Atom Cybersecurity — two practices, one standard
Reference • CMMC Level 1 • FAR 52.204-21

Level 1: 17 controls, for FCI.

The lowest tier of CMMC 2.0 protects Federal Contract Information (FCI) — information provided by or generated for the government under a contract that is not intended for public release. Level 1 comprises 17 practices, derived from the 15 basic safeguarding requirements in FAR 52.204-21, verified by an annual self-assessment and an annual affirmation in SPRS. No C3PAO. This page explains where the 17 come from and who they apply to.

What Level 1 is

The 17 practices come from FAR 52.204-21.

Level 1 is not a new invention. Its 17 practices derive from the 15 basic safeguarding requirements in the Federal Acquisition Regulation clause FAR 52.204-21, which has obligated contractors handling FCI to apply basic cyber hygiene for years. CMMC Level 1 verifies those same safeguards — expressed as 17 practices with 59 assessment objectives. They align to a subset of NIST SP 800-171 — the standard used at Level 2 — but Level 1 stops at the basics.

The data type is the whole point. Level 1 covers Federal Contract Information: information the government provides or that is generated under a contract that is not for public release. It does not cover CUI. The moment your contract involves CUI, you are no longer a Level 1 organization.

  • 17 practices — access control, identification, media, physical, and system-integrity basics.
  • FAR 52.204-21 — its 15 requirements become the 17 CMMC Level 1 practices.
  • Aligns to a subset of NIST SP 800-171 — the same family structure, fewer requirements.
  • Protects FCI, not CUI — the data type sets the level.
How Level 1 is verified

You assess yourself — every year.

Level 1 uses an annual self-assessment. You evaluate your environment against the 17 requirements, confirm they are met, and record an annual affirmation in SPRS — the Supplier Performance Risk System — signed by a senior official. There is no third-party assessment: a C3PAO is not required for Level 1.

That does not make it optional or informal. The affirmation is an attestation the government relies on, and a false affirmation carries real consequences. Level 1 is lighter than Level 2, not looser.

  • Annual self-assessment — you measure against the 17, no assessor visit.
  • Annual affirmation in SPRS — recorded and signed by a senior official.
  • No C3PAO — third-party certification is a Level 2 concept.
  • Attestation carries weight — an affirmation is a representation to the government.
The distinction that matters

Level 1 vs Level 2.

Read the data type first. If your contract touches CUI, no amount of Level 1 posture is enough — you are a Level 2 organization and the rest follows.

Level 1

Foundational • FCI

  • DataFCI
  • Controls17
  • OriginFAR 52.204-21
  • Assessmentannual self
  • C3PAOnot required
Level 2

Advanced • CUI

  • DataCUI
  • Controls110
  • OriginNIST SP 800-171
  • AssessmentC3PAO third-party
  • Cycle3-year

See the 110 controls of Level 2 →

Who this applies to

Who only needs Level 1?

Organizations that handle FCI but never touch CUI. If any CUI enters your systems — often through a prime’s flow-down — you are past Level 1.

01

FCI only, no CUI

Suppliers and service providers whose contracts involve federal contract information but no controlled unclassified information at all.

02

Commodity & support work

Vendors providing goods or basic services under a DoD contract where no technical data or CUI is exchanged in performing the work.

03

Check the flow-down

Confirm your level from the solicitation and what your prime hands you. A single CUI document received or generated moves you to Level 2.

See all CMMC levels and the rollout →

Confirm your level

Sure you’re only Level 1?

Request a readiness assessment. We’ll confirm the data your contracts actually touch, verify the 17 requirements are met, and tell you plainly whether you’re Level 1 or already Level 2.

Request a Readiness Assessment