HomeGlossaryCMMC Level 1
Cybersecurity Compliance

CMMC Level 1

CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, requiring 17 basic cybersecurity practices and annual self-assessment for contractors that handle Federal Contract Information.

Quick answer

CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, requiring 17 basic cybersecurity practices and annual self-assessment for contractors that handle Federal Contract Information.


CMMC Level 1 represents the minimum cybersecurity baseline the DoD expects of any contractor whose work involves Federal Contract Information. It is designed to be achievable by small businesses without specialized cybersecurity staff, relying on widely understood basic hygiene practices.

What is CMMC Level 1?

CMMC Level 1 establishes 17 cybersecurity practices drawn from FAR clause 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems). These practices cover foundational controls including limiting system access to authorized users, using unique user IDs and passwords, sanitizing media before disposal, protecting physical access to systems, and maintaining basic incident response awareness. Contractors at Level 1 are required to conduct an annual self-assessment against these 17 practices, affirm their compliance in the Supplier Performance Risk System (SPRS), and have a senior official certify the accuracy of the assessment. Unlike Level 2, Level 1 does not require a third-party assessment by a C3PAO. Level 1 applies to contractors handling Federal Contract Information (FCI), which is information provided by or generated for the government under a contract that is not intended for public release.

Why CMMC Level 1 matters for government contractors

Even though Level 1 is the minimum tier, failure to complete the annual self-assessment and SPRS affirmation can render a contractor ineligible for contract awards. The 17 practices are straightforward but must be formally documented and affirmed. Small businesses that have not previously formalized their IT practices may need to make changes before they can honestly certify compliance.

Example

A small janitorial services firm holding a GSA building maintenance contract that involves access to government facility information conducts its CMMC Level 1 self-assessment. The firm's owner reviews each of the 17 practices, documents that it uses unique passwords and restricts system access, and submits the affirmation in SPRS before the contract renewal date.

Frequently Asked Questions

Who needs CMMC Level 1 certification?


Any defense contractor handling Federal Contract Information that is not intended for public release needs Level 1 compliance. This includes many service contractors who handle mundane but non-public government operational data.

What is SPRS?


The Supplier Performance Risk System is the DoD portal where contractors submit their CMMC self-assessment scores and affirmations. A valid SPRS score is required to be eligible for applicable DoD contract awards.

How long does a Level 1 self-assessment take?


For a small business with straightforward IT infrastructure, a Level 1 self-assessment typically takes a few hours to a few days depending on the rigor of documentation.

Does Level 1 require a System Security Plan?


The 17 Level 1 practices do not explicitly require a full NIST SP 800-171 System Security Plan. However, documenting the assessment findings and the practices in place is necessary to support the certification affirmation.

Can a contractor move from Level 1 to Level 2 if their contracts change?


Yes. If a contractor begins handling CUI under a new contract, the applicable CMMC level increases to Level 2 and the contractor must meet those higher requirements.

How Bidovate helps

Bidovate puts CMMC Level 1 to work inside your capture and proposal workflow.

Solicitation analysis

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.