top of page

CMMC Level 1 Requirements: All 15 Explained in Plain English

  • Writer: Shay
    Shay
  • Aug 14
  • 15 min read

In my last article, I talked about a landscaping client who unexpectedly ran into CMMC while working on a bid. They were asked whether their company was CMMC Level 1, Level 2 or Level 3, and they had no idea how to answer the question.

Once a small business figures out that CMMC Level 1 may apply, the next question is usually pretty straightforward.

What do I actually have to do?


CMMC Level 1 has 15 cybersecurity requirements. On paper, that sounds manageable, especially when you compare it with the 110 requirements associated with CMMC Level 2.

The number alone does not tell the whole story.


You need to understand what each requirement means inside your business, determine whether you are actually meeting it, and have evidence to support your answer.

For a small company with five or ten employees, this does not necessarily mean building an expensive or complicated IT environment. In many cases, some of the protections may already be there.

The first step is finding out.


In this article, I am going to walk through all 15 CMMC Level 1 requirements in plain language and explain what I would look for inside an ordinary small business.


Is CMMC Level 1 really only 15 requirements?

Yes. CMMC Level 1 is based on the 15 basic safeguarding requirements found in FAR 52.204-21.

You may find older CMMC articles online that refer to 17 Level 1 practices. Those articles are generally referring to an earlier version of the CMMC program.


You may also come across information about 110 requirements. Those are associated with CMMC Level 2 and NIST SP 800-171, not Level 1.

That distinction matters. If your contract requires CMMC Level 1, I would not want you spending money trying to solve Level 2 problems that do not apply to the work you are pursuing.

At the same time, "only 15 requirements" should not be interpreted as "answer 15 questions and you are finished."

Your company needs to determine whether those requirements are actually being met in the environment that processes, stores or transmits Federal Contract Information, commonly called FCI.


Here is what those requirements look like when we take away some of the government language.

1. Only authorized people and devices should have access

The first requirement deals with limiting access to authorized users, processes and devices.

For a small business, I would start with something very practical: who can get into your systems?


Suppose your company has eight employees. Each person has a company laptop and Microsoft 365 account, but there is also a shared office login that several employees know. Two old employee accounts are still active because nobody ever removed them.

That is where I would start asking questions.


Every person who can access the environment should have a reason to be there. When somebody leaves the company, their access should be removed. Devices that connect to the environment also need to be considered.


I would rather be able to identify exactly who and what has access than discover an old account six months after an employee left.


2. Authorized users should only be able to do what their jobs require

Giving someone access does not mean they should be able to do everything.

This requirement is about limiting the functions an authorized user can perform.

One of the most common examples I see in small businesses is administrative access.


An employee may need to use Microsoft 365, open company files and run the software required for their job. That does not necessarily mean the employee needs administrator rights on the computer or administrative access to Microsoft 365.

The owner of a five-person business may tell me, "Everyone is an administrator because it makes things easier."


It probably does make certain things easier. It also gives every one of those accounts considerably more control than may be necessary.

I would look at what employees actually need to do and assign access accordingly.


3. Control connections to outside systems

Small businesses connect to outside systems constantly.

Employees work from home. Files are uploaded to cloud services. Vendors remotely access computers. Someone plugs in a USB drive. An employee may use a personal laptop when the company computer is unavailable.


This requirement is asking the company to control those kinds of external connections.

Imagine an employee receives FCI through the company's approved environment but decides to copy it to a personal Google Drive account so they can finish something from home.

The company may have excellent security on its own systems, but the information has now moved somewhere else.


When I evaluate this area, I want to understand how employees work in the real world, not just what the written policy says they are supposed to do.


4. Control what gets posted to publicly accessible systems

This requirement can be easy to overlook.

A publicly accessible system could include your company website or another location where information is available to people outside the business.

Suppose an employee is updating the company's website and uploads a document related to a government project. Maybe the employee assumes the document is harmless because it does not contain anything that looks secret.


FCI is not classified information. That does not mean it is intended for public release.

A company handling FCI needs a way to prevent information that should remain protected from being posted publicly.


For a small company, that may include limiting who can publish information and making sure those employees understand what they should not post.


5. Know who or what is accessing your systems

This requirement is about identification.

If several people use the same username, it becomes difficult to know who actually performed an action.


I prefer individual user accounts for exactly this reason. If Mary signs into her computer and Microsoft 365 with an account assigned to Mary, I can identify the user. If Mary, John and the office manager all use an account called "Office," that becomes much less useful.

