APTSecurity Management

The 15 CMMC Level 1 Requirements in Plain English

Cody D. Martin//Updated August 9, 2026

CMMC Level 1 covers 15 basic safeguarding requirements drawn from FAR 52.204-21, handled by annual self assessment. They cover access control, media protection, physical security, system integrity and basic network protection for systems handling Federal Contract Information.

If you handle Federal Contract Information and no CUI, Level 1 is your path. Fifteen requirements, drawn from FAR 52.204-21, confirmed by annual self assessment rather than a third party audit.

They are genuinely basic. Most companies already do ten of them and have never written it down, which is the actual work.

Access control

1. Limit system access to authorised users. Every account belongs to a person, and people who have left do not have accounts.

2. Limit access to the types of transactions users are authorised to perform. Not everyone is an administrator. The failure here is universal small company practice: everyone has local admin because it was easier.

3. Verify and control connections to external systems. Know what connects outward. Cloud services, remote access, partner connections.

4. Control information posted on publicly accessible systems. Nobody posts FCI to the website or a public repository. This one is worth an actual check, because public repositories are where it usually happens.

Identification and authentication

5. Identify system users and devices. Individual accounts, not shared ones. A shared office login fails this and makes everything after it unprovable.

6. Authenticate identities before granting access. Passwords, and multifactor where you can. MFA is not strictly required at Level 1, and skipping it in 2026 is still a bad decision.

Media protection

7. Sanitise or destroy media before disposal or reuse. Wipe drives, shred paper. Write down what the process is.

Physical protection

8. Limit physical access to systems and equipment. Locked doors, locked server cupboard.

9. Escort visitors and monitor visitor activity. A sign in sheet counts.

10. Maintain audit logs of physical access. The same sign in sheet, kept.

11. Control and manage physical access devices. Know who has keys and badges, and collect them when someone leaves.

System and communications protection

12. Monitor and control communications at system boundaries. A firewall, configured, with someone who could explain the rules.

13. Implement subnetworks for publicly accessible components. Public facing systems separated from internal ones. A DMZ, or the cloud equivalent.

System and information integrity

14. Identify, report and correct system flaws in a timely manner. Patching, with some definition of timely that you actually meet.

15. Provide protection from malicious code, and update it. Endpoint protection, deployed everywhere and current. Coverage numbers reported against known assets are not the same as coverage against all assets.

What people get wrong

Shared accounts. They break requirements 1, 5 and 6 at once, and they make every access claim unprovable.

Local administrator everywhere. Fails requirement 2, and it is the single most common finding.

No written record. Doing the thing is not enough. Self attestation means a company official signs that these are in place, so there needs to be something to point at.

Assuming Level 1 because nobody mentioned CUI. Read the contract. If DFARS 252.204-7012 appears, you handle CUI and Level 1 is not your path.

What happens next

Self assess against these fifteen, score yourself in SPRS, and affirm annually. A senior company official signs it, which is worth remembering when deciding how generous to be with the assessment.

  • CMMC
  • FAR 52.204-21
  • FCI
  • Level 1

More on compliance