Skip to main content
Category: CMMC & DIB Assessment

CMMC Level 1 (Foundational)

Also known as: CMMC L1, CMMC Level 1, Foundational Level, Level 1 (Foundational)
Simply put

CMMC Level 1, called the 'Foundational' level, is the entry point of the Cybersecurity Maturity Model Certification framework used across the defense industrial base. It is generally aimed at contractors and subcontractors that work with the Department of Defense and handle Federal Contract Information (FCI). It establishes basic cybersecurity expectations rather than the more extensive requirements found at higher CMMC levels.

Formal definition

CMMC Level 1 is the foundational tier of the Cybersecurity Maturity Model Certification, generally applicable to organizations in the defense industrial base that process, store, or transmit Federal Contract Information (FCI). Based on the evidence, Level 1 is commonly described as comprising the 15 basic safeguarding requirements drawn from FAR clause 52.204-21, and it should not be conflated with the 110 controls of NIST SP 800-171, which are associated with CMMC Level 2. Readers should note that CMMC has undergone phased rollout and revisions, and that scope, assessment methodology, and self-assessment versus third-party requirements differ by level; the specific applicable requirements, effective dates, and clause citations should be verified against the current authoritative DoD and CMMC program text.

Why it matters

CMMC Level 1 matters because it sets the minimum cybersecurity bar for the large population of contractors and subcontractors across the defense industrial base (DIB) that handle Federal Contract Information (FCI). Because FCI is common in routine DoD contracting relationships, Level 1 reaches organizations that may never touch Controlled Unclassified Information (CUI) but still participate in DoD supply chains. Understanding where an organization falls within the CMMC framework is a prerequisite to determining what obligations actually apply, since requirements, scope, and assessment methods differ meaningfully by level.

A frequent and consequential mistake is conflating Level 1 with Level 2. Level 1 is generally described as the 15 basic safeguarding requirements drawn from FAR clause 52.204-21, while the 110 controls associated with NIST SP 800-171 belong to Level 2. Treating Level 1 as if it required the full NIST SP 800-171 control set can lead an organization to over-scope its program, while the reverse error can leave a contractor handling CUI dangerously under-prepared. Compliance officers and ISSMs should confirm the data types their organization handles before assuming which level applies.

Readers should also keep in mind that CMMC has undergone a phased rollout and revisions, and that compliance is not a permanent or one-time achievement. Meeting a baseline set of safeguarding requirements is not the same as being secure, and it does not by itself satisfy obligations tied to other frameworks or contract clauses. The specific applicable requirements, effective dates, self-assessment versus third-party expectations, and clause citations should always be verified against the current authoritative DoD and CMMC program text rather than relied upon from secondary summaries.

Who it's relevant to

DoD Contractors and Subcontractors Handling FCI
Organizations in the defense industrial base that process, store, or transmit Federal Contract Information are the primary audience for CMMC Level 1. Even contractors that do not handle CUI may fall within Level 1's scope because FCI is common across routine DoD contracting relationships. These organizations should confirm the data types they handle to verify whether Level 1, rather than a higher level, applies to them.
Compliance Officers and ISSMs
Those responsible for building and documenting a contractor's compliance program need to distinguish Level 1's basic safeguarding requirements from the more extensive requirements at higher levels. Correctly scoping the program prevents both over-scoping to the full NIST SP 800-171 control set and under-preparing when CUI is actually in play. They should verify the current applicable requirements and assessment expectations against authoritative DoD and CMMC program text.
Prime Contractors Managing Supply Chains
Primes that flow requirements down to subcontractors need to understand where Level 1 applies within their supply chain so that they can set appropriate expectations for lower-tier suppliers that handle FCI. Because assessment methodology and self-assessment versus third-party requirements can differ by level, primes should confirm the current obligations rather than assuming uniform treatment across all suppliers.
Assessors and Advisors
Professionals who assess or advise DIB organizations must accurately map Level 1 to the basic safeguarding requirements associated with FAR clause 52.204-21 and avoid conflating it with the 110 NIST SP 800-171 controls tied to Level 2. Given CMMC's phased rollout and revisions, they should anchor their guidance to the current authoritative program text and note that compliance is time-bound and distinct from security.

Inside CMMC L1

Foundational Cybersecurity Requirements
CMMC Level 1 corresponds to the basic safeguarding requirements generally associated with protecting Federal Contract Information (FCI) rather than Controlled Unclassified Information (CUI). Contractors and subcontractors should confirm the specific practices and their current mapping against the authoritative CMMC program text and the applicable DFARS provisions, because these can change across revisions of the program.
Scope Tied to Federal Contract Information (FCI)
Level 1 is generally intended for organizations that handle FCI, which is information provided by or generated for the Government under a contract that is not intended for public release. It is distinct from the higher CMMC levels associated with CUI protection, which draw on a broader control set.
Self-Assessment Approach
In most implementations as described in the phased CMMC model, Level 1 relies on an annual self-assessment by the contractor rather than a third-party assessment. Practitioners should verify the current assessment cadence and affirmation requirements against the governing CMMC rule text, as these details have evolved during the program's phased rollout.
Relationship to Underlying Safeguarding Standard
The Level 1 practices are generally aligned with the basic safeguarding of covered contractor information systems referenced in federal acquisition and DFARS provisions. The alignment and exact practice list should be confirmed against the applicable revision of the official CMMC materials rather than assumed to be static.

