CMMC Level 1 (Self): what a subcontractor handling FCI only declares
Level 1 covers Federal contract information. 32 CFR 170.14(c)(2) sets its requirements as those of FAR 52.204-21(b)(1)(i) through (xv): fifteen requirements. They are set out below as seventeen practice codes because (b)(1)(ix), which asks for three things (escort visitors and monitor visitor activity, keep physical access logs, control and manage physical access devices), carries three codes, PE.L1-3.10.3, PE.L1-3.10.4 and PE.L1-3.10.5; every other paragraph carries one. A subcontractor that will only process, store or transmit FCI needs Level 1 (Self) (32 CFR 170.23(a)(1)). The self-assessment is annual, an affirmation follows it every year, and no POA&M is permitted.
The rule sentences
5 cited32 CFR 170.23(a)(1)codified text, eCFR current to 24 Sep 2026If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor.
32 CFR 170.15(a)(1)codified text, eCFR current to 24 Sep 2026To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.
DFARS 252.204-7021, "current" (2)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Not older than 1 year for Final Level 1 (Self), with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.
32 CFR 170.21(a)(1)codified text, eCFR current to 24 Sep 2026A POA&M is not permitted at any time for Level 1 self-assessments.
The fifteen requirements as seventeen practice codes
FAR 52.204-21(b)(1)(i) to (xv)CMMC L1 AC.L1-3.1.1Authorized Access ControlCMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.1: Authorized Access Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(i) (3.1.1).
CMMC L1 AC.L1-3.1.2Transaction and Function ControlCMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.2: Transaction and Function Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ii) (3.1.2).
CMMC L1 AC.L1-3.1.20External ConnectionsCMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.20: External Connections - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iii) (3.1.20).
CMMC L1 AC.L1-3.1.22Control Public InformationCMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.22: Control Public Information - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iv) (3.1.22).
CMMC L1 IA.L1-3.5.1IdentificationCMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.1: Identification - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(v) (3.5.1).
CMMC L1 IA.L1-3.5.2AuthenticationCMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.2: Authentication - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vi) (3.5.2).
CMMC L1 MP.L1-3.8.3Media DisposalCMMC 2.0 Level 1 (Foundational) practice MP.L1-3.8.3: Media Disposal - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vii) (3.8.3).
CMMC L1 PE.L1-3.10.1Limit Physical AccessCMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.1: Limit Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(viii) (3.10.1).
CMMC L1 PE.L1-3.10.3Escort VisitorsCMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.3: Escort Visitors - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.3).
CMMC L1 PE.L1-3.10.4Physical Access LogsCMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.4: Physical Access Logs - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.4).
CMMC L1 PE.L1-3.10.5Manage Physical AccessCMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.5: Manage Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.5).
CMMC L1 SC.L1-3.13.1Boundary ProtectionCMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.1: Boundary Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(x) (3.13.1).
CMMC L1 SC.L1-3.13.5Public-Access System SeparationCMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.5: Public-Access System Separation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xi) (3.13.5).
CMMC L1 SI.L1-3.14.1Flaw RemediationCMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.1: Flaw Remediation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xii) (3.14.1).
CMMC L1 SI.L1-3.14.2Malicious Code ProtectionCMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.2: Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiii) (3.14.2).
CMMC L1 SI.L1-3.14.4Update Malicious Code ProtectionCMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.4: Update Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiv) (3.14.4).
CMMC L1 SI.L1-3.14.5System and File ScanningCMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.5: System and File Scanning - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xv) (3.14.5).
Confirm which deviation your contracting officer's agency has adopted. The register records what a subcontractor declares; it does not look anything up in SPRS.