[ LEVEL 1 READY ]All guides

GUIDE · CMMC LEVEL 1

The 15 CMMC Level 1 requirements, explained for small shops

A machinist in a small, cluttered industrial workshop
The shop these 15 requirements were written for - not an enterprise security team. Photo by Zoshua Colah on Unsplash

If you supply a prime or hold DoD contracts and someone just told you that you need "CMMC Level 1," here's the short version: you're required to self-assess against 15 basic safeguarding requirements (seen 17 quoted somewhere? that's the old count - here's why it's 15 now), submit the result to a government system called SPRS, and have a senior official legally affirm it - every year. The 15 requirements come from a federal contract clause, FAR 52.204-21, and they've been sitting in contracts since 2016. What changed is enforcement: since November 2025, CMMC has been phasing into DoD contracts, and primes have started refusing subcontractors who can't show a posture.

This guide walks all 15 in plain English, with what each one actually looks like in a small shop - a machine shop, an engineering firm, a logistics outfit with a dozen people and no in-house IT (plenty of these shops lean on an outside IT provider for part of it). That's who Level 1 was written for, even if it doesn't read that way. Your whole CMMC Level 1 self-assessment comes down to these 15 - an honest yes or no on each, a score, and the evidence to back it.

First, a 60-second scoping check

Level 1 applies if you handle Federal Contract Information (FCI) - drawings, specs, POs, quotes, contract emails - information provided by or generated for the government that isn't public. If you handle Controlled Unclassified Information (CUI), or your contracts include DFARS 252.204-7012, you're in Level 2 territory: 110 requirements, a different process, and nothing below covers you. Rough shorthand: most build-to-print shops are Level 1; shops receiving export-controlled or specifically marked technical data are usually Level 2. When in doubt, ask your prime - or, if you contract directly, your contracting officer - which clause is in your contract.

One more thing worth getting straight before the 15: Level 1 is scoped by system, not by headcount. The clause protects any information system that processes, stores, or transmits FCI, plus the facility around it - not just the handful of people who touch the files. Only 4 of the 15 requirements (1, 2, 5, and 6) are about users; the other 11 apply to your systems and building whether two people touch FCI or twenty. If you've been assuming "it's just the office manager and me, so we're basically out of scope," that's the assumption to drop. The full breakdown is here: what's actually in scope for Level 1 - systems, not headcount.

The 15 requirements, translated

FAR 52.204-21(b)(1)(i)1. Limit access to authorized users

Only your employees and specifically approved outsiders can get into systems holding FCI. In practice: you can name every person with access, and nobody's ex-employee login still works.

(b)(1)(ii)2. Limit access to what the job needs

The shop floor doesn't need the accounting folder; the bookkeeper doesn't need released drawings. Windows folder permissions handle this. The common gap: one file server, everyone can open everything.

(b)(1)(iii)3. Verify and control external connections

Customer portals, your accountant's remote QuickBooks access, the IT guy's remote tool - each connection into your systems should be known, written down, and approved. The requirement isn't zero connections; it's zero mystery connections.

(b)(1)(iv)4. Control what goes public

Nothing from a contract - drawings, part photos with customer info, PO details - gets posted to your website or social media. A simple owner-reviews-first habit meets this.

(b)(1)(v)5. Identify users and devices

Every person has their own account. The shared login on the shop-floor PC is the single most common Level 1 failure in small shops, and it fails this requirement and the next one at the same time.

(b)(1)(vi)6. Authenticate before access

Passwords on everything, no sharing, and multi-factor authentication wherever it's offered - it's free with Microsoft 365 and Google Workspace. Default passwords on routers and equipment get changed.

(b)(1)(vii)7. Sanitize media before disposal or reuse

That pile of retired towers in the storage room? Every drive in it potentially holds FCI. Wipe or physically destroy drives before computers are sold, donated, or trashed, shred the paper, and keep a one-line log per item. Cheap, fast, and almost nobody does it until they're asked.

(b)(1)(viii)8. Limit physical access

Locked doors, keys held by known people. Most shops already meet this - the evidence is just a key list.

(b)(1)(ix)9. Escort visitors and keep logs

A sign-in sheet at the front desk and a habit of walking visitors through the shop instead of letting them wander. The cheapest fix on the entire list, and one of the most commonly missing.

(b)(1)(x)10. Control the boundary with the internet

A firewall you actually manage - meaning you can log into it, you set its admin password, and remote administration is off. An ISP router on factory settings that nobody's ever logged into doesn't count as "monitoring and controlling."

(b)(1)(xi)11. Separate public systems from internal ones

Your website shouldn't live on the same network as your FCI. If it's hosted externally (Squarespace, Wix, WordPress hosting), you likely meet this already.

(b)(1)(xii)12. Fix flaws in a timely way

Security updates get installed - including on the server everyone forgets. Auto-update on workstations plus a monthly 30-minute patch-and-restart routine on the server, logged one line per month, covers it.

(b)(1)(xiii) and (xiv)13 and 14. Malware protection, kept current

Antivirus on every machine with automatic updates. Microsoft Defender, already in Windows, satisfies both when it's on and updating - the evidence is a quarterly screenshot of its status page.

(b)(1)(xv)15. Scan periodically and in real time

Real-time scanning of downloads and email attachments, plus scheduled full scans that someone actually confirms ran. Defender does both; the gap is usually that nobody's ever looked at the scan history.

Reading these and mentally ticking boxes? You can get an actual read in about three minutes - the free 5-question check samples these 15 and tells you where you'd stand today, no email to start.

The two rules people learn the hard way

There's no partial credit. Level 1 is pass/fail per requirement, and pass/fail overall - all 15 met, or you can't affirm. "Mostly" is a gap. Plans of Action and Milestones (POA&Ms) aren't allowed at Level 1 the way they are at Level 2.

And the affirmation is a legal statement. Your result goes into SPRS with a senior official's affirmation, renewed annually - and misrepresenting it carries False Claims Act exposure. Companies have already faced multi-million-dollar settlements over misrepresented cybersecurity compliance. The honest path: assess truthfully, fix the gaps, keep evidence (the DoD expectation is six years), and only then affirm.

The encouraging part: for most 5-50 person companies, closing the gaps that trip up most shops costs almost nothing but a few weekends. Individual logins, MFA, a sign-in sheet, a wipe log, a managed router, a monthly patch habit. The requirements were designed as basic hygiene, and basic is genuinely what they are - once someone translates them off the federal register page.

Where does your shop stand right now?

Five yes/no questions, instant grade, no email required. Know before you're asked.

Take the free 5-question check