Confidential — Internal Use Only

CMMC Level 1 — At a Glance

Enterprise Security Maturity Program · Protecting Federal Contract Information (FCI)

17practices
6domains
110SPRS target

What it is: CMMC Level 1 protects Federal Contract Information (FCI) — basic business data shared under DoD contracts (schedules, invoices, logistics). It requires 17 security practices across 6 domains, self-assessed annually and submitted to SPRS. The Senior Official (CEO/Owner) personally affirms compliance — a legal attestation.

The 17 Practices

AC Access Control (4)
  • AC.1.001 Limit access to authorized users
  • AC.1.002 Limit to authorized transactions
  • AC.1.003 Control external connections
  • AC.1.004 Control FCI on public systems
IA Identification & Auth (2)
  • IA.1.076 Identify users & processes
  • IA.1.077 Authenticate before access
MP Media Protection (1)
  • MP.1.118 Sanitize/destroy media before reuse
PE Physical Protection (4)
  • PE.1.131 Limit physical access
  • PE.1.132 Escort & monitor visitors
  • PE.1.133 Log physical access
  • PE.1.134 Manage access devices
SC System & Comms (2)
  • SC.1.175 Protect comms at boundaries
  • SC.1.176 Subnet public-facing systems
SI System Integrity (4)
  • SI.1.210 Identify & correct flaws
  • SI.1.211 Malicious code protection (AV/EDR)
  • SI.1.212 Periodic & real-time scans
  • SI.1.213 Update protection mechanisms

~8–10 Week Timeline (~66–96 hrs)

PHASE 1Foundation — MFA, Conditional Access, admin hardening, audit loggingWk 1–3
PHASE 2Email & Data — Defender, anti-phishing, DLP, SharePoint lockdownWk 3–4
PHASE 3Endpoints — Intune, compliance, BitLocker, patchingWk 5–7
PHASE 4Evidence & Attestation — SSP, screenshots, SPRSWk 8–9

Evidence Repository

  • Recommended: dedicated, private GCC SharePoint site (M365 Business Premium) — role-based access, audit logs, version history.
  • Folders: 00_Governance · 01_AC · 02_IA · 03_MP · 04_PE · 05_SC · 06_SI · 07_Annual-Assessment.
  • Avoid: personal Dropbox, non-GCC OneDrive, local shared drives — fail access-control & audit requirements.

FCI vs. CUI / ITAR

  • FCI (Level 1): commercial M365 is fine. No GCC High needed.
  • CUI / ITAR (Level 2+): different program — GCC High, stricter controls, legal review.
Definition of done: all 17 MET + evidence uploaded + SSP signed + Senior Official submits in SPRS (target 110) + annual reassessment date booked.