Devices and processes can also need identification depending on the environment.

For a small business, good account management goes a long way toward making this requirement understandable and manageable.


6. Verify identities before allowing access

Identifying a user is one part of access. Verifying that the person really is that user is another.

That is authentication.

The most familiar example is a password, although modern business environments increasingly use additional methods such as multifactor authentication.

If an employee signs into Microsoft 365 with an email address and password, the system is using those credentials to verify the person's identity.


This is where password practices matter. A password written on a sticky note under the keyboard defeats a lot of the value of having an individual account. The same is true when several employees know one another's passwords.


I would look at how users authenticate to the systems in scope and whether those methods provide reasonable assurance that the person signing in is actually who they claim to be.


7. Securely erase or destroy media containing FCI before getting rid of it

This is one of my favorite requirements to explain because almost every business owner immediately understands the example.Your company replaces an old laptop.

The laptop still works, so rather than throwing it away, you give it to an employee to take home.

What happened to the information on the hard drive?

If that computer contained FCI, simply deleting a folder or emptying the Recycle Bin is not the same thing as properly sanitizing the media.


The same issue can apply to old hard drives, USB drives and other storage media.

Before equipment containing FCI is disposed of or released for reuse, the information needs to be properly removed or the media needs to be destroyed.

This is as much about having a process as it is about having a particular piece of technology.


8. Limit physical access to systems and equipment

Cybersecurity is not limited to what happens over the internet. Physical access matters too.

Imagine that your office has a computer used to work with FCI, but it sits at the front desk where customers, delivery drivers and other visitors regularly walk through.


I would want to know how access to that computer is controlled.

The answer may involve the location of the equipment, locked doors, screen locking, who has keys and how the office handles areas where sensitive work is performed.

A small business does not necessarily need badges, turnstiles and security guards.

It does need to think about who can physically reach the systems and equipment that need protection.


9. Manage visitors and physical access

This requirement goes further into physical security.

Visitors should be escorted and their activity monitored where appropriate. The company also needs to maintain physical access records and control physical access devices.

The exact implementation is going to look different in a ten-person construction company than it does in a large defense facility.


For a small office, I would want to understand how visitors enter, which areas they can access and whether they can reach systems handling FCI.

Keys matter too. If an employee leaves the company but still has a key to the office, that is an access problem even if their Microsoft 365 account was disabled immediately.

Physical security and IT security overlap more often than people realize.


10. Protect information as it enters and leaves your network

This requirement deals with monitoring, controlling and protecting communications at external and important internal boundaries.The easiest place to start is usually the company's internet connection and firewall.


A business firewall helps control traffic entering and leaving the network. The configuration matters just as much as the hardware itself. I sometimes compare this to having a very good lock on the front door but leaving a side door open. Owning a business-grade firewall does not automatically mean the requirement is being met. I would want to know how it is configured, what services are exposed to the internet, whether remote access is being handled properly and what other network boundaries exist inside the environment.


11. Separate public-facing systems from the internal network

If your company operates systems that are accessible to the public, they should not simply sit inside the same internal network as everything else.

This requirement calls for publicly accessible system components to be placed in subnetworks that are physically or logically separated from internal networks.


For many small businesses, the company website is hosted by a third-party provider and is not sitting on a server in the office. That can make this requirement much less complicated.

The important part is understanding what you actually host. If your business does run a public-facing server or application, I would want to know where it lives and whether someone compromising that system could move directly into the internal environment where FCI is handled.


12. Find and fix system flaws in a timely manner

In everyday IT language, a big part of this requirement is patching and updates.

Software has vulnerabilities. Vendors release security updates to correct them.

The problem occurs when those updates never get installed. I have seen businesses with a computer that sits in the corner and only gets used once every few weeks. Nobody thinks much about it because it still turns on and runs the program they need.That computer may also be months behind on security updates.


For CMMC Level 1, I would want to understand how the company identifies problems and how updates and other necessary corrections are handled.

Windows updates are part of the conversation, but they are not necessarily the whole conversation. Applications, browsers, network equipment and other systems can also have vulnerabilities that need attention.


13. Protect systems from malicious code

This is the requirement most business owners associate with antivirus.

Yes, malware protection matters.


The question I care about is whether it is actually protecting the systems that need protection.


