.
What Counts as Evidence, and How Long Do You Keep It?
Assessors accept a range of artifact types: firewall configurations, screenshots of user access lists, training completion logs, printed security policies, visitor sign-in sheets, and malware scan reports. The guidance from the CMMC Assessment Guide favors simple, final-form documents over drafts. A signed policy beats a Word document still marked "review pending."
Retention runs six years from the CMMC Status Date, per 32 CFR § 170.15, so build a folder structure now that you can maintain for that long.
- Label evidence by asset and by practice number, not by date alone.
- If a managed service provider handles part of your environment, document exactly which control they cover and get their evidence in writing.
- Never submit a draft policy as your artifact. Assessors want the version actually in force.
Inherited controls from an External Service Provider are legitimate evidence, but you still own the documentation trail connecting their control to your specific practice.
Level 1 Readiness Checklist: What Trips Up Small Contractors
Run this before you touch SPRS:
- Inventory every asset that handles FCI, including paper files.
- Confirm antivirus and malicious code protection are current on every in-scope device.
- Verify unique logins exist for every user, with no shared credentials.
- Restrict administrator access to only the people who need it.
- Schedule periodic vulnerability scans and document the results.
- Confirm your media sanitization process for retired hardware.
The pitfalls that generate NOT MET findings are almost always avoidable. Mis-scoping tops the list, followed by incomplete evidence, where a contractor knows a control exists but never captured proof of it. Relying on a POA&M is a nonstarter at Level 1. Skipping the six-year retention plan and forgetting the SPRS affirmation round out the common mistakes.
Pro Tip: Build a one-page "evidence pack" for each in-scope asset: an identifier, a line on how it touches FCI, the artifact proving each applicable practice, and an inheritance note if a vendor covers part of it. This single habit resolves most audit friction before it starts.
For a broader IT-controls view that overlaps with several of these practices, see this CMMC IT requirements breakdown. And identity controls specifically, unique logins, access limits, deserve extra attention; this identity verification checklist from a compliance-focused partner is worth a look if authentication is your weak spot.
Why Small Contractors Underestimate Level 1

Most small contractors treat Level 1 as a formality because it sounds basic compared to Level 2's control count. That's a mistake. The "no POA&M" rule is unforgiving in a way higher levels aren't, and a contractor with one unmet practice, even a minor one like an unsanitized old laptop sitting in a closet, can't self-certify.
A local managed IT provider uses 24/7 monitoring and prioritized fixes rather than jargon-heavy audits. One client closed a Level 1 gap on malicious code protection simply by standardizing endpoint protection across five workstations that had been running mismatched, expired antivirus licenses. The fix took an afternoon. Finding the gap took a proper scope review first. That's usually the harder part.
— Nicholas
Get Help Meeting CMMC Level 1 Requirements in Oklahoma
There are practical alternatives to hiring a compliance consultant from out of state for CMMC Level 1 work that offer local response, plain-language explanations, and flexible service terms without long-term contracts. Scoping, malware protection, access control hardening, monitoring, and evidence collection all map directly to the 15 practices covered above, and our team builds the documentation trail as we go instead of reconstructing it right before your SPRS deadline.

If your last self-assessment left you unsure whether your scope was right or your evidence would hold up, a scoped readiness check is the fastest way to find out before it becomes a contract problem. Our managed IT support for small businesses covers exactly the controls Level 1 demands, and we can walk your environment asset by asset to confirm what's actually in scope. Reach out to Great Plains Networking and get a straight answer on where you stand.
Sources
- Acquisition
- 32 CFR 170.15 | CMMC Level 1 self-assessment and affirmation requirements | eCFR
- CMMC Scoping Guide—Level 1 (DoD CIO)
