CMMC Level 1 Requirements

CMMC has gone through several revisions over the past few years, and each update has created uncertainty for DoD contractors trying to understand CMMC Level 1 requirements. Level 1 remains intentionally streamlined, focusing on protecting Federal Contract Information (FCI), and is built on the 15 basic safeguarding requirements in FAR 52.204-21 — commonly represented as 17 CMMC Level 1 practices grouped into six domains for assessment purposes. These practices represent foundational cyber hygiene, not advanced security engineering. For most small organizations, Level 1 is achievable — and the Microsoft 365 tools they already use can support much of that work.

At Abel Solutions, we help small contractors interpret Level 1 requirements, map them to the Microsoft 365 tools they already own, and implement the safeguards that keep FCI protected. This guide breaks Level 1 into clear, manageable sections so you can move forward with confidence.

Why CMMC Level 1 Still Matters After Recent Changes

CMMC has evolved significantly since its introduction, and many contractors have watched the changes closely. Requirements shifted, timelines moved, and guidance changed. But throughout these updates, CMMC Level 1 requirements have remained consistent in their purpose: ensuring that organizations handling FCI follow basic cybersecurity practices. The DoD wants contractors to demonstrate that they can protect contract information from unauthorized access, accidental exposure, or simple mistakes.

The most recent change is the largest: on July 13, 2026, the Department of Defense suspended CMMC Phase 2 — the third-party (C3PAO) assessment milestone previously set for November 10, 2026 — and opened a 60-day program review. What did not change matters more here: Phase 1 obligations remain in place, including the annual Level 1 self-assessment and affirmation, and FAR 52.204-21 predates CMMC and applies wherever it appears in a contract. CMMC itself is formalized under 32 CFR Part 170, the Program’s governing rule.If you handle FCI, this work is still required.

Level 1 is intentionally accessible. It does not require a third‑party (C3PAO) assessment overseen by the Cyber AB, the CMMC Accreditation Body, or advanced tooling, but it does require a defensible self-assessment, supporting evidence, submission in SPRS, and an annual affirmation. The work is to understand the 17 practices, implement them, and self-assess annually. This structure makes Level 1 ideal for small contractors who need to meet DoD expectations without building a full security program from scratch.

The most important takeaway is this: Level 1 is achievable, and Microsoft 365 can support much of the work — alongside the people, processes, and physical practices it cannot replace.

Understanding the Six Domains of CMMC Level 1 Requirements

The 17 practices are grouped into six domains. Organizing them by domain helps contractors understand how the practices relate to each other and how they support the broader goal of protecting FCI. One step comes first, though: identify where FCI is processed, stored, or transmitted. That scope defines what your self-assessment covers. Below, we explore each domain in detail and how it maps to CMMC Level 1 requirements.

1. Access Control (AC)

Access Control ensures that only authorized individuals can access FCI. This domain focuses on limiting access based on job roles, responsibilities, and legitimate business needs. For small contractors, this often means reviewing who has access to shared drives, contract folders, email accounts, and collaboration spaces.

Level 1 Access Control includes:

  • Limiting access to authorized users
  • Ensuring users only access what they need
  • Controlling access based on job roles
  • Controlling connections to external information systems
  • Preventing FCI from being posted or processed on publicly accessible systems

These practices help prevent accidental exposure and reduce the risk of unauthorized access.

Microsoft 365 supports Access Control through several built‑in features. Conditional Access allows organizations to restrict access based on location, device compliance, or risk level. SharePoint and OneDrive permissions make it easy to ensure that only authorized users can access contract‑related files. Teams channel permissions help segment conversations and collaboration, and Microsoft Entra ID (formerly Azure AD) security groups simplify role‑based access management. These tools make Access Control practical — paired with a process for approving, reviewing, and removing access as roles change.

2. Identification & Authentication (IA)

Identification & Authentication ensures that users are who they claim to be. This domain focuses on verifying identity, enforcing secure authentication methods, and preventing unauthorized access. For small contractors, this often means strengthening password policies and enabling multi‑factor authentication (MFA).

Level 1 IA includes:

  • Uniquely identifying users, processes, and devices
  • Authenticating identities before access is granted

Strong authentication is one of the most effective ways to protect FCI.

Microsoft 365 provides robust support for this domain. Multi‑Factor Authentication (MFA) is not named in the Level 1 requirements, but it is one of the strongest implementation choices available and significantly reduces unauthorized access risk. Microsoft Entra ID supports unique user identities and password policy enforcement. Sign‑in logs help organizations verify authentication activity and identify suspicious behavior.

3. Media Protection (MP)

Media Protection focuses on safeguarding FCI stored on removable media or portable devices. This domain is especially important for small contractors who may rely on laptops, USB drives, or external storage devices. At Level 1, the core requirement is narrower than many expect: sanitize or destroy media containing FCI before disposal or release for reuse.

Level 1 MP includes:

  • Sanitizing or destroying media containing FCI before disposal
  • Sanitizing or destroying media before it is released for reuse
  • Reducing unnecessary use of removable storage

These practices help prevent accidental exposure and reduce the risk of data loss. The simplest approach is to minimize the use of removable media altogether. When media containing FCI reaches end of life, have a process for wiping or destroying it and documenting the disposal.

