Foundational • FCI
- DataFCI
- Controls17
- OriginFAR 52.204-21
- Assessmentannual self
- C3PAOnot required
The lowest tier of CMMC 2.0 protects Federal Contract Information (FCI) — information provided by or generated for the government under a contract that is not intended for public release. Level 1 comprises 17 practices, derived from the 15 basic safeguarding requirements in FAR 52.204-21, verified by an annual self-assessment and an annual affirmation in SPRS. No C3PAO. This page explains where the 17 come from and who they apply to.
Level 1 is not a new invention. Its 17 practices derive from the 15 basic safeguarding requirements in the Federal Acquisition Regulation clause FAR 52.204-21, which has obligated contractors handling FCI to apply basic cyber hygiene for years. CMMC Level 1 verifies those same safeguards — expressed as 17 practices with 59 assessment objectives. They align to a subset of NIST SP 800-171 — the standard used at Level 2 — but Level 1 stops at the basics.
The data type is the whole point. Level 1 covers Federal Contract Information: information the government provides or that is generated under a contract that is not for public release. It does not cover CUI. The moment your contract involves CUI, you are no longer a Level 1 organization.
Level 1 uses an annual self-assessment. You evaluate your environment against the 17 requirements, confirm they are met, and record an annual affirmation in SPRS — the Supplier Performance Risk System — signed by a senior official. There is no third-party assessment: a C3PAO is not required for Level 1.
That does not make it optional or informal. The affirmation is an attestation the government relies on, and a false affirmation carries real consequences. Level 1 is lighter than Level 2, not looser.
Read the data type first. If your contract touches CUI, no amount of Level 1 posture is enough — you are a Level 2 organization and the rest follows.
Organizations that handle FCI but never touch CUI. If any CUI enters your systems — often through a prime’s flow-down — you are past Level 1.
Suppliers and service providers whose contracts involve federal contract information but no controlled unclassified information at all.
Vendors providing goods or basic services under a DoD contract where no technical data or CUI is exchanged in performing the work.
Confirm your level from the solicitation and what your prime hands you. A single CUI document received or generated moves you to Level 2.
Request a readiness assessment. We’ll confirm the data your contracts actually touch, verify the 17 requirements are met, and tell you plainly whether you’re Level 1 or already Level 2.
Request a Readiness Assessment →