25+ Years Security Experience•Enterprise Security Leadership
CMMC Compliance

CMMC Level 1 Self-Assessment: The Complete Practitioner's Guide

15 controls. 59 assessment objectives. Zero room for POA&Ms. Here's what every defense contractor needs to know about achieving — and maintaining — their Level 1 compliance, from an RP who reviews these assessments every day.

By Dan Pitre, CMMC Registered Practitioner•Published March 2026•12 min read

What Is a CMMC Level 1 Self-Assessment?

A CMMC Level 1 self-assessment is an annual evaluation of your organization's implementation of 15 security requirements from FAR 52.204-21, required for defense contractors handling Federal Contract Information (FCI) under applicable DoD solicitations and contracts. The assessment evaluates 59 determination statements (assessment objectives) per the official CMMC Level 1 Assessment Guide, and each requirement is scored MET or NOT MET — no Plan of Action and Milestones (POA&Ms) are allowed. Your affirming official must attest that all 15 requirements are MET (commonly referred to as a "15/15 score") in SPRS to achieve Final Level 1 (Self) status.

This guide provides general compliance guidance and is not legal advice. Regulatory obligations depend on specific contract terms and facts. Consult qualified legal counsel for advice on your organization's specific compliance requirements.

Who Needs Level 1 — and Why It Matters Now

CMMC Level 1 applies when a DoD solicitation or contract (including subcontracts) includes a CMMC Level 1 requirement and your in-scope systems process, store, or transmit Federal Contract Information (FCI). Industry estimates suggest a majority of Defense Industrial Base (DIB) contractors fall into the Level 1 category rather than Level 2, making this the most broadly applicable CMMC tier.

Phase 1 Is Already Here

Phase 1 rollout began November 10, 2025. CMMC requirements now appear in applicable solicitations and contracts. Contractors without a current Final Level 1 (Self) status in SPRS may be ineligible for those contract awards. This isn't a future requirement — it's happening now on new solicitations. See our CMMC Phase 2 deadline timeline for the full four-phase rollout.

Level 1 is also an annual requirement — not one-and-done. You must re-affirm each year following your Final status date. And here's what makes accuracy critical: inaccurate or knowingly false compliance representations can create False Claims Act risk depending on contract terms, materiality, and the specific facts. The Department of Justice's Civil Cyber-Fraud Initiative has signaled enforcement focus on cybersecurity compliance misrepresentations.

This is one of the strongest reasons to engage a qualified CMMC Registered Practitioner before you affirm. An RP can independently validate your self-assessment, identify gaps you may have overlooked, and give your affirming official confidence that what you're signing is accurate.

The 15 Controls — What You're Actually Assessing

The 15 Level 1 requirements come from FAR 52.204-21(b)(1)(i)-(xv), organized into 6 control families. Each control maps to specific assessment objectives in the official CMMC Level 1 Assessment Guide (v2.13). Click any family to see the controls, what "MET" actually requires, and the pitfalls we see as practitioners.

Access Control
4 controls
Identification & Authentication
2 controls
Media Protection
1 control
Physical Protection
4 controls
System & Communications Protection
2 controls
System & Information Integrity
4 controls
AC.L1-3.1.1

Limit system access to authorized users

Only people who need access to your systems should have it. This means defining who's authorized, what types of access they get, and actively controlling that access.

What "MET" requires: The assessment objectives examine whether you've (a) defined types of access, (b) identified authorized users, AND (c) controlled access to the system. A password policy alone doesn't satisfy all three.

Common pitfall: Many contractors check this box because they have passwords. But the objectives ask whether you've defined access types and identified authorized users — not just whether login exists.

AC.L1-3.1.2

Limit system access to authorized functions

Users should only be able to perform the functions they need for their role. Administrative functions should be restricted to administrators.

What "MET" requires: Examines whether you've defined authorized functions (transactions and system commands) and whether those functions are actually limited to authorized users.

Common pitfall: Everyone having admin rights is a common fail. If your office manager has the same system privileges as your IT lead, this control isn't MET.

AC.L1-3.1.20

Verify and control connections to external systems

Any connection between your systems and external systems (cloud services, partner networks, remote access) must be identified and controlled.

What "MET" requires: Examines whether external connections are identified and whether those connections are verified and controlled — meaning you know what's connecting and you've approved it.

Common pitfall: Shadow IT is the killer here. That free file-sharing service someone signed up for? That's an uncontrolled external connection.

