5.2 Level 1: 15 FAR Safeguarding Requirements & Annual Self-Assessment
Key Takeaways
- Level 1 has 15 FAR 52.204-21 security requirements; the assessment mapping contains 17 NIST rows because one PE requirement is split into three phrases.
- The scope includes assets that process, store, or transmit FCI and the people, technology, and facilities that protect them.
- The organization performs the assessment annually and records the result and affirmation in SPRS.
- Every applicable Level 1 requirement must be MET; POA&Ms and conditional status are not permitted.
- Level 1 is not a selectable C3PAO certification-assessment pathway.
5.2 Level 1: 15 FAR Safeguarding Requirements & Annual Self-Assessment
CMMC Level 1 protects Federal Contract Information (FCI) on contractor information systems. The current model uses the 15 basic safeguarding requirements in FAR 52.204-21. Earlier CMMC versions subdivided some safeguards and produced a 17-practice count; do not use that number for the current rule or exam.
Six families and fifteen requirements
| Family | Count | Core duties |
|---|---|---|
| Access Control | 4 | Limit access to authorized users and functions; verify external connections; control information on public systems |
| Identification and Authentication | 2 | Identify and authenticate users, processes acting for users, and devices |
| Media Protection | 1 | Sanitize or destroy media before disposal or release for reuse |
| Physical Protection | 2 | Limit physical access; the second requirement combines escort/monitoring, access logs, and access-device management |
| System and Communications Protection | 2 | Protect external and key internal boundaries; separate publicly accessible components |
| System and Information Integrity | 4 | Correct flaws; protect against malicious code; update protection; perform periodic and real-time scans as specified |
The rule numbers Level 1 from FAR paragraphs (b)(1)(i) through (xv). Section 170.15 then maps those 15 requirements to NIST SP 800-171A objectives. The mapping table has 17 rows because the three phrases in the second PE requirement map separately to NIST 3.10.3, 3.10.4, and 3.10.5. Do not convert those mapped rows into 17 security requirements.
FCI scope
FCI is nonpublic information provided by or generated for the government under a contract to develop or deliver a product or service, excluding public information and simple transactional information such as payment processing. The contract and FAR definition control.
The Level 1 assessment scope includes contractor assets that process, store, or transmit FCI. Scoping also considers the people, technologies, and facilities that provide protection. Assets without FCI can be outside the assessment scope when they do not provide protection to FCI assets and are physically or logically separated according to the Level 1 Scoping Guide.
Level 1 does not use the five formal Level 2 asset categories as if they were interchangeable. The underlying boundary questions still matter: where does FCI enter, move, reside, and leave; who can access it; which services protect it; and what separates other assets?
Annual self-assessment
The organization conducts the Level 1 self-assessment annually. It evaluates each requirement using the current Level 1 Assessment Guide and the available Examine, Interview, and Test procedures appropriate to the objective. Evidence must reflect the in-scope environment rather than a generic policy or an unverified vendor assertion.
The result is recorded in the Supplier Performance Risk System. The Affirming Official submits an affirmation at completion and as required by 32 CFR §170.22. The contractor is accountable for accuracy even when a consultant helps collect evidence.
There is no optional C3PAO Level 1 certification assessment in the program architecture. A third party can assist with readiness or an internal review, but that service does not change the official self-assessment type or transfer the affirmation.
All-or-nothing outcome
All 15 requirements must be MET. Level 1 does not use the Level 2 weighted score, conditional status, or a POA&M. If physical-access logs are not maintained as required, the organization cannot declare a passing Level 1 result merely because the other 14 requirements are satisfied. It remediates the deficiency, verifies implementation, and completes an accurate assessment.
Assessment objectives break a requirement into determinations. Every applicable objective must be satisfied for the requirement to be MET. One document may be relevant, but evidence sufficiency depends on whether it proves the implemented condition. There is no universal rule demanding two different methods for every objective.
Worked scope example
A machine shop receives a nonpublic purchase order and delivery schedule but no CUI. The office file server stores the FCI; employees access it from managed laptops; an identity provider authenticates them; a firewall protects the connection; and a managed provider administers those security services. The scope must cover the FCI systems and the protection supplied by the identity provider, firewall, administrator access, and relevant facilities. An isolated public kiosk with no FCI and no protective function may be outside the scope if separation is demonstrated.
Assessors or self-assessment personnel should follow the data and protection path rather than equating “FCI” with one file share. Email, backups, tickets, logs, mobile devices, printouts, and provider consoles can expand the actual scope.
Exam traps
Choose 15, not 17. Choose annual self-assessment, not triennial C3PAO. Choose no POA&M, not conditional status. Assign the affirmation to the organization's Affirming Official, not a CCP, CCA, or contracting officer. Finally, do not call CUI “enhanced FCI”; the categories have different authorities and drive different CMMC levels.
An organization meets 14 of 15 Level 1 requirements. What status can it claim?
Which assessment type applies to Level 1?
Which statement correctly distinguishes current from legacy material?