Common questions

Answers to the questions practitioners most commonly ask about CMMC L1.

Does achieving CMMC Level 1 mean my systems are secure?
No. CMMC Level 1 (Foundational) reflects the implementation of a foundational set of safeguarding practices, but compliance is not the same as security. Meeting Level 1 requirements demonstrates that a defined baseline of practices is in place; it does not guarantee protection against all threats, nor does it substitute for ongoing risk management. Treat Level 1 as a floor for safeguarding Federal Contract Information (FCI), not as evidence of a comprehensively secure environment.
Does a CMMC Level 1 status stay valid indefinitely once I attain it?
No status should be treated as permanent. CMMC assessments and self-assessments are point-in-time determinations tied to the scope and system state at the time of the assessment. As of the applicable CMMC program requirements, Level 1 generally involves a recurring self-assessment and an associated affirmation rather than a one-time achievement. Changes to your environment, scope, or the handling of Federal Contract Information can affect your status, so you should verify current recurrence and affirmation requirements against the official CMMC program text.
How is CMMC Level 1 typically assessed?
In most implementations, Level 1 is addressed through a self-assessment performed by the contractor rather than a third-party assessment. This differs from higher levels, which may require assessment by a third party. Because assessment approaches and affirmation mechanisms have evolved across the phased rollout and revisions of CMMC, confirm the current self-assessment and affirmation process against the authoritative CMMC program documentation before relying on it.
What type of information is CMMC Level 1 intended to protect?
Level 1 (Foundational) is generally oriented toward safeguarding Federal Contract Information (FCI), which is distinct from Controlled Unclassified Information (CUI). Protecting CUI is generally associated with higher CMMC levels. Determining which information types you actually handle is essential to identifying the correct level; where CUI is involved, Level 1 alone is generally not sufficient. Confirm the applicable definitions and scoping against current official sources.
How do I determine what falls within the scope of a Level 1 assessment?
Scoping generally focuses on the assets that process, store, or transmit Federal Contract Information. Accurately identifying that boundary is a prerequisite step, because the assessment applies to the in-scope environment rather than to your entire enterprise by default. Scoping guidance is issued as part of the CMMC program materials and has been subject to revision, so you should apply the current official scoping guidance and document your boundary determinations rather than assuming a fixed interpretation.
Does meeting CMMC Level 1 satisfy other DoD or federal contractual cybersecurity obligations?
Not necessarily. CMMC Level 1 addresses a foundational set of safeguarding practices, but it does not automatically satisfy other requirements that may apply through separate contract clauses or federal frameworks. Obligations can differ depending on the information involved and the specific contract terms. Because contractual, implementation, and legal specifics are out of scope here, you should confirm which requirements apply to your contracts against the current authoritative regulatory and contractual text.

Common misconceptions

CMMC Level 1 covers the protection of Controlled Unclassified Information (CUI).
Level 1 is generally oriented toward Federal Contract Information (FCI), not CUI. Protection of CUI is associated with higher CMMC levels and a broader control set. Readers should confirm the applicable scope for their contract against current authoritative CMMC and DFARS text.
Level 1 requires a third-party assessment like the higher levels.
In most implementations of the phased CMMC model, Level 1 relies on a self-assessment rather than an assessment by an external assessment organization. The assessment method, cadence, and any affirmation obligations should be verified against the current CMMC rule, since these have changed during the rollout.
Meeting CMMC Level 1 means an organization is fully secure or compliant across all applicable requirements.
Compliance with a foundational level is not the same as being secure, and it does not automatically satisfy other obligations that may apply to a contractor, such as higher-level CUI protections or separate contractual and regulatory requirements. Organizations should treat Level 1 as a baseline and confirm all applicable obligations against current official sources.

Best practices

Confirm whether your contract involves Federal Contract Information (FCI) versus Controlled Unclassified Information (CUI) before assuming Level 1 is the applicable tier, since CUI generally drives a higher level.
Verify the current Level 1 practice list, self-assessment cadence, and any affirmation requirements against the governing CMMC program text and applicable DFARS provisions, as these have evolved through the phased rollout.
Define and document the assessment boundary so it is clear which systems handle FCI and are therefore in scope for Level 1 self-assessment.
Retain evidence and documentation supporting your self-assessment so it can be produced if the affirmation or self-attestation is later reviewed.
Do not treat a Level 1 self-assessment as equivalent to being fully secure or as satisfying higher-level or separate contractual and regulatory obligations; identify and track those separately.
Re-verify status on the required periodic basis rather than treating a single self-assessment as permanent, and consult current official CMMC sources whenever the program is revised.