If a company tells me it has endpoint security on all ten computers, I want to verify that. I also want to know whether the protection is running correctly and whether anyone is paying attention when the security platform reports a problem. Finding out that nine computers are protected and one has not checked into the security console for four months is exactly the kind of thing an assessment should uncover. Having antivirus is the starting point. Managing it is what makes it useful.


14. Keep malware protection updated

Malware changes constantly, which is why security software also needs to stay current.

This requirement specifically addresses updating malicious-code protection when new releases are available.


In a managed environment, I should be able to see the status of the endpoints rather than walking from computer to computer and hoping each one updated itself.

This is another example of why I like centralized management for small businesses.

It gives me a way to verify what is happening across the environment.

If an endpoint stops receiving updates, I want to know about it rather than discover the problem during an annual assessment.


15. Scan systems and files for malware

The final Level 1 requirement addresses malware scanning.

The requirement includes periodic system scans along with real-time scanning of files from external sources when those files are downloaded, opened or executed.

Think about how many files enter an ordinary business every day.

Employees receive email attachments, download documents from websites, open files sent by customers and sometimes connect external media.

Malware protection should be checking those files rather than relying on an employee to recognize every malicious attachment that reaches them.

For this requirement, I would want to verify that the security software is configured to perform the necessary scanning and that the protection is actually operating on the systems in scope.


Do I need expensive new technology for all 15 requirements?

Not necessarily. This is one of the reasons I think a technical review should happen before a small business starts buying products for CMMC.


You may already have a business-grade firewall. Your Microsoft 365 environment may already have useful security capabilities. Your computers may already be centrally managed, and your endpoint protection may already provide the malware protection and reporting you need. If those things are properly configured, I want to document and use what you already have. On the other hand, an assessment may uncover something that genuinely needs to change.

Maybe employees share accounts. Perhaps former employees still have access. Your firewall may be outdated, or several computers may not be receiving security updates.

Those are problems I would want to fix.


I do not want a business owner to confuse buying more security products with meeting the requirements.


Do all 15 requirements apply to my entire company?

The requirements apply to the covered contractor information systems within the Level 1 assessment scope. That is why understanding where FCI goes is so important.

If FCI moves through your normal company email, employee laptops, cloud storage, backups and office network, those systems can become relevant to the scope.


In some situations, a company may be able to create a smaller enclave for the employees and systems that handle FCI. I covered enclaves in more detail in my previous CMMC Level 1 article because limiting scope can sometimes make sense for a small contractor.

The key is that the boundary has to match what actually happens to the information.

Calling three computers an "enclave" does not help if employees regularly copy the FCI somewhere outside those three computers.


How do I prove that I meet the requirements?

This is where evidence becomes important. If you say that a requirement is MET, there should be something supporting that conclusion.


For a technical requirement, that might be a configuration inside Microsoft 365, information from an endpoint-security platform, firewall settings, computer configurations or account records. Physical and procedural requirements can involve different evidence. I would not wait until the end of the project and then try to remember why we decided each requirement was MET.


As I work through an environment, I want to identify the evidence along the way. That gives the business a much clearer record of what was reviewed and what supports the assessment.


What happens if I do not meet one of the 15 requirements?

Fix it before completing the final Level 1 self-assessment. CMMC Level 1 does not permit a POA&M. That means you cannot leave a Level 1 requirement unfinished, put it on a list to fix later and still achieve Final Level 1 (Self) status. This is another reason I prefer identifying the gaps before a company is facing an immediate contract deadline.

If something needs to be corrected, there is time to understand the problem, implement the change and verify that it is working.


CMMC Level 1 Checklist: Are You Ready for the Self-Assessment?

Before you begin a Level 1 self-assessment, see how many of these questions you can answer confidently.

Can you identify the systems that process, store or transmit FCI?

Do you know every employee who can access those systems and why they need that access?

Do employees have individual accounts?

Do you have a reliable process for removing access when someone leaves?

Do you know which employees have administrative privileges?

Are company computers receiving security updates?

Can you verify that malware protection is installed, current and scanning properly?

Do you know how your firewall is configured?

Can visitors physically reach systems that handle FCI?

Do you know what happens to old computers and hard drives before they are reused, donated or disposed of?

Do employees ever move company information to personal computers, personal cloud storage or other systems you do not manage?

Do you know where your FCI is backed up?

Most importantly, can you produce evidence supporting the answers you give during the assessment?


