Quick answer
CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, requiring 17 basic cybersecurity practices and annual self-assessment for contractors that handle Federal Contract Information.
CMMC Level 1 represents the minimum cybersecurity baseline the DoD expects of any contractor whose work involves Federal Contract Information. It is designed to be achievable by small businesses without specialized cybersecurity staff, relying on widely understood basic hygiene practices.
What is CMMC Level 1?
CMMC Level 1 establishes 17 cybersecurity practices drawn from FAR clause 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems). These practices cover foundational controls including limiting system access to authorized users, using unique user IDs and passwords, sanitizing media before disposal, protecting physical access to systems, and maintaining basic incident response awareness. Contractors at Level 1 are required to conduct an annual self-assessment against these 17 practices, affirm their compliance in the Supplier Performance Risk System (SPRS), and have a senior official certify the accuracy of the assessment. Unlike Level 2, Level 1 does not require a third-party assessment by a C3PAO. Level 1 applies to contractors handling Federal Contract Information (FCI), which is information provided by or generated for the government under a contract that is not intended for public release.
Why CMMC Level 1 matters for government contractors
Even though Level 1 is the minimum tier, failure to complete the annual self-assessment and SPRS affirmation can render a contractor ineligible for contract awards. The 17 practices are straightforward but must be formally documented and affirmed. Small businesses that have not previously formalized their IT practices may need to make changes before they can honestly certify compliance.
Example
A small janitorial services firm holding a GSA building maintenance contract that involves access to government facility information conducts its CMMC Level 1 self-assessment. The firm's owner reviews each of the 17 practices, documents that it uses unique passwords and restricts system access, and submits the affirmation in SPRS before the contract renewal date.
Frequently Asked Questions
Who needs CMMC Level 1 certification?
Any defense contractor handling Federal Contract Information that is not intended for public release needs Level 1 compliance. This includes many service contractors who handle mundane but non-public government operational data.
What is SPRS?
The Supplier Performance Risk System is the DoD portal where contractors submit their CMMC self-assessment scores and affirmations. A valid SPRS score is required to be eligible for applicable DoD contract awards.
How long does a Level 1 self-assessment take?
For a small business with straightforward IT infrastructure, a Level 1 self-assessment typically takes a few hours to a few days depending on the rigor of documentation.
Does Level 1 require a System Security Plan?
The 17 Level 1 practices do not explicitly require a full NIST SP 800-171 System Security Plan. However, documenting the assessment findings and the practices in place is necessary to support the certification affirmation.
Can a contractor move from Level 1 to Level 2 if their contracts change?
Yes. If a contractor begins handling CUI under a new contract, the applicable CMMC level increases to Level 2 and the contractor must meet those higher requirements.
How Bidovate helps
Bidovate puts CMMC Level 1 to work inside your capture and proposal workflow.
Solicitation analysisSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
CMMC Level 2
CMMC Level 2 requires defense contractors handling Controlled Unclassified Information to implement all 110 security requirements of NIST SP 800-171 and, for most programs, undergo triennial third-party assessments.
ViewCMMC Level 3
CMMC Level 3 is the highest tier of the Cybersecurity Maturity Model Certification, requiring implementation of NIST SP 800-172 controls in addition to all 800-171 requirements, with government-led assessments for contractors on the most critical defense programs.
ViewSection 889 (Huawei/ZTE Ban)
Section 889 of the FY2019 National Defense Authorization Act prohibits federal contractors from using or providing telecommunications equipment or services from Huawei, ZTE, and three other designated Chinese companies.
View