CMMC Level 1 requirements

The 15 safeguards required for CMMC Level 1.

CMMC Level 1 uses the 15 basic safeguarding requirements in FAR 52.204-21 to protect Federal Contract Information (FCI) on covered contractor information systems. The annual self-assessment evaluates whether each applicable requirement is implemented. Level 1 does not permit a POA&M, so all 15 requirements must be MET for a Final Level 1 status.

How to use this page

The summaries below track the 15 safeguards in FAR 52.204-21. The evidence examples are practical illustrations, not additional regulatory requirements. Your evidence should reflect how your own environment implements each safeguard.

Access control

Requirements 1–4: control who and what can access FCI.

1. Allow access only to authorized users, processes, and devices

Requirement: Restrict system access to approved users, approved processes acting for those users, and approved devices or systems.

Evidence examples: user and device inventories, account approvals, endpoint enrollment records, access-control settings, and account review records.

2. Limit users to authorized transactions and functions

Requirement: Authorized users should be able to perform only the functions and transactions their roles require.

Evidence examples: role assignments, group memberships, permissions, privileged-access records, and screenshots or exports showing access restrictions.

3. Control connections to external information systems

Requirement: Verify and control connections to, and use of, external systems before allowing them to interact with the covered contractor information system.

Evidence examples: approved remote-access methods, firewall or network rules, device-management restrictions, VPN configuration, and procedures for external-system use.

4. Control information placed on public systems

Requirement: Prevent FCI from being posted or processed on publicly accessible systems unless it is authorized for public release.

Evidence examples: website publishing procedures, content approval steps, public-sharing restrictions, and periodic reviews of externally accessible content.

Identification and authentication

Requirements 5–6: identify and authenticate access.

5. Identify users, processes, and devices

Requirement: Establish identifiable users, processes acting on behalf of users, and devices before they interact with organizational systems.

Evidence examples: unique user accounts, device identities, asset records, service-account inventories, and account lifecycle documentation.

6. Authenticate identities before granting access

Requirement: Verify the identity of a user, process, or device before allowing access to the system.

Evidence examples: authentication settings, password controls, MFA where used, device authentication, and identity-provider configuration.

Media and physical protection

Requirements 7–9: protect FCI when media or physical access is involved.

7. Sanitize or destroy media before disposal or reuse

Requirement: Remove FCI from system media before the media is discarded or released for reuse.

Evidence examples: media-sanitization procedures, destruction records, disposal receipts, device-wipe records, and reuse checklists.

8. Limit physical access to authorized individuals

Requirement: Restrict physical access to systems, equipment, and their operating environments to authorized personnel.

Evidence examples: office access controls, badge or key assignments, locked equipment areas, authorized-personnel lists, and physical-security procedures.

9. Control visitors and physical access devices

Requirement: Escort and monitor visitors, maintain records of physical access, and control physical access devices such as badges, keys, or similar mechanisms.

Evidence examples: visitor logs, escort procedures, badge inventories, key-control records, and access-log retention.

Network and communications protection

Requirements 10–11: protect system boundaries and public-facing components.

10. Monitor, control, and protect communications at system boundaries

Requirement: Protect information entering or leaving the system at external boundaries and important internal boundaries.

Evidence examples: firewall configuration, network diagrams, security-gateway settings, traffic-monitoring records, and boundary-protection procedures.

11. Separate public-facing components from internal networks

Requirement: Place publicly accessible system components in physically or logically separated network segments rather than directly on internal networks.

Evidence examples: network segmentation diagrams, VLAN or subnet configuration, cloud network-security rules, reverse-proxy architecture, and firewall rules.

System integrity

Requirements 12–15: correct flaws, block malicious code, and scan systems.

12. Identify, report, and correct system flaws promptly

Requirement: Find security flaws, report them through the appropriate process, and correct them in a timely manner.

Evidence examples: patch-management records, vulnerability findings, remediation tickets, update reports, and documented remediation timeframes.

13. Protect systems from malicious code

Requirement: Deploy malicious-code protection at appropriate locations within organizational systems.

Evidence examples: endpoint protection or anti-malware deployment reports, policy configuration, coverage reports, and alerting records.

14. Keep malicious-code protection current

Requirement: Update malicious-code protection mechanisms when new releases, signatures, or protection updates are available.

Evidence examples: update policies, endpoint-management reports, security-tool dashboards, and records showing current protection versions.

15. Perform periodic system scans and scan external files in real time

Requirement: Periodically scan the information system and scan files from external sources when they are downloaded, opened, or executed.

Evidence examples: scheduled scan configuration, scan reports, endpoint-protection settings, email or web security controls, and remediation records for detected threats.

Level 1 assesses implementation, not documentation alone.

Policies and procedures can document the intended process, but the annual self-assessment evaluates whether the safeguards are implemented in the systems that process, store, or transmit FCI. Cyberneza can identify the Level 1 boundary, evaluate each safeguard, remediate implementation gaps, and organize the evidence your organization will rely on when it performs and affirms the assessment.

Need to evaluate all 15 requirements against your environment?

Cyberneza can review the FCI boundary, assess each FAR 52.204-21 safeguard against the systems and procedures you use, identify specific gaps, and prepare a remediation and evidence plan for your Level 1 self-assessment.