What it is: CMMC Level 1 protects Federal Contract Information (FCI) — basic business data shared under DoD contracts (schedules, invoices, logistics). It requires 17 security practices across 6 domains, self-assessed annually and submitted to SPRS . The Senior Official (CEO/Owner) personally affirms compliance — a legal attestation.
The 17 Practices
AC Access Control (4)
AC.1.001 Limit access to authorized users
AC.1.002 Limit to authorized transactions
AC.1.003 Control external connections
AC.1.004 Control FCI on public systems
IA Identification & Auth (2)
IA.1.076 Identify users & processes
IA.1.077 Authenticate before access
MP Media Protection (1)
MP.1.118 Sanitize/destroy media before reuse
PE Physical Protection (4)
PE.1.131 Limit physical access
PE.1.132 Escort & monitor visitors
PE.1.133 Log physical access
PE.1.134 Manage access devices
SC System & Comms (2)
SC.1.175 Protect comms at boundaries
SC.1.176 Subnet public-facing systems
SI System Integrity (4)
SI.1.210 Identify & correct flaws
SI.1.211 Malicious code protection (AV/EDR)
SI.1.212 Periodic & real-time scans
SI.1.213 Update protection mechanisms
~8–10 Week Timeline (~66–96 hrs)
PHASE 1 Foundation — MFA, Conditional Access, admin hardening, audit logging Wk 1–3
PHASE 2 Email & Data — Defender, anti-phishing, DLP, SharePoint lockdown Wk 3–4
PHASE 3 Endpoints — Intune, compliance, BitLocker, patching Wk 5–7
PHASE 4 Evidence & Attestation — SSP, screenshots, SPRS Wk 8–9
Evidence Repository
Recommended: dedicated, private GCC SharePoint site (M365 Business Premium) — role-based access, audit logs, version history.
Folders: 00_Governance · 01_AC · 02_IA · 03_MP · 04_PE · 05_SC · 06_SI · 07_Annual-Assessment.
Avoid: personal Dropbox, non-GCC OneDrive, local shared drives — fail access-control & audit requirements.
FCI vs. CUI / ITAR
FCI (Level 1): commercial M365 is fine. No GCC High needed.
CUI / ITAR (Level 2+): different program — GCC High, stricter controls, legal review.
Definition of done: all 17 MET + evidence uploaded + SSP signed + Senior Official submits in SPRS (target 110) + annual reassessment date booked.
Enterprise Security Maturity Program · CMMC Level 1 Kickoff · June 26, 2026
Confidential — For authorized personnel only.