Microsoft 365 supports Media Protection by reducing the need for removable storage. OneDrive and SharePoint provide secure cloud‑based storage, making it easy to keep FCI off local drives and USB devices. Intune device policies can block USB storage or restrict data transfer. And Data Loss Prevention (DLP) policies, where licensing allows, can reduce accidental sharing. These tools help organizations protect FCI without relying on physical media.

4. Physical Protection (PE)

Physical Protection ensures that only authorized individuals can physically access systems that store or process FCI. This domain focuses on securing facilities, controlling visitor access, and maintaining physical safeguards. For small contractors, this often means reviewing office access, securing laptops, and ensuring that contract information is not left unattended.

Level 1 PE includes:

  • Limiting physical access to systems
  • Escorting visitors when necessary
  • Maintaining audit logs of physical access
  • Controlling and managing physical access devices, such as keys and badges

Microsoft 365 does not replace physical security practices, but it reduces what is at stake physically by limiting reliance on local storage. Cloud‑based storage means less FCI stored on physical devices. Intune device compliance ensures that only approved devices can access FCI. And BitLocker encryption protects laptops if they are lost or stolen. Contractors still need facility access practices, visitor escorts, physical access logs, and control of keys and badges.

5. System & Communications Protection (SC)

System & Communications Protection ensures that systems and communications are protected from unauthorized access or exposure. This domain focuses on monitoring communications, protecting system boundaries, and implementing basic safeguards for data transmission.

Level 1 SC includes:

  • Monitoring, controlling, and protecting communications at external and key internal boundaries
  • Protecting system boundaries
  • Safeguarding data transmission
  • Separating publicly accessible system components from internal networks

Microsoft 365 provides strong support for this domain. TLS encryption protects data in transit. Exchange Online protection filters malicious email. Teams and SharePoint encryption protect collaboration. And Defender for Office 365 (basic features) helps block unsafe attachments and links. These tools protect email and collaboration traffic; Level 1 also reaches beyond the tenant — firewalls, network boundaries, and public-facing sites connected to FCI systems deserve the same attention.

6. System & Information Integrity (SI)

System & Information Integrity focuses on identifying and addressing security issues quickly. This domain requires organizations to identify system flaws, protect systems from malicious code, and perform basic system monitoring.

Level 1 SI includes:

  • Identifying, reporting, and correcting system flaws
  • Protecting systems from malicious code
  • Keeping malicious code protection updated and performing periodic and real-time scans

Microsoft 365 supports this domain through several built‑in features. Microsoft Defender Antivirus provides baseline protection. Defender for Office 365 blocks phishing and malware. Secure Score highlights gaps and recommended improvements. And audit logs help track suspicious activity. These tools support the requirements — paired with a patching process and evidence that updates and scans actually happen.

Preparing for the Annual Self‑Assessment

CMMC Level 1 requirements include an annual self‑assessment. This process is straightforward and designed to help organizations verify that they meet the 17 practices. To achieve Final Level 1 (Self), every applicable requirement must be MET — POA&Ms (plans to fix gaps later) are not permitted at Level 1. The self‑assessment requires organizations to:

  • Identify where FCI is processed, stored, or transmitted, and define the assessment scope
  • Review each practice
  • Confirm that they follow it
  • Document their results and retain evidence – Level 1 artifacts must be kept for six years
  • Submit the results in SPRS (the Supplier Performance Risk System) and complete the annual affirmation, signed by a senior company official

We help clients prepare for this process by mapping each practice to their Microsoft 365 environment, identifying gaps, and providing guidance on how to address them. Our goal is to make the self‑assessment process clear, manageable, and repeatable.

Two More Things to Know

First, there are flow-down requirements. FAR 52.204-21’s substance must be included in subcontracts where FCI may reside in or transit through a subcontractor’s system. If you are the subcontractor, this is often how the requirement reaches you.

Second, the FCI/CUI boundary is central to CMMC Level 1 requirements for organizations handling FCI only. If your work involves Controlled Unclassified Information (CUI), Level 2 requirements may apply — assessed against NIST SP 800-171 Rev 2, the version currently used for CMMC assessments even though NIST has since published Rev 3 — and Level 1 is not the ceiling. Which one you handle is the first scoping question worth answering.

Move Toward Level 1 with Confidence

CMMC Level 1 requirements apply when a DoD solicitation or contract requires it for systems that process, store, or transmit Federal Contract Information, and they don’t have to be complicated. With the right guidance, you can meet the requirements with the Microsoft 365 platform you already rely on and the practical processes around it. We help small DoD contractors understand Level 1, implement the necessary safeguards, and prepare for annual self‑assessments. If you’d like to know where you stand, a short scoping conversation is the right first step — our CMMC consulting services team can help you identify where FCI lives, what your self-assessment must cover, and what to fix before you affirm.

STAY INFORMED, STAY INSPIRED!

  • This field is for validation purposes and should be left unchanged.
  • Use the form below to sign up for Microsoft 365 emails and receive industry-leading insights directly in your inbox.

READY TO GET STARTED?

CONTACT US TODAY!

Fill out the form below and within one business day a member of our team will reach out to schedule a call to learn more about your needs.

  • This field is for validation purposes and should be left unchanged.
  • Protected by reCAPTCHA. Google Privacy Policy and >Terms of Service apply.

Scroll to Top