[ LEVEL 1 READY ]All guides

GUIDE · SETTING THE RECORD STRAIGHT

CMMC Level 1: is it 17 requirements or 15?

Two similar documents side by side on a desk, suggesting comparison
Same requirements, two different counts - here is why. Photo by Dimitri Karastelev on Unsplash

Search "CMMC Level 1 requirements" and you'll hit a wall of contradiction. One page says 17 practices. The next says 15. A third splits the difference or doesn't mention a number at all. If you're a shop owner trying to figure out what you actually have to do, this is maddening - are there two requirements you're somehow missing, or are half these sources just wrong?

Here's the answer, and it's simpler than the confusion suggests: it's 15. The sources saying 17 aren't lying - they're describing an earlier version of the framework that the U.S. Department of Defense (DoD) has since consolidated. This guide explains what changed, why so many pages still show the old number, and why none of it changes what you actually need to do.

The short version

CMMC Level 1 maps to the safeguarding requirements in FAR 52.204-21, the federal contract clause that's been around since 2016. Early CMMC materials - including some the DoD itself published during the program's draft years - counted those safeguards as 17 practices. When CMMC was finalized in the 32 CFR Part 170 rule, the requirements were consolidated and expressed as 15. Same underlying protections, regrouped and renumbered. Nothing was removed from what you're obligated to do; two pairs of closely related practices were folded together.

If a source says 17, it's citing pre-final CMMC material. If it says 15, it's citing the finalized rule and current FAR clause. For anything you're basing real decisions on, 15 is the number that matches what a prime or an assessor will hold you to today.

Why the internet still says 17

Three reasons, and they're worth knowing because they tell you something about which sources to trust generally:

Old content ranks. A detailed compliance guide published in 2024 that said "17 practices" was correct when it was written, still ranks well on Google, and nobody went back to renumber it. Search rewards age and authority, so stale-but-established pages sit at the top of results long after the facts moved.

Some sources conflate Level 1 with NIST counts. A few guides describe the 17 as coming "from NIST SP 800-171," borrowing the framing used for Level 2. Level 1's requirements come from the FAR clause, not the full 800-171 catalog - the crossed wires produce a number that doesn't match the current rule.

A department renaming adds noise. You'll see some 2025-2026 sources refer to the Department by a newer name - a change that rippled through federal documentation - which signals a page was updated recently, but recency of the label doesn't guarantee recency of the requirement count. Plenty of freshly-edited pages still carry the old 17.

What actually got consolidated

You don't need to memorize the crosswalk, but seeing it kills the "am I missing two requirements?" anxiety for good. The consolidation grouped practices that were always meant to be done together:

WHAT THE OLD 17 SPLIT OUTHOW THE 15 GROUP IT
Separate practices for identifying users and identifying devices/processesHandled together under the identification requirement - you were always going to solve them the same way (individual accounts)
Separate malware practices for protection and for keeping it updated, counted as distinct line itemsExpressed as the malware-protection requirements without inflating the total - antivirus that's on and updating satisfies both

In plain terms: nothing left the list. The work is identical. A shop that meets the 15 met the 17, and vice versa. The renumbering was housekeeping, not a policy change - which is exactly why it's safe to ignore the discrepancy once you know its source.

Since the number doesn't change the work, the real question is where you stand on the 15. The free 5-question check gives you a read in about three minutes, no email to start.

The tell that separates current sources from stale ones

Since you'll keep running into both numbers, here's a quick filter. A source describing Level 1 today should get three things right: 15 requirements, tied to FAR 52.204-21, under the 32 CFR Part 170 rule that finalized CMMC. It should also know that Level 1 is a self-assessment - no third-party assessor - and that the result goes into SPRS with an annual affirmation. A page that nails those details is current. A page still selling you "17 NIST controls with a required third-party audit" is describing a version of CMMC that no longer exists, and you should weigh its other claims accordingly.

This matters beyond trivia. If you're building a compliance posture off a stale guide, you're not just counting wrong - you may be preparing for a certification process (third-party audit, a 110-control scope) that doesn't apply to you, spending money and weekends solving a Level 2 problem you don't have. The requirement count is the canary. When it's wrong, check everything else on the page.

So what do you actually do with this?

Work the 15. They're the current, correct, complete list, and we've translated every one into plain shop-floor English in our 15 requirements guide - what each means, where the common gaps hide, and the two rules that trip people up. If you're still not sure whether Level 1 is even your level, the Level 1 vs Level 2 guide runs the ten-minute clause test that settles it. Either way, you can stop worrying about the missing two. There aren't any.

Where does your shop stand right now?

Five yes/no questions, instant grade, no email required. Know before you're asked.

Take the free 5-question check