CMMC Level 1 (Foundational)
CMMC Level 1, called the 'Foundational' level, is the entry point of the Cybersecurity Maturity Model Certification framework used across the defense industrial base. It is generally aimed at contractors and subcontractors that work with the Department of Defense and handle Federal Contract Information (FCI). It establishes basic cybersecurity expectations rather than the more extensive requirements found at higher CMMC levels.
CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, generally applicable to organizations in the defense industrial base that process, store, or transmit Federal Contract Information (FCI). Based on the evidence, Level 1 is commonly described as comprising the 15 basic safeguarding requirements drawn from FAR clause 52.204-21, and it should not be conflated with the 110 controls of NIST SP 800-171, which are associated with CMMC Level 2. Readers should note that CMMC has undergone phased rollout and revisions, and that scope, assessment methodology, and self-assessment versus third-party requirements differ by level; the specific applicable requirements, effective dates, and clause citations should be verified against the current authoritative DoD and CMMC program text.
Why it matters
CMMC Level 1 matters because it sets the minimum cybersecurity bar for the large population of contractors and subcontractors across the defense industrial base (DIB) that handle Federal Contract Information (FCI). Because FCI is common in routine DoD contracting relationships, Level 1 reaches organizations that may never touch Controlled Unclassified Information (CUI) but still participate in DoD supply chains. Understanding where an organization falls within the CMMC framework is a prerequisite to determining what obligations actually apply, since requirements, scope, and assessment methods differ meaningfully by level.
A frequent and consequential mistake is conflating Level 1 with Level 2. Level 1 is generally described as the 15 basic safeguarding requirements drawn from FAR clause 52.204-21, while the 110 controls associated with NIST SP 800-171 belong to Level 2. Treating Level 1 as if it required the full NIST SP 800-171 control set can lead an organization to over-scope its program, while the reverse error can leave a contractor handling CUI dangerously under-prepared. Compliance officers and ISSMs should confirm the data types their organization handles before assuming which level applies.
Readers should also keep in mind that CMMC has undergone a phased rollout and revisions, and that compliance is not a permanent or one-time achievement. Meeting a baseline set of safeguarding requirements is not the same as being secure, and it does not by itself satisfy obligations tied to other frameworks or contract clauses. The specific applicable requirements, effective dates, self-assessment versus third-party expectations, and clause citations should always be verified against the current authoritative DoD and CMMC program text rather than relied upon from secondary summaries.
Who it's relevant to
Inside CMMC L1
Common questions
Answers to the questions practitioners most commonly ask about CMMC L1.