AC.L1-3.1.22

Control information posted publicly

Ensure that FCI isn't inadvertently posted to publicly accessible systems — websites, public file shares, social media.

What "MET" requires: Examines whether you've identified authorized individuals who can post publicly and whether you review content before posting.

Common pitfall: This catches people off guard — it's not just about your website. Shared drives with public links, public-facing support portals, and even email signatures can be vectors.

IA.L1-3.5.1

Identify system users and processes

Every user and process acting on behalf of a user must be uniquely identifiable. No shared accounts for FCI-handling systems.

What "MET" requires: Examines whether system users are identified and whether processes acting on behalf of users are identified.

Common pitfall: Shared logins — 'the front desk account' or 'the warehouse iPad' — are a direct fail. Every person needs their own identity.

IA.L1-3.5.2

Authenticate users and processes

Verify identity before granting access. This means passwords, MFA, biometrics, or other authentication mechanisms — appropriate to the system.

What "MET" requires: Examines whether users are authenticated and whether processes acting on behalf of users are authenticated before system access.

Common pitfall: Having authentication isn't enough — it needs to work. Auto-login PCs, tablets without lock screens, and systems that stay logged in indefinitely undermine this control.

MP.L1-3.8.3

Sanitize or destroy media before disposal or reuse

Before you throw out, sell, donate, or repurpose any storage media (hard drives, USB drives, phones, copiers), ensure FCI has been properly removed.

What "MET" requires: Examines whether system media is sanitized or destroyed before disposal and before reuse.

Common pitfall: People forget about copiers and multifunction printers — they have hard drives. Old laptops 'given to the warehouse' without being wiped are a compliance gap.

PE.L1-3.10.1

Limit physical access to authorized individuals

Only authorized people should be able to physically access areas where FCI is processed, stored, or transmitted.

What "MET" requires: Examines whether authorized individuals are identified and whether physical access is limited to those individuals.

Common pitfall: Open office layouts where visitors walk past FCI-handling workstations are a problem. This isn't just about locked server rooms.

PE.L1-3.10.3

Escort visitors and monitor visitor activity

Visitors in areas where FCI is handled must be escorted and their activity monitored.

What "MET" requires: Examines whether visitors are escorted and whether visitor activity is monitored.

Common pitfall: The delivery person who walks through the back office unescorted. The client who waits in a conference room with access to the hallway where FCI systems are located.

PE.L1-3.10.4

Maintain audit logs of physical access

Keep records of who accesses physical spaces where FCI is handled — sign-in logs, badge records, camera footage.

What "MET" requires: Examines whether audit logs of physical access are maintained.

Common pitfall: A sign-in sheet that nobody checks or reviews doesn't satisfy the 'maintain' standard. The log must be usable as an audit trail.

PE.L1-3.10.5

Control and manage physical access devices

Keys, badges, cards, and combinations used to access FCI areas must be controlled — tracked, inventoried, and changed when compromised.

What "MET" requires: Examines whether physical access devices are identified and whether those devices are controlled and managed.

Common pitfall: The key everyone copies. The door code that hasn't changed in three years. The badge that still works for the employee who left six months ago.

SC.L1-3.13.1

Monitor, control, and protect communications at boundaries

Protect information as it moves across network boundaries — between your internal network and the internet, between network segments, between your systems and partners.

What "MET" requires: Examines whether system communications are monitored, controlled, and protected at external and key internal boundaries.

Common pitfall: A basic firewall covers some of this, but the 'monitor' piece catches people. Are you actually watching what crosses your network boundary, or just blocking known bad traffic?

SC.L1-3.13.5

Implement subnetworks for publicly accessible systems

Any system that's publicly accessible (web server, email server, public-facing application) must be on a separate subnetwork from your internal systems that handle FCI.

What "MET" requires: Examines whether publicly accessible system components are identified and whether those components are on separate subnetworks.

Common pitfall: Your website and your internal file server on the same flat network is a fail. DMZ architecture isn't optional if you have public-facing services.

SI.L1-3.14.1

Identify, report, and correct system flaws

Find vulnerabilities, report them, and fix them in a timely manner. This means a patching process — not just antivirus.

What "MET" requires: Examines whether system flaws are identified, whether they're reported, and whether they're corrected.

Common pitfall: Having automatic updates turned on isn't enough. Third-party software, firmware, and applications outside the OS update cycle are common blind spots.

SI.L1-3.14.2

Provide protection from malicious code

Deploy and maintain malicious code protection mechanisms — antivirus, anti-malware, endpoint detection — and keep them updated.