If some of these questions are difficult to answer, that does not automatically mean your company needs an entirely new IT environment.

It tells us where we need to start looking.


How SNL-Tech Services can help with the 15 CMMC Level 1 requirements


SNL-Tech Services can work through the technical side of the Level 1 requirements with a small business and compare them against what is actually happening in the IT environment.

I can review Microsoft 365 or Google Workspace, employee computers, user accounts, endpoint security, firewalls, networking, remote access, system updates and the other technology involved in processing, storing or transmitting FCI.


Where something already meets the applicable requirement, I want to identify and document it rather than replace it simply because the company is preparing for CMMC.

If I find a technical gap, I can explain what the problem is and implement the changes needed to correct it.


There are also Level 1 requirements that extend beyond what happens inside Microsoft 365, a firewall or an employee's computer. Physical access, visitors and the way a company handles equipment are good examples.


I can help identify where those issues intersect with the technology, but the business still needs to look at its complete Level 1 environment rather than treating CMMC as an IT product.


The company remains responsible for its Level 1 self-assessment and affirmation.

My job on the technical side is to help make sure the answers are based on what is actually configured, identify the problems that need to be corrected and provide technical evidence supporting what is in place.


For a small contractor, I want that process to be understandable.

You should know why something needs to change before I recommend changing it.


CMMC Level 1 Requirements: Frequently Asked Questions


Are there 15 or 17 CMMC Level 1 requirements?

The current CMMC Level 1 uses 15 safeguarding requirements from FAR 52.204-21.

If you see an article referring to 17 Level 1 practices, check when it was written. It may be describing an earlier version of CMMC.


Do I need to meet all 15 CMMC Level 1 requirements?

Yes. All applicable Level 1 requirements must be MET to achieve Final Level 1 (Self) status.

CMMC Level 1 does not permit a POA&M for requirements that still need to be completed.


Do I need all 110 NIST SP 800-171 requirements for CMMC Level 1?

No. The 110 NIST SP 800-171 Rev. 2 requirements are associated with CMMC Level 2. Level 1 uses the 15 safeguarding requirements from FAR 52.204-21.

If your contract requires Level 1, make sure you understand the actual requirement before paying for a project designed around Level 2.


Does every computer in my company have to meet CMMC Level 1 requirements?

That depends on the assessment scope and where FCI is processed, stored or transmitted.

This is why I start by mapping where the information goes. If FCI is spread throughout the normal company environment, the scope can look very different from a business that keeps FCI inside a properly designed enclave.


What evidence do I need for a CMMC Level 1 self-assessment?

The evidence depends on the requirement. Technical evidence might come from user accounts, Microsoft 365 or Google Workspace configurations, endpoint-security platforms, firewall settings, computer configurations and other systems involved in the environment.

Other requirements may involve physical or procedural evidence.


The important point is that a MET answer should be supported by what is actually happening in the business.


Can my IT provider help me with CMMC Level 1?

Yes. A third party can assist a company with its Level 1 self-assessment and preparation.

The company itself remains responsible for the assessment results and affirmation.

An IT provider can be particularly useful when you need to determine whether technical controls are actually configured rather than simply confirming that a particular product has been purchased.


Can I use a POA&M for CMMC Level 1?

No. CMMC Level 1 does not allow POA&Ms. If a requirement is not MET, the issue needs to be corrected before achieving Final Level 1 (Self) status.


Where should a small business start?

Start by determining whether CMMC Level 1 applies to the contract you are pursuing and whether your company will handle FCI. Then identify where that information will go.

Once I know which employees, computers, cloud services, network equipment and other systems are involved, I can begin comparing that environment against the 15 requirements.

You may already have much more in place than you realize. The important part is finding that out before you start buying things.


Official CMMC Level 1 Resources

If you would like to read the actual government requirements behind CMMC Level 1, I recommend starting with these two official resources.

This is the federal regulation that lists the 15 basic safeguarding requirements that CMMC Level 1 is built around.

The CMMC Level 1 Assessment Guide goes further than simply listing the requirements. It explains the assessment process and provides guidance for evaluating each of the 15 requirements.


I have explained the requirements in plain language throughout this article, but when you are making compliance decisions for your business or responding to requirements in a government contract, I always recommend going back to the official government sources.


This article provides general educational information and is not legal advice, a CMMC certification, or a determination of the requirements that apply to a particular contract.

Comments


bottom of page