What "MET" requires: Examines whether malicious code protection mechanisms are employed and whether those mechanisms are updated when new releases are available.

Common pitfall: Antivirus that's installed but not updating, or that users can disable, doesn't meet this control. Check that definitions are current and the software is actually running.

SI.L1-3.14.4

Update malicious code protection when new releases are available

Keep your malicious code protection mechanisms current — automatic signature updates, engine updates, and definition updates.

What "MET" requires: Examines whether malicious code protection mechanisms are updated when new releases are available.

Common pitfall: This is often paired with 3.14.2 but is a separate control. Having antivirus isn't the same as keeping it updated. Check your update logs.

SI.L1-3.14.5

Perform periodic scans and real-time scans of files from external sources

Run regular scans of your systems and automatically scan files from external sources (email attachments, downloads, USB drives) in real time.

What "MET" requires: Examines whether periodic system scans are performed and whether real-time scanning of files from external sources is performed as files are downloaded, opened, or executed.

Common pitfall: Scheduled weekly scans cover periodic. But is real-time scanning actually enabled? USB drives plugged into shop-floor PCs are a common gap.

RP Practitioner Insight

"Many contractors check the box on AC.L1-3.1.1 ('limit system access to authorized users') because they have password policies. But the assessment objectives examine whether you've defined types of access, identified authorized users, AND controlled access to the system. A password policy alone doesn't satisfy all three objectives. This pattern repeats across most of the 15 controls — the gap between 'we do something related to this' and 'we fully satisfy the assessment objectives' is where most self-assessments break down."

The Assessment Process — Step by Step

Here's how to approach your Level 1 self-assessment methodically. Each step builds on the previous one — rushing past scoping to jump into control evaluation is the most common mistake we see.

1

Scope Your FCI Environment

Identify which systems, networks, and physical spaces process, store, or transmit FCI. This is where most assessments go wrong. Under-scoping means you miss assets and leave gaps in your assessment. Over-scoping means you're assessing (and securing) more than required, burning time and budget.

In a 15-person manufacturing firm, the FCI boundary often extends beyond the office — shop-floor PCs that access contract specs, the warehouse tablet that pulls delivery manifests, and the personal phone your project manager uses to check email all need to be considered.

2

Map Controls to Your Environment

For each of the 15 practices, determine how your organization implements the requirement. Document the specific method and identify the evidence. Don't just answer 'yes, we do this' — identify exactly how you do it and where the proof is.

3

Evaluate Using Assessment Objectives (EIT)

Each practice has 2-5 assessment objectives (59 total). Use the Examination/Interview/Testing methodology from NIST SP 800-171A (June 2018), as incorporated by reference in 32 CFR Part 170:

Examine

Review policies, procedures, system configurations, and documentation

Interview

Confirm that personnel understand and follow the controls in practice

Test

Verify that controls work as intended — test that terminated accounts are actually disabled, that physical access logs are maintained, that antivirus is actually updating

Note: NIST has since issued SP 800-171A Rev. 3, but CMMC Level 1 assessments still reference the June 2018 objectives as incorporated by the rule.

4

Score Your Assessment

Each practice is MET or NOT MET. All 15 must be MET to achieve Final Level 1 (Self) status. No POA&Ms, no partial credit. The SPRS entry for Level 1 is effectively a binary Yes/No — all requirements MET (commonly referred to as '15/15') or not. If even one control is NOT MET, you cannot affirm.

5

Affirming Official Attestation

Your affirming official signs the affirmation in SPRS, attesting that the assessment is accurate and complete. This is a legal representation to the federal government. Misrepresentations in this affirmation can create False Claims Act risk depending on the facts, materiality, and contract terms — this is why accuracy matters.

6

Submit to SPRS and Retain Evidence

Enter your score and affirmation in the Supplier Performance Risk System. Then preserve your evidence — assessment artifacts must be retained for six years from the CMMC Status Date. Screen captures, configuration exports, policy documents, access logs, and your scoping documentation all need to be preserved. While Level 1 does not require submitting a formal SSP to DoD, you should maintain documentation (often including an SSP or equivalent) to support your scope, evidence, and any exceptions.

Common Pitfalls — What an RP Catches That You Might Miss

After reviewing dozens of Level 1 self-assessments, these are the patterns we see most often. Every one of these can turn a "15/15" self-assessment into an inaccurate attestation.

Confusing 'Documented' with 'Implemented'

Having a policy that says you do something is not the same as evidence that you actually do it. Assessment objectives test implementation, not documentation. Your access control policy says you limit access to authorized users — great. Can you show me the access list, demonstrate how access is provisioned, and prove that terminated users are removed promptly?

Under-Scoping the FCI Boundary

Contractors often miss shared drives, email systems, or personal devices that touch FCI. If FCI flows through it, it's in scope. That personal laptop your project manager uses to review contract documents at home? In scope. The shared Dropbox folder where specs get uploaded? In scope.

Treating Level 1 as an IT Checklist

Physical protection (PE) controls cover physical spaces, not just digital systems. If unauthorized persons can walk past workstations where FCI is displayed, or access storage areas where FCI documents are kept, you have a gap — regardless of how strong your network security is.

Not Preparing Evidence Artifacts (or Not Retaining Them)

Level 1 does not require submitting a formal SSP to DoD, but you must maintain clear scope and evidence documentation and retain assessment artifacts for six years from the CMMC Status Date. Screen captures, configuration exports, policy documents, access logs — these are your proof, and they must be preserved. This 6-year retention requirement is explicit in the rule and is one of the most common compliance oversights we see.

Forgetting the Annual Cycle

Self-assessment isn't one-and-done. You must re-affirm annually following the Final status date. If your environment changes — new systems, new personnel, new locations handling FCI — those changes must be reflected in your assessment before your next affirmation.

RP Practitioner Insight

"The most common thing I see: a contractor scores themselves 15/15, but when I walk through the assessment objectives, we find 3-4 practices where the evidence doesn't fully support the 'MET' determination. That's not a technicality — an inaccurate affirmation can create real compliance risk. The gap between 'we think we're compliant' and 'we can demonstrate compliance' is where an RP adds the most value."

Level 1 as Your Foundation — What Comes Next

Level 1 is the starting point, not the destination. A solid Level 1 posture builds the security foundation that makes the jump to Level 2 manageable — many Level 1 controls are foundational to the 110 controls required at Level 2.

If Your Contracts Evolve

If you begin handling Controlled Unclassified Information (CUI), you'll need Level 2 — which requires all 110 controls from NIST SP 800-171 Rev. 2 and a C3PAO third-party assessment. Phase 2 expands certification requirements for applicable solicitations and contracts starting November 2026.

The vCISO Advantage

The organizations that are most successful with CMMC treat compliance as an ongoing posture, not a one-time project. A virtual CISO provides ongoing compliance leadership without full-time overhead — maintaining your Level 1 status, preparing for Level 2 when needed, and ensuring your security posture evolves with the threat landscape.

Frequently Asked Questions

A CMMC Level 1 self-assessment is an annual evaluation of your organization's implementation of 15 security requirements from FAR 52.204-21, required for defense contractors handling Federal Contract Information (FCI) under applicable DoD solicitations and contracts. Each requirement is scored MET or NOT MET with no POA&Ms allowed. Your affirming official must attest that all 15 requirements are MET in SPRS to achieve Final Level 1 (Self) status.

CMMC Level 1 requires implementing 15 security requirements across 6 control families: Access Control (4 practices), Identification & Authentication (2), Media Protection (1), Physical Protection (4), System & Communications Protection (2), and System & Information Integrity (4). The official Level 1 Assessment Guide breaks these into 59 determination statements (assessment objectives) that must each be satisfied.

No. CMMC Level 1 does not permit Plans of Action and Milestones (POA&Ms). Each of the 15 requirements must be scored MET or NOT MET, and all 15 must be MET to achieve Final Level 1 (Self) status. There is no partial credit — unlike Level 2, which allows limited POA&Ms for certain controls.

CMMC Level 1 self-assessment results must be recorded in SPRS annually, accompanied by an affirmation from the affirming official. Reaffirmation is required annually following the Final status date. If your environment changes significantly between annual assessments, you should reassess to ensure continued compliance.

Level 1 is a self-assessment, so an RP is not required. However, an RP can independently validate your control implementations against the 59 assessment objectives, identify gaps you may have overlooked, and give your affirming official confidence that the attestation is accurate — which matters given the potential False Claims Act implications of misrepresentation.

Free CMMC L1 Readiness Review

Level 1 self-assessment is more rigorous than most contractors expect. 59 assessment objectives demand real evidence, artifacts must be retained for six years, and your affirming official's attestation carries real compliance risk. Our RP-credentialed team will walk through your 15 controls and tell you exactly where you stand before your next affirmation.